Classification of cyber alerts into security incidents

By correlating cyber alerts into security incidents, the system addresses the challenge of overwhelming alert volumes, allowing for efficient incident response.

JP7802777B2Active Publication Date: 2026-01-20PALO ALTO NETWORKS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023519592
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-09-30
Filing Date
2021-09-22
Publication Date
2026-01-20
Estimated Expiration
2041-09-22

AI Technical Summary

Technical Problem

Existing systems face challenges in efficiently categorizing numerous cyber alerts from multiple sources into manageable security incidents due to the overwhelming volume and diversity of alerts generated by different protection appliances, making it impossible for security analysts to respond effectively to cyber-attacks.

Method used

A security server correlates alerts from various protection appliances, extracting cyber-artifacts to classify multiple alerts into a single security incident, enabling efficient response to cyber-attacks by issuing consolidated alerts.

Benefits of technology

Enables security analysts to respond to cyber-attacks more efficiently by categorizing multiple alerts into manageable security incidents, reducing the workload and improving response times.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007802777000001
    Figure 0007802777000001
  • Figure 0007802777000002
    Figure 0007802777000002
  • Figure 0007802777000003
    Figure 0007802777000003
Patent Text Reader

Abstract

A method, apparatus, and computer program implementing an embodiment of the present invention for protecting a computer network includes receiving, at a security server, a plurality of different types of alerts indicative of potentially malicious activity within the network detected by a plurality of different protection appliances deployed within the network, the alerts in the security server being correlated to identify a first alert of a first type from a first protection appliance within the network and a second alert of a second type, different from the first type, from a second protection appliance within the network, which together indicate a single attack on the network, and issuing a consolidated alert in response to the attack.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates generally to computer security and networks, and more particularly to classifying cyber-alerts into the security incidents that triggered them. [Background technology]

[0002] Many computer and network systems deploy multiple layers of security devices and software to detect and repel an ever-growing range of security threats. At the most basic level, computers use antivirus software to prevent malicious software from running on the computer. At the network level, intrusion detection and prevention systems analyze and control network traffic to detect and prevent malware from spreading through the network.

[0003] The above discussion is provided as an overview of the related art in this technical field and is not to be construed as an admission that it contains any information that constitutes prior art to the present patent application. Summary of the Invention

[0004] According to an embodiment of the present invention, there is provided a method for protecting a computer network, the method including receiving, at a security server, a plurality of different types of alerts indicative of potentially malicious activity in the network detected by a plurality of different protection appliances deployed in the network, correlating the alerts at the security server to identify a first alert of a first type from a first protection appliance in the network and a second alert of a second type different from the first type from a second protection appliance in the network that together indicate a single attack in the network, and issuing a consolidated alert in response to the attack.

[0005] In one embodiment, receiving a first alert includes receiving the first alert at a first time, receiving a second alert includes receiving the second alert at a second time after the first time, and the first alert and the second alert occur within a specified time period.

[0006] In another embodiment, the network includes a plurality of computing devices each executing a plurality of processes.

[0007] In an additional embodiment, the method also includes identifying, for each of the processes, a respective causal group owner (CGO), and wherein correlating the alerts includes detecting that the CGO of a given first process matches the CGO of a given second process.

[0008] In another embodiment, the method also includes identifying, for each of the processes, a respective execution chain, each of the processes including an endpoint of the respective execution chain, and wherein correlating the alerts includes detecting that the execution chain for a given first process matches the execution chain for a given second process.

[0009] In a supplemental embodiment, the method also includes calculating respective parent hashes for the processes, each given alert including a given process and a respective parent hash, and correlating the alerts includes detecting that a parent hash of a first alert matches a parent hash of a second alert.

[0010] In one embodiment, correlating the alerts includes detecting that the first alert indicates a given first computing device transmitting a first transmission to a suspected malicious Internet site, and detecting that the second alert indicates a given second computing device transmitting a second transmission to the Internet site.

[0011] In another embodiment, correlating the alerts includes detecting that the first alert indicates a given first computing device storing a suspected malicious file, and detecting that the second alert indicates a given second computing device storing an identical copy of the file.

[0012] In additional embodiments, each given protection appliance is selected from the group consisting of a firewall, a software application running on a given computing device, a data cloud firewall, and a data cloud security software application.

[0013] According to an embodiment of the present invention, there is also provided an apparatus for protecting a computer network, the apparatus including a network interface card (NIC) and at least one processor, the processor being configured to receive a plurality of different types of alerts indicative of potentially malicious activity in the network detected by a plurality of different protection appliances deployed in the network, correlate the alerts to identify a first alert of a first type from a first protection appliance in the network and a second alert of a second type, different from the first type, from a second protection appliance in the network, which together indicate a single attack on the network, and issue a consolidated alert in response to the attack.

[0014] According to an embodiment of the present invention, there is provided a computer software product for protecting a computer system, the product including program instructions stored on a non-transitory computer-readable storage medium that, when read by a computer, cause the computer to receive a plurality of different types of alerts indicative of potentially malicious activity in a network detected by a plurality of different protection appliances deployed in the network, correlate the alerts to identify a first alert of a first type from a first protection appliance in the network and a second alert of a second type, different from the first type, from a second protection appliance in the network, that together indicate a single attack on the network, and issue a consolidated alert in response to the attack. [Brief explanation of the drawings]

[0015] The present disclosure is herein described, by way of example only, with reference to the accompanying drawings. [Figure 1]FIG. 1 is a block diagram that schematically illustrates a computing facility including a security server configured to classify a plurality of cyber alerts into a set of security incidents, in accordance with one embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram illustrating an example of a computing device in communication with a security server, according to one embodiment of the present invention. [Figure 3] FIG. 3 is a block diagram of a security server according to one embodiment of the present invention. [Figure 4] FIG. 4 is a graph illustrating an exemplary process execution chain executing on a computing device according to one embodiment of the present invention. [Figure 5] FIG. 5 is a flow chart that schematically illustrates a method for categorizing multiple cyber alerts into a set of security incidents, according to one embodiment of the present invention. [Figure 6] FIG. 6 is a block diagram illustrating an example of displaying consolidated alerts for a given security incident on a display according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] A security analyst in an enterprise network may receive numerous cyber alerts (also referred to herein simply as alerts) received from multiple sources. In response to receiving the alerts, the security analyst is responsible for triaging, investigating, and responding to each one of these alerts. These alerts correspond to security incidents within the network, but each security incident typically generates multiple alerts of different types from different sources.

[0017] Given the number of alerts and the number of different sources for the alerts, categorizing the alerts into individual security incidents is virtually impossible for any one person (or group of people). For example, because there can be a large number of endpoints (e.g., 400) that can be infected by a single cyber attack, a large computer facility may "see" over 100,000 different cyber alerts in a short period of time (e.g., one week).

[0018] Embodiments of the present invention provide a method and system for protecting a computer network by categorizing cyber alerts into a manageable set of security incidents that can be investigated and resolved by security analysts. As described below, a security server receives a number of different types of alerts. In the embodiments described herein, the alerts (a) indicate potentially malicious activity within the network and (b) are detected by a number of different protection appliances deployed within the network. Examples of protection appliances include, but are not limited to, firewalls and cybersecurity software running on network endpoints such as computing devices.

[0019] The security server then correlates the alerts at the security server to identify a first alert of a first type from a first protection appliance in the network and a second alert of a second type, different from the first type, from a second protection appliance in the network that together indicate a single attack on the network. Correlating the alerts enables the security server to issue a consolidated alert in response to the attack.

[0020] As described below, the security server extracts cyber-artifacts (e.g., file and process hashes, and source and destination IP addresses) from the alerts and then classifies the alerts based on the extracted artifacts. By classifying multiple alerts into a single security incident, a system implementing an embodiment of the present invention enables security analysts to respond to cyber-attacks more efficiently (i.e., by responding to the security incident rather than investigating each alert).

[0021] System Description Figure 1 is a block diagram that schematically illustrates an exemplary computer facility 20 including a security server 22 configured to classify cyber alerts 24 into a set of security incidents, in accordance with one embodiment of the present invention. In the configuration shown in Figure 1, the security server is configured to communicate with a plurality of computing devices 26 over a data network, such as a local area network (LAN) 28. One example of a security server 22 is described below in the description with reference to Figure 3.

[0022] Each computing device 26 comprises an endpoint of a LAN 28 and may comprise any type of physical computer (e.g., a desktop / laptop / tablet computer, or a smartphone) or virtual computer (e.g., a virtual machine or container) coupled to the LAN 28 and having a local IP address 30 assigned for this purpose. One example of a given computing device is described in the description below with reference to FIG. 2.

[0023] In embodiments of the present invention, each given computing device 26 may include a device identifier (ID) 32. Examples of device ID 32 include, but are not limited to, a media access control (MAC) address and an internet protocol (IP) address, which may be used to uniquely identify each computing device 26. At any given time, each given computing device 26 is assigned a unique IP address, and a given computing device may be associated with multiple IP addresses over an extended period of time. For example, the IP address of a given computing device 26 may change after a reboot of the given computing device.

[0024] Computer equipment 20 may also include an Internet gateway 34 that connects computer equipment 20 to a public network 36, such as the Internet. To protect computing device 26, computing device 20 may also include a firewall 38 that controls data traffic, such as transmissions 40, between computing device 26 and Internet sites 42 based on predefined security rules. Thus, each given Internet site 42 is hosted by a remote server 44 coupled to Internet 36 and includes a public IP address 46 and a domain name 48 (also referred to herein simply as domain 48).

[0025] Computer equipment 20 also includes a private Domain Name System (DNS) server 50 "behind" firewall 38 and can communicate with computing devices 26 via LAN 28. In the configuration shown in Figure 1, computing devices can also communicate via LAN 28 and Internet 36 with a public DNS server 52 external to computer equipment 20 (i.e., "outside" the firewall).

[0026] In some embodiments, a given computing device 26 can access a given Internet site 42 by transmitting a DNS request for a given domain name 48 corresponding to the given Internet site to a given DNS server in a first transmission 40. In response to receiving the DNS request, the given DNS server transmits to the given computing device a DNS resolution including a given public IP address 46 corresponding to the given domain in a second transmission 40. Upon receiving the DNS resolution, the given computing system can transmit a transmission to a given remote server 44 that hosts the given Internet site and includes the given public IP address.

[0027] In an embodiment of the present invention, each cyber alert 24 is indicative of potential malicious activity. In one example, a given cyber alert 24 transmitted by a firewall 38 may be in response to a given transmission 40 from a given computing device 26 to a given internet site 42 that the firewall 38 has flagged as malicious. In another example, a given cyber alert 24 transmitted by a given endpoint agent 72 executing on a given computing device 26 is indicative of malicious behavior at the given computing device. Examples of malicious activity that a given endpoint agent 72 may detect on a given computing device 26 include, but are not limited to, the following:

[0028] A given file 66 stored on a given computing device 26 that does not have a valid digital signature or is not classified as benign by a threat intelligence service.

[0029] A given process 70 running on a given computing device does not have a valid digital signature or is not classified as benign by a threat intelligence service. One example of a given threat intelligence service is Wildfire, produced by Palo Alto Networks. TM , 3000 Tannery Way, Santa Clara, CA 95054 USA.

[0030] A given process 70 running on a given computing device 26 performs suspicious behavior. One example of a given suspicious behavior is the Windows TM It includes a given process 70 running on a given computing device running an operating system (manufactured by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052 USA) and alerting the registry of the operating system.

[0031] 2 is a block diagram illustrating an example of hardware and software components of a given computing device 26 according to one embodiment of the present invention. Each given computing device 26 may include, for example, a device processor 60, a device memory 62, one or more storage devices 64 configured to store files 66, and a device network interface card 68 that couples the given computing device to a LAN 28.

[0032] During operation, each processor 60 executes processes 70 and endpoint agents 72 from its respective memory 62. Each given process 70 may include an instance of a computer program executed by one or many threads on the given processor 60. In the embodiment described herein, each given endpoint agent 72 executing on a given processor 60 includes a software application configured to analyze information regarding the execution and activity of a set of processes 70 executing on the given processor and to transmit the analyzed information to the security server 22. One example of an endpoint agent 72 is XDR™, also manufactured by Palo Alto Networks, Inc.

[0033] 3 is a block diagram illustrating one example of hardware and software components of security server 22, according to one embodiment of the present invention. In some embodiments, security server 22 includes a system processor 80 and system memory 82, which are coupled by a system bus (not shown) to a network interface controller 84, which couples security to network 28. In some embodiments, security server 22 may include a user interface (UI) device 86 (e.g., an LED display) or another type of output interface.

[0034] 3, memory 82 stores a cyber alert log 88 containing a plurality of cyber alert records 90, a security incident log 92 containing a plurality of security incident records 94, and a set of profiles 96. Profiles 96 are described in Appendix 1 below.

[0035] In operation, cyber alerts 24 are received, and for each cyber alert 24, processor 80 extracts the cyber artifacts from the given alert, adds a new cyber alert record 90 to cyber alert log 88, and populates the added cyber alert record with the cyber artifacts. Thus, each cyber alert 24 has a corresponding cyber alert record 90.

[0036] 1, processor 80 may receive cyber alerts 24 from sources such as firewall 38 and endpoint agents 72 (also referred to herein as protection alliances). One example of a given cyber alert 24 that processor 80 may receive from firewall 38 includes detecting a given transmission 40 from a given computing device to a given internet site 42 that is flagged as malicious. One example of a given cyber alert 24 that processor 80 may receive from a given endpoint agent 72 executing on a given computing device 26 includes detecting a given file 66 on the given computing device that is suspected to be malicious (e.g., the given file may contain malware).

[0037] In additional embodiments, processor 80 may receive cyber alerts 24 from other sources, such as (a) cybersecurity software (e.g., antivirus) running on computing device 26, (b) a data cloud firewall capable of detecting port scans and malicious activity performed by spyware and viruses, and (c) a data cloud security software application capable of monitoring container and cloud-based software applications. In embodiments of the present invention, any software application or hardware device capable of generating and transmitting cyber alerts 24 to security server 22 may also be referred to as a protection appliance.

[0038] Examples of cyber artifacts that the processor 80 may extract from a given cyber alert 24 and store in a given cyber alert record 90 include, but are not limited to:

[0039] An alert identifier (ID) 98 for a given alert. Each cyber alert 24 has a corresponding unique alert ID 98.

[0040] Alert Source 100, indicating the source of a given alert (eg, firewall 38 or a given device ID).

[0041] An alert type 102 indicating the particular malicious activity (e.g., a given submission 40 to a malicious internet site 42 or malicious file 66) that caused a given alert.

[0042] A timestamp 104 indicating the date and time when a given source generated a given alert.

[0043] A source IP address 106 indicating the local IP address of a given computing device 26 that caused the alert (e.g., by transmitting a given transmission 40 to a malicious Internet site 42 or storing a malicious file 66).

[0044] Destination IP address 108. If a given alert was generated in response to a given transmission 40 from a given computing device to a given internet site 42, then the destination IP address 108 contains the public IP address of the given internet site.

[0045] Source port 110. If a given alert was generated in response to a given transmission 40 from a given computing device to a given internet site 42, then source port 110 indicates the source port of the given transmission.

[0046] Destination port 112. If a given alert was generated in response to a given transmission 40 from a given computing device to a given internet site 42, then destination port 112 indicates the destination port of the given transmission.

[0047] Execution chain 114. Processor 60 can identify an execution chain for each process 70. If a given alert is generated in response to malicious activity performed by a given process 70, execution chain 114 includes the chain of processes 70 whose endpoints include the given process. Execution chain 114 is described below in the description with reference to FIG. 4.

[0048] Parent hash 116. Processor 60 may compute a respective cryptographic parent hash 116 for each process 70. If a given alert was generated in response to malicious activity performed by a given process 70, parent hash 116 contains the cryptographic hash of the given process.

[0049] Causality group owner (CGO) hash 118. Processor 60 may compute a respective CGO cryptographic hash 118 for each CGO process of process 70. The CGO process, also referred to herein simply as CGO, is described below in the description with reference to FIG. 4. If a given alert was generated in response to malicious activity performed by a given process 70, then CGO hash 118 contains the cryptographic hash of the first process 70 in the execution chain ending at the given process.

[0050] Benign flag 120. If a given alert is generated in response to the execution of a given process 70 or the detection of a given file 66, the benign flag for the given process indicates whether the given process / file is classified as benign (e.g., by a threat intelligence service).

[0051] Signed flag 122. If a given alert is generated in response to the execution of a given process 70 or the detection of a given file 66, the signed flag for the given process indicates whether the given process / file contains a valid digital signature.

[0052] In the configuration shown in FIG. 3, each security incident record 94 includes:

[0053] Security Incident ID 124. Each security incident has a corresponding unique security incident ID 124.

[0054] A set of alert IDs 126, each given alert ID 126, corresponds to a given alert ID 98.

[0055] In embodiments of the present invention, processor 80 may categorize multiple cyber alerts 24 into a given security incident by categorizing multiple cyber alert records 90 into a single security incident record 94. Thus, each security incident has a corresponding security incident record. In embodiments described herein, categorizing multiple cyber alerts 24 into a given security incident by categorizing multiple cyber alert records 90 into a single security incident record 94 may also be referred to as correlating the alerts.

[0056] In one embodiment, processor 80 can categorize multiple cyber alert records 90 into a single security incident record 94 by identifying multiple cyber alert records 90 that have timestamps 104 within a specified period (e.g., 12, 24, or 48 hours) and have the same source IP 106, destination IP 108, source port 110, and destination port 112. Upon identifying multiple cyber alert records, processor 80 can add a new security incident record 94 to log 92, generate a unique security incident ID 124 to store in the added security incident record, and store the alert IDs 98 of the identified multiple cyber alert records 90 in alert ID 126 in the added security incident record.

[0057] In some embodiments, the task of analyzing transmissions 40, files 66, and processes 70 as described herein may be divided among multiple devices within computer facility 20 (e.g., one or more additional security servers 22 and / or computing devices 26) or external to the computer facility (e.g., a data cloud-based application). In additional embodiments, some or all of the functionality of computing device 26 and / or security server 22 may be deployed within computer facility 20 and / or Internet 36 as virtual machines and / or containers.

[0058] Processors 60 and 80 include general-purpose central processing units (CPUs) or special-purpose embedded processors programmed with software or firmware to perform the functions described herein. This software may be downloaded to security server 22 and computing device 26 in electronic form, for example, over a network. Additionally or alternatively, the software may be stored on a tangible, non-transitory computer-readable medium, such as an optical, magnetic, or electronic memory medium. Additionally or alternatively, at least some of the functions of processors 60 and 80 may be performed by hardwired or programmable digital logic circuitry.

[0059] Examples of memory 62 and 82 include dynamic random access memory and non-volatile random access memory. Examples of storage device 64 include non-volatile storage devices such as hard disk drives and solid state disk drives.

[0060] 4 is a graph 130 illustrating an exemplary process execution chain 114 that may be executed on a given computing device 26, according to an embodiment of the present invention. The process execution chain 114 includes respective endpoints 132 that represent given processes 70. In some embodiments, the given endpoints 132 represent given processes 70, the activity of which causes a given protection appliance to generate a given cyber alert 24.

[0061] In FIG. 4, processes 70, execution chains 114 (also known as causality chains), and endpoints 132 can be distinguished by appending letters to their identification numbers, so that processes include processes 70A-70G, execution chains include remote execution chains 114A-114C, and endpoints include endpoints 132A-132C.

[0062] 4, process 70A includes CGO processes 134 for execution chains 114A, 114B, and 114C. Additionally, the example shown in FIG.

[0063] Execution chain 114A includes processes 70A, 70B, and 70C, where process 70A calls process 70B, which calls 70C. Endpoint 132A for execution chain 114A includes process 70C.

[0064] Execution chain 114B includes processes 70A, 70B, and 70D, where process 70A calls process 70B, which calls 70D. Endpoint 132B for execution chain 114B includes process 70D.

[0065] Execution chain 114A includes processes 70A, 70B, 70E, 70F, and 70G, where process 70A calls process 70B, which calls 70E, which calls 70F, and process 70F calls process 70F. Endpoint 132C for execution chain 114C includes process 70F.

[0066] CGO process 134 includes process 70A for execution chains 114A, 114B, and 114C. Thus, if processes 70D, 70D, and 70G generated their respective cyber alerts 24, process 70A was the first process 70 in the causal chain that generated the alerts.

[0067] Cyber ​​Alert Classification FIG. 5 is a flow chart that schematically illustrates a method for categorizing a plurality of cyber alerts 24 into a set of security incident records 94 in accordance with one embodiment of the present invention.

[0068] In step 140 , processor 80 receives a series of cyber alerts 24 from security appliances such as firewall 38 and endpoint agent 72 .

[0069] In step 142, processor 80 may extract artifacts from each received cyber alert and store the extracted artifacts in a respective cyber alert record 90, as described above with reference to FIG. 3.

[0070] In step 144, processor 80 correlates the received cyber alerts into a set of security incidents, where each security incident is indicative of a single cyber attack on LAN 28 within computer equipment 20. To correlate the received cyber alerts into a set of security incidents, processor 80 may generate a given security incident record 144 by identifying multiple cyber alert records 90 having a timestamp 104 within a specified period of time (as described above with reference to FIG. 3) and the same source IP 106, destination IP 108, source port 11, 0, and destination port 112. In additional embodiments, processor 80 may perform step 144 by applying a given profile 96, as described in Appendix 1 below.

[0071] The cyber alerts that processor 80 categorizes into a single security incident may include at least a first and a second cyber alert 24. In some embodiments, the first and second cyber alerts (i.e., as indicated by their corresponding cyber alert records 90) include different respective alert sources 100 and different respective alert types 102. For example, processor 80 may receive a first alert from firewall 38 and a second alert from a given endpoint agent 72 running on a given computing device, where the first alert identifies a given transmission 40 from the given computing device to a given Internet site 42 that the firewall identified as suspicious, and where the second alert identifies a given file 66 on the given computing device that the given endpoint agent identified as potentially malicious (e.g., based on the given file's digital signature).

[0072] Continuing with this example, processor 80 may classify the first and second cyber alerts into a single one, where the second cyber alert follows the first cyber alert, and where the first and second cyber alerts occur within a specified period of time (e.g., 12, 24, or 48 hours) as indicated by the timestamps of the cyber alert records corresponding to the first and second cyber alerts.

[0073] Finally, in step 146, processor 80 may issue a respective consolidated alert for the classified security incidents, and the method ends. In some embodiments, for each given security incident, processor 80 may identify one or more computing devices responsible for or affected by the given security incident and issue a given consolidated alert to the identified computing devices. For example, processor 80 may receive a cyber alert 24 response from firewall 38 that detects respective transmissions 40 from different computing devices 26 to the same Internet site 42 that firewall 38 has identified as suspicious. Because this activity may indicate a phishing attack on LAN 28, processor 80 may issue a consolidated alert to the computing devices that transmitted the transmissions to the suspicious Internet site.

[0074] In one embodiment, processor 80 may issue a given consolidated alert to a given computing device 26 by instructing firewall 38 to block transmission 40 from the given computing device. In another embodiment, processor 80 may issue a given consolidated alert to a given computing device 26 by presenting a notification including the given consolidated alert to a system administrator on UI device 86.

[0075] FIG. 6 is a block diagram illustrating an example of displaying a consolidated alert 150 for a given security incident on a UI device 86 according to one embodiment of the present invention.

[0076] In this example, processor 80 displays:

[0077] A first area 152 that includes a security incident summary 154 that succinctly summarizes a given consolidated alert. The security incident summary 154 may include information such as the attack type (e.g., phishing) and the number of computing devices 26 affected by a given security incident.

[0078] A second region 156 includes a plurality of artifact entries 158. Each given artifact entry 158 may include information from a given cyber alert record 90 that the processor classified as part of a given security incident. For example, a given artifact entry 158 may present information from the given cyber alert record 90, such as a given destination IP address (i.e., for a given transmission 40), an execution chain 114, a given benign flag 120 (i.e., for a given file 66 or a given process 70), and a signed flag 122 (again, for a given file 66 or a given process 70). In some events, the region 156 may be scrollable on the UI device 86.

[0079] A third region 160 includes a plurality of alert entries 162. Each given alert entry 162 may include information from a given cyber alert record 90 that the processor has classified as part of a given security incident. For example, a given alert entry 162 may present information from the given cyber alert record 90, such as a timestamp, a given computing device 26, a source IP address, a source IP address indicating the alert sender, and an alert type. In some events, the region 160 may be scrollable on the UI device 86.

[0080] Attachment 1: Profile In some embodiments, the processor 80 may identify a given security incident by applying a given profile 96 to the cyber alert records to correlate two or more cyber alerts 24 by categorizing two or more corresponding cyber attack records 90 into a single security incident record 94 corresponding to the given security incident.

[0081] A first example of a given profile 96 may be referred to as a causality ID profile. In some embodiments, processor 80 may apply the causality ID profile by identifying at least two cyber alert records 90 that include identical execution chains 114 executed on a given computing device 26, adding a new security incident record 94 to security incident log 92, and populating the alert ID 126 in the new security incident record with the alert ID 98 in the identified cyber alert record.

[0082] One example of a given security incident of processor 80 classified via a causality ID profile includes a given execution chain 114 that includes an email application (i.e., a given first process 70) invoking a browser application (i.e., a given second process 70). This given security incident, as classified by processor 80, uses a causality ID profile.

[0083] The browser transmitted a given transmission 40 to a given Internet site 42 and the firewall 38 identified the given Internet site as suspicious and generated a first cyber alert 24 .

[0084] Within a specified period (e.g., 24 hours), the browser downloaded a given file that the endpoint agent identified as suspicious (i.e., running on the same computing device 26 as the browser) and generated a second cyber alert 24.

[0085] The second instance of the given profile 96 may be referred to as a causality profile. In some embodiments, the processor 80 may apply the causality profile by identifying at least two cyber alert records 90 that contain the same CGO hash 118 (and thereby identify a CGO process running on the given computing device 26), adding a new security incident record 94 to the security incident log 92, and populating the alert ID 126 in the new security incident record with the alert ID 98 in the identified cyber alert record.

[0086] One example of a given security incident classified via a causality profile includes a browser executed on a given computing device 26 (i.e., a first process 70 that is a CGO process), a first executable file 66 downloaded (i.e., a given processor executing as a given second process 70), and a second executable file 66 downloaded (i.e., a given processor executing as a given third process 70).

[0087] In this example, the first execution chain 114 includes a first process and a second process, and the second execution chain includes a first process and a third process. The given security incident, as classified by the processor 80, uses a causality ID profile.

[0088] The second process transmitted the given transmission 40 to the given internet site 42 and the firewall 38 identified the given internet site as suspicious and generated the first cyber alert 24 .

[0089] Within a specified period of time (e.g., 24 hours), a third process modified a registry value within the operating system running on the given computing device that an endpoint agent running on the given computing device identified as suspicious activity and generated a second cyber alert 24.

[0090] A third example of a given profile 96 may be referred to as a network profile. In some embodiments, processor 80 may apply the network profile by identifying cyber alert records 90 generated in response to cyber alerts 24 received from firewall 38 in response to the firewall detecting transmissions 40 from different computing devices 26 to the same Internet site 42 that the firewall identified as suspicious within a specified time period. Processor 80 may apply the network profile to classify these cyber alerts 24 as a single security incident that may be indicative of a phishing attack on LAN 28.

[0091] A fourth example of a given profile 96 is referred to as a process event profile. In some embodiments, processor 80 can apply the causality profile by identifying at least two cyber alert records 90 that contain the same parent hash 116 (and thereby indicate the same process 70), adding a new security incident record 94 to security incident log 92, and populating the alert ID 126 in the new security incident record with the alert ID 98 in the identified cyber alert record. In some embodiments, the benign flag and / or signed flag in the identified cyber alert record are false, thereby indicating that the same process is suspicious.

[0092] In one embodiment, the cyber alert records corresponding to an identified cyber alert may include the same alert source 100. In this embodiment, one or more identical processes 70 running on a given computing device 26 are responsible for the identified cyber alert.

[0093] In another embodiment, the cyber alert records corresponding to the identified cyber alerts may include different alert sources 100. In this embodiment, the same process 70 running on one or more computing devices 26 is responsible for the identified cyber alerts.

[0094] One example of a given security incident classified by processor 80 via a causality ID profile includes one or more identical processes 70 classified by processor 80 using a causality ID profile in response to the following events:

[0095] Either a single process, or one of the same processes, transmitted a given transmission 40 to a given Internet site 42, and a firewall 38 identified the given Internet site as suspicious and generated a first cyber alert 24.

[0096] Within a specified period of time (e.g., 24 hours), either a single process or one of the same processes modified a registry value within the operating system running on the given computing device that an endpoint agent running on the given computing device identified as suspicious activity and generated a second cyber alert 24.

[0097] A fifth example of a given profile 96 is referred to as a file event profile. In some embodiments, the processor 80 can apply the network profile by identifying cyber alert records 90 generated by the system processor in response to cyber alerts 24 received from different endpoint agents 72 executing on respective computing devices within a specified time period in response to the given endpoint 72 detecting at least one file 66 that the endpoint identified as suspicious (e.g., based on the detected file not being benign or signed). The processor 80 can apply the file event profile to classify these cyber alerts 24 as a single security incident.

[0098] It will be understood that the above-described embodiments are cited by way of example, and that the present invention is not limited to what has been particularly shown and described above. Rather, the scope of the present invention includes both combinations and subcombinations of the various features described above, as well as variations and modifications thereof that would occur to one skilled in the art after reading the above description and that are not disclosed in the prior art.

Claims

1. A method for securing a computer network in which a plurality of computing devices execute respective processes, the method comprising: receiving, at a security server, a plurality of different types of alerts indicative of potentially malicious activity within the computer network detected by a plurality of different protection appliances deployed within the computer network; identifying respective causality profiles for the processes that cause the alerts received by the security server; correlating alerts at the security server using the respective causality profiles to identify a first alert of a first type received from a first protection appliance in the computer network for a first process and a second alert of a second type different from the first type received from a second protection appliance in the computer network for a second process, which together indicate a single attack on the computer network; issuing a consolidated alert in response to the single attack; A method comprising:

2. receiving a first alert includes receiving the first alert at a first time; receiving a second alert includes receiving the second alert at a second time after the first time; and the first alert and the second alert exist within a specified time period; The method of claim 1.

3. The step of identifying each causal profile comprises: identifying a respective causal group owner (CGO) for the process that causes the alert; and correlating the alerts includes detecting that the CGO of a given first process matches the CGO of a given second process. The method of claim 1.

4. The step of identifying each causal profile comprises: identifying a respective execution chain for the process that causes the alert; each of the processes that cause the alert includes an endpoint of a respective execution chain; and correlating the alerts includes detecting that the execution chain for a given first process matches the execution chain for a given second process. The method of claim 1.

5. The step of identifying each causal profile comprises: calculating a parent hash of each of the processes that cause the alert; Each given alert contains a given process and its respective parent hash, and the step of correlating the alerts includes detecting that a parent hash of a first alert matches a parent hash of a second alert; The method of claim 1.

6. The step of correlating the alerts comprises: Detecting that the first alert is indicative of a given first computing device transmitting a first transmission to a suspected malicious internet site; and detecting that the second alert is indicative of a given second computing device transmitting a second transmission to the internet site; The method of claim 1 , comprising:

7. The step of correlating the alerts comprises: Detecting that the first alert indicates a given first computing device storing a suspected malicious file; and detecting that the second alert indicates a given second computing device storing an identical copy of the file; The method of claim 1 , comprising:

8. Each given protection appliance: selected from the group consisting of a firewall, a software application running on a given computing device, a data cloud firewall, and a data cloud security software application; The method of claim 1.

9. An apparatus for protecting a computer network in which a plurality of computing devices execute respective processes, the apparatus comprising: Network Interface Cards (NICs), and at least one processor; The processor: receiving a plurality of different types of alerts indicative of potentially malicious activity within the computer network, as detected by a plurality of different protection appliances deployed within the computer network; identifying respective causality profiles for the processes that cause the alerts received by a security server; correlating the alerts using the respective causality profiles to identify a first alert of a first type received from a first protection appliance in the computer network for a first process and a second alert of a second type different from the first type received from a second protection appliance in the computer network for a second process, which together indicate a single attack on the computer network; and issuing a consolidated alert in response to said single attack; The apparatus is configured to:

10. a given processor is configured to receive a first alert by receiving said first alert at a first time; and the given processor is configured to receive the second alert at a second time after the first time; the first alert and the second alert exist within a specified time period; 10. The apparatus of claim 9.

11. The method of claim 10, wherein each of the causal profiles is configured to identify a respective causal group owner (CGO) for the process that causes the alert; and the at least one processor is configured to correlate the alerts by detecting that the CGO of a given first process matches the CGO of a given second process.

11. The apparatus of claim 10.

12. The respective causality profiles include respective execution chains for the processes that cause the alerts; and each of the processes that cause the alert includes an endpoint of a respective execution chain; the at least one processor is configured to correlate the alert by detecting that the execution chain for a given first process matches the execution chain for a given second process.

11. The apparatus of claim 10.

13. The respective causality profiles are configured to calculate respective parent hashes for the processes that cause the alerts; and Each given alert contains a given process and its respective parent hash, the at least one processor is configured to correlate the alerts by detecting that a parent hash of a first alert matches a parent hash of a second alert.

11. The apparatus of claim 10.

14. A given processor may: by detecting that the first alert is indicative of a given first computing device transmitting a first transmission to a suspected malicious internet site; and detecting that the second alert indicates a given second computing device transmitting a second transmission to the internet site; configured to correlate the alerts.

11. The apparatus of claim 10.

15. A given processor may: by detecting that the first alert indicates a given first computing device storing a suspected malicious file; and detecting that the second alert indicates a given second computing device storing an identical copy of the file; configured to correlate the alerts.

11. The apparatus of claim 10.

16. Each given protection appliance: selected from the group consisting of a firewall, a software application running on a given computing device, a data cloud firewall, and a data cloud security software application; 11. The apparatus of claim 10.

17. A computer program for protecting a computer system in which a plurality of computing devices execute respective processes, the computer program including a plurality of program instructions and stored on a non-transitory computer-readable storage medium; When the instructions are read and executed by a computer, the computer: receiving a plurality of different types of alerts indicative of potentially malicious activity within the computer network, as detected by a plurality of different protection appliances deployed within the computer network; identifying respective causality profiles for the processes that cause the alerts received by a security server; correlating the alerts using the respective causality profiles to identify a first alert of a first type received from a first protection appliance in the computer network for a first process and a second alert of a second type different from the first type received from a second protection appliance in the network for a second process, which together indicate a single attack on the computer network; and issuing a consolidated alert in response to said single attack; A computer program that makes

Citation Information

Patent Citations

  • Attack analysis apparatus, sensor, attack analysis method and program

    JP2004046742A

  • Network-based alert management

    US6704874B1

  • Information processing device, control method, and program

    WO2020100284A1