IP Library Granted Patent US 11,228,616
Granted Patent B2
US 11,228,616 · App. 16/211,762 · Granted Jan 18, 2022

Methods and systems for monitoring network security

Inventors: Khaled M. Khan (Jamisontown, AU); Dong Seong Kim (Christchurch, NZ); Jin Bum Hong (Christchurch, NZ); Simon Enoch Yusuf (Christchurch, NZ); Mengmeng Ge (Christchurch, NZ); Huy Kang Kim (Seoul, KR); Paul Kim (Christchurch, NZ); Armstrong Nhlabatsi (Hlathikhulu, SZ); Noora Fetais (Doha, QA)
Assignee: Qatar Foundation
H04L63/20G06F21/554H04L63/1408H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,228,616
App. No.
16/211,762
Granted
Jan 18, 2022
Kind
B2
Abstract

A computer-implemented method for monitoring the security of a computing network which includes a plurality of hosts and a plurality of edges which link connected hosts. The method comprises capturing and storing first and second network state information at first and second times respectively. The method comprises comparing the first and second network state information to detect a change in the security of the network during the time window between the first and second times. The method further comprises storing security change data which is indicative of the change in the security of the network during the time window for a user to monitor the change in the security of the network.

Claims (148)

1. A computer-implemented method for monitoring the security of a computing network, wherein the network comprises components which include a plurality of hosts and a plurality of edges which link connected hosts, and wherein the method comprises:

capturing first network state information at a first time;

storing the first network state information in a memory

capturing second network state information at a second time; and

storing the second network state information in the memory, wherein each of the first and second network state information comprises:

reachability information for at least one of the hosts, the reachability information being stored in an upper layer of a graphical security model (GSM); and

vulnerabilities information providing information about at least one vulnerability in at least one of the hosts or the edges, the vulnerabilities information being stored in a lower layer of the GSM;

wherein the method further comprises:

comparing, using a processing system, the first and second network state information;

detecting, using the processing system, a change in the security of the network during the time window between the first and second times;

storing, in the memory, security change data which is indicative of the change in the security of the network during the time window for a user to monitor the change in the security of the network; and

calculating a weight value for at least one of the components in the network, the weight value being indicative of the visibility of the component in the network over a predetermined period of time, wherein the weight value is calculated using the equation:

nc

j

α

=

(

OC

nc

j

NS

×

i

=

0

NS

t

(

nc

j

)

T

)

×

100.

2. The method of claim 1 , wherein the computing network is a dynamic network in which the configuration of at least one of the hosts or the edges changes over time.

3. The method of claim 2 , wherein the dynamic network is a network selected from a group including a cloud computing network, a software defined networking (SDN) arrangement or an Internet of Things (IoT) network.

4. The method of claim 1 , wherein the method further comprises:

capturing and storing network state information in response to at least one of a time-driven trigger, an event-driven trigger or a user-driven trigger.

5. The method of claim 1 , wherein detecting a change in the security of the network comprises detecting at least one of:

the addition of a new host to the network;

the removal of a host from the network;

the addition of a new edge to the network;

the removal of an edge from the network;

the addition of a vulnerability to a host in the network; or

the removal of a vulnerability from a host in the network.

6. The method of claim 1 , wherein the method further comprises:

calculating, using the processing system, at least one security metric for the network at the first time and at the second time.

7. The method of claim 1 , wherein the method further comprises:

constructing a 4-tuple, (U, L, C, w) based on the calculated weight value of a component that is less than or equal to a predetermined weight value threshold w, where U is the upper layer which models a set of hosts H and the set of hosts H reachability information and L is the lower layer (ATs) that models the set of vulnerabilities V for each host h i ∈ H respectively.

8. The method of claim 7 , wherein the method further comprises:

defining a mapping between the upper and lower layers as:

C ⊆{( h i ↔AT )}∀ h i ∈U, AT∈L

9. The method of claim 8 , wherein the method further comprises:

defining the upper layer as a 3-tuple (H, E, w), where H is a finite set of weighted hosts in the network where h i ∈ H and h i α ≤w, E⊆H×H is a set of weighted edges where e i ∈E and e i α ≤w, and w is the weight threshold value.

10. The method of claim 9 , wherein the method further comprises:

defining the lower layer as a 5-tuple (A, B, c, g, root), where A⊆V is a set of vulnerabilities, B={b 1 , b 2 , . . . } is a set of gates, c⊆{b j →e l }∀b j ∈B, e l ∈ A∪B is a mapping of gates to vulnerabilities and other gates, g⊆{b j →{AND,OR}} specifies the type of each gate, and root ∈A∪B is the root node of the AT.

11. A non-transitory computer readable medium storing executable instructions which, when executed by a processor of a computing system, cause the computing system to monitor the security of a computing network, wherein the network comprises components which include a plurality of hosts and a plurality of edges which link connected hosts, and wherein the monitoring comprises:

capturing first network state information at a first time;

storing the first network state information in a memory

capturing second network state information at a second time; and

storing the second network state information in the memory, wherein each of the first and second network state information comprises:

reachability information for at least one of the hosts, the reachability information being stored in an upper layer of a graphical security model (GSM); and

vulnerabilities information providing information about at least one vulnerability in at least one of the hosts or the edges, the vulnerabilities information being stored in a lower layer of the GSM;

wherein the method further comprises:

comparing, using a processing system, the first and second network state information;

detecting, using the processing system, a change in the security of the network during the time window between the first and second times;

storing, in the memory, security change data which is indicative of the change in the security of the network during the time window for a user to monitor the change in the security of the network; and

calculating a weight value for at least one of the components in the network, the weight value being indicative of the visibility of the component in the network over a predetermined period of time, wherein the weight value is calculated using the equation:

nc

j

α

=

(

OC

nc

j

NS

×

i

=

0

NS

t

(

nc

j

)

T

)

×

100.

12. A system for monitoring the security of a computing network, the network comprising components which include a plurality of hosts and a plurality of edges which link connected hosts, wherein the system comprises a processor and a memory, the memory storing executable instructions which, when executed by the processor, cause the system to monitor the security of the computing network by:

capturing first network state information at a first time;

storing the first network state information in a memory

capturing second network state information at a second time; and

storing the second network state information in the memory, wherein each of the first and second network state information comprises:

reachability information for at least one of the hosts, the reachability information being stored in an upper layer of a graphical security model (GSM); and

vulnerabilities information providing information about at least one vulnerability in at least one of the hosts or the edges, the vulnerabilities information being stored in a lower layer of the GSM;

wherein the method further comprises:

comparing, using a processing system, the first and second network state information;

detecting, using the processing system, a change in the security of the network during the time window between the first and second times;

storing, in the memory, security change data which is indicative of the change in the security of the network during the time window for a user to monitor the change in the security of the network; and

calculating a weight value for at least one of the components in the network, the weight value being indicative of the visibility of the component in the network over a predetermined period of time, wherein the weight value is calculated using the equation:

nc

j

α

=

(

OC

nc

j

NS

×

i

=

0

NS

t

(

nc

j

)

T

)

×

100.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: QATAR FOUNDATION
To: QATAR FOUNDATION; QATAR UNIVERSITY
Reel/Frame 065363/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: QATAR FOUNDATION
To: QATAR FOUNDATION; QATAR UNIVERSITY
Reel/Frame 062710/0976 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2019
From: KIM, DONG SEONG; KHAN, KHALED; NHLABATSI, ARMSTRONG; KIM, HUY KANG; HONG, JIN BUM; GE, MENGMENG; KIM, PAUL; YUSUF, SIMON ENOCH; FETAIS, NOORA
To: QATAR FOUNDATION
Reel/Frame 048551/0817 →
Continuity (2)
Provisional Application 62595307 · Dec 6, 2017
Related Publication 20190190955A1 · Jun 20, 2019
Cited By (1)
US 12,500,920