IP Library Granted Patent US 10,474,788
Granted Patent B2
US 10,474,788 · App. 15/637,765 · Granted Nov 12, 2019

Artificial intelligence (AI) techniques for learning and modeling internal networks

Inventors: Almog Ohayon (Tel Aviv, IL); Guy Franco (Tel Aviv, IL); Roi Abutbul (Be'er Sheva, IL)
Assignee: Symantec Corporation
G06F17/509G06N20/00H04L41/12H04L41/145H04L41/16H04L41/0866H04L61/1505H04L61/255
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,474,788
App. No.
15/637,765
Granted
Nov 12, 2019
Kind
B2
Abstract

Introduced here are techniques for modeling networks in a discrete manner. More specifically, various embodiments concern a virtual machine that collects data regarding a network and applies algorithms to the data to discover network elements, which can be used to discover the topology of the network and model the network. The algorithms applied by the virtual machine may also recognize patterns within the data corresponding to naming schemes, subnet structures, application logic, etc. In some embodiments, the algorithms employ artificial intelligence techniques in order to more promptly respond to changes in the data. The virtual machine may only have read-only access to certain objects residing within the network. For example, the virtual machine may be able to examine information hosted by a directory server, but the virtual machine may not be able to effect any changes to the information.

Claims (59)

1. A computer-implemented method for modeling an internal network, the method comprising:

causing a security module to be installed on a computing device executing a Microsoft Windows operating system,

wherein the computing device resides within an internal network;

establishing a communication link between the security module and an Active Directory database that includes valid network identities used to facilitate a directory service for the internal network;

executing one or more algorithms that identify common characteristics of the valid network identities;

creating a model of the valid network identities based on the common characteristics;

continually monitoring whether changes have been made to the valid network identities; and

in response to determining that a change was made to a valid network identity,

modifying the model of the valid network identities to account for the change.

2. The computer-implemented of claim 1 , wherein the security module is executed by a virtual machine hosted on the computing device.

3. The computer-implemented method of claim 1 , further comprising:

injecting supplemental information into an operating system process responsible for enforcing a security policy on the computing device;

determining that an attempt was made to access the internal network using the supplemental information; and

notifying a network administrator of the attempt.

4. The computer-implemented method of claim 3 , wherein the operating system process includes one or more valid identities corresponding to one or more authenticated users of the internal network.

5. The computer-implemented method of claim 3 , wherein the computing device executes a Microsoft Windows operating system, and wherein the operating system process is a Local Security Authority Subsystem Service (LSASS).

6. The computer-implemented method of claim 3 , wherein the attempt to access the internal network is indicative of an unauthorized entity attempting to breach the internal network.

7. The computer-implemented method of claim 3 , wherein the network administrator is responsible for managing the internal network, the security module, or both.

8. The computer-implemented method of claim 1 , wherein the computing device is a server or an endpoint device.

9. A computer-implemented method comprising:

installing a virtual machine on a computing device that resides within a network;

communicatively coupling the virtual machine to an identity database that includes valid network identities used to facilitate a directory service for the network;

executing an algorithm that identifies common characteristics of the valid network identities;

creating a model of the valid network identities based on the common characteristics;

performing a system operation using the model;

continually monitoring whether changes have been made to any of a subset of the valid network identities; and

in response to determining that a change was made to a valid network identity included in the subset, modifying the model of the valid network identities to account for the change.

10. The computer-implemented method of claim 9 , wherein the network is an internal network associated with an enterprise.

11. The computer-implemented method of claim 9 , wherein the algorithm employs artificial intelligence techniques, data mining techniques, machine learning techniques, or some combination thereof.

12. The computer-implemented method of claim 9 , wherein creating the model of the valid network identities comprises:

parsing the valid network identities to identify an identity syntax; and

crafting an executable in accordance with the identity syntax so that the executable is indistinguishable from authentic executables maintained by the computing device.

13. The computer-implemented method of claim 9 , wherein the subset includes valid network identities having a specified characteristic.

14. The computer-implemented method of claim 9 , further comprising:

notifying a network administrator of an occurrence of said modifying.

15. The computer-implemented method of claim 14 , wherein notifying the network administrator comprises performing at least one of:

transmitting an email message to an email address associated with the network administrator;

transmitting a text message to a phone number associated with the network administrator;

causing a push notification to be presented by an application running on a user device associated with the network administrator; and

causing an alert to be generated by a software program running on a user device associated with the network administrator.

16. A computer-implemented method comprising:

installing a virtual machine on a computing device that resides within a network;

communicatively coupling the virtual machine to an identity database that includes valid network identities used to facilitate a directory service for the network;

executing an algorithm that identifies common characteristics of the valid network identities;

creating a model of the valid network identities based on the common characteristics, wherein creating the model of the valid network identities comprises parsing the valid network identities to identify an identity syntax, and crafting an executable in accordance with the identity syntax so that the executable is indistinguishable from authentic executables maintained by the computing device; and

performing a system operation using the model.

17. The computer-implemented method of claim 16 , wherein the network is an internal network associated with an enterprise.

18. The computer-implemented method of claim 16 , wherein the algorithm employs artificial intelligence techniques, data mining techniques, machine learning techniques, or some combination thereof.

19. The computer-implemented method of claim 16 , further comprising:

continually monitoring whether changes have been made to any of a subset of the valid network identities; and

in response to determining that a change was made to a valid network identity included in the subset, modifying the model of the valid network identities to account for the change.

20. The computer-implemented method of claim 19 , wherein the subset includes valid network identities having a specified characteristic.

21. The computer-implemented method of claim 19 , further comprising:

notifying a network administrator of an occurrence of said modifying.

22. The computer-implemented method of claim 21 , wherein notifying the network administrator comprises performing at least one of:

transmitting an email message to an email address associated with the network administrator;

transmitting a text message to a phone number associated with the network administrator;

causing a push notification to be presented by an application running on a user device associated with the network administrator; and

causing an alert to be generated by a software program running on a user device associated with the network administrator.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2019
From: OHAYON, ALMOG; FRANCO, GUY; ABUTBUL, ROI
To: SYMANTEC CORPORATION
Reel/Frame 050416/0394 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2019
From: JAVELIN NETWORKS LLC
To: SYMANTEC CORPORATION
Reel/Frame 049307/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2018
From: OHAYON, ALMOG; FRANCO, GUY; ABUTBUL, ROI
To: JAVELIN NETWORKS, INC.
Reel/Frame 045752/0137 →
Continuity (2)
Provisional Application 62356391 · Jun 29, 2016
Related Publication 20180004870A1 · Jan 4, 2018