Apparatus, system, and method for summarizing analytical observations

The method and system for deduplicating security case alerts using key-value pairs and a slotting system address the challenge of managing redundant alerts in network security, enhancing efficiency and reducing analyst workload.

JP2025517620AActive Publication Date: 2025-06-10BLUEVOYANT LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024564570
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-12
Filing Date
2023-05-10
Publication Date
2025-06-10
Estimated Expiration
2043-05-10

AI Technical Summary

Technical Problem

Existing network security systems face challenges in efficiently deduplicating security case alerts and generating representative key-value pairs for cyber event or cyber asset behavior, leading to unnecessary alerts and increased analyst workload.

Method used

A method and system that utilize key-value pairs, including a hash value representing the behavior of a cyber event or asset and an asset identifier, to deduplicate security case alerts. This involves processing behavior observation data, executing queries, generating hash values, and implementing a slotting system to suppress subsequent alerts within a predetermined time interval.

Benefits of technology

The proposed solution effectively reduces the number of security case alerts by approximately 50% through deduplication, improving analyst efficiency and reducing alert fatigue while maintaining accurate tracking of asset behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025517620000001_ABST
    Figure 2025517620000001_ABST
Patent Text Reader

Abstract

Representative key: A method for generating a pair of values for the behavior of a cyber event or cyber asset and eliminating duplicates for a plurality of alerts associated with the behavior of the cyber event or cyber asset. The key: value pair includes a hash value representing the behavior of the cyber event or cyber asset and an asset identifier. The key: value pair provides an identifier queryable by a security operations center, easily tracks the behavior of the asset, and determines the number of cyber event observations over a given period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims priority to U.S. Provisional Patent Application No. 63 / 341,264, filed on May 12, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS", the disclosure of which is hereby incorporated by reference in its entirety.

Background Art

[0002] The present disclosure generally relates to network security, and more specifically, to improved devices, systems, and methods for generating representative key - value pairs of cyber event or cyber asset behavior, and to deduplication of multiple alerts associated with cyber event or cyber asset behavior. The key - value pairs include a hash value representing the behavior of a cyber event or cyber asset and an asset identifier. The key - value pairs provide an identifier queryable by a security operation center and facilitate tracking of asset behavior.

Summary of the Invention

[0003] The following summary is provided to facilitate an understanding of some of the innovative features specific to the aspects disclosed herein and is not intended to be a complete description. A complete understanding of the various aspects can be obtained by taking the entire specification, claims, and summary.

[0004] In one aspect, the present disclosure is a method for deduplicating security case alerts based on the identification of key:value pairs for behavior observation data and asset identifiers, the method comprising: receiving, by a processor, a dataset including behavior observation data from one or more data sources; executing, by the processor, a query including a search stored in security detection, the query searching the dataset of behavior observation data for data entries that match one or more searches stored in security detection; generating, by the processor, search results from the dataset, the search results including a matching of dataset entries with searches stored in security detection, each matching entry in the search results being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier; determining, by the processor, one or more dynamic fields of each search stored in security detection based on the query results of each search stored in security detection; excluding, by the processor, one or more dynamic fields from the query; concatenating, by the processor, a search string including all fields that are not excluded; generating, by the processor, a hash value of the concatenated search string; generating, by the processor, a first key:value pair having the first generated hash value that summarizes the behavior of the asset and the asset identifier; determining, by the processor, a predetermined slotting interval for the key:value pair, the slotting interval indicating the amount of time between alerts for security cases for the first key:value pair; issuing, by the processor, a first security case alert that is the first security case within the slotting interval for the first key:value pair and starting a counter for the first key:value pair; detecting, by the processor, a second query result that matches the first key:value pair; determining, by the processor, that the counter is less than the slotting interval; and, by the processor, during the predetermined slotting interval,Suppress subsequent security case warnings for a second query result that matches the first key:value pair, and update the throttling log associated with each key:value pair to include the total number of matching key:value pairs detected during the throttling interval by a processor. A method for deduplicating security case alerts is described.

[0005] In another aspect, the present disclosure is a system for generating a unique hash value representing a queryable threat event, the system comprising at least one processor, at least one memory communicatively coupled to the at least one processor, an input / output interface configured to access data from one or more external sources, each of the plurality of external sources communicatively coupled to the at least one processor, and a database stored in the at least one memory and configured to store data. The at least one memory is configured to receive, by the at least one processor, a dataset including behavior observation data from one or more data sources, execute a query including a search stored in a security detection, the query searching the dataset of behavior observation data for data entries that match one or more searches stored in a security detection, generate a search result from the dataset, the search result including a matching between a dataset entry and a search stored in a security detection, each matching entry of the search result being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier, generate the search result, determine one or more dynamic fields of each search stored in a security detection based on the query result of each search stored in a security detection, exclude the one or more dynamic fields from the query, concatenate a search string including all fields that are not excluded, generate a hash value for the concatenated search string, generate a first key:value pair having the first generated hash value that summarizes the behavior of the asset and the asset identifier, determine a predetermined slotting interval for the key:value pair, the slotting interval indicating an amount of time between alerts for a security case for the first key:value pair, issue a first security case alert that is the first security case within the slotting interval for the first key:value pair and start a counter for the first key:value pair, detect a second query result that matches the first key:value pair,To determine that a counter is less than a slotting interval, to suppress subsequent security case warnings for a second query result that matches a first key:value pair during a predetermined slotting interval, and to update a slotting log associated with each key:value pair to include the total number of matching key:value pairs detected at the slotting interval, a system configured to store executable instructions is described.

Brief Description of the Drawings

[0006]

Figure 1

[0007]

Figure 2

[0008]

Figure 3

[0009]

Figure 4

[0010]

Figure 5

[0011]

Figure 6

[0012]

Figure 7

[0013] Corresponding reference numerals indicate corresponding parts throughout the several views. The examples described herein illustrate various aspects of the present invention in one form, and such examples should not be construed as limiting the scope of the present invention in any way.

DETAILED DESCRIPTION OF THE INVENTION

[0014] The applicant of the present application owns the following U.S. provisional patent applications, the entire disclosures of each of which are incorporated herein by reference in their entirety. - U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS - U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM - International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS - International Patent Application No. PCT / US2022 / 072743, filed on June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS -- U.S. Provisional Patent Application No. 63 / 365,819, filed on June 3, 2022, entitled DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY -SCALABLE, EFFICIENT COMPOSITE RECORD INDEX -- U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING,PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS - U.S. Provisional Patent Application No. 63 / 366,903, filed on June 23, 2022, entitled DEVICES, SYSTEMS, AND METHOD FOR GENERATING AND USEING A QUERYABLE INDEX IN A CYBER DATA MODEL TO ENHANCE NETWORK SECURITY - U.S. Provisional Patent Application No. 63 / 368,567, filed on July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTWORKED, COMPUTER-ASSISED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT" -- U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CONULOUSLY ENHANCING THE IMPLEMENT OF CODE CHANGES VIA ENRICHED PIPELINES" - International Patent Application No. PCT / US2022 / 082167, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - International Patent Application No. PCT / US2022 / 082173, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS" - International Patent Application No. PCT / US2023 / 061069, filed on January 23, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION’S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE" - International Patent Application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS.

[0015] Numerous specific details are described in this disclosure and are described to provide a complete understanding of the overall structure, function, manufacture, and use of the embodiments illustrated in the accompanying drawings. Well-known operations, components, and elements are not described in detail so as not to obscure the embodiments described herein. The reader will understand that the embodiments described and illustrated herein are non-limiting embodiments. Accordingly, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary. Changes and modifications can be made without departing from the scope of the claims.

[0016] Before detailing the various aspects and methods of the systems disclosed herein, it should be noted that the exemplary embodiments are not limited to the application or use of the details disclosed in the accompanying drawings and description. Of course, the exemplary embodiments may be implemented or incorporated in other embodiments, variations, and modifications and may be practiced or implemented in various ways. Further, unless otherwise indicated, the terms and expressions used herein are selected for the purpose of describing the exemplary embodiments for the convenience of the reader and are not intended to be limiting. For example, any reference herein to a particular manufacturer, software suite, application, or development platform is merely intended to illustrate some of the many aspects of this disclosure. This includes any reference to trademarks. Accordingly, it should be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any use purpose and / or user preference.

[0017] As used herein, the term "server" refers to, or may include, one or more computing devices that are operated by, or facilitate, communication and processing for multiple parties in a network environment, such as the Internet or any public or private network. As used herein, a reference to a "server" or "processor" may refer to previously enumerated servers and / or processors that perform previous steps or functions, different servers, and / or processors, and / or combinations of servers, and / or combinations of processors, as enumerated.

[0018] As used herein, the term "network" refers to, or can include, an entire enterprise information technology (IT) system introduced by a tenant. For example, a network can include a group of two or more nodes (e.g., assets) that are connected by any physical and / or wireless connection and configured to communicate and share information with one or more other nodes. However, the term "network" is not limited to any particular node or any particular means of connecting those nodes. A network can be connected to Ethernet, an intranet, and / or an extranet, and can be configured to communicate with each other via ad hoc connections (e.g., Bluetooth®, Near Field Communication (NFC), etc.), local area connections ("LAN"), wireless local area networks ("WLAN"), and / or virtual private networks ("VPN") regardless of the physical location of each device. The network can include any combination of assets (e.g., devices, servers, desktop computers, laptop computers, personal digital assistants, mobile phones, wearables, smart home appliances, etc.). The network can further include any tools, applications, and / or services that are deployed by a device or otherwise utilized by enterprise IT systems such as firewalls, email clients, document management systems, office systems, etc. In some non-limiting aspects, "network" can include third-party devices, applications, and / or services that are owned and controlled by a third party but that the tenant is authorized to access for the enterprise IT system.

[0019] As used herein, the term "platform" may include software architecture, hardware architecture, and / or combinations thereof. A platform may include any of a stand-alone software product, a network architecture, and / or a software product configured to be integrated within a software architecture and / or a hardware architecture as necessary to provide its technical benefits to the software product. For example, a platform may include any combination of a chipset, a processor, a logic-based device, memory, storage, a graphical user interface, a graphics subsystem, an application, and / or a communication module (e.g., a transceiver). In other words, a platform can provide the resources necessary to enable the technical benefits provided by the software. According to some non-limiting aspects, the technical benefits provided by the software are provided to other software employed by the physical resources of the ecosystem, or physical resources within the ecosystem (e.g., APIs, services, etc.). According to other non-limiting aspects, a platform may include a framework for several software applications intended and designed to function together.

[0020] As used herein, the term "security monitoring platform" refers to, or may include, software configured to aggregate and analyze activities from many different resources across an information technology (IT) infrastructure. For example, a security monitoring platform may include a security information and event management (SIEM) platform, and / or other types of platforms used for data monitoring and / or analysis (e.g., enterprise security, Microsoft Sentinel, Datadog security monitoring, ELK, etc.). The various aspects of the devices, systems, and methods disclosed herein related to SIEM may similarly be applied to any type of security monitoring platform.

[0021] Implementing SIEM can aggregate data (e.g., log data, event data, threat intelligence data, etc.) from multiple platforms and analyze that data to capture abnormal behavior or potential cyberattacks. SIEM can collect security data from network devices, servers, domain controllers, etc. Implementing SIEM can apply storage, normalization, aggregation, and analysis to that data to detect trends, detect threats, and enable an organization to investigate any alerts. Known SIEM tools (also referred to herein as SIEM detection engines) provide excellent functionality, including event monitoring, data collection, and issuance of security alerts across a network, but such tools are typically customized to the implementing organization, i.e., more specifically, to a particular network architecture that can be complex in many cases.

[0022] FIG. 1 shows a system 1000 configured for security information and event management (SIEM) implementation across multiple tenants, according to at least one non-limiting aspect of the present disclosure. The system 1000 may include a SIEM security analysis server 1002 having a memory 1004 and a processor 1006. In various aspects, the SIEM security analysis server 1002 may further include computer systems 7000 and their various components (e.g., the processor 1006 may be similar to the processor(s) 7004, and the memory 1004 may be similar to the main memory 7006, etc.) described with reference to FIG. 7.

[0023] In various aspects, the memory 1004 may be configured to store instructions that, when executed by the processor 1006, generate requests for data from multiple data sources. The security analysis server 1002 may be configured to receive or request data from multiple data sources. The multiple data sources include a third-party data source 1020 and a network entity 1010. The third-party data source 1020 is configured to monitor and record global Internet traffic and store the data in a local repository 1022. The network entity 1010 includes multiple cyber assets 1012, 1014 and provides data to the security analysis server 1002 associated with each cyber asset 1012, 1014. The data may include security observations, software versions, firmware versions, behavioral data, or other security data that is recorded at predetermined intervals and transmitted to the security analysis server 1002 for processing. The security analysis server 1002 may correlate various security observations to cyber assets. In one aspect, the security analysis server 1002 may flag behavioral data as correlating to a predetermined security risk according to a behavioral model. The security analysis server 1002 may send the data to a specific analyst 1030 or randomly shuffle the data to the next available analyst 1030.

[0024] In one aspect, the security analysis server 1002 receives behavior observation data from a plurality of data sources including a third party 1020 and a network entity 1010. The behavior observation data includes an asset identifier paired with a relevant behavior observation, such as the time an asset was accessed by a system, resource, or domain. The asset identifier may include a source IP address, a destination IP address, or a network domain. The server aggregates the behavior observation data from the plurality of data sources into a dataset, and the observation data is processed to evaluate security vulnerabilities, risks, security events, likelihood of attack, and the like. The server processes the behavior observation data by executing a query that compares the behavior observation data to a search stored in a plurality of security detections. Each search stored in a security detection includes a behavior profile that associates potential security risks with an asset's assets or malicious behavior. In one aspect, the searches stored in a security detection may be continuously updated or refreshed at a predetermined interval to ensure that the behavior profiles are up to date.

[0025] Based on the behavior profile, the system may identify behavior observations that correlate with a suspect file of a tenant's network or one of the tenant's assets. Suspect files may include malicious content such as malware, ransomware, or other content indicative of a cyber attack. In one aspect, the system has administrative privileges to remotely delete suspect files from one or more storage locations on the tenant's network. In another aspect, the system communicates directly with a tenant security administrator who locally manages the tenant's network. When a suspect file is detected, the system automatically generates an alert (e.g., email, text, phone) to the security administrator. The alert may include an identification of the malicious content on the suspect file, the location where the suspect file is stored, and the actions or interventions necessary to mitigate the threats associated with the suspect file.

[0026] In another aspect, the behavior observations are classified into a queryable table and can be sent to an analyst for further evaluation. When the behavior observation data is matched to a stored search in security detection, the system returns the query results in RowKey format. Each row in the RowKey format contains multiple fields associated with the asset identifier. The system evaluates each field corresponding to a stored search of an individual security detection and determines which fields are dynamic and which are non-dynamic. The system selects only the non-dynamic fields from the RowKey and generates a concatenated string value. The system uses the concatenated string as input to summarize the observed behavior of the asset and generate a hash value that matches the stored search of the security detection. The hash value is generated using a hash algorithm such as SHA1, SHA256, or MD5.

[0027] Dynamic field values are not desirable for generating representative identifiers for cyber behavior data because observation data with dynamic field values generates a unique hash and does not capture multiple occurrences of the same behavior. Dynamic fields, such as timestamps, vendor-specific identifiers, and processor-generated metadata, are excluded from the hash value generation process to ensure that the hash value is not unique and can be used to identify historical or future occurrences of the same behavior. When the system generates a hash value, the system creates a key:value pair where the key can be "dedup_hash" and the value can be the hash value associated with the finding. When the key:value pair is matched to a stored search in security detection, the system generates a security case associated with the key:value pair and issues the security case to the available analyst to perform post-triage analysis.

[0028] In various aspects, three types of dynamic fields are typically identified in the RowKey table and excluded from the hash value. These dynamic fields include usage-based fields (e.g., timestamp, start time / end time, session duration), vendor-introduced artifacts (e.g., vendor unique identifier), and dynamic fields introduced by the query itself (e.g., process-generated metadata). Examples of dynamic fields include the count of issues (the number of issue events collected by source detection), alertURL (the vendor creates a new alertURL for each iteration of the detected activity), the description of the issue (text that may include the timestamp of the issue), the period (the period between individual events, which is likely to change in subsequent activities), and internally added metadata (metadata created by a vendor such as BMS that includes server information, statistical artifacts added by a search component such as ufence, the score, max / min, processing of artifacts added by a search component such as WhiteList, the earliest / latest search_id, and result_id). In comparison, examples of non-dynamic fields include the destination IP address, source IP address, file name, file path, hash_md5, hash_sha1, hash_sha256, http_user_agent, process_command_line, process_path, signature, signature ID, user, source user, and target user.

[0029] The network security computing system further comprises a slotting system that determines a predetermined slotting interval for each search saved in a security detection. The slotting system issues a first security case associated with a key:value pair and starts a slotting interval counter that measures the period since the first security case was issued. During the slotting interval, subsequent security cases associated with the same key:value pair are suppressed. Evidence of cases shows that case suppression reduces the total number of security cases issued by about 50 percent. The slotting system can calculate this based on the log of the total number of behavior observations associated with the key:value pair at a given slotting interval and the number of deduplicated hash values. Before issuing a security case, the slotting system determines whether the slotting interval is active for the key:value pair. If the slotting interval is not valid, a new security case is issued. Further, when the slotting interval counter equals zero (countdown) or the slotting interval (count up), a new security case is issued for the same key:value pair.

[0030] Figure 2 shows a flowchart of method 2000 for generating unique behavior identifiers corresponding to cyber behavior data and eliminating duplicates of behavior security cases before cases are sent to analysts for further evaluation. Security analysis server 1002 fetches data 2002 from a plurality of data sources including third party 1020 and network entity 1010, and aggregates the data into a single data set at 2004. Security analysis server 1002 obtains a list 2006 of searches saved in security detection from an external source or local repository, and queries 2008 the aggregated data set with the searches saved in security detection. The security analysis server generates a RowKey table 2006 where the query results match the searches saved in security detection, and each RowKey represents a match result. Security analysis server 1002 evaluates each RowKey to determine dynamic and non-dynamic fields, and flags the dynamic fields 2014. Security analysis server 1002 generates a concatenated string for each RowKey based on the non-dynamic fields. The concatenated string is used to generate (2018) a hash value representing the cyber event behavior. Security analysis server 1002 creates (2020) key:value pairs including the asset ID and the hash value corresponding to the cyber event observation. The security analysis server determines (2022) the slotting interval for each key:value pair, and issues one security case alert for each slotting interval (2024). Security analysis server 1002 starts a first slotting interval counter used to monitor the period of the slotting interval (2026). The security analysis server determines (2026) that a second key:value pair matches the first key:value pair and the first slotting interval is still active (2030). Based on this determination (2026), security analysis server 1002 suppresses (2032) the security case alert for the second key:value pair. When the security case alert is suppressed, the security analysis server updates the slotting log of the key:value pair.

[0031] Improve hash values based on the expected number of occurrences of related behavior

[0032] In various aspects, the system can evaluate the accuracy of a behavior summary identifier (hash value) by comparing the expected number of occurrences with the measured number of occurrences identified by the throttling interval. The expected number of occurrences can vary widely and can be estimated according to the search stored for each security detection. In one aspect, the expected number of occurrences is estimated according to the security event type, the relative age of security utilization, or the average amount of network traffic, etc.

[0033] When the system determines the expected number of occurrences for the detected behavior, the system can generate an upper threshold value and a lower threshold value for the expected number of occurrences. In one aspect, the system can calculate the upper threshold value and the lower threshold value based on the standard deviation and / or variance of the expected number of occurrences. The upper threshold value and the lower threshold value can be used to automatically verify that the hash value generated for the observed behavior is within the expected range.

[0034] In one aspect, the system compares the observed number of occurrences with the upper threshold value and the lower threshold value of the expected number of occurrences. If the observed number of occurrences is below the lower threshold value, the system can determine that the hash value was generated in a dynamic field and resulted in a unique hash value. If the observed number of occurrences exceeds the upper threshold value, the system can determine that the hash value was generated with sufficient fields and is therefore too broad to be proficient in many different behavior observations. The fields used to generate the hash value can be automatically updated to conform to a predetermined acceptable range for the expected number of occurrences by adding, removing, or replacing fields.

[0035] The system can adjust the hash value by creating a hierarchy of the RowKey fields. The system can hierarchically classify the RowKey fields from dynamic fields to static or non-dynamic fields. The system can evaluate each field by comparing the field with the same field in different rows to determine the possibility of variation and generating a hierarchy of fields for the stored search of each security detection. The hierarchy can classify each field along a continuous spectrum according to the degree of change of the field over time. For example, the system may classify the timestamp field as the most dynamic field and the asset identifier as the least dynamic field.

[0036] Figure 3 shows a flowchart for evaluating the observed occurrence number of key:value pairs correlated with cyber events or actions based on the expected occurrence number of cyber events or behaviors. The security analysis server determines (3002) the expected occurrence number for the detected behavior associated with the key:value pair. The server calculates (3004) an upper threshold value and a lower threshold value based on the expected occurrence number. The server queries (3006) the slot log associated with the first key:value pair to determine the total number of observations identified at one or more slotting intervals. The server compares (3008) the total number of observations with the upper threshold value and the lower threshold value. The server determines (3010) whether the total number of observations is below the lower threshold value or exceeds the upper threshold value.

[0037] Figure 4 shows a method of adjusting key:value pairs that exceed the upper threshold of the expected number of occurrences for behavior matching the key:value pair. The server determines that the total number of observations exceeds the upper threshold (4002) and updates the hash value by generating a new concatenated string with one or more additional fields from the field hierarchy. The server selects one or more at least dynamic fields from the field hierarchy and includes or replaces fields in the new RowKey field string (4004). The server concatenates the new string (4006) and generates a new hash value (4008). The server updates the new hash value and the key:value pair for the search saved in security detection (4010). By adding another field or replacing the current field, the hash value is adjusted more narrowly by a specific behavior and is less likely to capture unintended behavior.

[0038] Figure 5 shows a method of adjusting key:value pairs that fall below the lower threshold for the expected number of occurrences for behavior matching the key:value pair. The server determines that the total number of observations is below the lower threshold (5002) and updates the hash value by generating a new concatenated string with one or more deleted fields based on the field hierarchy. The server selects one or more of the most dynamic fields used to concatenate the string (5004) and removes or replaces the most dynamic field with the least dynamic field in the field hierarchy (5006). The server concatenates the new string (5008) and generates a new hash value (5010). The server updates the new hash value and the key:value pair for the search saved in security detection (5012). By adding another field or replacing the current field, the hash value is adjusted more narrowly by a specific behavior and is less likely to capture unintended behavior.

[0039] Determination of inconsistent triage post-analysis conclusions by different analysts

[0040] In various aspects, the system can track post-triage analysis performed by an analyst using key:value pairs or hash values. Post-triage analysis includes security conclusions regarding security cases. In various aspects, an analyst can determine whether a security case associated with a key:value pair is not a security threat, is a security threat, or is uncertain. The analyst may further determine that a security threat is associated with a particular type of security threat such as a DDOS attack, the latest software known for a particular vulnerability, unauthorized third-party access to a client system, etc.

[0041] For well-established security problems arising from observed behavior, the system can formulate an estimated conclusion with sufficient data from multiple analysts. In other cases, the security vulnerability may be too new to speculate on a conclusion. In the case of a recently identified security vulnerability, the system may compare the conclusions of individual analysts and identify a lack of continuity and consistency between the analysts' conclusions. If there is a contradiction between the analysts' conclusions, there may not be enough information to determine which analyst reached an inaccurate conclusion. The system flags the post-triage analysis and feeds subsequent occurrences to different analysts until a quorum is reached. In other cases, the system may determine that it cannot reach a quorum and may need to update the behavior identifier.

[0042] FIG. 6 shows a flowchart for determining anomalies in security case analysis based on inconsistent post-triage analysis conclusions by different analysts. The server queries a post-triage analysis performed by one of a plurality of analysts based on a key:value pair (6002). Each post-triage analysis corresponds to a different slotting interval since only one security case alert is sent per slotting interval. The server determines whether the key:value pair is associated with a new or well-established security case (6004). A well-established security case has a predetermined number of consistent post-triage analysis conclusions.

[0043] For a well-established security case, the system can compare the analyst's post-triage analysis with a conclusion estimated based on the aggregation of consistent post-triage analysis conclusions (6006). The server determines whether the post-triage analysis matches the estimated conclusion and indicates whether the conclusion is inconsistent (6008).

[0044] For a new security case or case without a predetermined number of consistent post-triage analysis conclusions, the server compares the first post-triage analysis conclusion with the second post-triage analysis conclusion (6010). The server determines whether the post-triage analysis matches the estimated conclusion and indicates whether the conclusion is consistent or inconsistent (6012).

[0045] For inconsistent post-triage analysis conclusions, the server shuffles subsequent security case alerts (6014) to different analysts than the first and second post-triage analyses. The server determines (6016) whether it has reached a quorum to establish an estimated conclusion based on subsequent security case alerts. If the server determines that it has reached a quorum in a given number of consistent cases, the server compares (6018) the analyst's post-triage analysis to the estimated conclusion. The server determines (6020) whether the post-triage analysis matches the estimated conclusion and indicates whether the first or second conclusion is inconsistent. If the server determines that it has not reached a quorum, the server shuffles (6014) subsequent security case alerts to another analyst or until it reaches a quorum.

[0046] FIG. 7 shows a diagram of a computing system 7000 according to at least one non-limiting aspect of the present disclosure. The computing system 7000 and various components included therein can be used to implement and / or execute any of the various components of the systems and methods 2000, 3000, 4000, 5000, and 6000 described above in connection with FIGS. 2-6 as described below.

[0047] According to a non-limiting aspect of FIG. 7, the computer system 7000 can include a bus 7002 (i.e., an interconnect), one or more processors 7004, main memory 7006, read-only memory 7008, removable storage media 7010, mass storage 7012, and one or more communication ports 7014. As should be understood, components such as removable storage media are optional and not necessary in all systems. The communication port 7014 can be connected to one or more networks through which the computer system 7000 can receive and / or transmit data.

[0048] As used herein, a processor can mean, regardless of architecture, one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, or similar devices, or any combination thereof. The device for implementing a process can include, for example, a processor and those devices such as input devices and output devices appropriate for implementing the process.

[0049] The processor(s) 7004 can be any known processor, such as, but not limited to, processors manufactured and / or sold by INTEL®, AMD®, MOTOROLA®, etc., which are generally well-known to those skilled in the art and clearly defined in the literature. The communication port(s) 7014 can be any of, for example, an RS-232 port for use in a modem-based dial-up connection, a 10 / 100 Ethernet port, a gigabit port using copper or fiber, or a USB port. The communication port(s) 7014 can be selected according to the network, such as a local area network (LAN), a wide area network (WAN), a CDN, or any network to which the computer system 7000 is connected. The computer system 7000 may communicate with peripheral devices (e.g., a display screen 7016, input device(s) 7018) via an input / output (I / O) port 7020.

[0050] The main memory 7006 can be a random access memory (RAM) or any other dynamic storage device(s) commonly known in the art. The read-only memory 7008 can be any static storage device(s) such as a programmable read-only memory (PROM) chip for storing static information such as instructions for the processor 7004. The mass storage device 7012 can be used to store information and instructions. For example, a hard disk such as the Adaptec® family of small computer serial interface (SCSI) drives, an optical disk, an array of disks such as a redundant array of independent disks (RAID) such as the Adaptec® family of RAID drives, or any other mass storage device can be used.

[0051] The bus 7002 communicatively couples the processor(s) 7004 to other memory, storage, and communication blocks. The bus 7002 can be, for example, a PCI / PCI-X, SCSI, or a Universal Serial Bus (USB)-based system bus (or others) depending on the storage devices used. The removable storage medium 7010 can be any kind of external hard drive, floppy drive, IOMEGA® Zip drive, compact disk read-only memory (CD-ROM), compact disk rewritable (CD-RW), digital versatile disk read-only memory (DVD-ROM), and the like.

[0052] Aspects described herein may be provided as one or more computer program products, which may include a machine-readable medium having instructions stored thereon, which may be used to program a computer (or other electronic device) to perform a process. As used herein, the term "machine-readable medium" refers to any medium, multiple media, or combination of different media involved in providing data (e.g., instructions, data structures) that can be read by a computer, processor, or similar device. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks and other persistent memories. Volatile media includes dynamic random access memory, which typically constitutes the main memory of a computer. Transmission media includes coaxial cables, copper wire, and fiber optics, including wires that make up a system bus coupled to a processor. Transmission media may include, or convey, acoustic waves, light waves, and electromagnetic radiation, such as those generated during radio frequency (RF) and infrared (IR) data communications.

[0053] Machine-readable media can include, but are not limited to, floppy disks, optical disks, CD-ROMs, magneto-optical disks, ROMs, RAMs, erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic or optical cards, flash memory, or other types of media / machine-readable media suitable for storing electronic instructions. Further, aspects described herein may also be downloaded as a computer program product, where the program may be transferred from a remote computer to a requesting computer by a data signal embodied in a carrier wave or other propagation medium via a communication link (e.g., a modem or network connection).

[0054] Various forms of computer-readable media may be involved in carrying data (e.g., a sequence of instructions) to a processor. For example, the data may (i) be delivered from RAM to the processor, (ii) be carried on a wireless transmission medium, (iii) be formatted and / or transmitted according to a number of formats, standards, or protocols, and / or (iv) be encrypted in any of a variety of ways well known in the art.

[0055] A computer-readable medium can store program elements (in any suitable format) appropriate for implementing a method.

[0056] As shown, main memory 7006 is encoded with application(s) 7022 that support the functions discussed herein (application 7022 may be an application that provides some or all of the functions of the CD service described herein, including client applications). Application(s) 7022 (and / or other resources described herein) can be embodied as software code, such as data and / or logical instructions (e.g., code stored in memory or on another computer-readable medium such as a disk) that support processing functions in different manners described herein.

[0057] During operation of one aspect, processor(s) 7004 accesses main memory 7006 via the use of bus 7002 to launch, execute, run, interpret, or otherwise execute the logical instructions of application(s) 7022. Execution of application(s) 7022 generates processing functions for services associated with the application(s). In other words, process(es) 7024 represents one or more portions of application(s) 7022 that are executed within or on processor(s) 7004 within computer system 7000.

[0058] In addition to the process(es) 7024 that carry out the operations discussed herein, it should be noted that other aspects described herein include the application 7022 itself (i.e., unexecuted or non-executing logical instructions and / or data). The application 7022 can be stored on a computer-readable medium such as a disk (e.g., a repository), or within an optical medium. According to other aspects, the application 7022 can also be stored in a memory-type system such as firmware, read-only memory (ROM), or, as in this example, executable code within the main memory 7006 (e.g., within random access memory or RAM). For example, the application 7022 can also be stored on the removable storage medium 7010, read-only memory 7008, and / or the mass storage device 7012.

[0059] One of ordinary skill in the art will understand that the computer system 7000 can include other processes and / or software and hardware components such as an operating system that controls the allocation and use of hardware resources.

[0060] The various aspects of the subject matter described herein are set forth in the following numbered examples.

[0061] Example 1: A method for eliminating duplicates of security case alerts based on the identification of key:value pairs for behavior observation data and asset identifiers, comprising: receiving, by a processor, a dataset including behavior observation data from one or more data sources; executing, by the processor, a query including a search saved in security detection, the query searching the dataset of behavior observation data for data entries that match one or more searches saved in security detection; generating, by the processor, a search result from the dataset, the search result including a matching of a dataset entry with a search saved in security detection, each matching entry of the search result being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier; determining, by the processor, for each of the searches saved in security detection, one or more dynamic fields for each of the searches saved in security detection based on the respective search result; excluding, by the processor, the one or more dynamic fields from the query; concatenating, by the processor, a search string including all non-excluded fields; generating, by the processor, a hash value of the concatenated search string; generating, by the processor, a hash value and a first key:value pair that summarizes asset behavior and asset identifier; determining, by the processor, a slotting interval for the key:value pair, the slotting interval indicating an amount of time between security case alerts for the first key:value pair; issuing, by the processor, a first security case alert that is a first security case issued at the slotting interval for the first key:value pair and starting a counter for the first key:value pair; detecting, by the processor, a second query result that matches the first key:value pair; determining, by the processor, that the counter is less than the slotting interval; by the processor,Suppressing subsequent security case alerts for the second query result that matches the first key:value pair during a specified slotting interval, and updating, by a processor, a slotting log associated with each of the key:value pairs, the updating including the total number of key:value pairs that match during the slotting interval. A method.

[0062] Example 2: A method for deduplicating security case alerts according to Example 1, where one or more dynamic fields include a timestamp field, a vendor unique identifier field, or a processor-generated metadata field.

[0063] Example 3: A method for deduplicating security case alerts according to Example 1 or 2, where the asset identifier includes a source IP address, a destination IP address, and / or a network domain.

[0064] Example 4: A method for deduplicating security case alerts according to Example 3, where the asset identifier is a network domain, the network domain is rewritten in reverse, the top-level domain is the first component, the network domain remains the central component, and the world wide web indicator is the last component.

[0065] Example 5: A method for deduplicating security case alerts according to Examples 1 to 4, where the searches saved in security detection include a plurality of search criteria related to malicious behavior of an asset or susceptibility to malicious behavior of an asset.

[0066] Example 6: A method for deduplicating security case alerts according to Examples 1 to 5, where the hash value is generated by the SHA1, SHA256, or MD5 hash algorithm.

[0067] Example 7: Determining, by a processor, the total number of matching key:value pairs detected at a completed rotation interval, wherein the counter value is greater than the rotation interval for the completed rotation interval; and comparing, by the processor, the total number of matching key:value pairs with an upper threshold value and a lower threshold parameter, wherein the upper threshold value indicates an abnormally high occurrence count and the lower threshold value indicates an abnormally low occurrence count; a method for deduplication of security case alerts according to Examples 1 to 6, further comprising the above.

[0068] Example 8: Determining, by a processor, that the total number of detected matching key:value pairs exceeds an upper threshold parameter; removing a predetermined field from a concatenated string by the processor; generating, by the processor, a new hash value for a first key:value pair; and updating, by the processor, the first key:value pair with the new hash value; a method for deduplication of security case alerts according to Example 7, further comprising the above.

[0069] Example 9: Determining, by a processor, that the total number of detected matching key:value pairs is less than or equal to a lower threshold parameter; adding one or more dynamic fields removed from a concatenated string by the processor; generating, by the processor, a new hash value for a first key:value pair; and updating, by the processor, the first key:value pair with the new hash value; a method for deduplication of security case alerts according to Example 7, further comprising the above.

[0070] Example 10: Querying, by a processor, a first post-triage analysis associated with a first key:value pair, where the first post-triage analysis includes a first analyst identifier and the first analyst identifier is associated with a first analysis; querying, by a processor, an aggregation of post-triage analyses associated with the first key:value pair and a plurality of different analysts, where the aggregation of post-triage analyses is determined based on a predetermined number of different analysts and the predetermined number of different analysts reach the same conclusion regarding the first key:value pair; comparing, by a processor, the first post-triage analysis with the aggregation of post-triage analyses; determining, by a processor, that the first analyst and the plurality of different analysts have reached different conclusions associated with the key:value pair; and further flagging, by a processor, that the first post-triage analysis by the first analyst is inconsistent with the aggregation of post-triage analyses. A method for deduplicating security case alerts of Examples 1-9.

[0071] Example 11: Querying, by a processor, a first post-triage analysis associated with a first key:value pair, the first post-triage analysis including a first analyst identifier associated with a first analyst; querying, by the processor, a second post-triage analysis associated with the first key:value pair and a second analyst, the second analyst identifier being associated with a second analyst and different from the first analyst identifier; comparing, by the processor, the first post-triage analysis and the second post-triage analysis; determining, by the processor, that the first analyst and the second analyst have reached different conclusions associated with the key:value pair, the first analyst concluding that the first key:value pair is associated with a security threat and the second analyst concluding that the first key:value pair is not associated with a security threat; and further including the method for deduplication of security case alerts according to claims 1 to 10.

[0072] Example 12: Determining, by a processor, whether there is a predetermined amount of additional analyst data sufficient to resolve a conflict between a first analyst and a second analyst; determining, by the processor, that an analyst threshold amount has reached the same conclusion; and flagging, by the processor, the first analyst or the second analyst based on a disagreement with the threshold conclusion, and further including the method for deduplication of security case alerts according to Example 11.

[0073] Example 13: The method for eliminating duplicate security case alerts according to Example 11 further includes: determining, by a processor, that there is a predetermined amount of additional analyst data that is insufficient to resolve a conflict between a first analyst and a second analyst; and stopping, by the processor, subsequent security case alerts associated with a first key:value pair for an analyst not associated with the first analyst identifier and the second analyst identifier.

[0074] Example 14: A system for generating a unique hash value representing a queryable threat event, comprising at least one processor, at least one memory communicatively coupled to the at least one processor, an input / output interface configured to access data from one or more external sources, each of the plurality of external sources being communicatively coupled to the at least one processor, and a database stored in the at least one memory and configured to store data. The at least one memory is configured to receive, by the at least one processor, a dataset including behavior observation data from one or more data sources, execute a query including a search stored in security detection, the query being to search the dataset of behavior observation data for data entries that match one or more searches stored in security detection, generate search results from the dataset, the search results including a matching between dataset entries and searches stored in security detection, each matching entry of the search results being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier, generate the search results, determine one or more dynamic fields of each search stored in security detection based on the query results of each search stored in security detection, exclude the one or more dynamic fields from the query, concatenate a search string including all fields that are not excluded, generate a hash value for the concatenated search string, generate a first key:value pair having the first generated hash value that summarizes the behavior of the asset and the asset identifier, determine a predetermined slotting interval for the key:value pair, the slotting interval indicating the amount of time between alerts for a security case for the first key:value pair, issue a first security case alert that is the first security case within the slotting interval for the first key:value pair and start a counter for the first key:value pair, detect a second query result that matches the first key:value pair,Determining that a counter is less than a slotting interval, suppressing subsequent security case warnings for a second query result that matches a first key:value pair during a predetermined slotting interval, and updating a slotting log associated with each key:value pair to include the total number of matching key:value pairs detected at the slotting interval, a system configured to store executable instructions.

[0075] Example 15: The system according to Example 14, wherein one or more dynamic fields include a timestamp field, a vendor unique identifier field, or a processor-generated metadata field.

[0076] Example 16: The system according to Examples 14 to 15, wherein the asset identifier includes a source IP address, a destination IP address, and / or a network domain.

[0077] Example 17: The system according to Example 16, wherein the asset identifier is a network domain, the network domain is rewritten in reverse orientation, the top-level domain is the first component, the network domain remains the central component, and the World Wide Web indicator is the last component.

[0078] Example 18: The system according to Examples 14 to 17, wherein the stored search for security detection includes a plurality of search criteria related to malicious behavior of an asset or susceptibility to malicious behavior of an asset.

[0079] Example 19: The system according to Examples 14 to 18, wherein the hash value is generated by the SHA1, SHA256, or MD5 hash algorithm.

[0080] Example 20: The system of Examples 14 - 19, further configured to perform: at least one processor queries a first post - triage analysis associated with a first key: value pair, where the first post - triage analysis includes a first analysis identifier associated with a first analysis; queries an aggregation of post - triage analyses associated with the first key: value pair and a plurality of different analysts, where the aggregation of post - triage analyses is determined based on a predetermined number of different analysts and the predetermined number of different analysts reach the same conclusion regarding the first key: value pair; compares, by the processor, the first post - triage analysis and the aggregation of post - triage analyses; determines that the first analyst and the plurality of different analysts have reached different conclusions regarding the key: value pair; and flags the first post - triage analysis by the first analyst as conflicting with the aggregation of post - triage analyses.

[0081] All patents, patent applications, publications, or other disclosure materials described herein are hereby incorporated by reference in their entirety as if each individual reference were expressly incorporated by reference. All references said to be incorporated by reference herein, and any materials, or portions thereof, are incorporated herein only to the extent that the incorporated materials do not conflict with existing definitions, descriptions, or other disclosure materials described in this disclosure. Therefore, and to the extent necessary, the disclosure set forth herein supersedes any conflicting materials incorporated herein by reference, and the disclosure is described explicitly within the scope of this application.

[0082] Various illustrative and exemplary aspects are described. The aspects described herein are to be understood as providing illustrative features of various details of various aspects of the present disclosure, and thus, unless otherwise specified, without departing from the scope of the present disclosure, as much as possible, one or more features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure may be combined, separated, exchanged, and / or rearranged with one or more other features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the illustrative aspects may be made without departing from the claimed subject matter. Further, those skilled in the art can, by a review of this specification, recognize, or confirm, many equivalents to the various aspects of the present disclosure using only routine experimentation. Accordingly, the present disclosure is not limited by the description of the various aspects, but only by the claims.

[0083] Those skilled in the art will generally recognize that terms used herein, and particularly in the appended claims (e.g., the body of the appended claims), are generally intended to be terms such as “unrestricted” (e.g., the term “including” should be construed as “including but not limited to”, the term “having” should be construed as “having at least”, the term “includes” should be construed as “including but not limited to”, etc.). Those skilled in the art will further understand that where a specific number of introduced claim listings is intended, such intent is explicitly recited in the claims, and where there is no such listing, such intent does not exist. For example, by way of aid in understanding, the following appended claims may include the use of the introductory phrases “at least one” and “one or more” to introduce claim listings. However, the use of such phrases should not be construed as implying that the introduction of a claim listing by the indefinite article “a” or “an” limits any particular claim that includes such introduced claim listing to a claim scope that includes only one such listing. The same applies to the use of the definite article used to introduce a claim listing, even if the same claim includes introductory phrases such as “one or more” or “at least one” and indefinite articles such as “a” or “an” (e.g., “a” and / or “an” should generally be construed as meaning “at least one” or “one or more”).

[0084] Furthermore, even if a specific number of the recited introduced claims is explicitly recited, one of ordinary skill in the art will recognize that such a recitation should typically be interpreted to mean at least the recited number (e.g., a mere recitation of "two recitations" would typically be understood to mean at least two recitations or two or more recitations without other qualifying language). Further, in these instances where a convention similar to "at least one of A, B, and C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). In instances where a convention similar to "at least one of A, B, or C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). It will be further understood by those of skill in the art that in any of the description, claims, or drawings, disjunctive and / or phrases presenting two or more alternative terms will typically be understood to contemplate the possibility of including one of the terms, any of the terms, or both terms, unless the context indicates otherwise. For example, the phrase "A or B" will typically be understood to include the possibility of "A" or "B" or "A and B".

[0085] Regarding the appended claims, those skilled in the art will understand that the operations listed therein may generally be performed in any order. Also, although the claims are presented in a (multiple) sequential order, it should be understood that the various operations may be performed in other orders than those described, or simultaneously. Examples of such alternative orders include, unless the context otherwise indicates, repetition, interleaving, interruption, reordering, incrementing, preparation, supplementation, simultaneous, reverse, or other variant orders. Further, unless the context otherwise indicates, terms such as "responding", "relating", or other past participles generally do not intend to exclude such variants.

[0086] It should be noted that any reference to "one aspect", "aspect", "exemplification", "an exemplification", and the like means that the particular features, structures, or characteristics described in relation to the aspect are included in at least one aspect. Thus, the appearances of the phrases "in one aspect", "in an aspect", "in an exemplification", and "in an exemplification" at various places throughout this specification do not necessarily all refer to the same aspect. Further, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0087] As used herein, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" include plural references.

[0088] For example, but not limited to, directional terms used herein such as up, down, left, right, below, above, front, back, and variations thereof relate to the orientation of the elements shown in the accompanying drawings and are not limiting with respect to the claims unless otherwise explicitly stated.

[0089] As used herein, the terms "about" or "approximately" mean an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the terms "about" or "approximately" mean within 1, 2, 3, or 4 standard deviations. In certain embodiments, the terms "about" or "approximately" mean within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0090] As used herein, unless otherwise indicated, all numerical parameters are to be construed as being preceded by the term "about," which in all cases means that the numerical parameter has the inherent variability of the measurement technique used to determine the value of the parameter. At a minimum, and not as an attempt to limit the application of the doctrine of equivalents to the claims, each numerical parameter herein should at least be construed in light of the reported number of significant digits and by applying ordinary rounding techniques.

[0091] Any numerical range recited herein includes all sub-ranges subsumed within the recited range. For example, a range from 1 to 100 includes all sub-ranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., all sub-ranges having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the endpoints of the recited range. For example, a range from 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, Applicants reserve the right to amend this specification, including the claims, to expressly recite sub-ranges expressly within the ranges expressly recited herein. All such ranges are inherently described herein.

[0092] Any patent application, patent, non-patent publication, or other disclosure material mentioned in this specification and / or listed in any application data sheet is incorporated herein by reference, provided that the incorporated material is not inconsistent with this specification. Accordingly, and to the extent necessary, the present disclosure as explicitly described herein prevails over any conflicting material incorporated herein by reference. Although said to be incorporated herein by reference, any material or portion thereof that conflicts with an existing definition, statement, or other disclosure material specified herein is incorporated only to the extent that no conflict arises between the incorporated material and the existing disclosure material.

[0093] The terms "comprise" (and any form of comprise such as "comprises", "comprising", etc.), "have" (and any form of have such as "has", and "having"), "include" (and any form of include such as "includes" and "including"), and "contain" (and any form of contain such as "contains" and "containing") are open-ended conjunctive verbs. As a result, a system that "comprises", "has", "includes", or "contains" one or more elements possesses those one or more elements, but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises", "has", "includes", or "contains" one or more features possesses those one or more features, but is not limited to possessing only those one or more features.

[0094] The foregoing detailed description has described various forms of devices and / or processes by use of block diagrams, flowcharts, and / or examples. Where such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented individually and / or collectively by a wide variety of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented as one or more computer programs operating on one or more computers (e.g., as one or more programs operating on one or more computer systems), as one or more programs operating on one or more processors (e.g., as one or more programs operating on one or more microprocessors), as firmware, or substantially any combination thereof, and that all or part thereof can be equivalently integrated into an integrated circuit, and that the design of the circuitry, and / or the description of the software code, and also the firmware, are within the scope of the skills of those skilled in the art in light of the present disclosure. Further, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal-carrying medium used to actually carry out the distribution.

[0095] The instructions used to program the logic to implement the various disclosed aspects may be stored in memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Further, the instructions may be distributed via a network or via other computer-readable media. Thus, a machine-readable medium is any mechanism, but not limited to, a floppy disk, optical disk, compact disk, read only memory (CD-ROM), and magneto-optical disk, read only memory (ROM), random access memory (RAM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), magnetic or optical card, flash memory, or tangible machine-readable storage devices used to transmit information on the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Thus, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0096] As used in any aspect of this specification, the term "control circuit" can refer to, for example, a wired circuit, a programmable circuit (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA), a state machine circuit, firmware storing instructions executed by a programmable circuit, and any combination thereof). The control circuit can be embodied, collectively or individually, as part of a larger system, such as an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuit" includes, but is not limited to, an electrical circuit having at least one discrete electrical circuit, an electrical circuit having at least one integrated circuit, an electrical circuit having at least one application specific integrated circuit, an electrical circuit forming a general purpose computing device configured by a computer program (e.g., a general purpose computer configured by a computer program that at least partially executes a process, and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process, and / or a device described herein), an electrical circuit forming a memory device (e.g., in the form of a random access memory), and / or an electrical circuit forming a communication device (e.g., a modem, a communication switch, or an optoelectronic device). One of ordinary skill in the art will recognize that the subject matter described herein can be implemented in an analog or digital fashion or some combination thereof.

[0097] When used in any aspect of this specification, the term "logic" can refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software can be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware can be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) within a memory device.

[0098] When used in any aspect of this specification, terms such as "component", "system", "module", etc. can refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.

[0099] When used in any aspect of this specification, "algorithm" refers to a self-consistent order of steps that yields a desired result, and "step" refers to an operation on physical quantities and / or a logical state that can, although not necessarily, take the form of electrical or magnetic signals that can be stored, transferred, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms may be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

Claims

1. A method for deduplicating security case alerts based on the identification of multiple key:value pairs for behavior observation data and asset identifiers, comprising: receiving, by a processor, a dataset including behavior observation data from one or more data sources; executing, by the processor, a query including a search saved in security detection, the query searching the dataset of the behavior observation data for data entries that match the search saved in the security detection; generating, by the processor, search results from the dataset, the search results including a matching of a dataset entry and the search saved in the security detection, each matching entry of the search results being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier; determining, by the processor, for each of the search results of the search saved in the security detection, one or more dynamic fields for each of the searches saved in the security detection; excluding, by the processor, the one or more dynamic fields from the query; concatenating, by the processor, search strings including all non-excluded fields to create a concatenated search string; generating, by the processor, a hash value of the concatenated search string; generating, by the processor, a first key:value pair of the hash value summarizing asset behavior and the asset identifier; determining, by the processor, a slotting interval for the key:value pair, the slotting interval indicating an amount of time between security case alerts for the first key:value pair; issuing, by the processor, a first security case alert that is the first security case issued at the slotting interval for the first key:value pair, and starting a counter for the first key:value pair; detecting, by the processor, a second query result that matches the first key:value pair; The processor determines that the counter is less than the slotting interval; The processor suppresses subsequent security case alerts for the second query result that matches the first key:value pair during the slotting interval; The processor updates a slotting log associated with each of the plurality of key:value pairs, the slotting log including the total number of key:value pairs that match during the slotting interval, the updating. A method comprising:

2. The method for eliminating duplicate security case alerts according to claim 1, wherein the one or more dynamic fields include a timestamp field, a vendor unique identifier field, or a processor-generated metadata field.

3. The method for eliminating duplicate security case alerts according to claim 1, wherein the asset identifier includes a source IP address, a destination IP address, and / or a network domain.

4. The method for eliminating duplicate security case alerts according to claim 3, wherein the asset identifier is a network domain, the network domain is rewritten in reverse, the top-level domain is the first component, the network domain remains the central component, and the world wide web indicator is the last component.

5. The method for eliminating duplicate security case alerts according to claim 1, wherein the search saved in the security detection includes a plurality of search criteria related to malicious behavior of an asset or susceptibility to malicious behavior of an asset.

6. The method for eliminating duplicate security case alerts according to claim 1, wherein the hash value is generated by the SHA1, SHA256, or MD5 hash algorithm.

7. The processor determines the total number of key:value pairs that match during the completed rotation interval, the counter being greater than the rotation interval for the completed rotation interval, the determining; The processor further compares the total number of matching key:value pairs with an upper threshold value and a lower threshold value, where the upper threshold value indicates an abnormally high occurrence count and the lower threshold value indicates an abnormally low occurrence count, and the method for deduplication of security case alerts according to claim 1.

8. The processor determines that the total number of the matching key:value pairs exceeds the upper threshold value. The processor removes a predetermined field from the concatenated search string. The processor generates a new hash value for the first key:value pair. The processor further updates the first key:value pair with the new hash value, and the method for deduplication of security case alerts according to claim 7.

9. The processor determines that the total number of the matching key:value pairs is less than the lower threshold value. The processor adds one or more dynamic fields removed from the concatenated search string. The processor generates a new hash value for the first key:value pair. The processor further updates the first key:value pair with the new hash value, and the method for deduplication of security case alerts according to claim 7.

10. The processor queries a first post-triage analysis associated with the first key:value pair, where the first post-triage analysis includes a first analyst identifier and the first analyst identifier is associated with a first analyst. The processor queries an aggregation of post-triage analyses associated with the first key:value pair and a plurality of different analysts, where the aggregation of post-triage analyses is determined based on a predetermined number of different analysts and the predetermined number of different analysts reach the same conclusion associated with the first key:value pair. The processor compares the first post-triage analysis with the aggregation of post-triage analyses. The processor determines that the first analyst and the plurality of different analysts reach different conclusions associated with the key:value pair; The method for eliminating duplication of security case alerts according to claim 1, further comprising: the processor flagging the first post-triage analysis by the first analyst as conflicting with the aggregation of the post-triage analyses.

11. The processor queries a first post-triage analysis associated with the first key:value pair, wherein the first post-triage analysis includes a first analyst identifier, and the first analyst identifier is associated with a first analyst; The processor queries a second post-triage analysis associated with the first key:value pair and a second analyst identifier, wherein the second analyst identifier is associated with a second analyst, and the second analyst identifier is different from the first analyst identifier; The processor compares the first post-triage analysis and the second post-triage analysis; The method for eliminating duplication of security case alerts according to claim 1, further comprising: the processor determines that the first analyst and the second analyst reach different conclusions associated with the key:value pair, wherein the first analyst concludes that the first key:value pair is associated with a security threat, and the second analyst concludes that the first key:value pair is not associated with a security threat.

12. The processor determines that there is a predetermined amount of additional analyst data to resolve a conflict between the first analyst and the second analyst; The processor determines that an analyst threshold amount reaches the same conclusion; The method for eliminating duplication of security case alerts according to claim 11, further comprising: the processor flags the first analyst or the second analyst based on a discrepancy with a threshold conclusion.

13. The processor determines that there is a predetermined amount of additional analyst data that is insufficient to resolve the conflict between the first analyst and the second analyst; The method for deduplication of security case alerts according to claim 11, further comprising shuffling, by the processor, subsequent security case alerts associated with the first key: value pair to analysts not associated with the first analyst identifier and the second analyst identifier.

14. A system for generating a unique hash value representing a queryable threat event, A security analysis server, At least one processor; At least one memory communicatively coupled to the at least one processor; An input / output interface configured to access data from one or more external sources, each of the one or more external sources being communicatively coupled to the at least one processor; A security analysis server including a database stored in the at least one memory and configured to store the data; The at least one memory is configured by the at least one processor to Receive a dataset including behavior observation data from the one or more external sources; Executing a query including a query stored in the security detection, the query searching the dataset of the behavior observation data for data inputs that match the query stored in the security detection; Generating search results from the dataset, the search results including matching dataset entries to the query stored in the security detection, each matching entry of the search results being generated as a row having a plurality of fields, the plurality of fields including at least an asset identifier; Determining, based on the search results for each of the queries stored in the security detection, one or more dynamic fields for each of the queries stored in the security detection; Excluding the one or more dynamic fields from the query; Concatenate a search string that includes all non-excluded fields to create a concatenated search string; Generate a hash value for the concatenated search string; Generate a first key:value pair of a plurality of key:value pairs having the hash value that summarizes asset behavior and the asset identifier; Determine a slotting interval for the key:value pair, wherein the slotting interval indicates an amount of time between security case alerts for the first key:value pair; Initiate by issuing a first security case alert for the first key:value pair and activating a counter for the first key:value pair, wherein the first security case alert is the first security case issued at the slotting interval; Detect a second query result that matches the first key:value pair; Determine that the counter is less than the slotting interval; Suppress subsequent security case alerts for the second query result that matches the first key:value pair during the slotting interval; Update a slotting log associated with each of the plurality of key:value pairs, wherein the slotting log includes a total number of matching key:value pairs at the slotting interval, a system configured to store executable instructions to perform.

15. The system of claim 14, wherein the one or more dynamic fields include a timestamp field, a vendor unique identifier field, or a processor-generated metadata field.

16. The system of claim 14, wherein the asset identifier includes a source IP address, a destination IP address, and / or a network domain.

17. The system of claim 16, wherein the asset identifier is a network domain, the network domain is rewritten in reverse orientation, the top-level domain is the first component, the network domain remains the middle component, and the world wide web indicator is the last component.

18. The system of claim 14, wherein the search saved by the security detection includes a plurality of search criteria related to malicious behavior of the asset or susceptibility to malicious behavior of the asset. **Claim 19** The system of claim 14, wherein the hash value is generated by an SHA1, SHA256, or MD5 hash algorithm. **Claim 20** The at least one processor querying a first post-triage analysis associated with the first key:value pair, the first post-triage analysis including a first analyst identifier, the first analyst identifier being associated with a first analyst; querying an aggregation of post-triage analyses associated with the first key:value pair and a plurality of different analysts, the aggregation of post-triage analyses being determined based on a predetermined number of different analysts, the predetermined number of different analysts reaching the same conclusion associated with the first key:value pair; comparing the first post-triage analysis with the aggregation of post-triage analyses; determining that the first analyst and the plurality of different analysts have reached different conclusions regarding the key:value pair; The system of claim 14, configured to perform flagging the first post-triage analysis by the first analyst as conflicting with the aggregation of post-triage analyses.

Citation Information

Patent Citations

  • Methods and systems for key-value-tuple-encoded storage

    US20160188591A1

  • Security system for managed computer system

    US20190068622A1

  • Extensible Attack Monitoring by a Storage System

    US20210216630A1