IP Library › Granted Patent US 12,010,127
Granted Patent B1
US 12,010,127 · App. 17/979,132 · Granted Jun 11, 2024

Cyberattack detection using probabilistic graphical models

Inventors: Nitzan Niv (Nesher, IL); Gad Naor (Tel Aviv, IL)
H04L63/1416G06F9/546G06N20/00G06Q30/0271H04L41/142H04L41/145H04L43/062H04L63/102H04L63/104H04L63/1425H04L63/1441H04L67/30H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,127
App. No.
17/979,132
Filed
Nov 2, 2022
Granted
Jun 11, 2024
Kind
B1
Art Unit
2447
USPC
726/23
Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.

Claims (43)

1. A method for detecting cyberattacks using audit logs, the method comprising:

using one or more processors to perform:

determining, based on first audit log data, a plurality of baseline profiles associated with operational activity within a cloud compute environment, wherein the plurality of baseline profiles is associated with a probabilistic graph, wherein the probabilistic graph comprises nodes and edges, wherein the nodes represent factors associated with respective probabilistic distributions and the edges represent probabilistic dependencies among the factors represented by the nodes;

updating the probabilistic graph based on second audit log data;

determining, based on third audit log data and on one or more probabilistic dependencies associated with the probabilistic graph, a number of deviations of operational activity;

determining, based on the number of deviations being greater than a threshold value, detection data indicative of a cyberattack; and

generating, based on the detection data, an alert indicative of the cyberattack.

2. The method of claim 1 , wherein the probabilistic graph comprises a Bayesian Belief Network.

3. The method of claim 1 , wherein the detection data is based on two or more combinations of profile deviations associated with the plurality of baseline profiles.

4. The method of claim 1 , wherein the detection data is indicative of one or more resources associated with the cyberattack.

5. The method of claim 1 , wherein the detection data is indicative of credential data associated with the cyberattack.

6. The method of claim 1 , further comprising:

determining, based on additional audit log data, one or more updates to the probabilistic graph.

7. The method of claim 1 , further comprising:

determining, based on suppressing additional detection data associated with additional anomalous behavior, one or more updates that result in the probabilistic graph to not be indicative of a cyberattack for operational activity similar to operational activity associated with the additional anomalous behavior.

8. The method of claim 1 , wherein updating the probabilistic graph comprises: adjusting the probabilistic distribution of at least one of the factors represented by the nodes based on a change in the probabilitistic distribution of at least one other factor represented by at least one node in the probabilistic graph and the probabilistic dependencies among the at least one factor and the at least one other factor as specified by the edges of the probabilistic graph.

9. A system comprising:

a memory storing executable instructions; and

one or more processors that execute the executable instructions to:

determine, based on first audit log data, a plurality of baseline profiles associated with operational activity within a cloud compute environment, wherein the plurality of baseline profiles is associated with a probabilistic graph, wherein the probabilistic graph comprises nodes and edges, wherein the nodes represent factors associated with respective probabilistic distributions and the edges represent probabilistic dependencies among the factors represented by the nodes;

update the probabilistic graph based on second audit log data;

determine, based on third audit log data and on one or more probabilistic dependencies associated with the probabilistic graph, a number of deviations of operational activity;

determine, based on the number of deviations being greater than a threshold value, detection data indicative of a cyberattack; and

generate, based on the detection data, an alert indicative of the cyberattack.

10. The system of claim 9 , wherein the probabilistic graph comprises a Bayesian Belief Network.

11. The system of claim 9 , wherein the detection data is based on two or more combinations of profile deviations associated with the plurality of baseline profiles.

12. The system of claim 9 , wherein the detection data is indicative of one or more resources associated with the cyberattack.

13. The system of claim 9 , wherein the detection data is indicative of credential data associated with the cyberattack.

14. The system of claim 9 , wherein the one or more processors further execute the executable instructions to:

determine, based on additional audit log data, one or more updates to the probabilistic graph.

15. The system of claim 9 , wherein updating the probabilistic graph comprises:

adjusting the probabilistic distribution of at least one of the factors represented by the nodes based on a change in the probabilistic distribution of at least one other factor represented by at least one node in the probabilistic graph and the probabilistic dependencies among the at least one factor and the at least one other factor as specified by the edges of the probabilistic graph.

16. One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause a computer system to:

determine, based on first audit log data, a plurality of baseline profiles associated with operational activity within a cloud compute environment, wherein the plurality of baseline profiles is associated with a probabilistic graph, wherein the probabilistic graph comprises nodes and edges, wherein the nodes represent factors associated with respective probabilistic distributions and the edges represent probabilistic dependencies among the factors represented by the nodes;

update the probabilistic graph based on second audit log data;

determine, based on third audit log data and on one or more probabilistic dependencies associated with the probabilistic graph, a number of deviations of operational activity;

determine, based on the number of deviations being greater than a threshold value, detection data indicative of a cyberattack; and

generate, based on the detection data, an alert indicative of the cyberattack.

17. The non-transitory computer-accessible storage media of claim 16 , wherein the probabilistic graph comprises a Bayesian Belief Network.

18. The non-transitory computer-accessible storage media of claim 16 , wherein the detection data is based on two or more combinations of profile deviations associated with the plurality of baseline profiles.

19. The non-transitory computer-accessible storage media of claim 16 , wherein the detection data is indicative of one or more resources associated with the cyberattack.

20. The non-transitory computer-accessible storage media of claim 16 , wherein updating the probabilistic graph comprises:

adjusting the probabilistic distribution of at least one of the factors represented by the nodes based on a change in the probabilistic distribution of at least one other factor represented by at least one node in the probabilistic graph and the probabilistic dependencies among the at least one factor and the at least one other factor as specified by the edges of the probabilistic graph.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2025
From: RAPID7 ISRAEL TECHNOLOGIES LTD.
To: INTSIGHTS CYBER INTELLIGENCE LTD.
Reel/Frame 072392/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2025
From: RAPID7, INC.
To: RAPID7 ISRAEL TECHNOLOGIES LTD.
Reel/Frame 069806/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: NIV, NITZAN; NAOR, GAD
To: RAPID7, INC.
Reel/Frame 061971/0095 →
Continuity (2)
Continuation In Part 17590221 · Feb 1, 2022
Continuation 16263322 · Jan 31, 2019
Cited By (4)
US 12,591,667 US 12,688,277 US 12,694,125 US 12,739,106