System and Method for Cyber Security Threat Detection
Abstract
A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system includes one or more collector engines. Each of the collector engines includes a service and an agent operating on a corresponding system endpoint of the system endpoints. The service is configured to take a first snapshot of the corresponding system endpoint. The first snapshot includes event activity information associated with the system endpoint. The agent is configured to take a second snapshot of the corresponding system endpoint. The second snapshot includes behavioral activity information associated with the corresponding system endpoint. The system further includes an aggregator engine configured to aggregate the first snapshot and the second snapshot from each of the system endpoints into an aggregated snapshot. The system further includes one or more analytics engines configured to: generate and store baseline profiles associated with the system endpoints based on a previously received aggregated snapshot, receive the aggregated snapshot from the aggregator engine, determine deviation values for each of the system endpoints based on the received aggregated snapshot and the stored baseline profiles, and generate, for each of the system endpoints, a cumulative risk value based on the deviation values. The system further includes one or more alerting engines configured to determine whether to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the cumulative risk value.
Claims
exact text as granted — not AI-modified1 .- 22 . (canceled)
23 . A cyber security threat detection system operating within a computing environment, the system comprising:
one or more collector engines operating at least in part within a computing environment, and configured to acquire behavioral activity information over a period of time; a prediction engine operating on the acquired behavioral activity information, and configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine a probability of occurrence of the new behavioral activity based on the comparison; an analytics engine configured to generate a security risk level based on the probability of occurrence of the new behavioral activity; and an alerting engine configured to issue one or more alerts in response to a determination that the security risk level has exceeded a risk threshold.
24 . The cyber security threat detection system of claim 23 , wherein the probability of occurrence of the new behavioral activity increases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity.
25 . The cyber security threat detection system of claim 23 , wherein the probability of occurrence of the new behavioral activity decreases if the new behavioral activity diverges from the expected behavioral activity, thereby indicating a possible security breach.
26 . The cyber security threat detection system of claim 23 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa.
27 . The cyber security threat detection system of claim 23 , wherein each of the one or more collector engines is installed on an endpoint operating within the computing environment.
28 . The cyber security threat detection system of claim 23 , wherein the probability of occurrence of the new behavioral activity is combined with additional metrics to derive an overall security risk level.
29 . The cyber security threat detection system of claim 23 , wherein the computing environment includes one or more operations in a cloud service.
30 . The cyber security threat detection system of claim 24 , wherein a probability of breach decreases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity.
31 . The cyber security threat detection system of claim 30 , wherein the probability of breach increases if the new behavioral activity diverges from the expected behavioral activity.
32 . A cyber security threat detection system operating within a computing environment, the system comprising:
one or more collector engines operating at least in part within a computing environment, and configured to acquire behavioral activity information over a period of time; a prediction engine operating on the acquired behavioral activity information, and configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine whether an activity with a high probability of occurrence from the new behavioral activity is absent based on the comparison; an analytics engine configured to generate a security risk level based on the determination whether the expected activity is absent; and an alerting engine configured to issue one or more alerts in response to a determination that the security risk level has exceeded a risk threshold.
33 . The cyber security threat detection system of claim 32 , wherein the security risk level increases in response to a determination that the activity with the high probability of occurrence from the new behavioral activity is absent.
34 . The cyber security threat detection system of claim 32 , wherein each of the one or more collector engines is installed on an endpoint operating within the computing environment.
35 . The cyber security threat detection system of claim 33 , wherein the absent activity includes a service normally present within the computing environment, but has suddenly disappeared, has become disabled, or is not operating.
36 . The cyber security threat detection system of claim 33 , wherein the absent activity includes an absence of a metric.
37 . The cyber security threat detection system of claim 36 , wherein the absence of a metric increases a probability of abnormal behavior and a weighted risk level associated the metric.
38 . The cyber security threat detection system of claim 32 , wherein the computing environment includes one or more operations in a cloud service.
39 . A computer-implemented method for cyber security threat detection, the method implemented by one or more processors operating within a computing environment, the method comprising:
receiving behavioral activity information that has been acquired over a period of time; operating on the received behavioral activity information to predict expected behavioral activity based on historic behavioral activity from the received behavioral activity information; and determining a probability of occurrence of new behavioral activity based on a comparison of the new behavioral activity with the expected behavioral activity.
40 . The method of claim 39 , wherein the comparison determines activity deviations between the new behavioral activity and the expected behavioral activity.
41 . The method of claim 39 , further comprising:
generating a security risk level based on the probability of occurrence of the new behavioral activity.
42 . The method of claim 40 , wherein determining the probability of occurrence of new behavioral activity comprises increasing the probability of occurrence if the new behavioral activity substantially behaves in accordance with the expected behavioral activity.
43 . The method of claim 40 , wherein determining the probability of occurrence of new behavioral activity comprises decreasing the probability of occurrence if the new behavioral activity diverges from the expected behavioral activity.
44 . The method of claim 41 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa.
45 . The method of claim 41 , wherein
operating on the received behavioral activity information to predict expected behavioral activity comprises predicting an operation pattern that an application is expected to follow using the historic behavioral activity, and the probability of occurrence of new behavioral activity is a determined probability that the application follows the predicted operation pattern.
46 . The method of claim 45 , wherein the security risk level is generated based on an amount of diversion from the predicted operation pattern.
47 . The method of claim 46 , further comprising assigning a weighted risk value to each successive diversion from the predicted operation pattern.
48 . The method of claim 39 , wherein the received behavioral activity information is collected from one or more endpoints operating within the computing environment.
49 . The method of claim 39 , wherein the computing environment includes one or more operations in a cloud service.Join the waitlist — get patent alerts
Track US2018255080A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.