EP4046331B1

Endpoint network sensor and related cybersecurity infrastructure

Abstract

This record has no abstract on file.

EP4046331B1, drawing sheet 1
Sheet 1 of 27

Term

15.2 yearsleft in the term

Expires 14 December 2041.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

17 claims: 7 independent, 10 dependent

  1. 1
    An endpoint agent (616) configured, when executed on an endpoint device (312), to:access via a local traffic access function of the endpoint device (616) network traffic local to the endpoint device, the local network traffic comprising: copies of all outgoing packets sent from a network interface of the endpoint device to a packet-switched network (630) and carrying in their payloads outbound payload data generated by one or more processes (602) executed on the endpoint device (312), and copies of all incoming packets received at the network interface from the packet-switched network (630) and carrying in their payloads inbound payload data intended for the one or more processes (602) executed on the endpoint device (312);extract network traffic telemetry from the headers and the payloads of the copies of the outgoing and incoming packets, the extracted network traffic telemetry including header data of the incoming and outgoing packets, and additionally summarizing the outbound and inbound payload data of the outgoing and incoming packets, wherein said extracting comprises processing each packet to determine whether the packet constitutes the start of a network flow or pertains to an existing network flow;and transmit, to a cybersecurity service, a series of network telemetry records identifying all new network flows observed by the endpoint agent, and containing the extracted network traffic telemetry that includes the header data and summarizes the payload data for use in performing a cybersecurity threat analysis.
  2. 6
    The endpoint agent of any of claims 3 to 5, wherein the incident of local activity is one of the processes accessing a file and the at least one network telemetry record contains information about the file.
  3. 7
    The endpoint agent of any preceding claim, configured to determine a user account associated with at least one packet of the incoming and/or outgoing packets, and associate at least one network telemetry record of the series of network telemetry records with user information of the user account, the at least one network telemetry record pertaining to the at least one packet.
  4. 8
    The endpoint agent of any preceding claim, wherein the local traffic access function is provided by a network activity application programming interface, API, of an operating system (604) of the endpoint device, the endpoint agent configured to access the incoming and outgoing packets via the network activity API;wherein the endpoint agent is configured to obtain, via the operating system (604) of the endpoint device, a piece of endpoint data associated with one or more network packets of the incoming and/or outgoing packets, wherein at least one network telemetry record of the series of network telemetry records pertains to the one or more network packets with which the piece of endpoint data is associated, and the endpoint agent is configured to augment or enrich the at least one network telemetry record with the piece of endpoint data, or link at least one of the network telemetry records with at least one other record containing the piece endpoint data and transmitted from the endpoint device to the cybersecurity service.
  5. 11
    The endpoint agent of any preceding claim, wherein the series of network telemetry records is generated independently of any local threat detection performed at the endpoint device (312).
  6. 12
    An endpoint device (312) comprising:a network interface (610) configured to send incoming packets carrying inbound payload data and/or receive outgoing packets carrying outbound payload data;one or more processing units configured to execute: one or more processes (602) configured to process the inbound payload data and/or generate the outbound payload data, and the endpoint agent (616) of any preceding claim, configured to extract the network traffic telemetry from the incoming and outgoing packets sent from and received at the network interface.
  7. 13
    A method of aggregating network telemetry records received from multiple endpoint agents (616) executed on multiple endpoint devices (312), the method comprising:receiving from each of the endpoint agents (616) a series of network telemetry records, the network telemetry records containing telemetry summarising local network traffic observed at the endpoint device on which the endpoint agent is executed, the network telemetry records having been associated by the endpoint agent (616) with endpoint data captured by monitoring local activity by one or more processes executed at the endpoint device (602), wherein the local network traffic comprises copies of all outgoing and incoming packets sent from and received at a network interface of the endpoint device on which the endpoint agent is executed, and the endpoint agent (616) extracts the telemetry from the headers and the payloads of the copies of the outgoing and incoming packets, and processes each packet to determine whether it constitutes the start of a network flow or pertains to an existing network flow, and wherein the network telemetry records identify all new network flows observed by the endpoint agent, and the telemetry includes header data of the incoming and outgoing packets, and additionally summarizes the outbound and inbound payload data of the outgoing and incoming packets;detecting at least one duplicate network telemetry record received from a second of the endpoint devices, the duplicate network telemetry record duplicating network traffic information conveyed in a first network telemetry record received from a first of the endpoint devices in communication with the second endpoint device, wherein the duplicate network telemetry record is detected by matching a second deduplication key thereof with a first deduplication key of the first network telemetry record, the deduplication keys identifying a common flow to which those telemetry records pertain;extracting from the duplicate network telemetry record a second piece of endpoint data captured at the second endpoint;and associating the first network telemetry record received from the first endpoint device with the extracted piece of endpoint data as captured at the second endpoint device, the first network telemetry record having been additionally associated with a first piece of endpoint data at the first endpoint device.
  8. 16
    The method of any of claims 13 to 15, wherein the first network telemetry record is enriched or otherwise associated with the extracted piece of endpoint data, and the duplicate network telemetry record is discarded once that piece of endpoint data has been extracted.
  9. 17
    The method of any of claims 13 to 16, comprising receiving at least one piece of network information about the first and/or second endpoint from a network monitoring system, and enriching or otherwise associating the first network telemetry record with the at least one piece of network information, wherein the at least one piece of network information optionally comprises MPLS and/or VLAN label(s).