IP Library Granted Patent US 12,238,014
Granted Patent B2
US 12,238,014 · App. 18/404,403 · Granted Feb 25, 2025

Identifying unmanaged cloud resources with endpoint and network logs

Inventors: Blake Harrell Anderson (Chapel Hill, NC); Andrew Chi (Chapel Hill, NC); David Arthur McGrew (Poolesville, MD); Saran Singh Ahluwalia (Apex, NC)
Assignee: Cisco Technology, Inc.
H04L47/82G06N20/00H04L43/08H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,014
App. No.
18/404,403
Granted
Feb 25, 2025
Kind
B2
Abstract

Techniques and mechanisms for identifying unmanaged cloud resources with endpoint and network logs and attributing the identified cloud resources to an entity of an enterprise that owns the cloud resources. The process collects data from sources, e.g., endpoint and network logs, with respect to traffic in a computer network and based at least in part on the data, extracts relationships related to the traffic. The process applies rules to the relationships to extract destinations in the computer network that provide cloud resources in a cloud environment, wherein the cloud resources are owned by an enterprise. One or more users or business entities of the enterprise are identified as accessing the cloud resources.

Claims (36)

1. A method comprising:

collecting, by an electronic device, first data with respect to traffic in a computer network;

based at least in part on the first data, extracting, by the electronic device, relationships related to the traffic;

applying rules to the relationships to extract destinations in the computer network that provide enterprise-owned resources in a cloud environment, wherein the enterprise-owned resources are cloud resources comprising at least one of computing instances or storage buckets located within the cloud environment and are owned by an enterprise; and

identifying, by the electronic device, (i) one or more users that are accessing the enterprise-owned resources or (ii) one or more business entities accessing the enterprise-owned resources.

2. The method of claim 1 , wherein collecting the first data comprises collecting one or more of (i) second data from logs of an endpoint monitoring application or (ii) third data from logs of a network monitoring application.

3. The method of claim 1 , wherein a monitoring application provides a list of enterprise-owned cloud resources.

4. The method of claim 1 , wherein extracting relationships comprises constructing a bipartite knowledge graph.

5. The method of claim 4 , further comprising annotating edges of the bipartite knowledge graph with information.

6. The method of claim 5 , wherein the information comprises one or more of (i) a process that initiated the traffic, (ii) an identification of a destination port, (iii) an identification of a source device, or (iv) a timestamp.

7. The method of claim 1 , wherein identifying, by the electronic device, (i) one or more users that are associated with the enterprise and accessing the enterprise-owned resources or (ii) one or more business entities that are associated with the enterprise and accessing the enterprise-owned resources comprises summarizing the enterprise-owned resources and indicating users and/or business units of the enterprise in a compact computer-readable format.

8. The method of claim 1 , wherein applying rules to the relationships comprises applying the rules using a machine learning algorithm.

9. An apparatus comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

collecting, by an electronic device, first data with respect to traffic in a computer network;

based at least in part on the first data, extracting, by the electronic device, relationships related to the traffic;

applying rules to the relationships to extract destinations in the computer network that provide enterprise-owned resources in a cloud environment, wherein the enterprise-owned resources are cloud resources comprising at least one of computing instances or storage buckets located within the cloud environment and are owned by an enterprise; and

identifying, by the electronic device, (i) one or more users that are accessing the enterprise-owned resources or (ii) one or more business entities accessing the enterprise-owned resources.

10. The apparatus of claim 9 , wherein collecting the first data comprises collecting one or more of (i) second data from logs of an endpoint monitoring application or (ii) third data from logs of a network monitoring application.

11. The apparatus of claim 9 , wherein a monitoring application provides a list of enterprise-owned cloud resources.

12. The apparatus of claim 9 , wherein extracting relationships comprises constructing a bipartite knowledge graph.

13. The apparatus of claim 12 , further comprising annotating edges of the bipartite knowledge graph with information.

14. The apparatus of claim 13 , wherein the information comprises one or more of (i) a process that initiated the traffic, (ii) an identification of a destination port, (iii) an identification of a source device, or (iv) a timestamp.

15. The apparatus of claim 9 , wherein identifying, by the electronic device, (i) one or more users that are associated with the enterprise and accessing the enterprise-owned resources or (ii) one or more business entities that are associated with the enterprise and accessing the enterprise-owned resources comprises summarizing the enterprise-owned resources and indicating users and/or business units of the enterprise in a compact computer-readable format.

16. The apparatus of claim 9 , wherein applying rules to the relationships comprises applying the rules using a machine learning algorithm.

17. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:

collecting, by an electronic device, first data with respect to traffic in a computer network;

based at least in part on the first data, extracting, by the electronic device, relationships related to the traffic;

applying rules to the relationships to extract destinations in the computer network that provide enterprise-owned resources in a cloud environment, wherein the enterprise-owned resources are cloud resources comprising at least one of computing instances or storage buckets located within the cloud environment and are owned by an enterprise; and

identifying, by the electronic device, (i) one or more users that are accessing the enterprise-owned resources or (ii) one or more business entities accessing the enterprise-owned resources.

18. The one or more non-transitory computer-readable media of claim 17 , wherein collecting the first data comprises collecting one or more of (i) second data from logs of an endpoint monitoring application or (ii) third data from logs of a network monitoring application.

19. The one or more non-transitory computer-readable media of claim 17 , wherein a monitoring application provides a list of enterprise-owned cloud resources.

20. The one or more non-transitory computer-readable media of claim 17 , wherein extracting relationships comprises constructing a bipartite knowledge graph and the actions further comprise:

annotating edges of the bipartite knowledge graph with information,

wherein the information comprises one or more of (i) a process that initiated the traffic, (ii) an identification of a destination port, (iii) an identification of a source device, or (iv) a timestamp.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2024
From: ANDERSON, BLAKE HARRELL; CHI, ANDREW; MCGREW, DAVID ARTHUR; AHLUWALIA, SARAN SINGH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066205/0071 →
Continuity (2)
Continuation 17390319 · Jul 30, 2021
Related Publication 20240297852A1 · Sep 5, 2024
References Cited (14)
US 8289968B1 · Zhuang · 2012 [cited by applicant]
US 9049117B1 · Nucci · 2015 [cited by applicant]
US 10848382B1 · Allshouse et al. · 2020 [cited by applicant]
US 20140123269A1 · Drihem et al. · 2014 [cited by applicant]
US 20160294614A1 · Searle · 2016 [cited by examiner]
US 20170063909A1 · Muddu et al. · 2017 [cited by applicant]
US 20180026984A1 · Maker · 2018 [cited by examiner]
US 20190155961A1 · Alonso · 2019 [cited by applicant]
US 20200137097A1 · Zimmermann et al. · 2020 [cited by applicant]
US 20210020036A1 · Adetiloye · 2021 [cited by examiner]
US 20230029656A1 · Anderson · 2023 [cited by applicant]
McAfee, “What is a CASB,” downloaded Feb. 3, 2021, from https://www.mcafee.com/enterprise/en-in/security-awareness/cloud/what-is-a-casb.html, 12 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/390,319, mailed on May 9, 2023, Anderson, “Identifying Unmanaged Cloud Resources With Endpoint and Network Logs”, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/390,319, mailed on Dec. 19, 2022, Blake Harrell Anderson, “Identifying Unmanaged Cloud Resources With Endpoint and Network Logs”, 7 pages. [cited by applicant]