US2019173904A1PendingUtilityA1

Entity Group Behavior Profiling

Assignee: HEWLETT PACKARD ENTPR DEV LPPriority: Jun 23, 2014Filed: Feb 5, 2019Published: Jun 6, 2019
Est. expiryJun 23, 2034(~7.9 yrs left)· nominal 20-yr term from priority
Inventors:Jisheng Wang
H04L 63/1425H04W 4/38
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Entity group behavior profiling. An entity group is created that includes multiple entities, where each entity represents one of a user, a machine, and a service. A behavior profile is created for each one of the entities of the entity group. The behavior of each of one of the entities of the entity group is monitored to detect behavior change. An indicator of compromise is detected based on multiple ones of the entities experiencing substantially a same behavior change.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 creating an entity group that includes a plurality of entities, wherein each one of the plurality of entities represents one of a user, a machine, and a service;   creating a behavior profile for each one of the plurality of entities of the entity group;   monitoring behavior of each one of the plurality of entities of the entity group to detect behavior change; and   detecting an indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change.   
     
     
         2 . The method of  claim 1 , wherein creating the entity group is performed responsive to receiving input from a user that specifies the plurality of entities belonging to the entity group. 
     
     
         3 . The method of  claim 1 , wherein creating the entity group is automatically performed and populated with the plurality of entities based on a set of one or more attributes common to those plurality of entities. 
     
     
         4 . The method of  claim 1 , wherein creating the entity group is automatically performed and populated with the plurality of entities based on those plurality of entities previously showing similar behavior. 
     
     
         5 . The method of  claim 1 , wherein the created behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior between the plurality of entities. 
     
     
         6 . The method of  claim 1 , wherein the created behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior of the created entity group as compared to behavior of a different entity group. 
     
     
         7 . The method of  claim 6 , wherein the set of features are extracted or derived from metadata and other items of interest including one or more of: network packets propagating to/from devices, log information, and flow based connection records. 
     
     
         8 . The method of  claim 7 , wherein detecting the indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change includes finding a distance change of current behavior versus historical behavior for each of the multiple ones of the plurality of entities that is within a threshold or percentage change. 
     
     
         9 . A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations comprising:
 creating an entity group that includes a plurality of entities, wherein each one of the plurality of entities represents one of a user, a machine, and a service;   creating a behavior profile for each one of the plurality of entities of the entity group;   monitoring behavior of each one of the plurality of entities of the entity group to detect behavior change; and   detecting an indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change.   
     
     
         10 . The non-transitory machine-readable storage medium of  claim 9 , wherein creating the entity group is performed responsive to receiving input from a user that specifies the plurality of entities belonging to the entity group. 
     
     
         11 . The non-transitory machine-readable storage medium of  claim 9 , wherein creating the entity group is automatically performed and populated with the plurality of entities based on a set of one or more attributes common to those plurality of entities. 
     
     
         12 . The non-transitory machine-readable storage medium of  claim 9 , wherein creating the entity group is automatically performed and populated with the plurality of entities based on those plurality of entities previously showing similar behavior. 
     
     
         13 . The non-transitory machine-readable storage medium of  claim 9 , wherein the created behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior between the plurality of entities. 
     
     
         14 . The non-transitory machine-readable storage medium of  claim 9 , wherein the created behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior of the created entity group as compared to behavior of a different entity group. 
     
     
         15 . The non-transitory machine-readable storage medium of  claim 14 , wherein the set of features are extracted or derived from metadata and other items of interest including one or more of: network packets propagating to/from devices, log information, and flow based connection records. 
     
     
         16 . The non-transitory machine-readable storage medium of  claim 15 , wherein detecting the indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change includes finding a distance change of current behavior versus historical behavior for each of the multiple ones of the plurality of entities that is within a threshold or percentage change. 
     
     
         17 . An apparatus for collaborative and adaptive threat intelligence, comprising:
 a processor; and   a non-transitory machine-readable storage medium containing instructions executable by said processor whereby said apparatus is operative to:
 create an entity group that includes a plurality of entities, wherein each one of the plurality of entities represents one of a user, a machine, and a service; 
 create a behavior profile for each one of the plurality of entities of the entity group; 
 monitor behavior of each one of the plurality of entities of the entity group to detect behavior change; and 
 detect an indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change. 
   
     
     
         18 . The non-transitory machine-readable storage medium of  claim 17 , wherein creation of the entity group is performed responsive to receiving input from a user that specifies the plurality of entities belonging to the entity group. 
     
     
         19 . The non-transitory machine-readable storage medium of  claim 17 , wherein creation of the entity group is automatically performed and populated with the plurality of entities based on a set of one or more attributes common to those plurality of entities. 
     
     
         20 . The non-transitory machine-readable storage medium of  claim 17 , wherein creation of the entity group is automatically performed and populated with the plurality of entities based on those plurality of entities previously showing similar behavior. 
     
     
         21 . The non-transitory machine-readable storage medium of  claim 17 , wherein once created, the behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior between the plurality of entities. 
     
     
         22 . The non-transitory machine-readable storage medium of  claim 17 , wherein once created, the behavior profile for each one of the plurality of entities of the entity group includes a set of one or more features that are used to distinguish behavior of the created entity group as compared to behavior of a different entity group. 
     
     
         23 . The non-transitory machine-readable storage medium of  claim 22 , wherein the set of features are extracted or derived from metadata and other items of interest including one or more of: network packets propagating to/from devices, log information, and flow based connection records. 
     
     
         24 . The non-transitory machine-readable storage medium of  claim 23 , wherein detection of the indicator of compromise based on multiple ones of the plurality of entities experiencing substantially a same behavior change includes a finding that a distance change of current behavior versus historical behavior for each of the multiple ones of the plurality of entities that is within a threshold or percentage change.

Join the waitlist — get patent alerts

Track US2019173904A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.