US2017223030A1PendingUtilityA1
Detection of security transactions
Est. expiryJan 29, 2036(~9.5 yrs left)· nominal 20-yr term from priority
Inventors:Munawar Monzy Merza
H04L 63/02H04L 63/1416
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
In a method, a plurality of events is accessed, wherein an event of the plurality of events includes a portion of raw-machine data from a data source of a plurality of data sources. For at least one event of the plurality of events, a transaction phase of a computer security transaction is correlated with the at least one event based at least in part on a data source associated with the at least one event. The transaction phase of the at least one event is correlated with a particular asset of a plurality of assets.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources; for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and correlating the transaction phase of the at least one event with a particular asset of a plurality of assets.
2 . The method of claim 1 wherein the computer security transaction includes a. plurality of transaction phases indicative of a progressive cyber-attack.
3 . The method of claim 2 , wherein the plurality of transaction phases are defined by an attack chain security model, wherein the plurality of transaction phases comprises: a reconnaissance transaction phase, a weaponizati on transaction phase, a delivery transaction phase, an exploitation transaction phase, an installation transaction phase, a command and control transaction phase, and an actions on objectives transaction phase.
4 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to receiving the event of the plurality of events.
5 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to searching the plurality of events.
6 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to indexing the plurality of events.
7 . The method of claim 1 , wherein the data source is one of an intrusion detection system (IDS), a next-generation firewall (NGFW) device, an anti-virus (AV) application, an endpoint threat detection and response (ETDR) application, an electronic mail (e-mail) application, and an operating system.
8 . The method of claim 1 , wherein the correlating the transaction phase of the at least one event with a particular asset associated with the at least one event comprises:
correlating the transaction phase of the at least one event with a particular user associated with the particular asset and associated with the at least one event.
9 . The method of claim 1 , further comprising:
aggregating transactions phases for the plurality of assets.
10 . The method of claim 9 , further comprising:
providing an indication of particular assets having correlated transaction phases, the indication identifying the correlated transaction phases for the particular assets.
11 . The method of claim 1 , further comprising:
responsive to a determining that the transaction phase has occurred, generating a notification indicating that the transaction phase involving the particular asset has occurred.
12 . The method of claim 1 , further comprising:
responsive to determining that a plurality of transaction phases of the computer security transaction has occurred for a particular asset, generating a notification indicating that the plurality of transaction phases of the computer security transaction has occurred.
13 . The method of claim 12 , further comprising:
responsive to the plurality of transaction phases comprising non-successive transaction phases of the computer security transaction, generating a notification indicating a potential visibility gap in the detection of transaction phases of the computer security transaction.
14 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:
accessing a table of a plurality of sources and respective corresponding transaction phases.
15 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:
for the at least one event in the plurality of events, generating a metadata field identifying the transaction phase associated with the at least one event.
16 . The method of claim 15 , further comprising:
searching the plurality of events to identify an event that indicates an association between a particular user identifier and the particular asset; and in response to the search, generating a data structure for storing the association between the particular asset and the particular user identifier.
17 . The method of claim 16 , wherein the correlating the transaction phase of the at least one event with a particular asset of a plurality of assets comprises:
updating the data structure to append the metadata field to the association between the particular asset and the particular user identifier.
18 . The method of claim 16 , wherein the event that indicates an association between the particular user and the particular asset is a successful authentication operation of the particular user identifier on the particular asset.
19 . The method of claim 1 , further comprising:
searching, based on a set of criteria, the plurality of events to identify the at least one ever
20 . A system, comprising:
one or more data processors; and a non-transitory computer-readable storage medium containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including:
accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;
for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data. source associated with the at least one event; and
correlating the transaction phase of the at least one event with a particular asset of a plurality of assets.
21 . A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to:
access a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources; for at least one event of the plurality of events, correlate a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and correlate the transaction phase of the at least one event with a particular asset of a plurality of assets.Join the waitlist — get patent alerts
Track US2017223030A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.