IP Library Granted Patent US 12,074,902
Granted Patent B2
US 12,074,902 · App. 18/337,785 · Granted Aug 27, 2024

System and method for cybersecurity threat monitoring using dynamically-updated semantic graphs

Inventors: Scott Eric Coull (Cary, NC); Jeffrey Thomas Johns (Leesburg, VA)
Assignee: GOOGLE LLC
H04L63/1433G06F16/9024H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,074,902
App. No.
18/337,785
Granted
Aug 27, 2024
Kind
B2
Abstract

A method for performing cyber-security analysis includes generating a semantic graph in which each object is represented as a node, and each event associated with an object is represented as an edge. A cyber-threat related alert, with an associated alert type, is received from a source. A first object from the plurality of objects is modified based on the alert. A plurality of threat scores, each associated with an object, are calculated, substantially concurrently, based on the alert type. Subsequently, a plurality of modified threat scores are determined for each object, based on: (1) the threat score for that object, (2) a connectivity of that object to each of the remaining objects within the semantic graph; and (3) the threat score for each remaining object from the plurality of objects. A subgraph of the semantic graph is identified based on normalized versions of the modified threat scores.

Claims (42)

1. A network traffic analysis method comprising:

storing, in a memory, a semantic graph associated with a plurality of monitored computer-based entities and a plurality of monitored relationships, the semantic graph including a plurality of nodes and a plurality of edges, each node from the plurality of nodes representing a monitored computer-based entity from the plurality of monitored computer-based entities, each edge from the plurality of edges representing a monitored relationship from the plurality of monitored relationships and having an associated tally that updates in response to additional instances of an event associated with that edge;

updating, via a processor operably coupled to the memory, the semantic graph in response to receiving event data, the updating including:

modifying an alert attribute of a first monitored computer-based entity from the plurality of monitored computer-based entities when the event data includes an alert received from a source, the alert applicable to the first monitored computer-based entity,

decomposing the event data into a set of objects and a set of events, and updating the tally associated with an edge from the plurality of edges, based on the set of events and the set of one or more modified threat scores, to generate an updated semantic graph; and

monitoring the updated semantic graph for one or more reportable profiles for tuning performance or managing the plurality of monitored computer-based entities.

2. The method of claim 1 , wherein decomposing the event data into a set of objects and a set of events comprises: each object of the set of objects being represented as a node and each event of the set of events being represented as an edge.

3. The method of claim 1 , wherein updating the semantic graph in response to receiving the event data comprising: updating the tally associated with an edge of the plurality of edges, based on a set of relationships among the set of entities, to (i) generate an updated semantic graph, or (ii) add at least one of a new node or new edge to the semantic graph.

4. The method of claim 1 , wherein the monitoring the managing the plurality of monitored computer-based entities comprises at least one of (i) analyzing changes in inventory of computer devices represented by the set of objects, (ii) analyzing traffic workload of the computer-based entity, or (iii) shaping and congestion of the computer-based entity.

5. The method of claim 1 , wherein modifying the alert attribute of the first monitored computer-based entity from the plurality of monitored computer-based entities comprises:

receiving a second alert data;

incrementing a number of occurrences associated with at least one relationship represented by a plurality of edges in the semantic graph to produce an incremented number of occurrences; and

sending a signal, in response to incrementing the number of occurrences, to cause display of a modified subgraph reflecting the incremented number of occurrences.

6. The method of claim 1 , wherein the updating the semantic graph comprises:

updating the semantic graph in response to detection, over time, of at least one of: a new entity, a new event, or a new alert.

7. The method of claim 1 , wherein managing the plurality of monitored computer-based entities comprises identifying a related communication based on at least one edge between at least a first node and a second node.

8. The method of claim 1 , wherein managing the plurality of monitored computer-based entities comprises circumventing an anonymity technique.

9. The method of claim 1 , wherein the event data comprises at least one of an observed network traffic characteristic for a network monitored by an SOC or data associated with a processing activity monitored by the SOC.

10. The method of claim 1 , wherein the semantic graph is a representation between network elements monitored by an SOC.

11. A network traffic analysis apparatus, comprising:

a compute device including a processor and a memory storing instructions that, when executed by the processor, cause the processor to:

send a signal to cause display, via a GUI, of a semantic graph, the semantic graph including a plurality of nodes and a plurality of edges, each node from the plurality of nodes representing an entity from a plurality of entities, each edge from the plurality of edges representing an event from a plurality of events and having an associated tally that updates in response to additional instances of the event associated with that edge;

update the semantic graph in the memory, in response to receiving event data, by:

updating the tally associated with an edge from the plurality of edges, based on the event data, and

modifying a score of each entity from the plurality of entities based on the event data, to define a plurality of modified scores;

detecting, subsequent to the display of the semantic graph, a subgraph of the semantic graph based on the plurality of modified scores; and

sending a signal to cause display, via the GUI, of the subgraph, in a manner to distinguish the subgraph from a remaining portion of the semantic graph.

12. The network traffic analysis apparatus of claim 11 , wherein the signal to cause display, via the GUI, of the subgraph does not cause display of the remaining portion of the semantic graph.

13. The network traffic analysis apparatus of claim 11 , wherein the event data includes at least one of an observed characteristic for a network monitored by a security operations center (SOC) or data associated with a processing activity monitored by the SOC.

14. The network traffic analysis apparatus of claim 11 , further comprising updating the semantic graph in response to detection, over time, of at least one of: a new entity, a new event, or an alert.

15. The network traffic analysis apparatus of claim 11 , wherein the semantic graph is a representation of a relationship between network elements monitored by a security operations center (SOC).

16. The network traffic analysis apparatus of claim 11 , wherein each entity from the plurality of entities represents a compute device within a network monitored by a security operations center (SOC).

17. The network traffic analysis apparatus of claim 11 , wherein the modified score comprises a threat score.

18. A non-transitory processor-readable medium storing code representing instructions to cause a processor to:

send a signal to cause display, via a GUI, of a semantic graph, the semantic graph including a plurality of nodes and a plurality of edges, each node from the plurality of nodes representing an entity from a plurality of entities, each edge from the plurality of edges representing an event from a plurality of events and having an associated tally that updates in response to additional instances of the event associated with that edge;

update the semantic graph in a memory, in response to receiving event data, by:

updating the tally associated with an edge from the plurality of edges, based on the event data, and

modifying a score of each entity from the plurality of entities based on the event data, to define a plurality of modified scores;

detecting, subsequent to the display of the semantic graph, a subgraph of the semantic graph based on the plurality of modified scores; and

sending a signal to cause display, via the GUI, of the subgraph, in a manner to distinguish the subgraph from a remaining portion of the semantic graph.

19. The non-transitory processor-readable medium of claim 18 , wherein the signal to cause display, via the GUI, of the subgraph does not cause display of the remaining portion of the semantic graph.

20. The non-transitory processor-readable medium of claim 18 , further comprising updating the semantic graph in response to detection, over time, of at least one of: a new entity, a new event, or an alert.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: COULL, SCOTT ERIC; JOHNS, JEFFREY THOMAS
To: FIREEYE, INC.
Reel/Frame 064098/0959 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: MANDIANT, INC.
To: GOOGLE LLC
Reel/Frame 064099/0001 →
CHANGE OF NAME Recorded Jun 28, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 064151/0773 →
Continuity (3)
Continuation 17549147 · Dec 13, 2021
Continuation 16370199 · Mar 29, 2019
Related Publication 20240007495A1 · Jan 4, 2024