IP Library › Granted Patent US 12,177,236
Granted Patent B2
US 12,177,236 · App. 16/861,636 · Granted Dec 24, 2024

Methods and systems for analyzing cybersecurity threats

Inventors: Richard Edwin Heimann (Washington, DC); Jonathan Lee Ticknor (Brambleton, VA); Amanda Lynn Traud (Arlington, VA); Marshall Thomas Vandegrift (Atlanta, GA); Kaska Adoteye (Arlington, VA); Jesse Pruitt Jeter (Arlington, VA); Michael Toru Czerny (Alexandria, VA)
Assignee: CYBRAICS, INC.
H04L63/1425G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,177,236
App. No.
16/861,636
Granted
Dec 24, 2024
Kind
B2
Abstract

To analyze cybersecurity threats, an analysis module of a processor may receive log data from at least one network node. The analysis module may identify at least one statistical outlier within the log data. The analysis module may determine that the at least one statistical outlier represents a cybersecurity threat by applying at least one machine learning algorithm to the at least one statistical outlier.

Claims (27)

1. A method of analyzing cybersecurity threats comprising:

performing processing associated with receiving, with an analysis module of a processor, log data from at least one network node;

performing processing associated with identifying with the analysis module, using Community, scalable Ghost 1 and scalable Ghost 2 , at least one statistical outlier within the log data, wherein Ghost 1 and Ghost 2 comprise a process that use unsupervised learning to identify outliers comprising a feature generation process which extracts features from raw data and/or an outlier detection piece which uses extracted features, and wherein the identifying comprising:

performing processing associated with determining, with the analysis module, that the at least one statistical outlier represents a cybersecurity threat by applying at least one machine learning algorithm to the at least one statistical outlier, wherein the at least one statistical outlier is driven by an unsupervised score engine that uses network-based behavioral analytics to score observations and produce score events, wherein the at least one statistical outlier is standardized to facilitate automation.

2. The method of claim 1 , further comprising transforming the log data into community data, wherein the transforming comprises determining connections between network nodes from the log data.

3. The method of claim 1 , further comprising performing processing associated with identifying the analysis module using User-based Entity Behavioural Analyses (UEBA).

4. The method of claim 1 , wherein identifying the analysis module comprises performing processing associated with examining a sequence of actions used by users to find normal user behaviour and then finding for anomalous behaviour.

5. The method of claim 1 , further comprising performing processing associated with identifying the analysis module using Dark Matter.

6. The method of claim 1 , wherein identifying the analysis module comprises using unsupervised clustering algorithms that partition data into largely homogenized groups.

7. The method of claim 6 , further comprising looking for observations that are unlike any other group.

8. The method of claim 1 , further comprising performing processing associated with identifying the analysis module using Targeted Behavioural Analytics.

9. The method of claim 8 , wherein supervised algorithms elucidate known patterns from known behaviours on a variety of data sources.

10. The method of claim 1 , wherein Community finds groups of nodes that are more connected to each other than the rest of the network.

11. The method of claim 10 , further comprising identifying a GraphX object, and then splitting each time window into groups of IPs that are more connected to each other than to the rest of the network and/or communities.

12. A system of analyzing cybersecurity threats comprising:

a processor configured for:

performing processing associated with receiving, with an analysis module of a processor, log data from at least one network node;

performing processing associated with identifying with the analysis module, using Community, scalable Ghost 1 and scalable Ghost 2 , at least one statistical outlier within the log data, wherein Ghost 1 and Ghost 2 comprise a process that use unsupervised learning to identify outliers comprising a feature generation process which extracts features from raw data and/or an outlier detection piece which uses extracted features, and wherein the identifying comprising:

performing processing associated with determining, with the analysis module, that the at least one statistical outlier represents a cybersecurity threat by applying at least one machine learning algorithm to the at least one statistical outlier, wherein the at least one statistical outlier is driven by an unsupervised score engine that uses network-based behavioral analytics to score observations and produce score events, wherein the at least one statistical outlier is standardized to facilitate automation.

13. The system of claim 12 , wherein the processor is further configured for identifying the analysis module using User-based Entity Behavioural Analyses (UEBA).

14. The system of claim 12 , wherein the processor is further configured for identifying the analysis module by examining a sequence of actions used by users to find normal user behaviour and then finding for anomalous behaviour.

15. The system of claim 12 , wherein the processor is further configured for identifying the analysis module using Dark Matter.

16. The system of claim 12 , wherein identifying the analysis module comprises using unsupervised clustering algorithms that partition data into largely homogenized groups.

17. The system of claim 16 , wherein the processor is further configured for looking for observations that are unlike any other group.

18. The system of claim 12 , wherein the processor is further configured for performing processing associated with identifying the analysis module using Targeted Behavioural Analytics.

19. The system of claim 18 , wherein supervised algorithms elucidate known patterns from known behaviours on a variety of data sources.

20. The system of claim 12 , wherein the processor is further configured for identifying a GraphX object, and then splitting each time window into groups of IPs that are more connected to each other than to the rest of the network and/or communities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2020
From: HEIMANN, RICHARD EDWIN; TICKNOR, JONATHAN LEE; TRAUD, AMANDA LYNN; VANDEGRIFT, MARSHALL THOMAS; ADOTEYE, KASKA; JETER, JESSE PRUITT; CZERNY, MICHAEL TORU
To: CYBRAICS, INC.
Reel/Frame 052801/0757 →
Continuity (2)
Continuation 15411460 · Jan 20, 2017
Related Publication 20200258004A1 · Aug 13, 2020