US2018255080A1PendingUtilityA1

System and Method for Cyber Security Threat Detection

Assignee: ResponSight Pty LtdPriority: Mar 2, 2017Filed: Feb 26, 2018Published: Sep 6, 2018
Est. expiryMar 2, 2037(~10.6 yrs left)· nominal 20-yr term from priority
Inventors:Jeffrey Paine
H04L 63/20H04L 63/1466H04L 63/1433H04L 63/1416H04L 63/145H04L 63/1425G06F 21/554G06F 21/552G06F 21/57G06F 2221/034H04L 2463/141H04L 63/18H04L 67/10G06F 21/55
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system includes one or more collector engines. Each of the collector engines includes a service and an agent operating on a corresponding system endpoint of the system endpoints. The service is configured to take a first snapshot of the corresponding system endpoint. The first snapshot includes event activity information associated with the system endpoint. The agent is configured to take a second snapshot of the corresponding system endpoint. The second snapshot includes behavioral activity information associated with the corresponding system endpoint. The system further includes an aggregator engine configured to aggregate the first snapshot and the second snapshot from each of the system endpoints into an aggregated snapshot. The system further includes one or more analytics engines configured to: generate and store baseline profiles associated with the system endpoints based on a previously received aggregated snapshot, receive the aggregated snapshot from the aggregator engine, determine deviation values for each of the system endpoints based on the received aggregated snapshot and the stored baseline profiles, and generate, for each of the system endpoints, a cumulative risk value based on the deviation values. The system further includes one or more alerting engines configured to determine whether to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the cumulative risk value.

Claims

exact text as granted — not AI-modified
1 .- 22 . (canceled) 
     
     
         23 . A cyber security threat detection system operating within a computing environment, the system comprising:
 one or more collector engines operating at least in part within a computing environment, and configured to acquire behavioral activity information over a period of time;   a prediction engine operating on the acquired behavioral activity information, and configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine a probability of occurrence of the new behavioral activity based on the comparison;   an analytics engine configured to generate a security risk level based on the probability of occurrence of the new behavioral activity; and   an alerting engine configured to issue one or more alerts in response to a determination that the security risk level has exceeded a risk threshold.   
     
     
         24 . The cyber security threat detection system of  claim 23 , wherein the probability of occurrence of the new behavioral activity increases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity. 
     
     
         25 . The cyber security threat detection system of  claim 23 , wherein the probability of occurrence of the new behavioral activity decreases if the new behavioral activity diverges from the expected behavioral activity, thereby indicating a possible security breach. 
     
     
         26 . The cyber security threat detection system of  claim 23 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa. 
     
     
         27 . The cyber security threat detection system of  claim 23 , wherein each of the one or more collector engines is installed on an endpoint operating within the computing environment. 
     
     
         28 . The cyber security threat detection system of  claim 23 , wherein the probability of occurrence of the new behavioral activity is combined with additional metrics to derive an overall security risk level. 
     
     
         29 . The cyber security threat detection system of  claim 23 , wherein the computing environment includes one or more operations in a cloud service. 
     
     
         30 . The cyber security threat detection system of  claim 24 , wherein a probability of breach decreases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity. 
     
     
         31 . The cyber security threat detection system of  claim 30 , wherein the probability of breach increases if the new behavioral activity diverges from the expected behavioral activity. 
     
     
         32 . A cyber security threat detection system operating within a computing environment, the system comprising:
 one or more collector engines operating at least in part within a computing environment, and configured to acquire behavioral activity information over a period of time;   a prediction engine operating on the acquired behavioral activity information, and configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine whether an activity with a high probability of occurrence from the new behavioral activity is absent based on the comparison;   an analytics engine configured to generate a security risk level based on the determination whether the expected activity is absent; and   an alerting engine configured to issue one or more alerts in response to a determination that the security risk level has exceeded a risk threshold.   
     
     
         33 . The cyber security threat detection system of  claim 32 , wherein the security risk level increases in response to a determination that the activity with the high probability of occurrence from the new behavioral activity is absent. 
     
     
         34 . The cyber security threat detection system of  claim 32 , wherein each of the one or more collector engines is installed on an endpoint operating within the computing environment. 
     
     
         35 . The cyber security threat detection system of  claim 33 , wherein the absent activity includes a service normally present within the computing environment, but has suddenly disappeared, has become disabled, or is not operating. 
     
     
         36 . The cyber security threat detection system of  claim 33 , wherein the absent activity includes an absence of a metric. 
     
     
         37 . The cyber security threat detection system of  claim 36 , wherein the absence of a metric increases a probability of abnormal behavior and a weighted risk level associated the metric. 
     
     
         38 . The cyber security threat detection system of  claim 32 , wherein the computing environment includes one or more operations in a cloud service. 
     
     
         39 . A computer-implemented method for cyber security threat detection, the method implemented by one or more processors operating within a computing environment, the method comprising:
 receiving behavioral activity information that has been acquired over a period of time;   operating on the received behavioral activity information to predict expected behavioral activity based on historic behavioral activity from the received behavioral activity information; and   determining a probability of occurrence of new behavioral activity based on a comparison of the new behavioral activity with the expected behavioral activity.   
     
     
         40 . The method of  claim 39 , wherein the comparison determines activity deviations between the new behavioral activity and the expected behavioral activity. 
     
     
         41 . The method of  claim 39 , further comprising:
 generating a security risk level based on the probability of occurrence of the new behavioral activity.   
     
     
         42 . The method of  claim 40 , wherein determining the probability of occurrence of new behavioral activity comprises increasing the probability of occurrence if the new behavioral activity substantially behaves in accordance with the expected behavioral activity. 
     
     
         43 . The method of  claim 40 , wherein determining the probability of occurrence of new behavioral activity comprises decreasing the probability of occurrence if the new behavioral activity diverges from the expected behavioral activity. 
     
     
         44 . The method of  claim 41 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa. 
     
     
         45 . The method of  claim 41 , wherein
 operating on the received behavioral activity information to predict expected behavioral activity comprises predicting an operation pattern that an application is expected to follow using the historic behavioral activity, and   the probability of occurrence of new behavioral activity is a determined probability that the application follows the predicted operation pattern.   
     
     
         46 . The method of  claim 45 , wherein the security risk level is generated based on an amount of diversion from the predicted operation pattern. 
     
     
         47 . The method of  claim 46 , further comprising assigning a weighted risk value to each successive diversion from the predicted operation pattern. 
     
     
         48 . The method of  claim 39 , wherein the received behavioral activity information is collected from one or more endpoints operating within the computing environment. 
     
     
         49 . The method of  claim 39 , wherein the computing environment includes one or more operations in a cloud service.

Join the waitlist — get patent alerts

Track US2018255080A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.