×

Event correlation across heterogeneous operations

  • US 9,742,788 B2
  • Filed: 08/31/2015
  • Issued: 08/22/2017
  • Est. Priority Date: 04/09/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for correlating domain activity data, the method being executed by one or more processors and comprising:

  • receiving first domain activity data from a first network domain and second domain activity data from a second network domain, the first domain activity data and the second domain activity data including events, alerts, or both from the respective first and second network domains;

    filtering the first domain activity data and the second domain activity data to remove irrelevant activity data, based on a first set of profile data for devices in the first network domain and a second set of profile data for devices in the second network domain;

    aggregating unfiltered first domain activity data and unfiltered second domain activity data;

    correlating aggregated unfiltered first domain activity data and unfiltered second domain activity data to determine an attack path for an attack that occurs across the first network domain and the second network domain, based on attack signatures and profiles associated with previously identified attacks;

    wherein correlating further includes;

    labeling the aggregated unfiltered first domain activity data and unfiltered second domain activity data to identify two or more alerts, meta-alerts, or both that are associated with a particular attacker;

    linking the activity data that is labeled as being associated with the particular attacker to identify a chain of two or more alerts, meta-alerts, or both; and

    determining the attack path that occurs across the first network domain and the second network domain, including determining a series of communications between one or more devices in the first network domain and one or more devices in the second network domain; and

    generating a visualization of the attack path.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×