IP Library Granted Patent US 11,601,442
Granted Patent B2
US 11,601,442 · App. 16/544,401 · Granted Mar 7, 2023

System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using provenance tags and customizable policy

Inventors: Ramasubramanian Sekar (East Setauket, NY); Junao Wang (Centereach, NY); Md Nahid Hossain (Stony Brook, NY); Sadegh M. Milajerdi (Chicago, IL); Birhanu Eshete (Chicago, IL); Rigel Gjomemo (Chicago, IL); V. N. Venkatakrishnan (Chicago, IL); Scott Stoller (Setauket, NY)
Assignees: THE RESEARCH FOUNDATION FOR THE STATE UNIVERSITY OF NEW YORK; THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,442
App. No.
16/544,401
Granted
Mar 7, 2023
Kind
B2
Abstract

A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path. A corresponding method and computer-readable medium are also disclosed.

Claims (45)

1. A system for detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign in a victim system environment, the system comprising:

a memory configured to store instructions; and

a processing device coupled to the memory, the processing device executing a real-time attack scenario reconstruction application with the instructions stored in memory, wherein the application is configured to:

receive an audit data stream associated with cyber events;

identify trustworthiness values in a portion of data associated with the cyber events;

assign provenance tags to the portion of the data based on the identified trustworthiness values;

generate an initial visual representation based on the assigned provenance tags to the portion of the data;

condense the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and

generate a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path.

2. The system as recited in claim 1 , wherein the system is further configured to condense the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file.

3. The system as recited in claim 1 , wherein the system is further configured to generate a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths.

4. The system as recited in claim 1 , wherein the provenance tags further comprise trustworthiness tags.

5. The system as recited in claim 1 , wherein the provenance tags further comprise confidentiality tags assigned to the portion of the data based on identified confidentiality values.

6. The system as recited in claim 1 , wherein the portion of the data comprises one or more of objects and subjects.

7. The system as recited in claim 6 , wherein the objects are referenced within events using an index into a per-subject table of object identifiers.

8. The system as recited in claim 1 , wherein the provenance tags are further assigned to the portion of the data based on identified sensitivity values.

9. A method for detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign in a victim system environment, the method comprising:

a processing device coupled to a memory that stores instructions, the processing device executing a real-time attack scenario reconstruction application with the instructions stored in memory, wherein the application is configured to perform the following operations:

receiving an audit data stream associated with cyber events;

identifying trustworthiness values in a portion of data associated with the cyber events;

assigning provenance tags to the portion of the data based on the identified trustworthiness values;

generating an initial visual representation based on the assigned provenance tags to the portion of the data;

condensing the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and

generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path.

10. The method as recited in claim 9 , wherein the method further comprises condensing the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file.

11. The method as recited in claim 9 , wherein the method further comprises generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths.

12. The method as recited in claim 9 , wherein the provenance tags further comprise trustworthiness tags.

13. The method as recited in claim 9 , wherein the provenance tags further comprise confidentiality tags assigned to the portion of the data based on identified confidentiality values.

14. The method as recited in claim 9 , wherein the portion of the data comprises one or more of objects and subjects.

15. The method as recited in claim 14 , wherein the objects are referenced within events using an index into a per-subject table of object identifiers.

16. The method as recited in claim 9 , wherein the provenance tags are further assigned to the portion of the data based on identified sensitivity values.

17. A non-transitory computer-readable medium storing instructions that, when executed by a real-time attack scenario reconstruction processing device, performs operations that include:

receiving an audit data stream associated with cyber events associated with a cyber-attack in a victim system environment;

identifying trustworthiness values in a portion of data associated with the cyber events;

assigning provenance tags to the portion of the data based on the identified trustworthiness values;

generating an initial visual representation based on the assigned provenance tags to the portion of the data;

condensing the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and

generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path.

18. The computer readable medium as recited in claim 17 , wherein the operations further comprise condensing the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file.

19. The computer readable medium as recited in claim 17 , wherein the operations further comprise generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths.

20. The computer readable medium as recited in claim 17 , wherein the provenance tags further comprise trustworthiness tags.

21. The computer readable medium as recited in claim 17 , wherein the provenance tags further comprise confidentiality tags assigned to the portion of the data based on identified confidentiality values.

22. The computer readable medium as recited in claim 17 , wherein the portion of the data comprises one or more of objects and subjects.

23. The computer readable medium as recited in claim 22 , wherein the objects are referenced within events using an index into a per-subject table of object identifiers.

24. The computer readable medium as recited in claim 17 , wherein the provenance tags are further assigned to the portion of the data based on identified sensitivity values.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: SEKAR, RAMASUBRAMANIAN; WANG, JUNAO; HOSSAIN, MD NAHID; STOLLER, SCOTT
To: THE RESEARCH FOUNDATION FOR THE STATE UNIVERSITY OF NEW YORK
Reel/Frame 062594/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: VENKATAKRISHNAN, V.N.
To: THE BOARD OF TRUSTEES OF THE UNIVERSITY OF ILLINOIS
Reel/Frame 062605/0860 →
Continuity (2)
Provisional Application 62719197 · Aug 17, 2018
Related Publication 20200059481A1 · Feb 20, 2020
Cited By (2)
US 12,445,466 US 12,505,565