Unifying of the network device entity and the user entity for better cyber security modeling along with ingesting firewall rules to determine pathways through a network
Abstract
A device linking service can unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network. The device linking service creates a unified network device identifier for the different device identifiers from the different sources of access into the network. The device linking service supplies the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine. The prediction engine runs a simulation of attack paths for the network that a cyber threat may take.
Claims
exact text as granted — not AI-modified1 . An apparatus, comprising:
a device linking service configured to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network, where the device linking service is configured to create a unified network device identifier for the different device identifiers from the different sources of access into the network, where the device linking service is configured to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine, where the prediction engine is configured to run a simulation of attack paths for the network that a cyber threat may take, and where any instructions for the device linking service and the prediction engine are stored in an executable format on one or more non-transitory computer readable mediums, which are executable by one or more processors.
2 . The apparatus of claim 1 ,
where the device linking service is configured to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network, where the device linking service is configured to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network, and where the cyber security appliance is configured to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat.
3 . The apparatus of claim 2 , where the cyber security appliance is configured to have an autonomous response module to autonomously respond to mitigate the cyber threat as well as to cooperate with the prediction engine in order to determine how to properly autonomously respond to a cyber attack by the cyber threat based upon simulations run in the prediction engine modelling the attack paths into and through the network.
4 . The apparatus of claim 1 ,
where the device linking service is configured to cooperate with a firewall configuration ingester and the prediction engine, where the prediction engine is configured to monitor traffic into the network in order to map all of the paths into and through the network taken by the monitored traffic, where the firewall configuration ingester is configured to ingest firewall rules to determine theoretically possible paths through the network in accordance with the firewall rules and a mapping of nodes of the network, and where the prediction engine is configured to combine all of the paths into and through the network taken by the monitored traffic with the possible paths through the network theoretically possible in accordance with the firewall rules from the firewall configuration ingester in light of the unified network device identifier with a user entity in the network from the device linking service to determine possible attack paths when running the simulation of attack paths for the network that the cyber threat may take.
5 . The apparatus of claim 1 , where the device linking service is configured to passively monitor the data streams from different sources having access into the network as well as to actively query third party platforms to gather and ingest device data, user data, and activity data from multiple third party vendors and then analyze the ingested data, and then pass the ingested data into the prediction engine to perform the simulation of attack paths for the network that the cyber threat may take.
6 . The apparatus of claim 1 , where the device linking service is configured to maintain data from the data streams in their generic format as well as put relevant data into a uniform analysis format in a central data store via translation and mapping and then using the central data store to store the relevant data for the uniform analysis format.
7 . The apparatus of claim 1 , where the device linking service is configured to 1) apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network as well as 2) use a central data store to store data points organized by how the data points relate to another data point.
8 . The apparatus of claim 1 , where the device linking service is configured to aggregate network presence information about a user of the network and their different user accounts on different third-party applications served from third-party platforms external to the network, who is then also associated with this particular individual physical network device.
9 . The apparatus of claim 1 , further comprising:
a firewall configuration ingester configured to cooperate with the device linking service, where the firewall configuration ingester is configured to examine rules of firewall configurations and their settings to model changes in these rules over time to detect unusual rules over time to the firewall configurations that cause new attack path modelling routes into the network.
10 . The apparatus of claim 1 , further comprising:
a firewall configuration ingester configured to cooperate with the device linking service and the prediction engine, where the firewall configuration ingester is configured to examine firewall rules implemented by a firewall to identify routes into the network allowed by a current firewall rules and supply the prediction engine with a set of possible routes that a cyber attack by the cyber threat may take into the network and permitted reasons into the network.
11 . A non-transitory computer readable medium configured to store instructions in an executable format in the non-transitory computer readable medium, which when executed by one or more processors cause operations, comprising:
providing a device linking service to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network, providing the device linking service to create a unified network device identifier for the different device identifiers from the different sources of access into the network, providing the device linking service to then link the unified network device identifier with a user in the network, and providing the device linking service to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine, where the prediction engine is configured to run a simulation of attack paths for the network that a cyber threat may take.
12 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the device linking service to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network, providing the device linking service to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network, and providing the cyber security appliance to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat.
13 . The non-transitory computer readable medium of claim 12 , further comprising:
providing the cyber security appliance to have an autonomous response module to autonomously respond to mitigate the cyber threat as well as to cooperate with the prediction engine in order to determine how to properly autonomously respond to a cyber attack by the cyber threat based upon simulations run in the prediction engine modelling the attack paths into and through the network.
14 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the prediction engine to monitor traffic into the network in order to map all of the paths into and through the network taken by the monitored traffic, providing a firewall configuration ingester to ingest firewall rules to determine theoretically possible paths through the network in accordance with the firewall rules and a mapping of nodes of the network, and providing the prediction engine to combine all of the paths into and through the network taken by the monitored traffic with the possible paths through the network theoretically possible in accordance with the firewall rules from the firewall configuration ingester in light of the unified network device identifier with a user entity in the network from the device linking service to determine possible attack paths when running the simulation of attack paths for the network that the cyber threat may take.
15 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the device linking service to passively monitor the data streams from different sources having access into the network as well as to actively query third party platforms to gather and ingest device data, user data, and activity data from multiple third party vendors and then analyze the ingested data, and then pass the ingested data into the prediction engine to perform the simulation of attack paths for the network that the cyber threat may take.
16 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the device linking service to maintain data from the data streams in their generic format as well as put relevant data into a uniform analysis format in a central data store via translation and mapping and then using the central data store to store the relevant data for the uniform analysis format.
17 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the device linking service to 1) apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network as well as 2) use a central data store to store data points organized by how the data points relate to another data point.
18 . The non-transitory computer readable medium of claim 11 , further comprising:
providing the device linking service to aggregate network presence information about the user of the network and their different user accounts on different third-party applications served from third-party platforms external to the network, who is then also associated with this particular individual physical network device.
19 . The non-transitory computer readable medium of claim 11 , further comprising:
providing a firewall configuration ingester to examine rules of firewall configurations and their settings to model changes in these rules over time to detect unusual rules over time to the firewall configurations that cause new attack path modelling routes into the network.
20 . The non-transitory computer readable medium of claim 11 , further comprising:
providing a firewall configuration ingester to examine firewall rules implemented by a firewall to identify routes into the network allowed by a current firewall rules and supply the prediction engine with a set of possible routes that a cyber attack by the cyber threat may take into the network and permitted reasons into the network.Join the waitlist — get patent alerts
Track US2024031380A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.