Presentation of threat history associated with network activity

US2016173446A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016173446-A1
Application numberUS-201414568771-A
CountryUS
Kind codeA1
Filing dateDec 12, 2014
Priority dateDec 12, 2014
Publication dateJun 16, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for extracting, processing, displaying, and analyzing events that are associated with one or more threats are provided. According to one embodiment, threat information, including information from one or more of firewall logs and historical threat logs, is maintained in a database. Information regarding threat filtering parameters, including one or more of types of threats to be extracted from the database, parameters of the threats, network-level details of the threats, a time interval of detection of the threats and source-destination details of the threats, is received. Information regarding threats matching the threat filtering parameters are extracted from the database and is presented in a form of an interactive historical graph. Responsive to receiving from a user an indication regarding a selected subset of time in which to zoom into for further details, a list of threats within the selected subset is presented in tabular form.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: maintaining, by a computing device, threat information in a database comprising one or more of firewall logs and historical threat logs; receiving information regarding a plurality of threat filtering parameters, by the computing device, wherein the information includes one or more of types of threats to be extracted from the database, parameters of the threats, network-level details of the threats, a time interval of detection of the threats and source-destination details of the threats; extracting, by the computing device, information regarding a plurality of threats from the database based on the plurality of threat filtering parameters; and presenting, by the computing device, the extracted information in a form of a historical graph illustrating a number of threats by type during a particular period of time; and receiving from a user, by the computing device, an indication regarding a selected subset of the particular period of time in which to zoom into for further details; and responsive to the indication regarding the selected subset, presenting, by the computing device, a list of threats of the plurality of threats corresponding to the selected subset, wherein the list of threats is presented in tabular form, grouped and counted by type of threat and ordered by group in accordance with their associated risk levels. 2 . The method of claim 1 , wherein the database is updated in real-time. 3 . The method of claim 1 , wherein the firewall logs, for one or more network traffic flows, store information regarding one or more of parameters of network traffic flows, levels of risk, packet information, source-destination information, host names, infected websites, top destinations for potential threats, top sources of potential threats, origin points of potential threats, event identifiers, types of analysis, bandwidth usage, source Internet Protocol (IP) addresses, destination IP addresses, importance, application details, port information, timestamps, time frames, user details, source device details, destination device details, levels of trust, source operating system details, virus scan levels and schedules. 4 . The method of claim 1 , wherein the historical threat logs comprise information regarding each of a plurality of observed threats including one or more of a severity, a type and source-destination attributes. 5 . The method of claim 6 , wherein the historical graph comprises one or more of a stacked area graph, a stacked bar chart, a stacked column chart, a line chart, a point chart, a pie chart, a histogram, a line chart, a tree chart, a organizational chart, a timeline chart, a flowchart, a cartogram, a pedigree chart, a waterfall chart, a polar area chart, and a bubble chart. 6 . The method of claim 1 , further comprising receiving from the user presentation parameters for customizing the historical graph viewable parameters of the plurality of threats, wherein the customization comprises viewing details of threats, viewing relationships between threats, zooming options for minutely assessing details of threats, drag-select options for positioning threats. 7 . The method of claim 1 , wherein the step of reporting comprises presenting one or more of trends, indicators, and suggestions based on the plurality of threats, wherein the trends indicate manner and/or mode in which the plurality of threats have taken place, and wherein suggestions indicate comments on potential future threats. 8 . The method of claim 1 , wherein the historical graph is updated in real-time by continuously extracting information from the database based on the plurality of threat filters. 9 . The method of claim 1 , wherein the historical graph is updated at pre-defined intervals by periodically extracting information from the database based on the plurality of threat filters. 10 . A system comprising: one or more processors; a communication interface device; one or more internal data storage devices operatively coupled to the one or more processors and storing; a threat history identification module configured to extract threat information from a database comprising one or more of firewall logs and historical threat logs; a threat history processing module configured to process the extracted threat information based on one or more of threats to be detected, parameters of threats to be presented, network level details of the threats, time interval for which threats are to be presented, and source-destination details of the threats; and a threat reporting module configured to report a plurality of threats selected from the one or more threats based on one or a combination of presentation parameters, timing parameters, and threat content parameters. 11 . The system of claim 10 , wherein the database is updated in real-time. 12 . The system of claim 10 , wherein the firewall logs, for one or more network traffic flows, store information regarding one or a combination of parameters of network traffic flow, level of risk, packet information, source-destination information, host names, infected websites, top destinations for threats, top sources of threats, origin points of threats, event identifiers, type of analysis, bandwidth usage, source Internet Protocol (IP) address, destination IP address, importance, application details, port information, timestamps and/or time frames, user details, source device details, destination device details, level of trust, source operating system details, virus scan level, and schedule. 13 . The system of claim 10 , wherein the historical threat logs comprise information on one or more threats, number of threats, severity of threats, type of threats, and source-destination attributes relating to the threats. 14 . The system of claim 10 , wherein the threat history processing module is further configured to identify the plurality of threats that are to be reported. 15 . The system of claim 10 , wherein the presentation parameters indicate graphic representation of the threats, wherein the graphic representation comprises one or a combination of textual, graphical, audio, and video based representation. 16 . The system of claim 15 , wherein the graphic representation comprises one or more of stacked area graph, a stacked bar chart, a stacked column chart, a line chart, a point chart, a pie chart, a histogram, a line chart, a tree chart, a organizational chart, a timeline chart, a flowchart, a cartogram, a pedigree chart, a waterfall chart, a polar area chart, and a bubble chart. 17 . The system of claim 10 , wherein the threat reporting module is further configured to allow users to customize the viewable parameters of the plurality of threats, wherein the customization comprises viewing details of threats, viewing relationships between threats, zooming options for minutely assessing details of threats, drag-select options for positioning threats. 18 . The system of claim 10 , wherein timing parameters comprise time intervals for which threats are to be viewed. 19 . The system of claim 10 , wherein the threat reporting module is further configured to present one or more of trends, indicators, and suggestions based on the plurality of threats, wherein the trends indicate manner and/or mode in which the plurality of threats have taken place, and wherein suggestions indicate comments on potential future threats. 20 . The system of claim 10 , wherein the threat history processing module and the threat reporting module are conf

Assignees

Inventors

Classifications

  • Timestamp · CPC title

  • H04L63/02Primary

    for separating internal from external traffic, e.g. firewalls · CPC title

  • Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016173446A1 cover?
Methods and systems for extracting, processing, displaying, and analyzing events that are associated with one or more threats are provided. According to one embodiment, threat information, including information from one or more of firewall logs and historical threat logs, is maintained in a database. Information regarding threat filtering parameters, including one or more of types of threats to…
Who is the assignee on this patent?
Fortinet Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/02. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 16 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).