Integrating security policy and event management

US9548994B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9548994-B2
Application numberUS-201414487927-A
CountryUS
Kind codeB2
Filing dateSep 16, 2014
Priority dateOct 18, 2011
Publication dateJan 17, 2017
Grant dateJan 17, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A plurality of security events is detected in a computing system, each security event based on at least one policy in a plurality of security policies. Respective interactive graphical representations are presented in a graphical user interface (GUI) of either or both of the security events or security policies. The representations include interactive graphical elements representing the respective security events or security policies. User selection of a particular event element via the interactive GUI causes a subset of the security policies to be identified, each security policy in the subset serving as a basis for at least one particular security event represented by the particular event element. User selection of a particular policy element via the interactive GUI causes a subset of the security policies to be identified, each security event in the subset based at least in part on a particular security policy represented by the particular policy element.

First claim

Opening claim text (preview).

What is claimed is: 1. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to: access security data identifying a plurality of security events detected in a computing system, wherein each of the plurality of security events is based on a respective one of a plurality of security policies; determine, for each of the plurality of security events, attributes of the event from the security data; present a representation of the plurality of security events in an interactive graphical user interface, wherein the representation comprises a plurality of graphical elements, each graphical element represents a respective subset of the plurality of security events corresponding to an intersection of at least two respective event attributes, size of each graphical element is rendered to indicate an amount of the plurality of security events included in the corresponding subset; and detect a user interaction with a particular one of the plurality of graphical elements through the graphical user interface, wherein the particular graphical element corresponds to a particular subset of the plurality of security events, and the user interaction causes a presentation of a view, within the graphical user interface, identifying a respective subset of the plurality of security policies corresponding to detection of the particular subset of security events. 2. The storage medium of claim 1 , wherein each graphical element is presented to indicate whether the subset of security events comprises at least one event of a particular type. 3. The storage medium of claim 2 , wherein the particular type comprises a critical security event. 4. The storage medium of claim 2 , wherein a color of the graphical element indicates whether the subset of security events comprises at least one event of the particular type. 5. The storage medium of claim 1 , wherein each graphical element comprises a selectable element and selection of the element causes a view to be presented to describe details of security events in the subset corresponding to the element. 6. The storage medium of claim 1 , wherein the representation further comprises a grid, an x-axis of the grid corresponds to a first plurality of event attributes of a first type, a y-axis of the grid corresponds to a second plurality of event attributes of a second type, each grid intersection corresponds to an intersection of a respective one of the event attributes of the first type and a respective one of the event attributes of the second type, and each of the graphical elements is located at a respective one of the grid intersections and represents an amount of detected security events having both the corresponding event attribute of the first type and the corresponding event attributes of the second type. 7. The storage medium of claim 1 , wherein each of the plurality of graphical elements comprises a respective circular graphical element and the size comprises a diameter of the respective graphical element to indicate the amount of events represented by the circular graphical element. 8. The storage medium of claim 1 , wherein the plurality of security policies comprise a plurality of security policies defined for the computing system. 9. The storage medium of claim 1 , wherein the subset of security policies includes all security policies serving as a basis for any one of the particular subset of security events corresponding to the particular event. 10. The storage medium of claim 1 , wherein the view comprises a listing of the subset of the security policies and the instructions, when executed, further cause the machine to receive, via the interactive graphical user interface, a user selection of a particular security policy presented in the listing of the subset of security policies. 11. The storage medium of claim 10 , wherein selection of the particular security policy presented in the listing causes a window to be displayed including a view of attributes of the particular security policy. 12. The storage medium of claim 11 , wherein the instructions, when executed, further cause the machine to: receive user inputs, via the window, indicating a modification to the particular security policy; and modify the particular security policy in accordance with the indicated modification. 13. The storage medium of claim 1 , wherein the security data is generated by at least one security tool adapted to detect security events in a computing system. 14. The storage medium of claim 1 , wherein at least one of the event attributes corresponds to a type of the security event. 15. A method comprising: accessing security data identifying a plurality of security events detected in a computing system, wherein each security event in the plurality of security events is based on at least one policy in a plurality of security policies defined for the computing system; determining, for each of the plurality of security events, attributes of the event from the security data; presenting a representation of the plurality of security events in an interactive graphical user interface, wherein the representation comprises a plurality of graphical elements, each graphical element represents a respective subset of the plurality of security events corresponding to an intersection of at least two respective event attributes, size of each graphical element is rendered to indicate an amount of the plurality of security events included in the corresponding subset; and detecting a user interaction with a particular one of the plurality of graphical elements through the graphical user interface, wherein the particular graphical element corresponds to a particular subset of the plurality of security events, and the user interaction causes a presentation of a view, within the graphical user interface, identifying a respective subset of the plurality of security policies corresponding to detection of the particular subset of security events. 16. A system comprising: at least one processor device; at least one memory element; an event manager, comprising logic when executed by the at least one processor device to: access security data identifying a plurality of security events detected in a computing system, each security event in the plurality of security events based on at least one policy in a plurality of security policies defined for the computing system; and determine, for each of the plurality of security events, attributes of the event from the security data; and a security event user interface engine, comprising logic when executed by the at least one processor device to: present a representation of the plurality of security events in an interactive graphical user interface, wherein the representation comprises a plurality of graphical elements, each graphical element represents a respective subset of the plurality of security events corresponding to an intersection of at least two respective event attributes, size of each graphical element is rendered to indicate an amount of the plurality of security events included in the corresponding subset; and detect a user interaction with a particular one of the plurality of graphical elements through the graphical user interface, wherein the particular graphical element corresponds to a particular subset of the plurality of security events, and the user interaction causes a presentation of a view, within the graphical user interface, identifying a respective subset of the plurality of security policies corresponding to detection of the particula

Assignees

Inventors

Classifications

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • involving event detection and direct action · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9548994B2 cover?
A plurality of security events is detected in a computing system, each security event based on at least one policy in a plurality of security policies. Respective interactive graphical representations are presented in a graphical user interface (GUI) of either or both of the security events or security policies. The representations include interactive graphical elements representing the respect…
Who is the assignee on this patent?
Mcafee Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 17 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).