Customizable threat rules in a computer network

US12323452B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-12323452-B1
Application numberUS-202117316560-A
CountryUS
Kind codeB1
Filing dateMay 10, 2021
Priority dateApr 30, 2017
Publication dateJun 3, 2025
Grant dateJun 3, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosed embodiments include a method performed by a computer system. The method includes causing display of one or more graphical controls enabling a user to define attributes of a threat rule, the attributes including a type of computer network entity and an anomaly pattern associated with the type of computer network entity. The method further includes generating the threat rule based on interaction by a user with the one or more graphical controls, wherein the threat rule identifies a security threat to the computer network that satisfies the attributes of the threat rule based on one or more detected anomalies on the computer network.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: causing display of a plurality of graphical controls on each of a plurality of displays that enable a user to define a plurality of attributes of a customizable threat rule, the plurality of graphical controls including: an entity type graphical control usable to define a computer network entity attribute that specifies a type of a computer network entity of a computer network, an anomaly pattern graphical control usable to define an anomaly pattern attribute, a time period graphical control usable to define a time period for processing anomalies, and an action graphical control usable to specify a remedial or mitigative action to perform in response to an anomaly that satisfies the plurality of attributes of the customizable threat rule; wherein the user can navigate between respective displays of the plurality of displays; generating the customizable threat rule based on the attributes defined by user selections on the plurality of displays, wherein generating the customizable threat rule includes: customizing the computer network entity attribute that specifies the type of computer network entity in response to selection by the user of a type of computer network entity from among a displayed set of selectable types of computer network entities using the entity type graphical control, wherein the displayed set of selectable types of computer network entities includes a user entity type, a device entity type and a session entity type; customizing the anomaly pattern attribute in response to an interaction by the user with the anomaly pattern graphical control, the anomaly pattern graphical control being selected based on the selection of the type of computer network entity, and the anomaly pattern attribute defining a detectable variation from an expected pattern of behavior associated with the type of computer network entity; customizing the time period for processing anomalies in response to an interaction by the user with the time period graphical control; and customizing the remedial or mitigative action in response to an interaction by the user with the action graphical control; receiving, at a security platform, input indicating detection, based on an anomaly model, of a detected anomaly on the computer network; in response to receiving the input, processing the detected anomaly by the security platform using the customizable threat rule; and performing the customized remedial or mitigative action in response to the detected anomaly when the detected anomaly is associated with an entity that satisfies the customized computer network entity attribute of the customizable threat rule, the detected anomaly satisfies the customized anomaly pattern attribute of the customizable threat rule, and the detected anomaly is detected during the customized time period for processing anomalies of the customizable threat rule. 2. The method of claim 1 , further comprising, prior to causing the display of the plurality of graphical controls: receiving user input based on interaction with a graphical control causing a display for the user to create the customizable threat rule. 3. The method of claim 1 , further comprising: causing display of an entry for each of a plurality of threat rules including the customizable threat rule, each entry including a threat rule name and at least one of a threat type, a count of threats satisfying the customizable threat rule, an identifier of the user that created the customizable threat rule, or a point in time at which the customizable threat rule was created. 4. The method of claim 1 , further comprising: causing display of an entry for each of a plurality of threat rules including the customizable threat rule, each entry including a threat rule name and a graphical control selectable by the user to enable or disable the customizable threat rule. 5. The method of claim 1 , wherein the plurality of attributes includes a filter for the type of computer network entity, the filter including at least one of: an anomalies count; a geographic location; a specific entity; an entity record; a security threat count; an entity status; or an entity watchlist. 6. The method of claim 1 , wherein the type of computer network entity is selected by the user from a first display, and the anomaly pattern graphical control is included in a second display displayed after the first display. 7. The method of claim 1 , wherein defining the plurality of attributes comprises: defining an anomaly condition of the anomaly pattern attribute based on user interaction with one or more graphical controls of the plurality of graphical controls. 8. The method of claim 1 , wherein defining the plurality of attributes comprises: defining an anomaly type of the anomaly pattern attribute based on user interaction with one or more graphical controls of the plurality of graphical controls. 9. The method of claim 1 , wherein defining the plurality of attributes comprises: defining an anomaly type of the anomaly pattern attribute, an anomaly count of the anomaly type, and an anomaly filter of the anomaly type. 10. The method of claim 1 , wherein the anomaly pattern graphical control comprises anomaly type graphical controls that each correspond to a respective anomaly type, and wherein defining the plurality of attributes comprises: defining an anomaly type of the anomaly pattern attribute in response to a selection by the user of one of the anomaly type graphical controls. 11. The method of claim 1 , wherein the plurality of attributes includes a plurality of ordered anomaly conditions. 12. The method of claim 1 , wherein the plurality of attributes includes a plurality of unordered anomaly conditions. 13. The method of claim 1 , wherein the type of computer network entity is selected by the user from a first display, the anomaly pattern graphical control is displayed on a second display, and the time period graphical control is displayed on a third display. 14. The method of claim 1 , wherein the plurality of attributes includes a property of security threats satisfying the customizable threat rule, the property including at least one of a threat score, a custom threat type, or a threat description. 15. The method of claim 1 , further comprising: storing in a memory the customizable threat rule, including information specifying the type of computer network entity and the anomaly pattern attribute; receiving user input to retrieve the customizable threat rule stored in the memory; receiving user input to edit an attribute of the plurality of attributes of the customizable threat rule based on an interaction with one or more graphical controls, wherein the user input to edit the attribute of the plurality of attributes results in an edited threat rule; storing the edited threat rule in the memory; and identifying a security threat to the computer network that satisfies the plurality of attributes of the edited threat rule. 16. The method of claim 1 , further comprising: causing display of the security threat or data indicative of the security threat. 17. A computer system comprising: a processor; and memory containing instructions that, when executed by the processor, cause the computer system to: cause display of a plurality of graphical controls on each of a plurality of displays that enable a user to define a plurality of attributes of a customizable threat rule, the plurality of graphical controls including: an entity type graphical control usable to define a computer network entity

Assignees

Inventors

Classifications

  • involving event detection and direct action · CPC title

  • Configuration of triggering conditions · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Distributed architectures, e.g. distributed firewalls · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12323452B1 cover?
The disclosed embodiments include a method performed by a computer system. The method includes causing display of one or more graphical controls enabling a user to define attributes of a threat rule, the attributes including a type of computer network entity and an anomaly pattern associated with the type of computer network entity. The method further includes generating the threat rule based o…
Who is the assignee on this patent?
Splunk Llc, Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 03 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).