US2023300155A1PendingUtilityA1

Performing cybersecurity operations based on impact scores of computing events over a rolling time interval

Assignee: VMWARE INCPriority: Jan 16, 2021Filed: May 23, 2023Published: Sep 21, 2023
Est. expiryJan 16, 2041(~14.5 yrs left)· nominal 20-yr term from priority
G06F 16/245H04L 63/0263H04L 63/1416H04L 63/1433H04L 63/20G06N 5/04G06N 7/01H04L 63/1441
68
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosure herein describes automatically performing security operations associated with a client system based on aggregated event impact scores of computing events during a rolling time interval. Event data is obtained, wherein the event data is from a plurality of computing devices of the client system associated with computing events occurring during a time interval after an endpoint of the rolling time interval. Event impact scores are calculated for the computing events of the obtained event data over the time interval based at least on cardinality estimation. The calculated event impact scores are merged into the set of aggregated event impact scores associated with the rolling time interval and event impact scores associated with an expired time interval are removed from the set of aggregated event impact scores. Based on the set of aggregated event impact scores, at least one security operation is performed for at least one computing event.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computerized method of enforcing an event rule based on an aggregated event impact score of computing events during a rolling time interval, the computerized method comprising:
 obtaining, by a processor, event data from a plurality of computing devices of a client system, the event data being associated with computing events occurring during a time interval after an endpoint of the rolling time interval;   calculating, by the processor, event impact scores for the computing events of the obtained event data based at least on cardinality estimation;   merging, by the processor, the calculated event impact scores into a set of aggregated event impact scores;   generating, by the processor, a recommended event rule based on the set of aggregated event impact scores; and   enforcing, by the processor, the recommended event rule on the client system.   
     
     
         2 . The computerized method of  claim 1 , further comprising:
 identifying, by the processor, from the computing events, a computing event associated with an aggregated event impact score, of the set of aggregated event impact scores, that exceeds an impact score threshold;   obtaining, by the processor, an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enabling, by the processor, the existing event rule on the client system.   
     
     
         3 . The computerized method of  claim 1 , further comprising:
 identifying, by the processor, from the computing events, a computing event associated with an aggregated event impact score, of the set of aggregated event impact scores, that is in an impact score percentile range;   obtaining, by the processor, an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enabling, by the processor, the existing event rule on the client system.   
     
     
         4 . The computerized method of  claim 1 , further comprising:
 providing, by the processor, the recommended event rule to a user via a recommendation interface;   receiving, by the processor, an approval from the user via the recommendation interface; and   updating, by the processor, the client system to include the recommended event rule.   
     
     
         5 . The computerized method of  claim 1 , further comprising:
 providing, by the processor, the recommended event rule to a user via a recommendation interface;   receiving, by the processor, feedback from the user via the recommendation interface;   storing, by the processor, the feedback in a recommendations data store; and   using, by the processor, the stored feedback to generate future event rule recommendations.   
     
     
         6 . The computerized method of  claim 4 , further comprising:
 providing, by the processor, along with the recommended event rule, information indicating how often the recommended event rule is used by another system.   
     
     
         7 . The computerized method of  claim 1 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule. 
     
     
         8 . A computer system for enforcing an event rule based on aggregated event impact scores of computing events during a rolling time interval, the computer system comprising:
 a processor; and   a non-transitory computer readable medium having stored program code for transferring data to another computer system, the program code causing the processor to:
 obtain event data from a plurality of computing devices of a client system associated with computing events occurring during a time interval after an endpoint of the rolling time interval; 
 calculate event impact scores for the computing events of the obtained event data based at least on cardinality estimation; 
 merge the calculated event impact scores into a set of aggregated event impact scores; 
 generate a recommended event rule based on the set of aggregated event impact scores; and 
 enforce the recommended event rule on the client system. 
   
     
     
         9 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 identify, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that exceeds an impact score threshold;   obtain an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enable the existing event rule on the client system.   
     
     
         10 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 identify, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that is in an impact score percentile range;   obtain an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enable the existing event rule on the client system.   
     
     
         11 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 provide the recommended event rule to a user via a recommendation interface;   receive an approval from the user via the recommendation interface; and   update the client system to include the recommended event rule.   
     
     
         12 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 provide the recommended event rule to a user via a recommendation interface;
 receive feedback from the user via the recommendation interface; 
 store the feedback in a recommendations data store; and 
 use the stored feedback to generate future event rule recommendations. 
   
     
     
         13 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 provide, along with the recommended event rule, information indicating how often the recommended event rule is used by other systems.   
     
     
         14 . The computer system of  claim 8 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule. 
     
     
         15 . A non-transitory computer storage medium having stored thereon program code executable by a first computer system, the program code embodying a method comprising:
 obtaining event data from a plurality of computing devices of a client system associated with computing events occurring during a time interval after an endpoint of a rolling time interval;   calculating event impact scores for the computing events of the obtained event data based at least on cardinality estimation;   merging the calculated event impact scores into a set of aggregated event impact scores;   generating a recommended event rule based on the set of aggregated event impact scores;   providing the recommended event rule to a user via a recommendation interface;   receiving an approval from the user via the recommendation interface; and   enforcing the recommended event rule on the client system.   
     
     
         16 . The non-transitory computer storage medium of  claim 15 , wherein the method embodied by the program code further comprises:
 identifying, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that exceeds an impact score threshold;   obtaining an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enabling the existing event rule on the client system.   
     
     
         17 . The non-transitory computer storage medium of  claim 15 , wherein the method embodied by the program code further comprises:
 identifying, from the computing events, a computing event associated with an aggregated event impact score, of the set of the aggregated event impact scores, that is in an impact score percentile range;   obtaining an existing event rule configured to trigger a security operation based on detection of the identified computing event; and   enabling the existing event rule on the client system.   
     
     
         18 . The non-transitory computer storage medium of  claim 15 , wherein the method embodied by the program code further comprises:
 receiving feedback from the user via the recommendation interface;   storing the feedback in a recommendations data store; and   using the stored feedback to generate future event rule recommendations.   
     
     
         19 . The non-transitory computer storage medium of  claim 15 , wherein the method embodied by the program code further comprises:
 providing, along with the recommended event rule, information indicating how often the recommended event rule is used by other systems.   
     
     
         20 . The non-transitory computer storage medium of  claim 15 , wherein the recommended event rule comprises a deny-list-based endpoint device security rule.

Join the waitlist — get patent alerts

Track US2023300155A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.