System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using provenance tags and customizable policy

US11601442B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11601442-B2
Application numberUS-201916544401-A
CountryUS
Kind codeB2
Filing dateAug 19, 2019
Priority dateAug 17, 2018
Publication dateMar 7, 2023
Grant dateMar 7, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path.A corresponding method and computer-readable medium are also disclosed.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign in a victim system environment, the system comprising: a memory configured to store instructions; and a processing device coupled to the memory, the processing device executing a real-time attack scenario reconstruction application with the instructions stored in memory, wherein the application is configured to: receive an audit data stream associated with cyber events; identify trustworthiness values in a portion of data associated with the cyber events; assign provenance tags to the portion of the data based on the identified trustworthiness values; generate an initial visual representation based on the assigned provenance tags to the portion of the data; condense the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and generate a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path. 2. The system as recited in claim 1 , wherein the system is further configured to condense the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file. 3. The system as recited in claim 1 , wherein the system is further configured to generate a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths. 4. The system as recited in claim 1 , wherein the provenance tags further comprise trustworthiness tags. 5. The system as recited in claim 1 , wherein the provenance tags further comprise confidentiality tags assigned to the portion of the data based on identified confidentiality values. 6. The system as recited in claim 1 , wherein the portion of the data comprises one or more of objects and subjects. 7. The system as recited in claim 6 , wherein the objects are referenced within events using an index into a per-subject table of object identifiers. 8. The system as recited in claim 1 , wherein the provenance tags are further assigned to the portion of the data based on identified sensitivity values. 9. A method for detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign in a victim system environment, the method comprising: a processing device coupled to a memory that stores instructions, the processing device executing a real-time attack scenario reconstruction application with the instructions stored in memory, wherein the application is configured to perform the following operations: receiving an audit data stream associated with cyber events; identifying trustworthiness values in a portion of data associated with the cyber events; assigning provenance tags to the portion of the data based on the identified trustworthiness values; generating an initial visual representation based on the assigned provenance tags to the portion of the data; condensing the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path. 10. The method as recited in claim 9 , wherein the method further comprises condensing the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file. 11. The method as recited in claim 9 , wherein the method further comprises generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths. 12. The method as recited in claim 9 , wherein the provenance tags further comprise trustworthiness tags. 13. The method as recited in claim 9 , wherein the provenance tags further comprise confidentiality tags assigned to the portion of the data based on identified confidentiality values. 14. The method as recited in claim 9 , wherein the portion of the data comprises one or more of objects and subjects. 15. The method as recited in claim 14 , wherein the objects are referenced within events using an index into a per-subject table of object identifiers. 16. The method as recited in claim 9 , wherein the provenance tags are further assigned to the portion of the data based on identified sensitivity values. 17. A non-transitory computer-readable medium storing instructions that, when executed by a real-time attack scenario reconstruction processing device, performs operations that include: receiving an audit data stream associated with cyber events associated with a cyber-attack in a victim system environment; identifying trustworthiness values in a portion of data associated with the cyber events; assigning provenance tags to the portion of the data based on the identified trustworthiness values; generating an initial visual representation based on the assigned provenance tags to the portion of the data; condensing the initial visual representation based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect process and/or file to an entry point process and/or file; and generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on the identified shortest path. 18. The computer readable medium as recited in claim 17 , wherein the operations further comprise condensing the initial visual representation based on a forward traversal of the initial visual representation in identifying the shortest path from the suspect process and/or file to the entry point process and/or file. 19. The computer readable medium as recited in claim 17 , wherein the operations further comprise generating a scenario visual representation that specifies processes and/or files in the victim system environment having a higher likelihood, compared to other processes and/or files in the victim system environment, of contributing to the cyber events associated with the cyber-attack based on multiple identified shortest paths. 20. The computer readable medium as recited in claim 17 , wherein the provenance tags further comprise trustworthines

Assignees

Inventors

Classifications

  • Traffic logging, e.g. anomaly detection · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11601442B2 cover?
A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data…
Who is the assignee on this patent?
Univ New York State Res Found, The Univ Of Illinois At Chicago, Univ Illinois
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 07 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).