Methods and systems for cyber-monitoring and visually depicting cyber-activities
Abstract
The present invention relates to methods and systems for cyber-monitoring and visually depicting cyber-activities. In certain embodiments, there is provided a method for visually depicting cyber-activities, entities, and/or entity-relations, said method comprising: displaying on a graphical user interface multiple visual representations comprising graphical components of one or more elements in a chronological order, using a time based tracking model, wherein each of said one or more elements is selected from a cyber-activity, entity, and entity-relation; wherein each of said visual representations represents a different level of a granularity and/or hierarchy; b) optionally displaying, optionally in response to a user action, a link to a selected element in each of said multiple visual representations.
Claims
exact text as granted — not AI-modifiedThe embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:
1 . A method for cyber-monitoring and visually depicting cyber-activities, said method comprising:
a) tracking cyber-activities derived from event stream(s); b) extracting, building or extracting and building one or more entities and one or more entity-relations from said tracked cyber-activities, wherein each of said entity is a representative component of a particular cyber-activity; c) characterizing the entities from step b) as normally-occurring, unknown or anomalous; d) excluding entities which are normally-occurring from further review; and e) reviewing any unknown or anomalous entity(ies) by:
(i) displaying on a panel of a graphical user interface (GUI) a set of relational stack representations where each stack represents a different level of granularity; each stack comprising cells in a chronological order, where each cell represents an entity from the one or more entities not excluded in step d); and wherein each cell comprises information regarding the entity the cell represents that can be visualized in response to user input;
(ii) selecting an entity from step e)(1) to visualize across levels of granularity;
(iii) displaying, automatically or in response to a user action, links between the selected entity in neighboring stacks to provide a pathway following the selected entity across levels of granularity and thereby produce a pattern of relations for said selected entity across said levels of granularity; and
(iv) characterizing said selected entity as normal or anomalous based on said pattern of relations.
2 . The method of claim 1 , wherein step c) comprises application of one or more rules to characterize the entities as being normal.
3 . The method of claim 1 , wherein each cell can be expanded or compressed.
4 . The method of claim 1 , wherein each cell has color coding.
5 . The method of claim 1 , wherein step b) comprises:
(i) selecting entities from said cyber-activity(ies); and (ii) selecting an entity-relations tracking model.
6 . The method of claim 1 , wherein said relational stack representations comprise stacks representing entities at organization, domain, user and device levels of granularity.
7 . The method of claim 1 , wherein said relational stack representations comprise stacks representing entities at devices, processes and events levels of granularity.
8 . The method of claim 1 , wherein the GUI is a multiple panel format and one or more panels are linked such that user action in one panel is reflected in one or more other panels.
9 . The method of claim 8 , wherein said GUI comprises panels displaying different levels of processing.
10 . The method of claim 8 , further comprising displaying a tree representation in a second panel.
11 . The method of claim 8 , wherein said GUI comprises one or more panels providing a visualization of rules for the automated processing that have been applied and/or rules generation.
12 . The method of claim 8 , wherein said GUI comprises a panel for implementing a workflow.
13 . The method of claim 1 , wherein the characterization as normal or anomalous is automatic based on rules.
14 . The method of claim 1 , further comprising initiating downstream actions following characterization of an entity as anomalous.
15 . The method of claim 1 , further comprising displaying on a second panel of said GUI a further relational set of stack representations having the same levels of granularity; each stack comprising cells in a chronological order, where each cell represents an entity from the one or more entities not excluded in step d); and wherein each cell comprises information regarding the entity the cell represents that can be visualized in response to user input.Join the waitlist — get patent alerts
Track US2023156028A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.