US2017223030A1PendingUtilityA1

Detection of security transactions

Assignee: SPLUNK INCPriority: Jan 29, 2016Filed: Jan 29, 2016Published: Aug 3, 2017
Est. expiryJan 29, 2036(~9.5 yrs left)· nominal 20-yr term from priority
H04L 63/02H04L 63/1416
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a method, a plurality of events is accessed, wherein an event of the plurality of events includes a portion of raw-machine data from a data source of a plurality of data sources. For at least one event of the plurality of events, a transaction phase of a computer security transaction is correlated with the at least one event based at least in part on a data source associated with the at least one event. The transaction phase of the at least one event is correlated with a particular asset of a plurality of assets.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;   for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and   correlating the transaction phase of the at least one event with a particular asset of a plurality of assets.   
     
     
         2 . The method of  claim 1  wherein the computer security transaction includes a. plurality of transaction phases indicative of a progressive cyber-attack. 
     
     
         3 . The method of  claim 2 , wherein the plurality of transaction phases are defined by an attack chain security model, wherein the plurality of transaction phases comprises: a reconnaissance transaction phase, a weaponizati on transaction phase, a delivery transaction phase, an exploitation transaction phase, an installation transaction phase, a command and control transaction phase, and an actions on objectives transaction phase. 
     
     
         4 . The method of  claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to receiving the event of the plurality of events. 
     
     
         5 . The method of  claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to searching the plurality of events. 
     
     
         6 . The method of  claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to indexing the plurality of events. 
     
     
         7 . The method of  claim 1 , wherein the data source is one of an intrusion detection system (IDS), a next-generation firewall (NGFW) device, an anti-virus (AV) application, an endpoint threat detection and response (ETDR) application, an electronic mail (e-mail) application, and an operating system. 
     
     
         8 . The method of  claim 1 , wherein the correlating the transaction phase of the at least one event with a particular asset associated with the at least one event comprises:
 correlating the transaction phase of the at least one event with a particular user associated with the particular asset and associated with the at least one event.   
     
     
         9 . The method of  claim 1 , further comprising:
 aggregating transactions phases for the plurality of assets.   
     
     
         10 . The method of  claim 9 , further comprising:
 providing an indication of particular assets having correlated transaction phases, the indication identifying the correlated transaction phases for the particular assets.   
     
     
         11 . The method of  claim 1 , further comprising:
 responsive to a determining that the transaction phase has occurred, generating a notification indicating that the transaction phase involving the particular asset has occurred.   
     
     
         12 . The method of  claim 1 , further comprising:
 responsive to determining that a plurality of transaction phases of the computer security transaction has occurred for a particular asset, generating a notification indicating that the plurality of transaction phases of the computer security transaction has occurred.   
     
     
         13 . The method of  claim 12 , further comprising:
 responsive to the plurality of transaction phases comprising non-successive transaction phases of the computer security transaction, generating a notification indicating a potential visibility gap in the detection of transaction phases of the computer security transaction.   
     
     
         14 . The method of  claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:
 accessing a table of a plurality of sources and respective corresponding transaction phases.   
     
     
         15 . The method of  claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:
 for the at least one event in the plurality of events, generating a metadata field identifying the transaction phase associated with the at least one event.   
     
     
         16 . The method of  claim 15 , further comprising:
 searching the plurality of events to identify an event that indicates an association between a particular user identifier and the particular asset; and   in response to the search, generating a data structure for storing the association between the particular asset and the particular user identifier.   
     
     
         17 . The method of  claim 16 , wherein the correlating the transaction phase of the at least one event with a particular asset of a plurality of assets comprises:
 updating the data structure to append the metadata field to the association between the particular asset and the particular user identifier.   
     
     
         18 . The method of  claim 16 , wherein the event that indicates an association between the particular user and the particular asset is a successful authentication operation of the particular user identifier on the particular asset. 
     
     
         19 . The method of  claim 1 , further comprising:
 searching, based on a set of criteria, the plurality of events to identify the at least one ever   
     
     
         20 . A system, comprising:
 one or more data processors; and   a non-transitory computer-readable storage medium containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including:
 accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources; 
 for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data. source associated with the at least one event; and 
 correlating the transaction phase of the at least one event with a particular asset of a plurality of assets. 
   
     
     
         21 . A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to:
 access a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;   for at least one event of the plurality of events, correlate a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and   correlate the transaction phase of the at least one event with a particular asset of a plurality of assets.

Join the waitlist — get patent alerts

Track US2017223030A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.