IP Library › Granted Patent US 12,206,693
Granted Patent B1
US 12,206,693 · App. 17/745,482 · Granted Jan 21, 2025

Graph-based detection of network security issues

Inventor: Georgios Apostolopoulos (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L63/1425G06F16/9024
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,693
App. No.
17/745,482
Filed
May 16, 2022
Granted
Jan 21, 2025
Kind
B1
Art Unit
2431
USPC
726/23
Abstract

The disclosed techniques relate to a graph-based network security analytic framework to combine multiple sources of information and security knowledge in order to detect risky behaviors and potential threats. In some examples, the input can be anomaly events or simply regular events. The entities associated with the activities can be grouped into smaller time units, e.g., per day. The riskiest days of activity can be found by computing a risk score for each day and according to the features in the day. A graph can be built with links between the time units. The links can also receive scoring based on a number of factors. The resulting graph can be compared with known security knowledge for adjustments. Threats can be detected based on the adjusted risk score for a component (i.e., a group of linked entities) as well as a number of other factors.

Claims (54)

1. A method comprising:

accessing a relationship graph in which entities associated with an information technology network are represented as nodes and relationships among the nodes are represented as links;

assigning the nodes in the relationship graph to groups to form a plurality of groups, each group of the plurality of groups including nodes associated with activities that occurred within a same unit of time;

constructing links between nodes across different groups of the plurality of groups, to form a chain of linked nodes, the chain of linked nodes forming a component;

computing a score for the component, wherein the score is indicative of a level of interest associated with nodes attached to a given link, and wherein each node had been assigned an anomaly score from a previous data analytic stage;

identifying the component for security scrutiny based on the computed score; and

performing a network security related action on the identified component.

2. The method of claim 1 , further comprising:

adjusting the score for the component based on comparing events underlying the component with a pattern of interest, wherein the pattern of interest identifies an expected temporal order and/or logical relationship in underlying events for the component to be of interest.

3. The method of claim 2 , wherein the compared events comprise events that have been earmarked as anomalies, and wherein each node is assigned an anomaly score from a previous data analytic stage.

4. The method of claim 1 , wherein the relationship graph is a subset of a composite relationship graph that includes edges representing a plurality of anomalous activities conducted by entities.

5. The method of claim 1 , further comprising:

determining a link score for the component.

6. The method of claim 1 , further comprising:

determining a link score for each link in the component, based on a number of common nodes between the groups with which the component is associated.

7. The method of claim 1 , further comprising:

determining a link score for the component, based on a distance in time between the groups with which the component is associated.

8. The method of claim 1 , further comprising:

determining a link score for the component, based on an anomaly score of each node in the component.

9. The method of claim 1 , further comprising:

determining a link score for each link in the component, wherein the score for the component is based on the link score of the link that connects the nodes in the component.

10. The method of claim 1 , further comprising: creating a new graph using the component.

11. The method of claim 1 , further comprising:

creating a new graph using the component, wherein the new graph includes nodes with respective links and a corresponding group, and wherein the nodes in the new graph are coupled to underlying events so that, responsive to a request, the underlying events are output as supporting evidence.

12. The method of claim 1 , further comprising:

before assigning the nodes in the relationship graph to groups, filtering the nodes and links in the relationship graph by removing nodes that include a whitelisted entity.

13. The method of claim 1 , further comprising:

before assigning the nodes in the relationship graph to groups, filtering the nodes and links in the relationship graph by removing nodes that include an entity having more than a threshold number of anomaly links to other entities.

14. A computer system comprising:

a processor; and

a communication device, operatively coupled to the processor, through which to receive event data indicative of activity of entities associated with an information technology network;

wherein the processor is configured to perform operations including:

accessing a relationship graph in which the entities associated with the information technology network are represented as nodes and relationships among the nodes are represented as links;

assigning the nodes in the relationship graph to groups to form a plurality of groups, each group of the plurality of groups including nodes associated with activities that occurred within a same unit of time;

constructing links between nodes across different groups of the plurality of groups, to form a chain of linked nodes, the chain of linked nodes forming a component;

computing a score for the component, wherein the score is indicative of a level of interest associated with nodes attached to a given link, and wherein each node had been assigned an anomaly score from a previous data analytic stage;

identifying the component for security scrutiny based on the computed score; and

performing a network security related action on the identified component.

15. The computer system of claim 14 , wherein said operations further include:

adjusting the score for the component based on comparing events underlying the component with a pattern of interest, wherein the pattern of interest identifies an expected temporal order and/or logical relationship in underlying events for the component to be of interest.

16. The computer system of claim 15 , wherein the compared events that have been earmarked as anomalies, and wherein each node is assigned an anomaly score from a previous data analytic stage.

17. A non-transitory machine-readable storage medium for use in a processing system, the non-transitory machine-readable storage medium storing instructions, execution of which in the processing system causes the processing system to perform operations comprising:

accessing a relationship graph in which entities associated with an information technology network are represented as nodes and relationships among the nodes are represented as links;

assigning the nodes in the relationship graph to groups to form a plurality of groups, each group of the plurality of groups including nodes associated with activities that occurred within a same unit of time;

constructing links between nodes across different groups of the plurality of groups, to form a chain of linked nodes, the chain of linked nodes forming a component;

computing a score for the component, wherein the score is indicative of a level of interest associated with nodes attached to a given link, and wherein each node had been assigned an anomaly score from a previous data analytic stage;

identifying the component for security scrutiny based on the computed score; and

performing a network security related action on the identified component.

18. The non-transitory machine-readable storage medium of claim 17 , said operations further including:

determining a link score for the component.

19. The non-transitory machine-readable storage medium of claim 17 , said operations further including:

determining a link score for each link in the component, based on a number of common nodes between the groups with which the component is associated.

20. The non-transitory machine-readable storage medium of claim 17 , further comprising:

determining a link score for the component, based on an anomaly score of each node in the component.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: APOSTOLOPOULOS, GEORGIOS
To: SPLUNK INC.
Reel/Frame 059921/0304 →
Continuity (3)
Continuation 16828812 · Mar 24, 2020
Continuation 16219852 · Dec 13, 2018
Continuation 15419959 · Jan 30, 2017
References Cited (108)
US 7555523B1 · Hartmann · 2009 [cited by applicant]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 9015843B2 · Griffin et al. · 2015 [cited by applicant]
US 9027127B1 · Soldo et al. · 2015 [cited by applicant]
US 9055012B2 · Ehrlich et al. · 2015 [cited by applicant]
US 9166999B1 · Kulkarni et al. · 2015 [cited by applicant]
US 9202052B1 · Fang et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9356950B2 · Vissamsetty et al. · 2016 [cited by applicant]
US 9407652B1 · Kesin · 2016 [cited by examiner]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9558056B2 · Sasturkar · 2017 [cited by examiner]
US 9558346B1 · Kolman et al. · 2017 [cited by applicant]
US 9729549B2 · Davis · 2017 [cited by examiner]
US 9860257B1 · Kumar et al. · 2018 [cited by applicant]
US 10009358B1 · Xie · 2018 [cited by examiner]
US 10015182B1 · Shintre · 2018 [cited by examiner]
US 10069849B2 · Muddu et al. · 2018 [cited by applicant]
US 10389738B2 · Muddu et al. · 2019 [cited by applicant]
US 10771345B1 · Louca et al. · 2020 [cited by applicant]
US 20050278703A1 · Lo et al. · 2005 [cited by applicant]
US 20060288415A1 · Wong · 2006 [cited by applicant]
US 20100241828A1 · Yu et al. · 2010 [cited by applicant]
US 20110055921A1 · Narayanaswamy et al. · 2011 [cited by applicant]
US 20110202391A1 · Fogel et al. · 2011 [cited by applicant]
US 20120041901A1 · Zhao · 2012 [cited by examiner]
US 20120180126A1 · Liu et al. · 2012 [cited by applicant]
US 20120254398A1 · Thomas et al. · 2012 [cited by applicant]
US 20130133052A1 · Davis · 2013 [cited by examiner]
US 20130152057A1 · Ke et al. · 2013 [cited by applicant]
US 20130191887A1 · Davis · 2013 [cited by examiner]
US 20130318236A1 · Coates et al. · 2013 [cited by applicant]
US 20130318604A1 · Coates et al. · 2013 [cited by applicant]
US 20140074817A1 · Neels et al. · 2014 [cited by applicant]
US 20140101763A1 · Harlacher et al. · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140222997A1 · Mermoud et al. · 2014 [cited by applicant]
US 20140282871A1 · Rowland et al. · 2014 [cited by applicant]
US 20150040231A1 · Oliphant et al. · 2015 [cited by applicant]
US 20150047026A1 · Neil et al. · 2015 [cited by applicant]
US 20150121518A1 · Shmueli et al. · 2015 [cited by applicant]
US 20150205954A1 · Jou et al. · 2015 [cited by applicant]
US 20150229662A1 · Hitt et al. · 2015 [cited by applicant]
US 20150235154A1 · Utschig · 2015 [cited by applicant]
US 20150244732A1 · Golshan et al. · 2015 [cited by applicant]
US 20150256413A1 · Du et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150355957A1 · Steiner et al. · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20150379083A1 · Lang et al. · 2015 [cited by applicant]
US 20150379425A1 · Dirac et al. · 2015 [cited by applicant]
US 20150379428A1 · Dirac et al. · 2015 [cited by applicant]
US 20160034529A1 · Nguyen et al. · 2016 [cited by applicant]
US 20160057159A1 · Yin et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160132787A1 · Drevo et al. · 2016 [cited by applicant]
US 20160147583A1 · Ben Simhon · 2016 [cited by examiner]
US 20160191559A1 · Mhatre et al. · 2016 [cited by applicant]
US 20160219066A1 · Vasseur · 2016 [cited by examiner]
US 20160253232A1 · Puri et al. · 2016 [cited by applicant]
US 20160269424A1 · Chandola et al. · 2016 [cited by applicant]
US 20160300142A1 · Feller et al. · 2016 [cited by applicant]
US 20160321265A1 · Cevahir · 2016 [cited by applicant]
US 20160330226A1 · Chen · 2016 [cited by examiner]
US 20160358099A1 · Sturlaugson et al. · 2016 [cited by applicant]
US 20160358103A1 · Bowers et al. · 2016 [cited by applicant]
US 20160359872A1 · Yadav · 2016 [cited by examiner]
US 20170048270A1 · Boyadjiev et al. · 2017 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063887A1 · Iliofotou et al. · 2017 [cited by applicant]
US 20170063888A1 · Zadeh et al. · 2017 [cited by applicant]
US 20170063889A1 · Iliofotou et al. · 2017 [cited by applicant]
US 20170063890A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063894A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063909A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree · 2017 [cited by examiner]
US 20170134415A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170192782A1 · Valentine et al. · 2017 [cited by applicant]
US 20170192872A1 · Awad et al. · 2017 [cited by applicant]
US 20170279844A1 · Bower et al. · 2017 [cited by applicant]
US 20170288979A1 · Yoshihira et al. · 2017 [cited by applicant]
US 20170295193A1 · Yang · 2017 [cited by examiner]
US 20170324759A1 · Puri · 2017 [cited by examiner]
US 20170353480A1 · Gao et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20180054452A1 · Muddu et al. · 2018 [cited by applicant]
US 20180198805A1 · Vejman et al. · 2018 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20180219894A1 · Crabtree · 2018 [cited by examiner]
US 20180288079A1 · Muddu et al. · 2018 [cited by applicant]
US 20180302423A1 · Muddu et al. · 2018 [cited by applicant]
US 20180351981A1 · Muddu et al. · 2018 [cited by applicant]
US 20180367551A1 · Mudou et al. · 2018 [cited by applicant]
US 20190124104A1 · Apostolopoulos · 2019 [cited by applicant]
US 20190327251A1 · Muddu et al. · 2019 [cited by applicant]
US 20200021607A1 · Muddu et al. · 2020 [cited by applicant]
US 20200228558A1 · Apostolopoulos · 2020 [cited by applicant]
US 20230053182A1 · Bertiger · 2023 [cited by examiner]
US 20230308464A1 · Dong · 2023 [cited by examiner]
WO 2016163903A1 · 2016 [cited by applicant]
“Palantir Cyber Intelligence: An End-to-End Analysis and Knowledge Management Platform”, http://web.archive.org/web/20140821212114/http://www.palantir.com/wp-assets/wp-content/uploads/2014/03/Solution-Overview_palantier… [cited by applicant]
“Palantir Cybermesh”, retrieved online via url: http://web.archive.org/web/20140821212016/http://www.palantir.com/wp-assets/media/capabilites-perspectives/Palantir-Cybermesh.pdf, Aug. 21, 2014, 5 pages. [cited by applicant]
Palantir Technologies, Product Brochure for “Palantir Cyber,” 2013, 9 pages. [cited by applicant]
Boora, N.K. , et al., “Efficient Algorithms for Intrusion Detection”, In: Ghosh R.K., Mohanty H. (eds) Distributed computing and Internet Technology; ICDCIT 2004; Lecture Notes in Computer Science, vol. 3347; Springer, … [cited by applicant]
Ranshous, Stephen , et al., “Anomaly detection in dynamic networks: a survey”, WIREs Computational Statistics; vol. 7, May/Jun. 2015, pp. 223-247. [cited by applicant]
Cited By (5)
US 12,425,309 US 12,613,761 US 12,621,325 US 12,671,706 US 12,695,769