IP Library Granted Patent US 9,124,621
Granted Patent B2
US 9,124,621 · App. 13/629,222 · Granted Sep 1, 2015

Security alert prioritization

Inventors: Pratyusa Kumar Manadhata (Piscataway, NJ); Prasad V. Rao (Metuchen, NJ)
Assignee: Hewlett-Packard Development Company, L.P.
H04L63/1416G06F21/552H04L63/14H04L63/1433G06F2221/2101G06F2221/2105G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,124,621
App. No.
13/629,222
Filed
Sep 27, 2012
Granted
Sep 1, 2015
Kind
B2
Examiner
ZEE, EDWARD
Art Unit
2435
USPC
726/22
Abstract

In one implementation, a security alert prioritization system identifies a host and a domain associated with a security alert that was generated in response to a communication between the host and the domain. The security alert prioritization system accesses a security state associated with the host and a security state associated with the domain, and compute a priority of the security alert based on the security state associated with the host and the security state associated with the domain.

Claims (56)

1. A non-transitory processor-readable medium storing code representing instructions that when executed by a processor cause the processor to:

identify a host associated with a security alert and a domain associated with the security alert, wherein the security alert is generated in response to a communication between the host and the domain;

access a first security state associated with the host and a second security state associated with the domain; and

compute a priority of the security alert based on a host-domain access map having a plurality of nodes, the plurality of nodes including a first node associated with the host and a second node associated with the domain, the host-domain access ma having an edge between the first node and the second node, the first node assigned the first security state based on a confidence measure associated with the security alert.

2. The processor-readable medium of claim 1 , further comprising instructions that when executed by the processor cause the processor to:

provide the security alert and the priority to a security monitor.

3. The processor-readable medium of claim 1 , wherein the first security state associated with the host and the second security state associated with the domain are defined by belief propagation.

4. The processor-readable medium of claim 1 , further comprising instructions that when executed by the processor cause the processor to:

generate the host-domain access map; and

define a security state for each node from the plurality of nodes using belief propagation, wherein the security state for the first node associated with the host comprises the first security state and the security state for the second node associated with the domain comprises the second security state.

5. The processor-readable medium of claim 1 , further comprising instructions that when executed by the processor cause the processor to:

generate the host-domain access map based at least in part on the security alert;

assign an initial security state to each node in a subset of the plurality of nodes based on a plurality of confidence measures related to a plurality of security alerts; and

apply an iteration of belief propagation to the initial security state for each node of the plurality of nodes, wherein the security state for the first node associated with the host comprises the first security state and the security state for the second node associated with the domain comprises the second security state.

6. The processor-readable medium of claim 1 , wherein the second security state associated with the domain comprises a default security state in response to a determination that the domain is unknown.

7. The processor-readable medium of claim 1 , wherein:

the first security state associated with the host comprises a multiclass classification vector; and

the second security state associated with the domain comprises a multiclass classification vector.

8. The processor-readable medium of claim 1 , wherein:

the priority of the security alert comprises a first priority in response to a first determination that the first security state associated with the host indicates a severe security risk and the second security state associated with the domain indicates a severe security risk; and

the priority of the security alert comprises a second priority different from the first priority in response to a second determination that the first security state associated with the host indicates a low security risk and the second security state associated with the domain indicates a low security risk.

9. The processor-readable medium of claim 1 , wherein:

the priority of the security alert comprises a first priority in response to a first determination that the first security state associated with the host indicates a severe security risk and the second security state associated with the domain indicates a severe security risk; and

the priority of the security alert comprises a second priority different from the first priority in response to a second determination that the first security state associated with the host indicates a first security risk different from a second security risk indicated by the second security state associated with the domain.

10. A security alert prioritization system, comprising:

a graph generator that generates a host-domain access map based on network activity records;

an inference module that:

seeds the host-domain map based on a first confidence measure associated with a security alert; and

applies belief propagation to the host-domain access map to assign a security state to each node within the host-domain access map;

an identification module that identifies a host associated with the security alert and a domain associated with the security alert; and

a priority module that assigns a priority to the security alert using a first security state assigned to a first node within the host-domain access map associated with the host and a second security state assigned to a second node within the host-domain access map associated with the domain.

11. The security alert prioritization system of claim 10 , further comprising:

a reporting module that reports the security alert and the priority assigned to the security alert to a security monitor.

12. The security alert prioritization system of claim 10 , wherein:

a first network activity record of the network activity records includes the security alert, the security alert being one of a plurality of security alerts generated at an intrusion detection system; and

the inference module seeds the host-domain access map based on confidence measures associated with the plurality of security alerts, the first confidence measure being one of the confidence measures.

13. The security alert prioritization system of claim 10 , wherein:

the inference module adds a new node to the host-domain access map and assigns a default security state to the new node in response to a determination that the domain associated with the security alert is not included in the host-domain access map, the new node being associated with the domain.

14. The security alert prioritization system of claim 10 , wherein the security state assigned to each node within the host-domain access map comprises a multiclass classification vector.

15. A computing system, comprising a processor-readable medium storing code representing instructions that when executed by a processor cause the processor to implement a security alert prioritization system including:

an identification module that identifies a host associated with a first security alert of a plurality of security alerts and a domain associated with the first security alert, the first security alert generated in response to network traffic between the host and the domain;

a priority module that:

determines a joint probability of a first class and a second class, the first class represented in a first security state assigned to a first node within a host-domain access map associated with the host and the second class represented in a second security state assigned to a second node within the host-domain access map associated with the domain; and

assigns a priority to the first security alert using the joint probability of the first security state assigned to the first node and a second security state assigned to the second node; and

a reporting module that reports the first security alert and the priority assigned to the first security alert to a security monitor.

16. The computing system of claim 15 , wherein the first security state assigned to the first node within the host-domain access map associated with the host and the second security state assigned to the second node within the host-domain access map associated with the domain are defined by belief propagation applied to the host-domain access map.

17. The computing system of claim 15 , further comprising:

an inference module that seeds the host-domain access map based on a confidence measure of each security alert from the plurality of security alerts and applies belief propagation to the host-domain access map to assign the first security state to the first node within the host-domain access map associated with the host and assign the second security state to the second node within the host-domain access map associated with the domain.

18. The computing system of claim 15 , wherein:

the priority module assigns a first priority to the first security alert in response to a first determination that the first security state associated with the host indicates a severe security risk and the second security state associated with the domain indicates a severe security risk; and

the priority module assigns a second priority different from the first priority to the first security alert in response to a second determination that the first security state associated with the host indicates a low security risk and the second security state associated with the domain indicates a low security risk.

19. The computing system of claim 15 , wherein:

the first security state assigned to the first node within the host-domain access map associated with the host comprises a first multiclass classification vector;

the second security state assigned to the second node within the host-domain access map associated with the domain comprises a second multiclass classification vector; and

the priority module determines a joint probability of each class represented in the first security state assigned to the first node within the host-domain access map associated with the host and in the second security state assigned to the second node within the host-domain access map associated with the domain to assign the priority to the first security alert.

20. The computing system of claim 15 , wherein the first security alert comprises an indication that the network traffic has been determined to be potentially malicious based on analysis of communication between the host and the domain and the priority comprises a classification of security issue significance based on a security risk.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2012
From: MANADHATA, PRATYUSA KUMAR; RAO, PRASAD V.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029050/0770 →
Continuity (1)
Related Publication 20140090056A1 · Mar 27, 2014