Differential dependency tracking for attack forensics

US9736173B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9736173-B2
Application numberUS-201514879876-A
CountryUS
Kind codeB2
Filing dateOct 9, 2015
Priority dateOct 10, 2014
Publication dateAug 15, 2017
Grant dateAug 15, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for intrusion attack recovery include monitoring two or more hosts in a network to generate audit logs of system events. One or more dependency graphs (DGraphs) is generated based on the audit logs. A relevancy score for each edge of the DGraphs is determined. Irrelevant events from the DGraphs are pruned to generate a condensed backtracking graph. An origin is located by backtracking from an attack detection point in the condensed backtracking graph.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for intrusion attack recovery, comprising: monitoring two or more hosts in a network to generate audit logs of system events; generating one or more dependency graphs (DGraphs) based on the audit logs; building a reference model, and determining a relevancy score for each of a plurality of edges of the DGraphs based on the reference model; pruning irrelevant events from the DGraphs to generate a condensed backtracking graph based on the relevance score, the pruning comprising: removing events from the DGraphs that are in paths exceeding a threshold length from an attack detection point, and removing resources determined to be unrelated to an attack; and backtracking from the attack detection point in the condensed backtracking graph to locate an origin. 2. The method of claim 1 , wherein pruning irrelevant events further comprises removing events from the DGraphs that do not lead to a relevant event in a path from the attack detection point. 3. The method of claim 1 , wherein pruning irrelevant events further comprises comparing events to a relevancy threshold. 4. The method of claim 3 , wherein pruning irrelevant events further comprises removing paths having no event that exceeds a relevancy threshold. 5. The method of claim 1 , wherein pruning irrelevant events further comprises removing events having an associated time that occurred after the attack detection point. 6. The method of claim 1 , wherein determining the relevancy score for each of a plurality of edges comprises performing a depth-limited search. 7. A system for intrusion attack recovery, comprising: a remote host monitor configured to monitoring two or more hosts in a network to generate audit logs of system events and to generate one or more dependency graphs (DGraphs) based on the audit logs; a relevance determiner comprising a memory coupled to a processor, the processor being configured to build a reference model, to determine a relevancy score for each of a plurality of edges of the DGraphs based on the reference model, and to for pruning irrelevant events from the DGraphs to generate a condensed backtracking graph based on the relevancy score, the pruning comprising: removing events from the DGraphs that are in paths exceeding a threshold length from an attack detection point; and removing resources determined to be unrelated to an attack; and a backtracker configured to backtrack from the attack detection point in the condensed backtracking graph to locate an origin. 8. The system of claim 7 , wherein the relevance determiner is further configured to remove events from the DGraphs that do not lead to a relevant event in a path from the attack detection point. 9. The system of claim 7 , wherein the relevance determiner is further configured to compare events to a relevancy threshold. 10. The system of claim 9 , wherein the relevance determiner is further configured to remove paths having no event that exceeds a relevancy threshold. 11. The system of claim 7 , wherein the relevance determiner is further configured to remove events having an associated time that occurred after the attack detection point. 12. The system of claim 7 , wherein the relevance determiner is further configured to perform a depth-limited search.

Assignees

Inventors

Classifications

  • Tracing the source of attacks · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Physics · mapped topic

  • Traffic logging, e.g. anomaly detection · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9736173B2 cover?
Methods and systems for intrusion attack recovery include monitoring two or more hosts in a network to generate audit logs of system events. One or more dependency graphs (DGraphs) is generated based on the audit logs. A relevancy score for each edge of the DGraphs is determined. Irrelevant events from the DGraphs are pruned to generate a condensed backtracking graph. An origin is located by ba…
Who is the assignee on this patent?
Nec Lab America Inc, Nec Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 15 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).