IP Library Patent Application 18322558
Patent Application
App. No. 18/322,558

PERFORMING CYBERSECURITY OPERATIONS BASED ON IMPACT SCORES OF COMPUTING EVENTS OVER A ROLLING TIME INTERVAL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/322,558
Abstract

The disclosure herein describes automatically performing security operations associated with a client system based on aggregated event impact scores of computing events during a rolling time interval. Event data is obtained, wherein the event data is from a plurality of computing devices of the client system associated with computing events occurring during a time interval after an endpoint of the rolling time interval. Event impact scores are calculated for the computing events of the obtained event data over the time interval based at least on cardinality estimation. The calculated event impact scores are merged into the set of aggregated event impact scores associated with the rolling time interval and event impact scores associated with an expired time interval are removed from the set of aggregated event impact scores. Based on the set of aggregated event impact scores, at least one security operation is performed for at least one computing event.

Claims (77)

1 . A computerized method of enforcing an event rule based on an aggregated event impact score of computing events during a rolling time interval, the computerized method comprising:

obtaining, by a processor, event data from a plurality of computing devices of a client system, the event data being associated with computing events occurring during a time interval after an endpoint of the rolling time interval;

calculating, by the processor, event impact scores for the computing events of the obtained event data based at least on cardinality estimation;

merging, by the processor, the calculated event impact scores into a set of aggregated event impact scores;

generating, by the processor, a recommended event rule based on the set of aggregated event impact scores; and

enforcing, by the processor, the recommended event rule on the client system.

2 . The computerized method of claim 1 , further comprising:

identifying, by the processor, from the computing events, a computing event associated with an aggregated event impact score, of the set of aggregated event impact scores, that exceeds an impact score threshold;

obtaining, by the processor, an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enabling, by the processor, the existing event rule on the client system.

3 . The computerized method of claim 1 , further comprising:

identifying, by the processor, from the computing events, a computing event associated with an aggregated event impact score, of the set of aggregated event impact scores, that is in an impact score percentile range;

obtaining, by the processor, an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enabling, by the processor, the existing event rule on the client system.

4 . The computerized method of claim 1 , further comprising:

providing, by the processor, the recommended event rule to a user via a recommendation interface;

receiving, by the processor, an approval from the user via the recommendation interface; and

updating, by the processor, the client system to include the recommended event rule.

5 . The computerized method of claim 1 , further comprising:

providing, by the processor, the recommended event rule to a user via a recommendation interface;

receiving, by the processor, feedback from the user via the recommendation interface;

storing, by the processor, the feedback in a recommendations data store; and

using, by the processor, the stored feedback to generate future event rule recommendations.

6 . The computerized method of claim 4 , further comprising:

providing, by the processor, along with the recommended event rule, information indicating how often the recommended event rule is used by another system.

7 . The computerized method of claim 1 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule.

8 . A computer system for enforcing an event rule based on aggregated event impact scores of computing events during a rolling time interval, the computer system comprising:

a processor; and

a non-transitory computer readable medium having stored program code for transferring data to another computer system, the program code causing the processor to:

obtain event data from a plurality of computing devices of a client system associated with computing events occurring during a time interval after an endpoint of the rolling time interval;

calculate event impact scores for the computing events of the obtained event data based at least on cardinality estimation;

merge the calculated event impact scores into a set of aggregated event impact scores;

generate a recommended event rule based on the set of aggregated event impact scores; and

enforce the recommended event rule on the client system.

9 . The computer system of claim 8 , wherein the program code further causes the processor to:

identify, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that exceeds an impact score threshold;

obtain an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enable the existing event rule on the client system.

10 . The computer system of claim 8 , wherein the program code further causes the processor to:

identify, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that is in an impact score percentile range;

obtain an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enable the existing event rule on the client system.

11 . The computer system of claim 8 , wherein the program code further causes the processor to:

provide the recommended event rule to a user via a recommendation interface;

receive an approval from the user via the recommendation interface; and

update the client system to include the recommended event rule.

12 . The computer system of claim 8 , wherein the program code further causes the processor to:

provide the recommended event rule to a user via a recommendation interface;

receive feedback from the user via the recommendation interface;

store the feedback in a recommendations data store; and

use the stored feedback to generate future event rule recommendations.

13 . The computer system of claim 8 , wherein the program code further causes the processor to:

provide, along with the recommended event rule, information indicating how often the recommended event rule is used by other systems.

14 . The computer system of claim 8 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule.

15 . A non-transitory computer storage medium having stored thereon program code executable by a first computer system, the program code embodying a method comprising:

obtaining event data from a plurality of computing devices of a client system associated with computing events occurring during a time interval after an endpoint of a rolling time interval;

calculating event impact scores for the computing events of the obtained event data based at least on cardinality estimation;

merging the calculated event impact scores into a set of aggregated event impact scores;

generating a recommended event rule based on the set of aggregated event impact scores;

providing the recommended event rule to a user via a recommendation interface;

receiving an approval from the user via the recommendation interface; and

enforcing the recommended event rule on the client system.

16 . The non-transitory computer storage medium of claim 15 , wherein the method embodied by the program code further comprises:

identifying, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that exceeds an impact score threshold;

obtaining an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enabling the existing event rule on the client system.

17 . The non-transitory computer storage medium of claim 15 , wherein the method embodied by the program code further comprises:

identifying, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that is in an impact score percentile range;

obtaining an existing event rule configured to trigger a security operation based on detection of the identified computing event; and

enabling the existing event rule on the client system.

18 . The non-transitory computer storage medium of claim 15 , wherein the method embodied by the program code further comprises:

receiving feedback from the user via the recommendation interface;

storing the feedback in a recommendations data store; and

using the stored feedback to generate future event rule recommendations.

19 . The non-transitory computer storage medium of claim 15 , wherein the method embodied by the program code further comprises:

providing, along with the recommended event rule, information indicating how often the recommended event rule is used by other systems.

20 . The non-transitory computer storage medium of claim 15 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule.

Assignments (1)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →