IP Library › Granted Patent US 12,045,152
Granted Patent B2
US 12,045,152 · App. 17/506,544 · Granted Jul 23, 2024

Prevention of malicious end point behavior through stateful rules

Inventors: Ross David Wolf (Denver, CO); Nicholas Charles Berlin (Eldersburg, MD); Brian Douglas McKinney (San Antonio, TX)
Assignee: Elasticsearch B.V.
G06F11/3072G06F9/5022G06F9/542G06F21/577G06F2201/835G06F2201/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,045,152
App. No.
17/506,544
Granted
Jul 23, 2024
Kind
B2
Abstract

Provided are methods and systems for preventing malicious behavior of an end point. An example method commences with monitoring a stream of events associated with the end point. The method further includes processing the stream to record a set of events to a memory. Processing an event of the stream includes determining that the event satisfies at least one rule in a sequence of rules and, in response to the determination, adding the event to the set of events in the memory. The method further includes determining that the set of events includes a sequence of events. Each state in the sequence of events corresponds to at least one rule in the sequence of rules. The method continues with executing at least one action on the end point in response to the determination that the set of events includes the sequence of events.

Claims (56)

1. A method for preventing malicious behavior of an end point, the method comprising, in real time:

monitoring a stream of events associated with the end point;

processing the stream to record a set of events to a memory, wherein processing an event of the stream includes:

determining that the event satisfies at least one rule in a sequence of rules; and

in response to the determination, adding the event to the set of events in the memory;

determining that the set of events includes a sequence of events, each state in the sequence of events corresponding to at least one rule in the sequence of rules; and

in response to the determination, executing at least one action on the end point.

2. The method of claim 1 , wherein events in the sequence of events are ordered by timestamps corresponding to the events and an order of the events in the sequence of events corresponds to an order of rules in the sequence of rules.

3. The method of claim 1 , wherein the event includes one or more of the following: an attempt to access a computing system via a port, an indication of a process started on the end point, an indication of starting a new network connection to another computing system, and one of an opening, a creating, and a modifying a file on the end point.

4. The method of claim 1 , wherein the at least one action includes one or more of the following: shutting down a process on the end point, deleting a file on the end point, issuing an alert message, and generating a report based on the sequence of events.

5. The method of claim 1 , further comprising, prior to the processing the events, enriching the events with information concerning a process associated with the event.

6. The method of claim 1 , further comprising, prior to the executing the at least one action:

extracting fields from events in the sequence of events and further fields from rules in the sequence of rules; and

determining, based on the fields and the further fields, a type of the at least one action.

7. The method of claim 1 , further comprising:

determining that the set of events includes a first event and a second event, wherein the first event and the second event are same and correspond to different rules of the sequence of rules; and

in response to the determination, releasing a part of the memory allocated for the first event or the second event.

8. The method of claim 1 , further comprising:

determining that a size of a part of memory allocated for the set of events exceeds a predetermined threshold; and

in response to the determination, removing an oldest event in the set of events and releasing a portion of the memory allocated for the oldest state.

9. The method of claim 1 , further comprising:

determining that a size of a part of memory allocated for a subset of the set of events exceeds a predetermined threshold, wherein the subset includes events corresponding to the same rule of the sequence of rules; and

in response to the determination, removing an oldest event in the subset from the set of events and releasing a portion of the memory allocated for the oldest event.

10. The method of claim 1 , wherein the end point includes one of the following: a personal computer, a server, a network device, and an Internet-of-Things device.

11. A system for preventing malicious behavior of an end point, the system comprising:

at least one processor; and

a memory communicatively coupled to the processor, the memory storing instructions executable by the at least one processor to perform a method comprising:

monitoring, in real time, a stream of events associated with the end point;

processing the stream to record a set of events to a memory, wherein processing an event of the stream includes:

determining that the event satisfies at least one rule in a sequence of rules; and

in response to the determination, adding the event to the set of events in the memory;

determining that the set of events includes a sequence of events, each state in the sequence of events corresponding to at least one rule in the sequence of rules; and

in response to the determination, executing at least one action on the end point.

12. The system of claim 11 , wherein events in the sequence of events are ordered by timestamps corresponding to the events and an order of the events in the sequence of events corresponds to an order of rules in the sequence of rules.

13. The system of claim 11 , wherein the event includes one or more of the following: an attempt to access a computing system via a port, an indication of a process started on the end point, an indication of starting a new network connection to another computing system, and one of an opening, a creating, and a modifying of a file on the end point.

14. The system of claim 11 , wherein the at least one processor is further configured to scope the set of events through a maxspan field to determine whether the set of events occurs within a predetermined time span set in the maxspan field.

15. The system of claim 11 , wherein, prior to the processing the events, the at least one processor is configured to perform the following: enriching the events with information concerning a process associated with the event.

16. The system of claim 11 , wherein, prior to the executing the at least one action, the at least one processor is configured to perform the following:

extracting fields from events in the sequence of events and further fields from rules in the sequence of rules; and

determining, based on the fields and the further fields, a type of the at least one action.

17. The system of claim 11 , wherein the at least one processor is further configured to:

determine that the set of events includes a first event and a second event, wherein the first event and the second event are same and correspond to different rules of the sequence of rules; and

in response to the determination, release a part of the memory allocated for the first event or the second event.

18. The system of claim 11 , wherein the at least one processor is further configured to:

determine that a size of a part of memory allocated for the set of events exceeds a predetermined threshold; and

in response to the determination, remove an oldest event in the set of events and releasing a portion of the memory allocated for the oldest state.

19. The system of claim 11 , wherein the at least one processor is further configured to:

determine that a size of a part of memory allocated for a subset of the set of events exceeds a predetermined threshold, wherein the subset includes events corresponding to the same rule of the sequence of rules; and

in response to the determination, remove an oldest event in the subset from the set of events and releasing a portion of the memory allocated for the oldest event.

20. A non-transitory computer-readable storage medium having embodied thereon instructions, which when executed by at least one processor, perform steps of a method, the method comprising:

monitoring, in real time, a stream of events associated with an end point;

processing the stream to record a set of events to a memory, wherein processing an event of the stream includes:

determining that the event satisfies at least one rule in a sequence of rules; and

in response to the determination, adding the event to the set of events in the memory;

determining that the set of events includes a sequence of events, each state in the sequence of events corresponding to at least one rule in the sequence of rules; and

in response to the determination, executing at least one action on the end point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: WOLF, ROSS DAVID; BERLIN, NICHOLAS CHARLES; MCKINNEY, BRIAN DOUGLAS
To: ELASTICSEARCH B.V.
Reel/Frame 058765/0492 →
Continuity (1)
Related Publication 20230123509A1 · Apr 20, 2023