Identity resolution in data intake stage of machine data processing platform
US-9838410-B2 · Dec 5, 2017 · US
US10956565B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10956565-B2 |
| Application number | US-201616076948-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 12, 2016 |
| Priority date | Feb 12, 2016 |
| Publication date | Mar 23, 2021 |
| Grant date | Mar 23, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Examples disclosed herein relate to visualization of associations among data records in a security information sharing platform. Some examples may enable creating, in the security information sharing platform, an association between a first data record comprising a security indicator, and a second data record. Some examples may further enable providing a visual representation of the first data record, the second data record, and the association, wherein the first data record represents a first node in the visual representation, the second data record represents a second node in the visual representation, and the association represents an edge that connects the first node and the second node.
Opening claim text (preview).
The invention claimed is: 1. A method for visualization of associations among data records in a security information sharing platform, the method comprising: creating, in the security information sharing platform that enables sharing of security information among a plurality of users, a first association between a first data record comprising a first security indicator, and a second data record; causing display of a visual representation in a graphical user interface, the visual representation comprising a first node, a second node, and a first edge between the first node and the second node, wherein the first node represents the first data record, wherein the second node represents the second data record, and wherein the first edge represents the first association between the first node and the second node; in response to a first user interaction with the first edge in the visual representation, providing a drill down option for the first edge in the visual representation to display a strength of the first association and information on which the strength of the first association is based; modifying the strength of the first association in response to a second user interaction with the first edge using the drill down option in the visual representation; and adjusting an indicator score for the first security indicator in response to the modification of the strength of the first association. 2. The method of claim 1 , comprising: determining the strength of the first association based on at least one of: a likelihood of change in the first association; a creator of the first association; an aging rate of the first association; or a quality of evidence that supports the first association. 3. The method of claim 1 , wherein the second data record represents at least one of: a second security indicator, an organization, an industry sector, a geography, a community of the security information sharing platform, a domain name, or a threat actor. 4. The method of claim 1 , wherein the visual representation comprises a third node that represents a third data record, and the method further comprising: adding, to the visual representation, a second edge that connects the second node and the third node; in response to the addition of the second edge, creating a second association between the second data record and the third data record in the security information sharing platform; and adjusting the indicator score for the first security indicator based on the addition of the second edge. 5. The method of claim 4 , wherein the second data record is a threat actor, and the method further comprising: adjusting a threat actor score for the second data record. 6. The method of claim 1 , wherein the first security indicator includes an observable, and the method further comprising: determining the indicator score for the first security indicator based on at least one of: a severity of a security threat posed by the first security indicator, a number of sightings of the observable, a reliability of a source entity for the first security indicator, or user feedback indicating whether the first security indicator is accurately submitted by the plurality of users of the security information sharing platform. 7. The method of claim 6 , comprising: obtaining, from a first source entity associated with the second data record, a first sighting of the observable, the first sighting of the observable indicating that the observable has been observed by the first source entity; obtaining, from a second source entity associated with the second data record, a second sighting of the observable, the second sighting of the observable indicating that the observable has been observed by the second source entity; determining a number of sightings of the observable, the number of sightings of the observable including the first sighting and the second sighting of the observable; and creating, in the security information sharing platform, the first association based on the number of sightings of the observable. 8. The method of claim 1 , comprising: causing the first edge to have a visual appearance indicating that the first association has been verified by a trusted authority. 9. The method of claim 1 , wherein the information on which the strength of the first association is based includes a creation time and/or a modified time of the first association, a source identity that created and/or modified the first association, and/or a combination thereof. 10. The method of claim 1 , comprising: in response to the modification of the strength of the first association based on the second user interaction with the first edge using the drill down option in the visual representation, adjusting the first security indicator for the first data record, causing an information update associated with the first data record and the second data record corresponding to the first association, and updating a display in the graphical user interface adjacent to the first node or the second node based on the modification of the strength of the first association. 11. A non-transitory machine-readable storage medium comprising instructions executable by a processor to: create, in a security information sharing platform, a first association between a first data record and a second data record, the first data record comprising a first security indicator; cause display of a visual representation in a graphical user interface, the visual representation comprising a first node, a second node, and a first edge between the first node and the second node, wherein the first node represents the first data record, wherein the second node represents the second data record, and wherein the first edge represents the first association between the first data record and the second data record; in response to a first user interaction with the first edge in the visual representation, provide a drill down option for the first edge in the visual representation to display a strength of the first association and information on which the strength of the first association is based; modify the strength of the first association in response to a second user interaction with the first edge using the drill down option in the visual representation; and adjust an indicator score for the first security indicator in response to the modification of the strength of the first association. 12. The non-transitory machine-readable storage medium of claim 11 , wherein the second data record represents at least one of: a second security indicator, an organization, an industry sector, a geography, a community of the security information sharing platform, a domain name, or a threat actor. 13. The non-transitory machine-readable storage medium of claim 11 , the instructions executable by the processor to: cause the first edge to have a visual appearance indicating that the first association has been verified by a trusted authority. 14. The non-transitory machine-readable storage medium of claim 11 , the instructions executable by the processor to: in response to the modification of the strength of the first association based on the second user interaction with the first edge using the drill down option in the visual representation, adjust the first security indicator for the first data record, cause an information update associated with the first data record and the second data record corresponding to the first association, and update a display in the graphical user interface adjacent to the first node or the second node based on the modification of the strength of the first association. 1
Visualization; Browsing · CPC title
Administration; Management · CPC title
involving long-term monitoring or reporting · CPC title
Risk analysis of enterprise or organisation activities · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.