Location enrichment in enterprise threat detection

US10542016B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10542016-B2
Application numberUS-201615253438-A
CountryUS
Kind codeB2
Filing dateAug 31, 2016
Priority dateAug 31, 2016
Publication dateJan 21, 2020
Grant dateJan 21, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Subnet information and location information is received from a database by a smart data streaming engine (SDS). A particular subnet of the subnet information is associated with a particular location of the location information by a globally unique location ID value. Log event data received in the SDS is normalized as normalized log event data. The normalized log event data is enriched with subnet and location information as enriched log event data and written into a log event persistence in the database. A subnet ID value retrieved from an enriched log event of the enriched log event data is used by an enterprise threat detection (ETD) system to determine a location associated with the enriched log event using a location ID value associated with the subnet ID.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: receiving subnet information and location information from a database into a smart data streaming engine (SDS) subnet-location cache, wherein a particular subnet of the subnet information is associated with a particular location of the location information by a globally unique location ID value, and wherein the information is stored in the subnet-location cache in the form of a dictionary table and a vector for fast data enrichment; receiving log event data in the SDS; normalizing the log event data in the SDS as normalized log event data; enriching the normalized log event data with the subnet information and the location information as enriched log event data; writing the enriched log event data into a log event persistence in the database; and using a subnet ID value retrieved from an enriched log event of the enriched log event data by an enterprise threat detection (ETD) system to determine a location associated with the enriched log event using the location ID value associated with the subnet ID value. 2. The computer-implemented method of claim 1 , wherein the subnet information and the location information is maintained in the database. 3. The computer-implemented method of claim 2 , wherein system information is maintained in the database, and wherein a particular system of the system information is associated with a particular location of the location information by a particular globally unique location ID value. 4. The computer-implemented method of claim 1 , comprising: reading the subnet information and the location information from the database; and writing the subnet information and the location information into the subnet-location cache of the SDS. 5. The computer-implemented method of claim 4 , wherein the subnet information and the location information is read from the subnet-location persistence and written to the subnet-location cache using an SDS database in adapter coupling the database and the SDS. 6. The computer-implemented method of claim 1 , wherein the enriched log event data is written to the log event persistence using an SDS database out adapter coupling the SDS and the database. 7. The computer-implemented method of claim 1 , comprising enriching the normalized log event data with a determined subnet ID value. 8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising: receiving subnet information and location information from a database into a smart data streaming engine (SDS) subnet-location cache, wherein a particular subnet of the subnet information is associated with a particular location of the location information by a globally unique location ID value, and wherein the information is stored in the subnet-location cache in the form of a dictionary table and a vector for fast data enrichment; receiving log event data in the SDS; normalizing the log event data in the SDS as normalized log event data; enriching the normalized log event data with the subnet information and the location information as enriched log event data; writing the enriched log event data into a log event persistence in the database; and using a subnet ID value retrieved from an enriched log event of the enriched log event data by an enterprise threat detection (ETD) system to determine a location associated with the enriched log event using the location ID value associated with the subnet ID value. 9. The non-transitory, computer-readable medium of claim 8 , wherein the subnet information and the location information is maintained in the database. 10. The non-transitory, computer-readable medium of claim 9 , wherein system information is maintained in the database, and wherein a particular system of the system information is associated with a particular location of the location information by a particular globally unique location ID value. 11. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to: read the subnet information and the location information from the database; and write the subnet information and the location information into the subnet-location cache of the SDS. 12. The non-transitory, computer-readable medium of claim 11 , wherein the subnet information and the location information is read from the subnet-location persistence and written to the subnet-location cache using an SDS database in adapter coupling the database and the SDS. 13. The non-transitory, computer-readable medium of claim 8 , wherein the enriched log event data is written to the log event persistence using an SDS database out adapter coupling the SDS and the database. 14. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to enrich the normalized log event data is enriched with a determined subnet ID value. 15. A computer-implemented system, comprising: a computer memory; and a hardware processor interoperably coupled with the computer memory and configured to perform operations comprising: receiving subnet information and location information from a database into a smart data streaming engine (SDS) subnet-location cache, wherein a particular subnet of the subnet information is associated with a particular location of the location information by a globally unique location ID value, and wherein the information is stored in the subnet-location cache in the form of a dictionary table and a vector for fast data enrichment; receiving log event data in the SDS; normalizing the log event data in the SDS as normalized log event data; enriching the normalized log event data with the subnet information and the location information as enriched log event data; writing the enriched log event data into a log event persistence in the database; and using a subnet ID value retrieved from an enriched log event of the enriched log event data by an enterprise threat detection (ETD) system to determine a location associated with the enriched log event using the location ID value associated with the subnet ID value. 16. The computer-implemented system of claim 15 , wherein the subnet information and the location information is maintained in the database. 17. The computer-implemented system of claim 16 , wherein system information is maintained in the database, and wherein a particular system of the system information is associated with a particular location of the location information by a particular globally unique location ID value. 18. The computer-implemented system of claim 15 , configured to: read the subnet information and the location information from the database; and write the subnet information and the location information into the subnet-location cache of the SDS. 19. The computer-implemented system of claim 18 , wherein the subnet information and the location information is read from the subnet-location persistence and written to the subnet-location cache using an SDS database in adapter coupling the database and the SDS, and wherein the enriched log event data is written to the log event persistence using an SDS database out adapter coupling the SDS and the database. 20. The computer-implemented system of claim 15 , configured to enrich the normalized log event data is enriched with a determined subnet ID value.

Assignees

Inventors

Classifications

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • when the policy decisions are valid for a limited amount of time · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10542016B2 cover?
Subnet information and location information is received from a database by a smart data streaming engine (SDS). A particular subnet of the subnet information is associated with a particular location of the location information by a globally unique location ID value. Log event data received in the SDS is normalized as normalized log event data. The normalized log event data is enriched with subn…
Who is the assignee on this patent?
Sap Se
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 21 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).