IP Library Granted Patent US 12,711,221
Granted Patent B2
US 12,711,221 · App. 18/761,554 · Granted Aug 18, 2026

Graphical user interface for presentation of network security risk and threat information

Inventors: James Apger (McKinney, TX); Allison Lindsey Drake (Rancho Santa Fe, CA); James Irwin Ebeling (Fort Myers, FL); Orville Esoy (San Diego, CA); Bhooshan Kulkarni (El Segundo, CA); Marquis L. Montgomery (Cumming, GA); Daniel Trenkner (Encinitas, CA)
Assignee: Cisco Technology, Inc.
G06F21/552G06F3/0482G06F21/577G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,711,221
App. No.
18/761,554
Filed
Jul 2, 2024
Granted
Aug 18, 2026
Kind
B2
Examiner
VANG, MENG
Art Unit
2443
USPC
726/1
Abstract

A graphical user interface (GUI) for presentation of network security risk and threat information is disclosed. A listing is generated of incidents identified by use of event data obtained from a networked computing environment. A particular incident is determined to be associated with a risk object, wherein a risk object is a component of the networked computing environment. The listing is populated with a name associated with the risk object. Risk events associated with the incident are determined, wherein each risk event contributes to a risk score for the incident. The risk score indicates a potential security issue associated with the risk object. The listing is populated with the risk score and a summary of the events. An action is associated with the listing, for triggering display of additional information associated with the risk object. The listing can be displayed in a first display screen of the GUI.

Claims (49)

1 . A method comprising:

accessing a plurality of event records, each of which is indicative of activity of an entity on a computer network;

identifying a plurality of risk events based on the plurality of event records, each risk event of the plurality of risk events being an event deemed indicative of a potential security threat to the computer network, wherein each risk event is associated with a corresponding risk object that generates the risk event, and wherein each risk event is associated with a corresponding threat object that is used, received, interacted with, or acted upon by the corresponding risk object in association with the risk event;

causing display of a first display screen that includes a first listing of a plurality of risk objects, each being associated with one or more risk events; and

causing, in response to a first user input directed to a particular risk object, display of a second display screen that includes a second listing of one or more risk events associated with the particular risk object, each risk event in the second listing including an identification of a threat object associated with the risk event, the second display screen further including a graph corresponding to a selected risk event in the second listing, the graph comprises a first node representing a threat object associated with the selected risk event, one or more second nodes, each representing one of one or more network entities that have interacted with the threat object, and one or more edges, wherein each of the one or more edges connects the first node and one of the one or more second nodes representing relationships between the threat object represented by the first node and a network entity represented by the connected second node.

2 . The method of claim 1 , further comprising:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events.

3 . The method of claim 1 , further comprising:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to a risk score for an incident, the incident being associated with all of the plurality of risk events.

4 . The method of claim 1 , further comprising:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to an incident risk score for an incident, the incident being associated with all of the plurality of risk events; and

causing display of a third display screen that includes a listing of a plurality of incidents, including the incident, wherein the third display screen indicates at least one of the plurality of incidents as being a risk notable with an associated risk score, and indicates at least one other of the plurality of incidents as being an ordinary notable.

5 . The method of claim 1 , wherein the identifying a plurality of risk events is based on a search of the event records.

6 . The method of claim 1 , wherein the identifying a plurality of risk events comprises determining, by use of a search of the event records, that the risk events are associated with a known attack tactic.

7 . The method of claim 1 , further comprising:

identifying a plurality of incidents from the plurality of event records; and

classifying at least one of the incidents as a risk notable, wherein each incident classified as a risk notable is deemed indicative of a potential security threat to a networked computing environment and contains an identification of a corresponding risk object.

8 . The method of claim 1 , wherein each risk event of the plurality of the events contributes to a risk score for an incident, the risk score being indicative of a potential security issue associated with the risk object, and wherein the risk score is calculated based on a user-specified risk score modifier.

9 . The method of claim 1 , wherein each risk event of the plurality of the events contributes to a risk score for an incident, the risk score being indicative of a potential security issue associated with the risk object, and wherein the risk score is calculated by applying a user-specified risk score modifier to events that satisfy a search query at least a specified number of times.

10 . The method of claim 1 , further comprising, in response to a first user input, causing display of a fourth display screen including the listing of the plurality of risk events, the fourth display screen further including a timeline graphic indicative of the plurality of risk events, the timeline graphic indicating a time period during which each risk event in the plurality of risk events occurred and a severity level of each risk event in the plurality of risk events.

11 . The method of claim 1 , in response to a first user input, causing display of a fourth display screen including the listing of the plurality of risk events, the fourth display screen further including a timeline graphic indicative of the plurality of risk events, the timeline graphic indicating a time period during which each risk event in the plurality of risk events occurred and a severity level of each risk event in the plurality of risk events, wherein at least one of the plurality of risk events indicated in the timeline graphic represents a plurality of underlying raw events, each of the underlying raw events containing machine data.

12 . The method of claim 1 , further comprising, in response to a first user input, causing display of a fourth display screen including a listing of risk events associated with an incident, the fourth display screen further including a timeline graphic indicative of the risk events in the listing of risk events, the timeline graphic indicating a time period during which each risk event in the listing of risk events occurred and a severity level of each risk event in the listing of risk events, wherein at least one risk event represented in the timeline graphic represents a plurality of underlying raw events, each of the underlying raw events containing machine data, wherein a second user input directed to a risk event indicated in the timeline graphic causes display of additional details about the risk event in the fourth display screen.

13 . At least one non-transitory machine-readable storage medium tangibly embodying instructions, execution of which in a computer system cause the computer system to perform operations comprising:

accessing a plurality of event records, each of which is indicative of activity of an entity on a computer network;

identifying a plurality of risk events based on the plurality of event records, each risk event of the plurality of risk events being an event deemed indicative of a potential security threat to the computer network, wherein each risk event is associated with a corresponding risk object that generates the risk event, and wherein each risk event is associated with a corresponding threat object that is used, received, interacted with, or acted upon by the corresponding risk object in association with the risk event;

causing display of a first display screen that includes a first listing of a plurality of risk objects, each being associated with one or more risk events; and

causing, in response to a first user input directed to a particular risk object, display of a second display screen that includes a second listing of one or more risk events associated with the particular risk object, each risk event in the second listing including an identification of a threat object associated with the risk event, the second display screen further including a graph corresponding to a selected risk event in the second listing, the graph comprises a first node representing a threat object associated with the selected risk event, one or more second nodes, each representing one of one or more network entities that have interacted with the threat object, and one or more edges, wherein each of the one or more edges connects the first node and one of the one or more second nodes representing relationships between the threat object represented by the first node and a network entity represented by the connected second node.

14 . The at least one non-transitory machine-readable storage medium of claim 13 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events.

15 . The at least one non-transitory machine-readable storage medium of claim 13 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to a risk score for an incident, the incident being associated with all of the plurality of risk events.

16 . The at least one non-transitory machine-readable storage medium of claim 13 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to an incident risk score for an incident, the incident being associated with all of the plurality of risk events; and

causing display of a third display screen that includes a listing of a plurality of incidents, including the incident, wherein the third display screen indicates at least one of the plurality of incidents as being a risk notable with an associated risk score, and indicates at least one other of the plurality of incidents as being an ordinary notable.

17 . A processing system comprising:

a communications interface;

a memory; and

a processor coupled to the communications interface and the memory, and configured to execute instructions to cause the processing system to perform operations comprising:

accessing a plurality of event records, each of which is indicative of activity of an entity on a computer network;

identifying a plurality of risk events based on the plurality of event records, each risk event of the plurality of risk events being an event deemed indicative of a potential security threat to the computer network, wherein each risk event is associated with a corresponding risk object that generates the risk event, and wherein each risk event is associated with a corresponding threat object that is used, received, interacted with, or acted upon by the corresponding risk object in association with the risk event;

causing display of a first display screen that includes a first listing of a plurality of risk objects, each being associated with one or more risk events; and

causing, in response to a first user input directed to a particular risk object, display of a second display screen that includes a second listing of one or more risk events associated with the particular risk object, each risk event in the second listing including an identification of a threat object associated with the risk event, the second display screen further including a graph corresponding to a selected risk event in the second listing, the graph comprises a first node representing a threat object associated with the selected risk event, one or more second nodes, each representing one of one or more network entities that have interacted with the threat object, and one or more edges, wherein each of the one or more edges connects the first node and one of the one or more second nodes representing relationships between the threat object represented by the first node and a network entity represented by the connected second node.

18 . The processing system of claim 17 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events.

19 . The processing system of claim 17 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to a risk score for an incident, the incident being associated with all of the plurality of risk events.

20 . The processing system of claim 17 , such that the operations further comprise:

determining a risk score for each risk event of the plurality of risk events, wherein the first display screen includes an indication of the risk score of each risk event of the plurality of risk events, wherein each risk event of the plurality of the events contributes to an incident risk score for an incident, the incident being associated with all of the plurality of risk events; and

causing display of a third display screen that includes a listing of a plurality of incidents, including the incident, wherein the third display screen indicates at least one of the plurality of incidents as being a risk notable with an associated risk score, and indicates at least one other of the plurality of incidents as being an ordinary notable.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2024
From: APGER, JAMES; DRAKE, ALLISON LINDSEY; EBELING, JAMES IRWIN; ESOY, ORVILLE; KULKARNI, BHOOSHAN; MONTGOMERY, MARQUIS L.; TRENKNER, DANIEL
To: SPLUNK INC.
Reel/Frame 068274/0932 →
Continuity (2)
Continuation 17515328 · Oct 29, 2021
Related Publication 20240354401A1 · Oct 24, 2024
References Cited (28)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10673880B1 · Pratt · 2020 [cited by examiner]
US 11201890B1 · Coull · 2021 [cited by examiner]
US 20070192474A1 · Decasper · 2007 [cited by examiner]
US 20170046519A1 · Cam · 2017 [cited by examiner]
US 20170063912A1 · Muddu · 2017 [cited by examiner]
US 20180316695A1 · Esman · 2018 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20200304537A1 · Zorlular et al. · 2020 [cited by applicant]
US 20200311630A1 · Risoldi et al. · 2020 [cited by applicant]
US 20200412758A1 · Trivellato et al. · 2020 [cited by applicant]
US 20210203673A1 · Dos Santos et al. · 2021 [cited by applicant]
US 20210286895A1 · Yang et al. · 2021 [cited by applicant]
US 20220019674A1 · Frey et al. · 2022 [cited by applicant]
US 20220261487A1 · Lounsberry · 2022 [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020, 6 pages. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
International Search Report and Written Opinion mailed Feb. 4, 2022 for International Patent Application No. PCT/US2021/057450, 12 pages. [cited by applicant]
“Enterprise Security Solutions: Splunk”, Splunk.com; retrieved online from url: https://web.archive.org/web/20201020211320/https://www.splunk.com/en_us/software/enterpris e-security.html, Oct. 20, 2020, pp. 1-10. [cited by applicant]