System and Method for Cyber Security Threat Detection
Abstract
A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system includes one or more collector engines. Each of the collector engines includes a service and an agent operating on a corresponding system endpoint of the system endpoints. The service is configured to take a first snapshot of the corresponding system endpoint. The first snapshot includes event activity information associated with the system endpoint. The agent is configured to take a second snapshot of the corresponding system endpoint. The second snapshot includes behavioral activity information associated with the corresponding system endpoint. The system further includes an aggregator engine configured to aggregate the first snapshot and the second snapshot from each of the system endpoints into an aggregated snapshot. The system further includes one or more analytics engines configured to: generate and store baseline profiles associated with the system endpoints based on a previously received aggregated snapshot, receive the aggregated snapshot from the aggregator engine, determine deviation values for each of the system endpoints based on the received aggregated snapshot and the stored baseline profiles, and generate, for each of the system endpoints, a cumulative risk value based on the deviation values. The system further includes one or more alerting engines configured to determine whether to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the cumulative risk value.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A cyber security threat detection system for a networked computing environment, the system comprising:
a plurality of network enabled hardware end points communicably linked to the networked computing environment enabled for user access; a collector engine comprising at least a collector service and an agent installed on the network enabled hardware end points, configured to acquire user behavioral activity information at the end point; an aggregator in the networked computing environment configured receive user behavioral activity information from the end points and to aggregate the received behavioral activity information and send it to a cloud service having a processing capability and storage in at least a cloud based processing system, for storage of the behavioral activity information and for processing the behavioral activity information; wherein the cloud service processing capability further comprise:
a prediction engine operating on the acquired behavioral activity information, configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine a probability of occurrence of the new behavioral activity based on the comparison;
an analytics engine configured to generate a security risk level based on the probability of occurrence of the new behavioral activity; and
the cloud service further configured to transfer the generated security risk level to the company security dashboard in the networked computing environment.
2 . The cyber security threat detection system of claim 1 , wherein the security risk level based on probability of occurrence of the new behavioral activity decreases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity; and
security risk level based on probability of occurrence of the new behavioral activity increases if the new behavioral activity substantially diverges from the expected behavioral activity, thereby indicating a possible security breach.
3 . The cyber security threat detection system of claim 1 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa.
4 . The cyber security threat detection system of claim 1 , wherein the probability of occurrence of the new behavioral activity is combined with additional metrics to derive an overall security risk level.
5 . The cyber security threat detection system of claim 1 , wherein the probability of occurrence of the new behavioral activity is combined with additional metrics to derive an overall security risk level.
6 . The cyber security threat detection system of claim 1 , wherein the security risk level increases in response to a determination that an expected activity with the high probability of occurrence is absent from the new behavioral activity.
7 . The cyber security threat detection system of claim 6 , wherein the absent activity includes an absence of an expected metric.
8 . The cyber security threat detection system of claim 7 , wherein the absence of an expected metric increases a probability of abnormal behavior and a weighted risk level associated the metric.
9 . A cyber security threat detection system for a networked computing environment, the system comprising:
a plurality of network enabled hardware end points communicably linked to the networked computing environment, from within and outside the computing environment, enabled for user access; a collector engine comprising at least a collector service and an agent installed on the network enabled hardware end points, configured to acquire user behavioral activity information at the end point; an aggregator in the networked computing environment configured receive user behavioral activity information from the end points within the networked computing environment and to aggregate the received behavioral activity information and send it to a cloud service; and the network enabled hardware end points outside the computing environments configured to provide the collected behavioral activity information to the cloud service over the network; wherein the cloud service is configured with a processing capability and storage in at least a cloud based processing system for storage of the behavioral activity information and for processing the behavioral activity information; wherein the cloud service processing capability further comprise:
a prediction engine operating on the acquired behavioral activity information, configured to predict expected behavioral activity based on historic behavioral activity from the recorded behavioral activity information, to compare new behavioral activity with the expected behavioral activity, and to determine a probability of occurrence of the new behavioral activity based on the comparison;
an analytics engine configured to generate a security risk level based on the probability of occurrence of the new behavioral activity; and
the cloud service further configured to transfer the generated security risk level to the company security dashboard in the networked computing environment.
10 . The cyber security threat detection system of claim 9 , wherein the security risk level based on probability of occurrence of the new behavioral activity decreases if the new behavioral activity substantially behaves in accordance with the expected behavioral activity; and
security risk level based on probability of occurrence of the new behavioral activity increases if the new behavioral activity substantially diverges from the expected behavioral activity, thereby indicating a possible security breach.
11 . The cyber security threat detection system of claim 9 , wherein a lower probability of occurrence of the new behavioral activity indicates a greater security risk level, and vice versa.
12 . The cyber security threat detection system of claim 9 , wherein the probability of occurrence of the new behavioral activity is combined with additional metrics to derive an overall security risk level.
13 . The cyber security threat detection system of claim 9 , wherein the security risk level increases in response to a determination that an expected activity is absent from the new behavioral activity.
14 . The cyber security threat detection system of claim 9 , wherein the absent activity is either a behavioral activity or a matric that is the behavior, or the metric expected at the network enabled hardware end points.
15 . A computer-implemented method for cyber security threat detection, the method implemented by one or more processors operating within a computing environment and a plurality of processors in the cloud service, the method comprising:
receiving behavioral activity information, collected by a collector service and a collector agent on hardware endpoints, that has been acquired over a period of time and aggregated; operating on the received behavioral activity information by a processor, associated with a prediction engine in a cloud service, to predict expected behavioral activity based on historic behavioral activity from the received and stored behavioral activity information; and determining by a processor associated with an analytic engine in the cloud service, a risk level from a probability of occurrence of new abnormal behavioral activity based on a comparison of the new behavioral activity with the expected behavioral activity.
16 . The method of claim 15 , wherein the method further comprise:
saving the received behavioral activity information, collected by a collector service and a collector agent on hardware endpoints, that has been acquired over a period of time in a memory as historic data in the cloud service.
17 . The method of claim 15 , wherein the determination by the risk level by the processor associated with the analytic engine in the cloud service further considering an absence of an expected metric as increasing a probability of occurrence of the abnormal behavioral activity.
18 . The method of claim 15 , further comprising generating and transmitting the generated security risk level to the company security operations dashboard in the networked computing environment.Join the waitlist — get patent alerts
Track US2022368707A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.