IP Library Granted Patent US 12,613,958
Granted Patent B2
US 12,613,958 · App. 18/762,308 · Granted Apr 28, 2026

Temporal cause analysis of cybersecurity events

Inventors: Barak Bercovitz (Even-Yehuda, IL); Tomer Schwartz (Tel Aviv, IL); Bernie Pinkenzon-Howard (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,613,958
App. No.
18/762,308
Granted
Apr 28, 2026
Kind
B2
Abstract

A system and method for temporal cause analysis of cybersecurity events. A method includes: creating a plurality of time series pairs for a computing environment, wherein each time series pair includes a first time series and a second time series, wherein each time series includes a series of data points arranged by time; determining a temporal relationship for at least one first time series pair of the plurality of time series pairs based on the series of data points of each time series of each of the plurality of time series pairs; identifying a root cause of a cyber event based on the temporal relationship of the at least one first time series pair; and remediating the cyber event based on the identified root cause.

Claims (51)

1 . A method for temporal cause analysis of cybersecurity events, comprising:

creating a plurality of time series pairs for a computing environment, wherein each time series pair includes a first time series and a second time series, wherein each time series includes a series of data points arranged by time;

determining a temporal relationship for at least one first time series pair of the plurality of time series pairs based on the series of data points of each time series of each of the plurality of time series pairs, wherein determining the temporal relationship for the at least one first time series pair further comprises:

identifying a plurality of events represented by each time series, each event having a corresponding time; and

analyzing the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs, wherein the temporal relationship for the at least one first time series pair is determined based on the analysis, wherein analyzing the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs further comprises:

calculating a plurality of distances between times of events of the first time series and times of events of the second time series of each time series pair, wherein the temporal relationship for the at least one first time series pair is determined based further on the calculated plurality of distances;

determining, for each of at least one antecedent-consequent time series pair among the plurality of time series pairs, that the first time series of the antecedent-consequent time series pair is an antecedent time series of the antecedent-consequent time series pair and that the second time series of the antecedent-consequent time series pair is a consequent time series of the antecedent-consequent time series pair based on the times of the events of the first time series and times of corresponding events among the events of the second time series of each time series pair;

identifying a root cause of a cyber event based on the temporal relationship of the at least one first time series pair; and

remediating the cyber event based on the identified root cause.

2 . The method of claim 1 , wherein the plurality of distances is calculated using dynamic time warping.

3 . The method of claim 1 , wherein identifying the root cause of the cyber event further comprises:

identifying a consequent time series among the plurality of time series pairs to which the cyber event belongs;

identifying an antecedent time series for the identified consequent time series based on the at least one antecedent-consequent time series pair; and

determining an antecedent event for the cyber event in the antecedent time series for the identified consequent time series, wherein the root cause of the cyber event is identified based on the determined antecedent event for the cyber event.

4 . The method of claim 3 , wherein determining the antecedent event for the cyber event further comprises:

analyzing a plurality of time deltas between events of the identified antecedent time series and the cyber event, wherein the antecedent event for the cyber event is identified based on the analyzed plurality of time deltas.

5 . The method of claim 1 , wherein identifying the plurality of events represented by a first time series of the plurality of time series further comprises:

determining the plurality of events of the first time series based on a plurality of values of the first time series, each of the plurality of values having a corresponding time; and

determining a time for each of the plurality of events of the first time series based on the corresponding times for the plurality of values of the first time series.

6 . The method of claim 1 , wherein the root cause of the cyber event is any of: an entity deployed in the computing environment, an activity performed with respect to the computing environment, and a condition of the computing environment.

7 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

creating a plurality of time series pairs for a computing environment, wherein each time series pair includes a first time series and a second time series, wherein each time series includes a series of data points arranged by time;

determining a temporal relationship for at least one first time series pair of the plurality of time series pairs based on the series of data points of each time series of each of the plurality of time series pairs, wherein determining the temporal relationship for the at least one first time series pair further comprises:

identifying a plurality of events represented by each time series, each event having a corresponding time; and

analyzing the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs, wherein the temporal relationship for the at least one first time series pair is determined based on the analysis, wherein analyzing the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs further comprises:

calculating a plurality of distances between times of events of the first time series and times of events of the second time series of each time series pair, wherein the temporal relationship for the at least one first time series pair is determined based further on the calculated plurality of distances;

determining, for each of at least one antecedent-consequent time series pair among the plurality of time series pairs, that the first time series of the antecedent-consequent time series pair is an antecedent time series of the antecedent-consequent time series pair and that the second time series of the antecedent-consequent time series pair is a consequent time series of the antecedent-consequent time series pair based on the times of the events of the first time series and times of corresponding events among the events of the second time series of each time series pair;

identifying a root cause of a cyber event based on the temporal relationship of the at least one first time series pair; and

remediating the cyber event based on the identified root cause.

8 . A system for temporal cause analysis of cybersecurity events, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

create a plurality of time series pairs for a computing environment, wherein each time series pair includes a first time series and a second time series, wherein each time series includes a series of data points arranged by time;

determine a temporal relationship for at least one first time series pair of the plurality of time series pairs based on the series of data points of each time series of each of the plurality of time series pairs, wherein determining the temporal relationship for the at least one first time series pair further comprises:

identify a plurality of events represented by each time series, each event having a corresponding time; and

analyze the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs, wherein the temporal relationship for the at least one first time series pair is determined based on the analysis, wherein analyzing the corresponding times for the plurality of events between the first and second time series of each of the plurality of time series pairs further comprises:

calculate a plurality of distances between times of events of the first time series and times of events of the second time series of each time series pair, wherein the temporal relationship for the at least one first time series pair is determined based further on the calculated plurality of distances;

determine, for each of at least one antecedent-consequent time series pair among the plurality of time series pairs, that the first time series of the antecedent-consequent time series pair is an antecedent time series of the antecedent-consequent time series pair and that the second time series of the antecedent-consequent time series pair is a consequent time series of the antecedent-consequent time series pair based on the times of the events of the first time series and times of corresponding events among the events of the second time series of each time series pair;

identify a root cause of a cyber event based on the temporal relationship of the at least one first time series pair; and

remediate the cyber event based on the identified root cause.

9 . The system of claim 8 , wherein the plurality of distances is calculated using dynamic time warping.

10 . The system of claim 8 , wherein the system is further configured to:

identify a consequent time series among the plurality of time series pairs to which the cyber event belongs;

identify an antecedent time series for the identified consequent time series based on the at least one antecedent-consequent time series pair; and

determine an antecedent event for the cyber event in the antecedent time series for the identified consequent time series, wherein the root cause of the cyber event is identified based on the determined antecedent event for the cyber event.

11 . The system of claim 10 , wherein the system is further configured to:

analyzing a plurality of time deltas between events of the identified antecedent time series and the cyber event, wherein the antecedent event for the cyber event is identified based on the analyzed plurality of time deltas.

12 . The system of claim 8 , wherein the system is further configured to:

determine the plurality of events of the first time series based on a plurality of values of the first time series, each of the plurality of values having a corresponding time; and

determine a time for each of the plurality of events of the first time series based on the corresponding times for the plurality of values of the first time series.

13 . The system of claim 8 , wherein the root cause of the cyber event is any of: an entity deployed in the computing environment, an activity performed with respect to the computing environment, and a condition of the computing environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2025
From: DAZZ, INC.
To: WIZ, INC.
Reel/Frame 071645/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: BERCOVITZ, BARAK; SCHWARTZ, TOMER; PINKENZON-HOWARD, BERNIE
To: DAZZ, INC.
Reel/Frame 067898/0931 →
Continuity (1)
Related Publication 20260010620A1 · Jan 8, 2026
References Cited (37)
US 8468244B2 · Redlich et al. · 2013 [cited by applicant]
US 8639506B2 · Miro et al. · 2014 [cited by applicant]
US 9800592B2 · Jain et al. · 2017 [cited by applicant]
US 10516857B2 · Lam et al. · 2019 [cited by applicant]
US 10546183B2 · Rodriguez et al. · 2020 [cited by applicant]
US 10929220B2 · Song · 2021 [cited by examiner]
US 10956566B2 · Shu · 2021 [cited by examiner]
US 11178166B2 · Al Faruque et al. · 2021 [cited by applicant]
US 11494618B2 · Xia · 2022 [cited by examiner]
US 11743287B2 · Nagarajegowda · 2023 [cited by examiner]
US 12153669B2 · Arnon · 2024 [cited by examiner]
US 12355794B1 · Black · 2025 [cited by examiner]
US 20150312304A1 · Landais et al. · 2015 [cited by applicant]
US 20170119283A1 · Ten Kate et al. · 2017 [cited by applicant]
US 20170364803A1 · Calmon et al. · 2017 [cited by applicant]
US 20180234447A1 · Mueen et al. · 2018 [cited by applicant]
US 20190087469A1 · Zhang · 2019 [cited by examiner]
US 20190114244A1 · Salunke et al. · 2019 [cited by applicant]
US 20200159600A1 · Thakore et al. · 2020 [cited by applicant]
US 20200201701A1 · Wang et al. · 2020 [cited by applicant]
US 20200233019A1 · Atobe · 2020 [cited by applicant]
US 20210026830A1 · Jain · 2021 [cited by examiner]
US 20210201165A1 · Pedersen · 2021 [cited by applicant]
US 20220078210A1 · Crabtree et al. · 2022 [cited by applicant]
US 20230092190A1 · Homayoun et al. · 2023 [cited by applicant]
US 20230144690A1 · Gou et al. · 2023 [cited by applicant]
US 20230325269A1 · Gusat et al. · 2023 [cited by applicant]
US 20230342454A1 · Pierre et al. · 2023 [cited by applicant]
US 20240005143A1 · Adcock · 2024 [cited by examiner]
US 20240118965A1 · Ashrafi et al. · 2024 [cited by applicant]
US 20240134978A1 · Licudi et al. · 2024 [cited by applicant]
US 20240346287A1 · Keshva Srinivas · 2024 [cited by examiner]
US 20250181712A1 · Kosan et al. · 2025 [cited by applicant]
EP 4303775A1 · 2024 [cited by applicant]
“Dynamic Time Warping,” Papers with Code (available at https://paperswithcode.com/method/dtw) (last accessed May 3, 2024 at 3:47 PM EST). [cited by applicant]
International Search Report for PCT/IB2025/056415, dated Sep. 1, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2025/056415, dated Sep. 1, 2025. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]