Graphical display suppressing events indicating security threats in an information technology system

US11178167B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11178167-B2
Application numberUS-201916526354-A
CountryUS
Kind codeB2
Filing dateJul 30, 2019
Priority dateJul 31, 2013
Publication dateNov 16, 2021
Grant dateNov 16, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security information. Determine a group of security events using the security information. Each security event includes a field value specified by a criteria. Present a graphical interface (GI) including a summary of the group of security events, other summaries of security events, and a remove element (associated with the summary). Receive input corresponding to an interaction of the remove element. Interacting with the remove element causes the summary to be removed from the GI. Update the GI to remove the summary from the GI.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: creating, by a computer system, an event group, the event group including a plurality of time-stamped events, each event in the event group having a respective portion of raw machine data, wherein each event in the event group is included in the event group based on the event matching criterion relating to one or more field values extracted from a respective one or more fields present in a respective portion of raw machine data; creating, by the computer system, an event group summary that summarizes one or more fields present in the portion of raw machine data included in the plurality of time-stamped events included in the event group; causing, by the computer system, display of a graphical user interface that includes a plurality of event group summaries including the event group summary; receiving first input indicating selection of the event group summary; receiving second input indicating a time frame; and suppressing, by the computer system, display of the event group summary by removing the event group summary from the graphical user, wherein the event group summary is suppressed during the time frame indicated by the second input. 2. The method as recited in claim 1 , wherein at least one event group summary of the plurality of event group summaries includes domain activity information. 3. The method as recited in claim 1 , further comprising: changing, by the computer system, a visual appearance of a particular event group summary among the plurality of event group summaries to indicate that the particular event group summary is a potential security threat. 4. The method as recited in claim 1 , further comprising: modifying, by the computer system, the event group summary based upon one or more fields present in raw machine data contained in new events identified as belonging to the event group. 5. The method as recited in claim 1 , further comprising: causing, by the computer system, display of a second graphical user interface displaying a second plurality of event group summaries including the selected event group summary, wherein each event group summary in the second plurality of event group summaries was removed from the plurality of event group summaries indicating that each event group summary in the second plurality of event group summaries is not a security threat. 6. The method as recited in claim 1 , wherein the raw machine data comprises log data; the method further comprising: organizing the raw machine data into the plurality of time-stamped events, wherein an event comprises at least a portion of log data within the raw machine data. 7. The method as recited in claim 1 , wherein the criterion is evaluated using a late binding schema applied to at least a portion of the plurality of time-stamped events. 8. The method as recited in claim 1 , wherein each event of the plurality of time-stamped events is associated with a time stamp, and wherein the event group summary encompasses events having time stamps within a specified time period. 9. The method as recited in claim 1 , wherein the event group summary includes a numerical count of events in the event group. 10. The method as recited in claim 1 , wherein the criterion includes a particular threshold string length for the one or more extracted field values. 11. The method as recited in claim 1 , wherein the criterion includes a particular threshold string length for a network resource locator. 12. The method as recited in claim 1 , wherein the criterion includes a source address associated with a security threat. 13. The method as recited in claim 1 , wherein the criterion relates to at least one of: an HTTP agent string, a network traffic size, a length of a uniform resource locator string, a byte count per request, a domain name, or a source address. 14. The method as recited in claim 1 , wherein the plurality of time-stamped events comprise unstructured data. 15. The method as recited in claim 1 , further comprising: receiving, by the computer system, an input corresponding to a selection of the event group summary; and in response to the user input corresponding to the selection of the event group summary, updating, by the computer system, the graphical interface to display information related to at least one event in the event group summary. 16. The method as recited in claim 1 , wherein the graphical interface includes a modify element associated with the event group summary, and wherein interaction with the modify element causes the event group summary to be visually modified in the graphical interface. 17. The method as recited in claim 1 , further comprising: generating, by the computer system, a display that includes an add element and one or more event group summaries that have been removed from the graphical interface, wherein the one or more event group summaries include the event group summary, and wherein a user interaction with the add element causes the event group summary to be added back to the graphical interface; and in response to a user interaction with the add element, updating, by the computer system, the graphical interface to add the event group summary back to the graphical interface. 18. The method of claim 1 , wherein the event group summary includes a result of a correlation search. 19. The method of claim 1 , wherein the event group is determined using an agent string that has been extracted from one or more events in a subset of the event group. 20. The method of claim 1 , wherein the event group is determined using a particular length of a uniform resource locator string that has been extracted from one or more events in the event group or a source address that has been extracted from one or more events in the event group. 21. The method of claim 1 , wherein each event in the plurality of time-stamped events is locatable in a searchable time-series data store using a time stamp of the event. 22. The method of claim 1 , further comprising: removing, by the computer system, an event from the plurality of time-stamped events when the event is not recognized as notable. 23. The method as recited in claim 1 , wherein each event in the plurality of time-stamped events includes information relating to security of an information technology environment. 24. The method as recited in claim 1 , further comprising: segmenting, by the computer system, stored raw machine data into the plurality of time-stamped events, wherein each event in the plurality of time-stamped events includes information relating to security of an information technology environment. 25. The method as recited in claim 1 , wherein the event group summary includes a count of a number of events in the event group summary. 26. The method as recited in claim 1 , further comprising: extracting, by the computer system, values for fields in events in the event group, by applying a late binding schema to at least a portion of the plurality of events. 27. The method as recited in claim 1 , further comprising: evaluating, by the computer system, whether events in the event group satisfy the criterion. 28. The method as recited in claim 1 , further comprising: evaluating, by the computer system, whether events in the event group satisfy the criterion by applying a late binding schema to at least a portion of the plurality of events.

Assignees

Inventors

Classifications

  • Time stamp · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Clustering or classification · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11178167B2 cover?
A disclosed computer-implemented method includes receiving and indexing the raw data. Indexing includes dividing the raw data into time stamped searchable events that include information relating to computer or network security. Store the indexed data in an indexed data store and extract values from a field in the indexed data using a schema. Search the extracted field values for the security i…
Who is the assignee on this patent?
Splunk Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 16 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).