IP Library › Granted Patent US 11,647,035
Granted Patent B2
US 11,647,035 · App. 17/021,801 · Granted May 9, 2023

Fidelity of anomaly alerts using control plane and data plane information

Inventors: Andrey Karpovsky (Haifa, IL); Roy Levin (Haifa, IL); Tomer Rotstein (Haifa, IL); Michael Makhlevich (Haifa, IL); Tamer Salman (Haifa, IL); Ram Haim Pliskin (Rishon Iezion, IL)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L63/1425G06N7/005G06N20/00H04L41/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,647,035
App. No.
17/021,801
Granted
May 9, 2023
Kind
B2
Abstract

An indication is received of a security alert. The indication is generated based on a detected anomaly in one of a data plane or a control plane of a computing environment. When the detected anomaly is in the data plane, the control plane is monitored for a subsequent anomaly in the control plane, and otherwise the data plane is monitored for a subsequent anomaly in the data plane. A correlation between the detected anomalies is determined. A notification of the security alert is sent when the correlation exceeds a predetermined threshold.

Claims (43)

1. A computing system comprising:

one or more processors; and

one or more computer-readable media having thereon computer-executable instructions that are structured such that, when executed by the one or more processors, cause the computing system to:

receive an indication of a security alert, the indication generated based on a detected anomaly in one of a data plane or a control plane of a computing environment;

when the detected anomaly is in the data plane, monitor the control plane for a subsequent anomaly in the control plane, and otherwise monitor the data plane for a subsequent anomaly in the data plane;

determine a first correlation between the detected anomaly and the subsequent anomaly in the control plane when the detected anomaly is in the data plane;

determine a second correlation between the detected anomaly and the subsequent anomaly in the data plane when the detected anomaly is in the control plane; and

send a notification of the security alert when the first correlation between the detected anomaly and the subsequent anomaly in the control plane or the second correlation between the detected anomaly and the subsequent anomaly in the data plane exceeds a predetermined threshold.

2. The computing system of claim 1 , wherein the indication is generated based on a detected anomaly in the data plane, and the detected anomaly is a new entity accessing a resource.

3. The computing system of claim 2 , wherein the new entity is an entity observed during a modeling period.

4. The computing system of claim 1 , wherein the indication is generated based on a detected anomaly in the control plane, and the detected anomaly is a user performing an anomalous pattern or amount of operations.

5. The computing system of claim 1 , wherein the first correlation and the second correlation are determined based on a similarity of a tuple comprising one or more of a resource, entity, or time-window.

6. The computing system of claim 5 , wherein the entity comprises one or more of a machine name, a username, an IP address, a process name, or a network identifier.

7. The computing system of claim 1 , wherein the anomaly is determined based on a detection model comprising evaluating mean and distance in standard deviations.

8. The computing system of claim 1 , further comprising computer-executable instructions that are structured such that, when executed by the one or more processors, cause the computing system to activate an active listening mode to monitor the control plane or the data plane.

9. The computing system of claim 1 , wherein the first correlation and the second correlation are determined by combining logs of data plane activity with logs of correlated control plane activity.

10. The computing system of claim 1 , further comprising computer-executable instructions that are structured such that, when executed by the one or more processors, cause the computing system to:

receive user feedback pertaining to notifications; and

input the user feedback as labels to a learning model for identifying security alerts.

11. The computing system of claim 1 , wherein data plane anomalies are determined based on an estimated probability model of an appearance of a new entity and control plane anomalies are determined using a score-based method for each user active at a resource.

12. A method for performing threat detection in a computing environment, the method comprising:

receiving, by a computing device, an indication of a security alert, the indication generated based on a detected anomaly in the computing environment, wherein the anomaly is detected in one of a data plane or a control plane of the computing environment;

determining a first correlation between the detected anomaly and a subsequent anomaly in the control plane when the detected anomaly is in the data plane;

determining a second correlation between the detected anomaly and a subsequent anomaly in the data plane when the detected anomaly is in the control plane; and

generating a security alert when the first correlation between the detected anomaly and the subsequent anomaly in the control plane or the second correlation between the detected anomaly and the subsequent anomaly in the data plane exceeds a predetermined threshold.

13. The method of claim 12 , wherein:

data plane anomalies are determined based on an estimated probability model of an appearance of a new entity; and

the appearance of the new entity is determined to constitute an anomaly when the estimated probability is below a predetermined threshold.

14. The method of claim 12 , wherein:

control plane anomalies are determined based on an anomaly model implemented using a score-based method for each user active at a resource as a time series signal; and

a high outlier of a score signifies a control plane anomaly.

15. The method of claim 12 , wherein the anomaly is detected in the data plane and the detected anomaly is a new entity accessing a resource.

16. The method of claim 12 , wherein the anomaly is detected in the control plane and the detected anomaly is a user performing an anomalous pattern or amount of operations.

17. The method of claim 12 , wherein the first correlation and the second correlation are determined based on a similarity of a tuple comprising one or more of a resource, entity, or time-window.

18. The method of claim 12 , further comprising activating an active listening mode to monitor the control plane or the data plane.

19. The method of claim 12 , further comprising:

receiving user feedback pertaining to notifications; and

inputting the user feedback as labels to a learning model for identifying security alerts.

20. A non-transitory computer program product comprising one or more computer-readable storage media having thereon computer-executable instructions that are structured such that, when executed by one or more processors of a computing system, cause the computing system to perform operations comprising:

receiving, by a computing device, an indication of a security alert, the indication generated based on a detected anomaly in a computing environment, wherein the anomaly is detected in one of a data plane or a control plane of the computing environment;

determining a first correlation between the detected anomaly and a subsequent anomaly in the control plane when the detected anomaly is in the data plane;

determining a second correlation between the detected anomaly and a subsequent anomaly in the data plane when the detected anomaly is in the control plane; and

generating a security alert when the first correlation between the detected anomaly and the subsequent anomaly in the control plane or the second correlation between the detected anomaly and the subsequent anomaly in the data plane exceeds a predetermined threshold.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: KARPOVSKY, ANDREY; LEVIN, ROY; ROTSTEIN, TOMER; MAKHLEVICH, MICHAEL; SALMAN, TAMER; PLISKIN, RAM HAIM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061291/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: KARPOVSKY, ANDREY; LEVIN, ROY; ROTSTEIN, TOMER; MAKHLEVICH, MICHAEL; SALMAN, TAMER; PLISKIN, RAM HAIM
To: MICROSOFT TECHNOLOGY LICENSING, LLC.
Reel/Frame 053779/0014 →
Continuity (1)
Related Publication 20220086180A1 · Mar 17, 2022
Cited By (1)
US 12,277,137