System and Method for Cyber Security Threat Detection
Abstract
A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system comprises a plurality of collector engines. Each of the collector engines is previously installed on an endpoint of a plurality of endpoints and configured to acquire statistical information at the endpoint. The statistical information includes behavioral information, resource information, and metric information associated with the endpoint. The system further comprises an aggregator engine configured to aggregate the statistical information from each of the endpoints into aggregated information. The system further comprises an analytics engine configured to receive the aggregated information, and to invoke learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints. The system further comprises an alerting engine configured to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A cyber security threat detection system for one or more endpoints within a computing environment, the system comprising:
a plurality of collector engines, each of the collector engines previously installed on an endpoint of a plurality of endpoints and configured to acquire statistical information at the endpoint, wherein the statistical information includes behavioral information and resource information associated with the endpoint; an aggregator engine configured to aggregate the statistical information from each of the endpoints into aggregated information; an analytics engine configured to receive the aggregated information, and to invoke learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints; and an alerting engine configured to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint.
2 . The system of claim 1 , wherein:
the analytics engine is further configured to generate a cumulative risk level based on the deviation information, and the alerting engine is configured to issue the alerts in response to the cumulative risk level.
3 . The system of claim 1 , wherein:
the behavioral information includes activity events associated with the endpoint, and the resource information includes central processing unit (CPU) utilization, memory footprint, disk free space, and network throughput of the endpoint.
4 . The system of claim 1 , wherein the analytics engine comprises:
a behavioral analytics engine configured to invoke the analytics rules to output some information of the deviation information, and a metric analytics engine configured to invoke the machine learning models to output other information of the deviation information.
5 . The system of claim 1 , wherein the analytics engine is further configured to perform individual metrics checking, historical and cross endpoint comparatives, and activity sequences using the aggregated information and the expected fingerprints associated with the endpoints.
6 . The system of claim 1 , wherein the analytics engine performs analysis of activity sequences from the behavioral information associated with the endpoint including a determination whether specific metrics are absent from any of the activity sequences.
7 . The system of claim 1 , wherein the analytics engine performs analysis of activity sequences from the behavior information associated with the endpoint including a determination whether one or more specific activities have occurred.
8 . The system of claim 1 , wherein to invoke the analytics rules and machine learning models to output the deviation information for each of the endpoints, the analytics engine further invokes a profile management handler that compares the aggregated information to the expected fingerprints and provides results of the comparison.
9 . The system of claim 1 , wherein:
the deviation information are associated with a plurality of categories of threat, each of the categories of threat associated with a specific risk value, and some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat.
10 . The system of claim 1 , wherein:
to issue the alerts indicating the security threats for each of the endpoints, the alerting system determines whether an alert is to be issued based on a cumulative risk level, the cumulative risk level being a summation of specific risk values associated with one or more categories of threat that are associated with the deviation information, wherein each category of threat is associated with one of the specific risk values that is registered each time an associated trigger event occurs, and the alert is to be issued in response to a determination that the cumulative risk level exceeds a risk threshold.
11 . The system of claim 10 , wherein some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat.
12 . The system of claim 11 , wherein:
a baseline level is computed over time for the cumulative risk level, value excursions for the cumulative risk level with respect to the baseline level are tracked over time, and the risk threshold is computed based on the tracked excursions.
13 . The system of claim 1 , wherein the behavioral information for the endpoint include at least one of the following: firewall metric, internet protocol (IP) address metric, activity counter metric, process information metric, keyboard metric, and mouse metric.
14 . The system of claim 1 , wherein the behavioral information for the endpoint include at least one of the following: mouse telemetry, keyboard connections and activations, process usage, and hot desk information.
15 . The system of claim 1 , wherein each of the security threats is classified as at least one of the following: manual or automated, malware or custom, hardware or software, and internal or external.
16 . The system of claim 5 , wherein the activity sequences include an activity sequence associated with an endpoint user logging into the endpoint using stolen credentials or using an unlocked endpoint.
17 . The system of claim 5 , wherein the activity sequences include an activity sequence associated with a cyber attack performed by attaching to a privileged process with reverse shell access.
18 . The system of claim 1 , wherein the alerting engine is further configured to issue no alert in response to a determination that an authorized user successfully answers a challenge sent out of band (OoB).
19 . The system of claim 1 , wherein:
the alerting engine is further configured to send a text message to a security administrator from a specific phone number, and a mobile device of the security administrator is programmed to respond with a specific tone when a time critical alert is generated.
20 . The system of claim 1 , further comprising:
a prediction engine configured to predict patterns of a software application based on a determined probability and context of an endpoint user, and to traverse an alert threshold according to the determined probability when operating patterns of the software application diverge from the predicted patterns.
21 . A method for detecting cyber security threat of one or more endpoints within a computing environment, the method comprising:
receiving aggregated information including statistical information from each of the endpoints, wherein the statistical information includes behavioral information and resource information associated with the endpoint; invoking learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints; and issuing one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint; wherein issuing the alerts comprising:
determining whether an alert is to be issued based on a cumulative risk level, the cumulative risk level being a summation of specific risk values associated with one or more categories of threat that are associated with the deviation information, wherein each category of threat is associated with one of the specific risk values that is registered each time an associated trigger event occurs, and
issuing the alert in response to a determination that the cumulative risk level exceeds a risk threshold.
22 . The method of claim 21 , wherein some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat.
23 . The method of claim 22 , further comprising:
computing a baseline level over time for the cumulative risk level, tracking, over time, value excursions for the cumulative risk level with respect to the baseline level, and computing the risk threshold based on the tracked excursions.Join the waitlist — get patent alerts
Track US2022353282A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.