Patent · US Active

Detecting advanced persistent threats

US8904531B1 · kind B1 · utility

21Cited by
1References
14Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 30, 2011
Grant dateDec 2, 2014
Priority date
Expiry dateApr 18, 2033

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1416
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques are provided for detecting the source of an APT-based leaked document by iteratively or recursively evaluating a set of network security logs (e.g., SIEM logs and FPC logs) for events consistent with APT behavior according to a set of heuristics to generate a reduced set of security events for consideration by the CIRT. A method of detecting an APT attack on an enterprise system is provided. The method includes (a) receiving, in a computerized device, an indication that a document has been leaked outside the enterprise system, (b) evaluating a log of security events of the enterprise system using a set of heuristics to produce a reduced set of events potentially relevant to the APT attack, and (c) outputting the reduced set of events over a user interface for consideration by a security analysis team. A system and computer program product for performing this method are also provided.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.