IP Library Granted Patent US 10,356,109
Granted Patent B2
US 10,356,109 · App. 15/328,018 · Granted Jul 16, 2019

Security indicator linkage determination

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,109
App. No.
15/328,018
Granted
Jul 16, 2019
Kind
B2
Abstract

According to an example, security indicator linkage determination may include parsing input data that is used to determine a plurality of sequences of steps that are involved in attacks. A linkage selected from temporal, spatial, and/or behavioral linkages may be applied to the parsed input data to determine the plurality of sequences of steps. A security indicator that is related to a potential attack may be received. The plurality of sequences of steps may be used to determine whether the security indicator matches a step in one of the plurality of sequences of steps. In response to a determination that the security indicator matches a step in one of the plurality of sequences of steps, linkage between the security indicator and another security indicator from the one of the plurality of sequences of steps that are involved in the attacks may be identified.

Claims (43)

1. A non-transitory computer readable medium comprising instructions that when executed cause at least one processor to:

parse input data;

apply a linkage to the parsed input data to determine a plurality of sequences of steps that are involved in attacks, the linkage comprising at least one selected from among temporal, spatial, or behavioral linkages, and the plurality of sequences of steps comprises a first sequence of steps and a second sequence of steps different from the first sequence of steps;

receive a security indicator that is related to a potential attack;

utilize the plurality of sequences of steps to determine whether the security indicator matches a step in one of the plurality of sequences of steps;

in response to a determination that the security indicator matches a step in one of the plurality of sequences of steps, identify a linkage between the security indicator and a further security indicator from the one of the plurality of sequences of steps; and

predict that the potential attack is likely to occur from an address included in the further security indicator.

2. The non-transitory computer readable medium of claim 1 , wherein the security indicator that is related to the potential attack includes at least one of: an Internet protocol (IP) address, a type of an attack, an attack timing, a domain related to an attack, and a location related to an attack.

3. The non-transitory computer readable medium of claim 1 , wherein a sequence of steps of the plurality of sequences of steps includes a combination selected from at least two of reconnaissance, perimeter infiltration, internal network zone infiltration, discovery, capture, exfiltration, and payload installation.

4. The non-transitory computer readable medium of claim 1 , wherein the temporal linkage is related to an order of steps in a sequence of steps of the plurality of sequences of steps.

5. The non-transitory computer readable medium of claim 1 , wherein the spatial linkage is related to an origination location of an attack in a sequence of steps of the plurality of sequences of steps.

6. The non-transitory computer readable medium of claim 1 , wherein the behavioral linkage is related to an occurrence of events and actions in a sequence of steps of the plurality of sequences of steps.

7. The non-transitory computer readable medium of claim 1 , wherein the instructions when executed cause the at least one processor to:

determine a confidence in an attack prediction represented by the identification of the linkage between the security indicator and the further security indicator.

8. The non-transitory computer readable medium of claim 1 , wherein the instructions when executed cause the at least one processor to:

receive selection of a granularity related to the linkage between the security indicator and the further security indicator wherein the granularity includes a range from low granularity to high granularity; and

in response to the selection of the granularity, identify the linkage between the security indicator and the further security indicator.

9. The non-transitory computer readable medium of claim 1 , wherein the attacks include cyber-attacks.

10. The non-transitory computer readable medium of claim 1 , wherein the instructions when executed cause the at least one processor to:

in response to a determination that the security indicator does not match any of the steps in the plurality of sequences of steps, identify the security indicator as a security indicator that does not match any of the steps in the plurality of sequences of steps.

11. The non-transitory computer readable medium of claim 1 , wherein the identified linkage between the security indicator and the further security indicator is one of a temporal linkage, a spatial linkage, or a behavioral linkage.

12. The non-transitory computer readable medium of claim 1 , wherein the first sequence of steps comprises a reconnaissance step and a perimeter infiltration step, and the second sequence of steps comprises installation of data payloads in a network.

13. The non-transitory computer readable medium of claim 12 , wherein the first sequence of steps further comprises a data exfiltration step.

14. A system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

determine a linkage in input data to determine a plurality of sequences of steps that are involved in attacks, the linkage comprising at least one selected from among temporal, spatial, or behavioral linkages, and the plurality of sequences of steps comprises a first sequence of steps and a second sequence of steps different from the first sequence of steps;

utilize the plurality of sequences of steps to determine whether a security indicator matches a step in one of the plurality of sequences of steps;

in response to a determination that the security indicator matches a step in one of the plurality of sequences of steps, identify a linkage between the security indicator and a further security indicator from the one of the plurality of sequences of steps; and

predict occurrence of a potential attack from an Internet protocol (IP) address included in the further security indicator.

15. The system of claim 14 , wherein the security indicator comprises at least one of: an IP address, a type of an attack, an attack timing, a domain related to an attack, and a location related to an attack.

16. The system of claim 14 , wherein a sequence of steps of the plurality of sequences of steps includes a combination selected from at least two of reconnaissance, perimeter infiltration, internal network zone infiltration, discovery, capture, exfiltration, and payload installation.

17. The system of claim 14 , wherein the identified linkage between the security indicator and the further security indicator is one of a temporal linkage, a spatial linkage, or a behavioral linkage.

18. The system of claim 14 , wherein the first sequence of steps comprises a perimeter infiltration step and a data exfiltration step, and the second sequence of steps comprises installation of data payloads in a network.

19. A method performed by a system comprising a hardware processor, comprising:

receiving data that is related to network activity of a network;

applying a linkage to the received data to determine a plurality of sequences of steps that are involved in attacks against the network, the linkage comprising at least one selected from among temporal, spatial, or behavioral linkages, and the plurality of sequences of steps comprises a first sequence of steps and a second sequence of steps different from the first sequence of steps;

analyzing the plurality of sequences of steps to determine whether a security indicator that is related to a potential attack against the network matches a step in one of the plurality of sequences of steps;

in response to a determination that the security indicator matches a step in one of the plurality of sequences of steps, identifying a linkage selected from the at least one of: the temporal, spatial, or behavioral linkages between the security indicator and a further security indicator from the one of the plurality of sequences of steps; and

predicting that the potential attack is likely to occur from a network address included in the further security indicator.

20. The method of claim 19 , wherein the temporal linkage is related to an order of steps in a sequence of steps of the plurality of sequences of steps, the spatial linkage is related to an origination location of an attack in a sequence of steps of the plurality of sequences of steps, and the behavioral linkage is related to an occurrence of events and actions in a sequence of steps of the plurality of sequences of steps.

21. The method of claim 19 , further comprising:

determining a confidence in an attack prediction represented by the identification of the linkage between the security indicator and the further security indicator.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2017
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 043626/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2017
From: SINGLA, ANURAG; ROSS, EDWARD; HEIN, BRIAN FREDERIK HOSEA CHE
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 041035/0064 →