IP Library › Granted Patent US 12,271,385
Granted Patent B2
US 12,271,385 · App. 17/733,155 · Granted Apr 8, 2025

Observation stream engine in a security management system

Inventors: Gueorgui Bonov Chkodrov (Redmond, WA); Ryan John Littlefield (Cheltenham, GB); Jeffrey Scott Shaw (Cheltenham, GB); Zane Alexander Coppedge (Sedona, AZ); Ying Qian (Bellevue, WA); Dan Alexandru Nicolescu (Bellevue, WA); Anitta M Miller (Bellevue, WA); Khoi Hong (Seattle, WA); Justin Matthew Powell (Seattle, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F16/24568G06F16/211G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,271,385
App. No.
17/733,155
Granted
Apr 8, 2025
Kind
B2
Abstract

Methods, systems, and computer storage media for providing observation stream data of security incidents using an observation stream engine in a security management system. An observation stream framework supports continuously generating and presenting observation stream data that facilitates developing a working hypothesis of an active security incident. The observation stream framework can also include observation stream query-types that can be selected for running queries against a plurality of security data sources. In operation, an observation stream query is accessed. The observation stream query is a user-generated observation stream query associated with an observation stream query-type. The observation stream query-type comprises parameters for querying a plurality of security data sources and dynamic tracking of a security incident. The observation stream query is executed and observation stream data is generated. The observation stream data is caused to be displayed on an observation stream interface comprising data visualizations of the observation stream data.

Claims (63)

1. A computerized system comprising:

one or more computer processors; and

computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations comprising:

accessing, at an observation stream engine, an observation stream query, the observation stream query is a user-generated observation stream query, wherein the observation stream query comprises parameters for querying a plurality of security data sources and performing dynamic tracking of a security incident;

causing execution of the observation stream query against the plurality of data security sources based on the parameters;

generating observation stream data associated with the observation stream query, the observation stream data provides an observation stream timeline associated with dynamic tracking of the security incident based on the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data, wherein the user-defined interpretation data is generated based on a parameter from the observation stream query,

wherein generating the user-defined interpretation data comprises extracting a portion of raw observation stream data associated with monitoring the security incident across a plurality of computing resources to define the observation stream timeline; and

communicating the observation stream data to cause display of the observation stream data on an observation stream interface comprising graphical interface elements associated with the observation stream data.

2. The system of claim 1 , wherein the observation stream query is associated with an observation stream query-type of a plurality of observation stream query-types, wherein observation stream query-types are selectable predefined security sensors comprising parameters for retrieving raw observation stream data and generating user-defined interpretation data.

3. The system of claim 1 , wherein the plurality of security data sources include a first data source that is configured for real-time queries and a second data source that is configured for query-on-timer queries, the first data source is associated with a first schema for storing event data and the second data source is associated with a second schema for storing event data; and

wherein the observation stream query comprises a first query portion having a real-time query for the first data source and a second query portion having a query-on-time query for the second data source.

4. The system of claim 1 , wherein causing execution of the observation stream query comprises:

causing execution of a first query portion that is a real-time query to receive a first set of event data;

causing execution of a second query portion that is a query-on-timer query to receive a second set of event data;

generating the raw observation stream data based on the first set of event data and the second set of event data.

5. The system of claim 1 , further comprising generating observation stream data associated with the observation stream query further comprises:

based on the parameters of the observation stream query, classifying an event in the observation stream data with a classification type, wherein the classification type is associated with interface highlighting element; and

tagging the event with the interface highlight element to cause presentation of the event based on the interface highlight element.

6. The system of claim 1 , wherein generating the user-defined interpretation data comprises identifying a presentation setting parameter associated with the use-defined interpretation data and mapping the presentation setting parameter with the user-defined parameter to cause presentation of the user-defined interpretation data based on the presentation setting parameter.

7. The system of claim 1 , further comprising an observation stream client to perform operations comprising:

receiving, via a query-authoring interface, parameters of the observation stream query, wherein the query-authoring interface comprises interface portions for inputting the parameters comprising query-type definition parameters, query parameters, and presentation settings parameters;

communicating the observation stream query to the observation stream engine to cause generation of the observation stream data;

receiving the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data; and

causing display, via a view interface, of the observation stream data, wherein the view interface comprises interface portions for presenting timestamps, an observation type corresponding to an observation stream query-type, and details the comprising user-defined interpretation data.

8. One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to:

access, at an observation stream engine, an observation stream query, the observation stream query is a user-generated observation stream query, wherein the observation stream query comprises parameters for querying a plurality of security data sources and performing dynamic tracking of a security incident;

cause execution of the observation stream query against the plurality of data security sources based on the parameters;

generate observation stream data associated with the observation stream query, the observation stream data provides an observation stream timeline associated with dynamic tracking of the security incident based on the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data, wherein the user-defined interpretation data is generated based on a parameter from the observation stream query,

wherein generating the user-defined interpretation data comprises extracting a portion of raw observation stream data associated with monitoring the security incident across a plurality of computing resources to define the observation stream timeline; and

communicate the observation stream data to cause display of the observation stream data on an observation stream interface comprising graphical interface elements associated with the observation stream data.

9. The media of claim 8 , wherein the observation stream query is associated with an observation stream query-type of a plurality of observation stream query-types, wherein observation stream query-types are selectable predefined security sensors comprising parameters for retrieving raw observation stream data and generating user-defined interpretation data.

10. The media of claim 8 , wherein the plurality of security data sources include a first data source that is configured for real-time queries and a second data source that is configured for query-on-timer queries, the first data source is associated with a first schema for storing event data and the second data source is associated with a second schema for storing event data; and

wherein the observation stream query comprises a first query portion having a real-time query for the first data source and a second query portion having a query-on-time query for the second data source.

11. The media of claim 8 , wherein causing execution of the observation stream query comprises:

causing execution of a first query portion that is a real-time query to receive a first set of event data;

causing execution of a second query portion that is a query-on-timer query to receive a second set of event data;

generating the raw observation stream data based on the first set of event data and the second set of event data.

12. The media of claim 8 , further comprising generating observation stream data associated with the observation stream query further comprises:

based on the parameters of the observation stream query, classifying an event in the observation stream data with a classification type, wherein the classification type is associated with interface highlighting element; and

tagging the event with the interface highlight element to cause presentation of the event based on the interface highlight element.

13. The media of claim 8 , wherein generating the user-defined interpretation data comprises identifying a presentation setting parameter associated with the use-defined interpretation data and mapping the presentation setting parameter with the user-defined parameter to cause presentation of the user-defined interpretation data based on the presentation setting parameter.

14. A computer-implemented method, the method comprising:

accessing, at an observation stream engine, an observation stream query, the observation stream query is a user-generated observation stream query, wherein the observation stream query comprises parameters for querying a plurality of security data sources and performing dynamic tracking of a security incident;

causing execution of the observation stream query against the plurality of data security sources based on the parameters;

generating observation stream data associated with the observation stream query, the observation stream data provides an observation stream timeline associated with dynamic tracking of the security incident based on the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data, wherein the user-defined interpretation data is generated based on a parameter from the observation stream query,

wherein generating the user-defined interpretation data comprises extracting a portion of raw observation stream data associated with monitoring the security incident across a plurality of computing resources to define the observation stream timeline; and

communicating the observation stream data to cause display of the observation stream data on an observation stream interface comprising graphical interface elements associated with the observation stream data.

15. The method of claim 14 , the method further comprising

receiving, via a query-authoring interface, parameters of the observation stream query, wherein the query-authoring interface comprises interface portions for inputting the parameters comprising query-type definition parameters, query parameters, and presentation settings parameters;

communicating the observation stream query to the observation stream engine to cause generation of the observation stream data;

receiving the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data; and

causing display, via a view interface, of the observation stream data, wherein the view interface comprises interface portions for presenting timestamps, an observation type corresponding to an observation stream query-type, and details the comprising user-defined interpretation data.

16. The method of claim 14 , wherein the observation stream query is associated with an observation stream query-type of a plurality of observation stream query-types, wherein observation stream query-types are selectable predefined security sensors comprising parameters for retrieving raw observation stream data and generating user-defined interpretation data.

17. The method of claim 14 , wherein the plurality of security data sources include a first data source that is configured for real-time queries and a second data source that is configured for query-on-timer queries, the first data source is associated with a first schema for storing event data and the second data source is associated with a second schema for storing event data; and

wherein the observation stream query comprises a first query portion having a real-time query for the first data source and a second query portion having a query-on-time query for the second data source.

18. The method of claim 14 , wherein causing execution of the observation stream query comprises:

causing execution of a first query portion that is a real-time query to receive a first set of event data;

causing execution of a second query portion that is a query-on-timer query to receive a second set of event data;

generating the raw observation stream data based on the first set of event data and the second set of event data.

19. The method of claim 14 , further comprising generating observation stream data associated with the observation stream query further comprises:

based on the parameters of the observation stream query, classifying an event in the observation stream data with a classification type, wherein the classification type is associated with interface highlighting element; and

tagging the event with the interface highlight element to cause presentation of the event based on the interface highlight element.

20. The method of claim 14 , wherein generating the user-defined interpretation data comprises identifying a presentation setting parameter associated with the use-defined interpretation data and mapping the presentation setting parameter with the user-defined parameter to cause presentation of the user-defined interpretation data based on the presentation setting parameter.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2022
From: CHKODROV, GUEORGUI BONOV; SHAW, JEFFREY SCOTT; COPPEDGE, ZANE ALEXANDER; NICOLESCU, DAN ALEXANDRU; MILLER, ANITTA M.; HONG, KHOI; POWELL, JUSTIN MATTHEW; LITTLEFIELD, RYAN JOHN; QIAN, YING
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 060593/0081 →
Continuity (1)
Related Publication 20230350900A1 · Nov 2, 2023
References Cited (19)
US 10514966B2 · Alfred et al. · 2019 [cited by applicant]
US 11100077B2 · Chkodrov et al. · 2021 [cited by applicant]
US 11528261B2 · Aslaksen · 2022 [cited by examiner]
US 11528287B2 · Murphy · 2022 [cited by examiner]
US 11533307B2 · Mahajan · 2022 [cited by examiner]
US 11575563B2 · Woolward · 2023 [cited by examiner]
US 11582264B2 · Verma · 2023 [cited by examiner]
US 11606373B2 · Dunn · 2023 [cited by examiner]
US 11641379B1 · Sarukkai · 2023 [cited by examiner]
US 11663544B2 · Zhang · 2023 [cited by examiner]
US 11665180B2 · Linton · 2023 [cited by examiner]
US 11689550B2 · Huang · 2023 [cited by examiner]
US 11700279B2 · Seeber · 2023 [cited by examiner]
US 11729219B2 · Chandana · 2023 [cited by examiner]
US 20170251013A1 · Kirti et al. · 2017 [cited by applicant]
US 20180157831A1 · Abbaszadeh et al. · 2018 [cited by applicant]
US 20190098068A1 · Iliofotou et al. · 2019 [cited by applicant]
US 20190109868A1 · Muddu et al. · 2019 [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2023/016789”, Mailed Date: Jul. 6, 2023, 12 Pages. [cited by applicant]