Patent · US Active

Event correlation across heterogeneous operations

US10148685B2 · kind B2 · utility

11Cited by
4References
22Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 17, 2017
Grant dateDec 4, 2018
Priority date
Expiry dateJul 17, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/10
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for determining a network security threat response. A data structure that represents communication events between computing devices of two or more network domains is received. The data structure is analyzed and a threat scenario that is based on a chain of communication events that indicates a potential attack path is determined. The chain of communication events include a sequence of communication events between computing devices proceeding from an originating computing device to a destination computing device, wherein the originating computing device and the destination computing device exist on different network domains. Attack pattern data, for the threat scenario and from a threat intelligence data source, that is associated with communications between computing devices that occurred during one or more prior attacks is received. Based on the threat scenario and the attack pattern data, one or more courses of action for responding to the threat scenario is determined, and information associated with the one or more courses of action is provided.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.