Cybersecurity system
29 claims: 5 independent, 24 dependent
- 1イベントを処理してスコア、警告、及び緩和アクションを生成するサイバーセキュリティシステムにおいて、複数のセンサと、分散型分析プラットフォームと、複数のスコア付けエンジンと、及び、リアルタイム分析エンジンとを含み、前記複数のセンサの各々は、 ネットワークからセンサデータを受信し、 前記 センサデータを処理してイベントを作成し、及び、 前記 イベントを伝送するように構成されており、前記分散型分析プラットフォームは、 前記複数のセンサから 前記 イベントを受信し、 前記 イベントを処理して分析ワークフロー及び分散型分析プラットフォームメッセージを作成し、ここで、 前記 分散型分析プラットフォームメッセージの各々は、警告、第1の分析モデルへの更新、及びサイバー振る舞い情報のうちの少なくとも一つと関連付けられており、 前記 分析ワークフローの各々は、一つ若しくはそれ以上の論理セグメントと関連付けられており、並びに、 前記 第1の分析モデル、第2の分析モデル、ルール、データ変換、及びデータ凝集のうちの、少なくとも一つを含み、 並びに、 前記 分析ワークフロー及び分散型分析プラットフォームメッセージを伝送するように構成されており、前記複数のスコア付けエンジンの各々は、 前記 分散型分析プラットフォームから 前記 分析ワークフローを受信し、 前記 複数のセンサの少なくとも一つから 前記 イベントを受信し、 前記 分析ワークフローを用いて、 前記 受信したイベントを処理してスコア付けエンジンメッセージを生成し、及び、 前記 スコア付けエンジンメッセージを伝送するように構成されており、並びに、前記リアルタイム分析エンジンは、 前記分散型分析プラットフォームから 前記 分析ワークフローを受信し、 分析ワークフローとイベント処理ルールを受信し、 前記複数のスコア付けエンジンから 前記 スコア付けエンジンメッセージを受信し、 前記分散型分析プラットフォームから 前記 分散型分析プラットフォームメッセージを受信し、並びに、 前記分散型分析プラットフォームからの 前記 分析ワークフロー、及び、 前記 分析ワークフローとイベント処理ルールを用いて、 前記 スコア付けエンジンメッセージと 前記 分散型分析プラットフォームメッセージを処理して脅威情報メッセージを作成するように構成されており、 前記 脅威情報メッセージは、前記リアルタイム分析エンジンが伝送するように構成されている、ブロードキャストメッセージと、緩和メッセージであって、前記リアルタイム分析エンジンによる 前記 処理が、緩和アクションが異常アクティビティのインパクトを限定することを示すとき、前記一つ若しくはそれ以上の論理セグメントのうちの第1の論理セグメントと関連付けられる緩和アクションを採るために、前記リアルタイム分析エンジンが前記緩和メッセージをコントロールプレーンエンジンに伝送するように構成されている、緩和メッセージと、及び、モデル更新メッセージであって、前記リアルタイム分析エンジンによる 前記 処理が、 前記 モデル更新メッセージが 前記 異常アクティビティの検出率と偽陽性率の減少との少なくとも一つを 改善 することを示すとき、一つ若しくはそれ以上の分析ワークフローを更新するために、前記リアルタイム分析エンジンが 前記 モデル更新メッセージを伝送するように構成されている、モデル更新メッセージとのうちの少なくとも一つを含み、前記一つ若しくはそれ以上の論理セグメントの各々は、 前記 第1の分析モデル、 前記 第2の分析モデル、第3の分析モデル、分析モデルのセット、及び分析ワークフローのうちの少なくとも一つと、 前記 論理セグメント内部のアクティビティについてのインプットの一つ若しくはそれ以上のソースと、並びに、 前記 論理セグメント内部で発生する 前記 異常アクティビティのインパクトを緩和する、アクションのセットと関連する、システム。
- 2前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、及び、前記コントロールプレーンエンジンが、帯域外ネットワークを用いて接続している、請求項1に記載のシステム。
- 3前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、及び、前記コントロールプレーンエンジンが、企業体システムバスに亘って関連するメッセージを送信することにより通信する、請求項1に記載のシステム。
- 4前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、及び、前記コントロールプレーンエンジンが、企業体システムバスに亘って関連するメッセージを送信することにより通信する、請求項2に記載のシステム。
- 5更に、摂取アクタモジュールを含み、前記摂取アクタモジュールは、サードパーティアプリケーションとサードパーティデバイスのうちの少なくとも一つからサードパーティアプリケーションデータを受信し、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、及び前記リアルタイム分析エンジンのうちの少なくとも一つによる更なる処理のために、 前記 サードパーティアプリケーションデータを伝送するように構成されている、請求項1に記載のシステム。
- 6前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、前記コントロールプレーンエンジン、及び前記摂取アクタモジュールが、帯域外ネットワークを用いて接続している、請求項5に記載のシステム。
- 7前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、前記コントロールプレーンエンジン、及び前記摂取アクタモジュールが、企業体システムバスに亘って関連するメッセージを送信することにより通信する、請求項5に記載のシステム。
- 8前記スコア付けエンジンが更に、 前記 モデル更新メッセージを受信し、及び、 前記 イベントの処理と同時に、 前記 更新メッセージを処理するように構成されている、請求項1に記載のシステム。
- 9前記 ブロードキャストメッセージ、 前記 緩和メッセージ、及び 前記 モデル更新メッセージのうちの少なくとも一つを作成するために、前記リアルタイム分析エンジンは更に、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、及び前記複数のセンサのうちの少なくとも一つから、第1の時間に第1のアウトプットを受信し、 前記 第1のアウトプットに対応する第1の状態情報を検索し、第1のアウトプットデータで 前記 第1の状態情報を更新し、前記リアルタイム分析エンジンと関連付けられる分析ワークフローにより、 前記 更新された第1の状態情報を処理して、処理された更新された第1の状態情報を作成し、 前記 処理された更新された第1の状態情報を前記リアルタイム分析エンジン内に格納し、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、及び前記複数のセンサのうちの少なくとも一つから、第2の時間に第2のアウトプットを受信し、 前記 第2のアウトプットに対応する第2の状態情報を検索し、第2のアウトプットデータで 前記 第2の状態情報を更新し、前記リアルタイム分析エンジンと関連付けられる 前記 分析ワークフローにより、 前記 更新された第2の状態情報を処理して、処理された更新された第2の状態情報を作成し、 前記 処理された更新された第2の状態情報に基づいて、 前記 ブロードキャストメッセージ、 前記 緩和メッセージ、及び 前記 モデル更新メッセージのうちの 前記 少なくとも一つを作成し、並びに、 前記 処理された更新された第2の状態情報を前記リアルタイム分析エンジン内に格納するように構成されている、請求項1に記載のシステム。
- 10前記リアルタイム分析エンジンは更に、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、及び前記複数のセンサのうちの少なくとも一つから、第3の時間に中間アウトプットを受信し、ここで、 前記 第3の時間は 前記 第1の時間の後であり且つ 前記 第2の時間の前であり、 前記 中間アウトプットに対応する中間状態情報を検索し、中間アウトプットデータで 前記 中間状態情報を更新し、前記リアルタイム分析エンジンと関連付けられる 前記 分析ワークフローにより、 前記 更新された中間状態情報を処理して、処理された更新された中間状態情報を作成し、並びに、 前記 処理された更新された中間状態情報を前記リアルタイム分析エンジン内に格納するように構成されている、請求項9に記載のシステム。
- 11前記 分析ワークフローは、モデル交換フォーマットドキュメントを含み、 前記 モデル交換フォーマットドキュメントは、分析モデルの合成と、分析モデルの区分と、分析モデルのアンサンブルと、ルールによる分析モデルの合成と、前処理及び後処理段階による分析モデルの合成と、及び、分析ワークフローとをサポートし、前処理及び後処理段階は、データ変換とデータ凝集を含み、 前記 分析ワークフローの各々は更に、 前記 分析モデル、 前記 ルール、 前記 データ変換、 前記 データ凝集、 前記 区分及び 前記 アンサンブルのうちの少なくとも一つの合成を、含む、請求項1に記載のシステム。
- 12前記リアルタイム分析エンジンは更に、 前記 分析ワークフローの一つ若しくはそれ以上への変更が閾値を超えるときに、更新された振る舞いモデルを前記複数のスコア付けエンジンの一つ若しくはそれ以上に伝送するように構成されている、請求項1に記載のシステム。
- 13前記 イベントは、ネットワークフローについてのデータ、パケットについてのデータ、エンティティについてのデータ、ユーザについてのデータ、ワークステーションとサーバについてのデータ、ルータとスイッチについてのデータ、外部ネットワークエンティティについてのデータ、並びに、 前記 ネットワークと相互作用する内部及び外部デバイスについてのデータのうちの、少なくとも一つを含む、請求項1に記載のシステム。
- 14前記複数のセンサと前記複数のスコア付けエンジンとのうちの、一つ若しくはそれ以上が、単独のアプリケーション内に統合される、請求項1に記載のシステム。
- 15前記リアルタイム分析エンジンが、前記複数のスコア付けエンジンのうちの一つ若しくはそれ以上と統合する、請求項1に記載のシステム。
- 16前記 緩和アクションは、少なくとも一つのポートを閉じること、少なくとも一つのパケットデータを修正すること、パケット若しくはフローの 前記 伝送をコントロールすること、サブネットをブロックすること、一つ若しくはそれ以上のインターネットプロトコル(IP)若しくはIPの範囲をブロックすること、及び、一つ若しくはそれ以上の内部の若しくは外部のIPをブロックすることのうちの少なくとも一つを含む、請求項1に記載のシステム。
- 17前記 緩和アクションは、サーバ及びワークステーションのオフラインの少なくとも一つを採ること、プロテクトされた画像から、新しい可視化サーバと新しい可視化ワークステーションのうちの少なくとも一つを形成すること、及び、 前記 サーバと 前記 ワークステーションのうちの少なくとも一つと関連付けられるアクションをブロックすることのうちの少なくとも一つを含む、請求項1に記載のシステム。
- 18前記 異常アクティビティは、偵察、セキュリティ上の弱点を突く手段、侵入、情報漏洩、インサイダ脅威、及び攻撃のうちの、少なくとも一つを含む、請求項1に記載のシステム。
- 19前記 緩和アクションは、少なくとも一つのパケットを修正すること、パケット若しくはフローの 前記 伝送をコントロールすること、及び、 前記 異常アクティビティと関連付けられるエンティティに対する許可及びアクセス権を除去することのうちの、少なくとも一つを含み、許可及びアクセス権を除去することは、ネットワークアクセスをブロックすること、ネットワークデバイスへのアクセスをブロックすること、サーバへのアクセスをブロックすること、ワークステーションへのアクセスをブロックすること、及び、他のコンピュータデバイスへのアクセスをブロックすることのうちの、少なくとも一つを含む、請求項18に記載のシステム。
- 20前記 異常アクティビティは、内部の悪いアクタと外部の悪いアクタとのうちの、少なくとも一つと関連付けられる、請求項18に記載のシステム。
- 21更に可視化エンジンを含み、 前記 可視化エンジンはモニタを含み、 前記 可視化エンジンは、 前記 リアルタイム分析エンジンによるスコア付けエンジンメッセージの 前記 処理と関連付けられる統計及びグラフィック画像を受信し、及び、 前記 モニタ上に 前記 統計及びグラフィック画像を表示するように構成されている、請求項1に記載のシステム。
- 22複数の、請求項1に記載の 前記 サイバーセキュリティシステムを含む、サイバーセキュリティ ネットワーク において、 前記 複数の 前記 サイバーセキュリティシステムの各々は、選択した脅威情報メッセージを、他のサイバーセキュリティシステムの一つ若しくはそれ以上と交換するように構成されており、 前記 選択した脅威情報メッセージは、暗号化されて、情報を伝送するための機密メカニズムを提供し、 前記 選択した脅威情報メッセージ内の 前記 情報は、 前記 伝送するサイバーセキュリティシステムに関する機密の内部情報を曝すことはしない、サイバーセキュリティ ネットワーク 。
- 23外部の脅威情報メッセージを、互換性のあるサードパーティシステムと交換するように構成されており、 前記 外部の脅威情報メッセージは、暗号化されて、情報を伝送するための機密メカニズムを提供し、 前記 外部の脅威情報メッセージ内の 前記 情報は、 前記 外部の脅威情報メッセージを伝送するシステムに関する機密の内部情報を曝すことはせず、及び、 前記 外部の脅威情報メッセージは、共通のモデル交換フォーマットでフォーマットされる、請求項1に記載のシステム。
- 24前記分散型分析プラットフォームは更に、 前記 スコア付けエンジンメッセージを受信し、及び、 前記 スコア付けエンジンメッセージを処理して脅威情報メッセージを作成するように構成されている、請求項1に記載のシステム。
- 25前記 ブロードキャストメッセージは、情報メッセージ、サイバーイベントメッセージ、及び警告メッセージのうちの、少なくとも一つを含む、請求項1に記載のシステム。
- 26前記複数の論理セグメントの各々は、 前記 ネットワークの分割、 前記 ネットワーク上の 前記 トラフィックの分割、 前記 ネットワーク上のユーザの分割、 前記 ネットワーク上のデバイスの分割、サードパーティデータに基づく分割、並びに、 前記 ネットワーク、 前記 ネットワーク上の 前記 トラフィック、 前記 ネットワーク上の 前記 ユーザ、 前記 ネットワーク上のデバイス、及び、サードパーティデータに、関する複数の 前記 分割の少なくとも一つと関連するデータのうちの、少なくとも一つと関連付けられる、請求項1に記載のシステム。
- 27少なくとも第1の分割は、少なくとも第2の分割とオーバラップする、請求項26に記載のシステム。
- 28前記複数のセンサ、前記複数のスコア付けエンジン、前記分散型分析プラットフォーム、前記リアルタイム分析エンジン、前記コントロールプレーンエンジン、及び、 前記 摂取アクタモジュールが、企業体システムバスに亘って関連するメッセージを送信することにより通信する、請求項27に記載のシステム。
- 29イベントを処理してスコア、警告、及び緩和アクションを生成するサイバーセキュリティシステムにおいて、複数のセンサと、分散型分析プラットフォームと、スコア付けエンジンと、及び、リアルタイム分析エンジンとを含み、前記複数のセンサの各々は、 ネットワークからセンサデータを受信し、 前記 センサデータを処理してイベントを作成し、及び、 前記 イベントを伝送するように構成されており、前記分散型分析プラットフォームは、 前記複数のセンサから 前記 イベントを受信し、 前記 イベントを処理して分析ワークフロー及び分散型分析プラットフォームメッセージを作成し、ここで、 前記 分散型分析プラットフォームメッセージの各々は、警告、第1の分析モデルへの更新、及びサイバー振る舞い情報のうちの少なくとも一つと関連付けられており、 前記 分析ワークフローの各々は、一つ若しくはそれ以上の論理セグメントと関連付けられており、並びに、 前記 第1の分析モデル、第2の分析モデル、ルール、データ変換、及びデータ凝集のうちの、少なくとも一つを含み、 並びに、 前記 分析ワークフロー及び分散型分析プラットフォームメッセージを伝送するように構成されており、前記スコア付けエンジンは、 前記 分散型分析プラットフォームから 前記 分析ワークフローを受信し、 前記複数のセンサの少なくとも一つから 前記 イベントを受信し、 前記 分析ワークフローを用いて、 前記 イベントを処理してスコア付けエンジンメッセージを生成し、及び、 前記 スコア付けエンジンメッセージを伝送するように構成されており、並びに、前記リアルタイム分析エンジンは、 前記分散型分析プラットフォームから 前記 分析ワークフローを受信し、 分析ワークフローとイベント処理ルールを受信し、 前記 スコア付けエンジンメッセージを受信し、 前記分散型分析プラットフォームから 前記 分散型分析プラットフォームメッセージを受信し、並びに、 前記分散型分析プラットフォームからの 前記 分析ワークフロー、及び、 前記 分析ワークフローとイベント処理ルールを用いて、 前記 スコア付けエンジンメッセージと 前記 分散型分析プラットフォームメッセージを処理して脅威情報メッセージを作成するように構成されており、 前記 脅威情報メッセージは、前記リアルタイム分析エンジンが伝送するように構成されている、ブロードキャストメッセージと、緩和メッセージであって、前記リアルタイム分析エンジンによる 前記 処理が、緩和アクションが異常アクティビティのインパクトを限定することを示すとき、前記一つ若しくはそれ以上の論理セグメントのうちの第1の論理セグメントと関連付けられる緩和アクションを採るために、前記リアルタイム分析エンジンが前記緩和メッセージをコントロールプレーンエンジンに伝送するように構成されている、緩和メッセージと、及び、モデル更新メッセージであって、前記リアルタイム分析エンジンによる 前記 処理が、 前記 モデル更新メッセージが 前記 異常アクティビティの検出率と偽陽性率の減少との少なくとも一つを 改善 することを示すとき、一つ若しくはそれ以上の分析ワークフローを更新するために、前記リアルタイム分析エンジンが 前記 モデル更新メッセージを伝送するように構成されている、モデル更新メッセージとのうちの少なくとも一つを含み、前記一つ若しくはそれ以上の論理セグメントの各々は、 前記 第1の分析モデル、 前記 第2の分析モデル、第3の分析モデル、分析モデルのセット、及び分析ワークフローのうちの少なくとも一つと、 前記 論理セグメント内部のアクティビティについてのインプットの一つ若しくはそれ以上のソースと、並びに、 前記 論理セグメント内部で発生する 前記 異常アクティビティのインパクトを緩和する、アクションのセットと関連する、システム。
Independent claims29
120 paragraphs, as filed
Cross-reference to related applications This application claims the priority of 35U.SC119 (e) of US Patent Provisional Application No. 62/066769 filed October 21, 2014, whose invention is entitled "Cyber Security System". , Its contents are incorporated herein by reference in its entirety.
Traditionally, cybersecurity systems have been limited by their ability to explain device differences in large networks and to implement them in real time. In large networks, there are many devices and their behavior is quite different. The traditional approach is to develop a model of simple behavior for the network or for individual types of devices in the network (workstations, servers, switches, routers, etc. in the network). .. The problem with this approach is that this type of approach does not capture differences between individual devices. Another limitation of traditional cybersecurity systems is that after sufficient data has been accumulated, investigated and analyzed by preliminary data analysis, a model of traditional behavior is manually constructed. Traditional systems are hand-built models, previous state information about entities of interest, and distributed / batch analysis that can process data in multiple paths to request distributed or disk-based data. Is often requested.
<p num="0003"> Although some techniques for predictive modeling are well known, the approaches described herein are segmented analytical modeling, which allows the system to take appropriate mitigation events for individual microsegments. Can be used to integrate with types of data center micro-segmentation. In other words, according to one embodiment, a large enterprise network first consists of a large number of homogeneous data center microsegments, users interacting with the entity, and within the microsegment, based on the behavior of the entity within the homogeneous data center microsegment. It is divided into packets and flows of. In particular, a large number of segments are formed within the enterprise where sensors capable of collecting data for one or more such segments are located. The model is then built for individual segments, which are monitored by sensors and scoring engines, and appropriate mitigation actions are taken for that particular microsegment. In other words, event-based modeling and the use of multiple models are integrated with real-time scoring engines and data center micro-segmentation, which ensures the effective application of appropriate mitigation events for individual microsegments. It will be possible.</p><p num="0004"> Separating the construction of analytical models (where special cases are models of behavior) and the scoring of analytical models using two different use cases is a standard technique in real-time system monitoring and alert generation. However, model exchanges such as Potable Format (PFA) for analysis using multiple sensors and multiple scoring engines that communicate across high-performance ESBs, and messages sent across ESBs. Ability to update format (MIF) models, gathering event-by-event evidence from multiple scoring engines, and ESB, each communicating across the ESB with threat information messages to the Real-Time Analysis Engine (RTAE). The processing of these TIMs by the RTAE to send out appropriate mitigation events (mitigation TIMs) over and over is a single scoring engine that processes a single stream of data that can only replace the model exchange format document with a new one. It is an individual and significant development for.</p>
<p num="0005"> According to the disclosed gist of the invention, systems, methods, and non-temporary computer-readable media are presented to provide cybersecurity systems that process events to generate scoring, alerting, and mitigation actions. To.</p><p num="0006"> In certain embodiments, the disclosed gist of the invention includes a cybersecurity system that processes events to generate scores, warnings, and mitigation actions. In certain embodiments, the system comprises a plurality of sensors, each of which is configured to receive sensor data from a network, process the sensor data to create an event, and transmit the event. ing. In one embodiment, the system includes a distributed analysis platform, which receives events from the plurality of sensors and processes the events to create an analysis workflow, wherein each of the analysis workflows is one. It is associated with one or more logical segments and is configured to carry analysis workflows and distributed analysis platform messages. In one embodiment, the system comprises a plurality of scoring engines, each of which receives an analysis workflow from a distributed analysis platform and an event from at least one of the warfare sensors. The analysis workflow is configured to process received events to generate scoring engine messages and transmit scoring engine messages. In certain embodiments, the system includes a real-time analysis engine, which receives analysis workflows from the distributed analysis platform, analysis workflows and event processing rules, and scores from the plurality of scoring engines. Receive a scoring engine message, receive a decentralized analysis platform message from the decentralized analysis platform, and use the analysis workflow from the decentralized analysis platform, and the analysis workflow and event handling rules to score the engine message. And distributed analytics platform is configured to process messages and create threat information messages. In certain embodiments, the threat information message is the real-time analysis engine. And one or more when the model update message indicates that the processing by the real-time analysis engine improves at least one of the detection rate of abnormal activity and the reduction of false positive rate. Includes at least one of a model update message, wherein the real-time analysis engine is configured to transmit a model update message to update the analysis workflow of. In certain embodiments, each of the one or more logical segments is an analytical model, a set of analytical models, or an analytical workflow, and one or more sources of input for activity within the logical segment, and , Related to a set of actions that mitigate the impact of anomalous activity that occurs inside a logical segment.</p><p num="0007"> In certain embodiments, the plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, and the control plane engine are connected using an out-of-band network.</p><p num="0008"> In certain embodiments, the plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, and the control plane engine transmit relevant messages across the corporate system bus. Communicate by.</p><p num="0009"> In certain embodiments, the plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, and the control plane engine transmit relevant messages across the corporate system bus. Communicate by.</p><p num="0010"> In one embodiment In addition, it includes an ingestion actor module, The ingestion actor module Receive third-party application data from at least one of the third-party application and third-party device, Transmit third-party application data for further processing by at least one of the plurality of scoring engines, the distributed analysis platform, and the real-time analysis engine. It is configured as follows.</p><p num="0011"> In one embodiment The plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, the control plane engine, and the intake actor module are connected by using an out-of-band network.</p><p num="0012"> In one embodiment The plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, the control plane engine, and the intake actor module transmit relevant messages across the enterprise system bus. connect.</p><p num="0013"> In one embodiment The scoring engine further Receive model update message and Process update messages at the same time as processing events It is configured as follows.</p><p num="0014"> In one embodiment To create at least one of a broadcast message, a mitigation message, and a model update message, The real-time analysis engine further The first output is received at the first time from at least one of the plurality of scoring engines, the distributed analysis platform, and the plurality of sensors. Search for the first state information that corresponds to the first output, Update the first state information with the first output data, The analysis workflow associated with the real-time analysis engine processes the updated first state information to create the processed updated first state information. The processed and updated first state information is stored in the real-time analysis engine. A second output is received at a second time from at least one of the plurality of scoring engines, the distributed analysis platform, and the plurality of sensors. Search for the second state information that corresponds to the second output, Update the second state information with the second output data, The analysis workflow associated with the real-time analysis engine processes the updated second state information to create the processed updated second state information. Create at least one of a broadcast message, a mitigation message, and a model update message based on the processed updated second state information. And Store the processed and updated second state information in the real-time analysis engine. It is configured as follows.</p><p num="0015"> In one embodiment The real-time analysis engine further The intermediate output is received at a third time from at least one of the plurality of scoring engines, the distributed analysis platform, and the plurality of sensors, where the third time is the first time. After and before the second time, Search for the intermediate state information corresponding to the intermediate output, Update the intermediate state information with the intermediate output data, The analysis workflow associated with the real-time analysis engine processes the updated intermediate state information to create the processed updated intermediate state information. And Store the processed and updated intermediate state information in the real-time analysis engine. It is configured as follows.</p><p num="0016"> In one embodiment The analysis workflow includes model exchange format documents Model exchange format document Analysis model synthesis and Analysis model classification and An ensemble of analytical models and Synthesis of analytical models by rules and Synthesis of analytical models by pre- and post-processing stages, and With analysis workflow Support, Pre- and post-processing steps include data conversion and data aggregation. Each of the analytical workflows includes at least one of analytical models, rules, data transformations, data aggregation, and analytical models, rules, data transformations, data aggregation, partitioning and ensemble synthesis.</p><p num="0017"> In one embodiment The real-time analysis engine further When a change to one or more of the analysis workflows exceeds the threshold, the updated behavior model is transmitted to one or more of the plurality of scoring engines. It is configured as follows.</p><p num="0018"> In one embodiment The event is Data about network flows, data about packets, data about entities, data about users, data about workstations and servers, data about routers and switches, data about external network entities, and interacting with the network Includes at least one of data about internal and external devices.</p><p num="0019"> In one embodiment One or more of the plurality of sensors and the plurality of scoring engines are integrated within a single application.</p><p num="0020"> In one embodiment The real-time analysis engine integrates with one or more of the plurality of scoring engines.</p><p num="0021"> In one embodiment Mitigation action Closing at least one port, Modifying at least one packet data, Controlling the transmission of packets or flows, Blocking subnets, Blocking one or more Internet Protocols (IPs) or ranges of IP, and Blocking one or more internal or external IPs Includes at least one of.</p><p num="0022"> In one embodiment Mitigation action Take at least one of the servers and workstations offline, Forming at least one of a new visualization server and a new visualization workstation from the protected image, and Blocking actions associated with at least one of a server and workstation Includes at least one of.</p><p num="0023"> In one embodiment Abnormal activity is Includes at least one of reconnaissance, means of exploiting security weaknesses, intrusions, information leaks, insider threats, and attacks.</p><p num="0024"> In one embodiment Mitigation action Modifying at least one packet, Controlling the transmission of packets or flows, and Includes at least one of removing permissions and access to entities associated with anomalous activity. Removing permits and access rights Blocking network access, Blocking access to network devices, Blocking access to the server, Blocking access to workstations and Blocking access to other computer devices Of, at least one is included.</p><p num="0025"> In one embodiment Anomalous activity is associated with at least one of the bad actors inside and the bad actors outside.</p><p num="0026"> In one embodiment It also includes a visualization engine, which includes a monitor, The visualization engine Receives and receives statistics and graphic images associated with the processing of scoring engine messages by the real-time analysis engine. Display statistics and graphic images on the monitor It is configured as follows.</p><p num="0027"> In one embodiment Cybersecurity systems, including the plurality of cybersecurity systems described herein, have been disclosed. Each of the multiple cybersecurity systems is configured to exchange selected threat information messages with one or more of the other cybersecurity systems. The selected threat information message is encrypted to provide a confidential mechanism for transmitting information, The information in the selected threat information message does not expose sensitive inside information about the cyber security system it transmits.</p><p num="0028"> In one embodiment It is configured to exchange external threat information messages with compatible third-party systems. External threat information messages are encrypted to provide a sensitive mechanism for transmitting information, The information in the external threat information message does not expose sensitive inside information about the system transmitting the external threat information message, and External threat information messages are formatted in a common model exchange format.</p><p num="0029"> In one embodiment The distributed analysis platform further Receive scoring engine messages and Process scoring engine messages to create threat information messages It is configured as follows.</p><p num="0030"> In one embodiment Broadcast messages include at least one of informational messages, cyber event messages, and warning messages.</p><p num="0031"> In one embodiment Each of the plurality of logical segments Network splitting, traffic splitting on the network, user splitting on the network, device splitting on the network, splitting based on third-party data, and network, network traffic, network user, network split , And the third-party data is associated with at least one of the data associated with at least one of the plurality of divisions involved.</p><p num="0032"> In one embodiment At least the first partition overlaps with at least the second partition.</p><p num="0033"> In one embodiment The plurality of sensors, the plurality of scoring engines, the distributed analysis platform, the real-time analysis engine, the control plane engine, and the intake actor module transmit relevant messages across the enterprise system bus. connect.</p><p num="0034"> In certain embodiments, the disclosed gist of the invention includes a cybersecurity system that processes events to generate scores, warnings, and mitigation actions. In certain embodiments, the system comprises a plurality of sensors, each of which receives sensor data from a network, processes the sensor data to create an event, and transmits the event. It is configured as follows. In certain embodiments, the system includes a distributed analysis platform, which receives events from the plurality of sensors, processes the events, and creates an analysis workflow, wherein each of the analysis workflows. It is associated with one or more logical segments and is configured to carry analysis workflows and distributed analysis platform messages. In certain embodiments, the system includes a scoring engine, which receives an analysis workflow from a distributed analysis platform, receives events from at least one of the plurality of sensors, and uses the analysis workflow. It is configured to process events, generate scoring engine messages, and transmit scoring engine messages. In certain embodiments, the real-time analysis engine includes a real-time analysis engine that receives an analysis workflow from the distributed analysis platform, receives analysis workflows and event processing rules, receives a scoring engine message, and receives the distributed analysis platform. Receive distributed analysis platform messages from the analysis platform, and process scoring engine messages and distributed analysis platform messages using the analysis workflow from the distributed analysis platform, and the analysis workflow and event processing rules. It is configured to create threat information messages. In certain embodiments, the threat information message is a broadcast message and a mitigation message that are configured to be transmitted by the real-time analysis engine, the processing by the real-time analysis engine, and the mitigation action impacting the anomalous activity. When indicating to limit, the real-time analysis engine controls the mitigation message to take mitigation actions associated with the first logical segment of the one or more logical segments. A mitigation message and a model update message that are configured to be transmitted to the engine, and the processing by the real-time analysis engine causes the model update message to reduce the detection rate of abnormal activity and the reduction of false positive rate. Of the model update messages, wherein the real-time analysis engine is configured to transmit a model update message to update one or more analysis workflows, indicating that at least one is to be improved. Includes at least one of. In certain embodiments, each of the one or more logical segments is an analytical model, a set of analytical models, or an analytical workflow, and one or more sources of input for activity within the logical segment, and , Related to a set of actions that mitigate the impact of anomalous activity that occurs inside a logical segment.</p><p num="0035"> These and other functions, which are the gist of the invention of the present disclosure, will be better understood after reviewing the following drawings, detailed description, and claims. As a matter of course, the expressions and terms used herein are for descriptive purposes and should not be considered limiting.</p>
Considered in connection with the following drawings, the various objectives, properties, and advantages of the disclosed gist of the invention may be better understood with reference to the following detailed description of the disclosed gist of the invention. The same reference number identifies the same element in the drawing.<figref num="1">FIG. 1 is a system diagram showing a cyber security framework according to an embodiment of the present disclosure.</figref><figref num="2">FIG. 2 is a system diagram showing a cyber security framework implemented over three networks according to an embodiment of the present disclosure.</figref><figref num="3">FIG. 3 is a system diagram showing network taps inserted in different parts of the corporate network according to an embodiment of the present disclosure.</figref><figref num="4">FIG. 4 is a block diagram showing a scoring engine according to an embodiment of the present disclosure.</figref><figref num="5">FIG. 5 is a flowchart showing a method of processing and transmitting a message by a real-time analysis engine according to an embodiment of the present disclosure.</figref><figref num="6A">FIG. 6A is a flowchart directly showing the processing of an input or event according to an embodiment of the present disclosure.</figref><figref num="6B">FIG. 6B is a flow chart showing the association of one or more persistence states with individual events according to an embodiment of the present disclosure.</figref><figref num="6C">FIG. 6C is a flowchart showing pre-processing and post-processing of the analysis model according to an embodiment of the present disclosure.</figref><figref num="7">FIG. 7 is a flowchart showing the processing of network traffic for generating an analytical model according to an embodiment of the present disclosure, the network traffic being imported into a scoring engine.</figref><figref num="8A">FIG. 8A is a system diagram showing an ensemble of models according to an embodiment of the present disclosure.</figref><figref num="8B">FIG. 8B is a system diagram showing the synthesis or chaining of models according to an embodiment of the present disclosure.</figref><figref num="8C">FIG. 8C is a system diagram showing a segmented model according to an embodiment of the present disclosure.</figref><figref num="9">FIG. 9 is a flowchart illustrating the flow of data between components within a cybersecurity framework according to an embodiment of the present disclosure.</figref><figref num="10">FIG. 10 is a system diagram showing the response of the cyber security framework to an external threat according to an embodiment of the present disclosure.</figref><figref num="11">FIG. 11 is a system diagram showing the response of the cyber security framework to an internal threat according to an embodiment of the present disclosure.</figref>
In the following description, in order to provide a full understanding of the disclosed gist of the present invention, there are many matters relating to the disclosed systems and methods of the gist of the present invention and the environment in which those systems and methods can operate. A specific explanation is provided. However, as a matter of course to those skilled in the art, the gist of the present invention disclosed can be carried out without such a specific explanation, and the well-known characteristics of the present invention are disclosed. It is not described in detail to avoid unnecessary complexity of the gist. Furthermore, as a matter of course, the embodiments shown below are examples, and it is considered that there are other systems and methods within the scope of the disclosed gist of the present invention.
One embodiment of the present disclosure relates to creating a cybersecurity framework. The cybersecurity framework implements near real-time detection and mitigation actions in decentralized enterprises, simplifying monitoring, analysis, and deployment.
The processes described herein in certain embodiments use out-of-band ESBs and out-of-band networks, thereby providing distributed analysis platforms; near real-time scoring; threat information messages (TIMs), mitigation events, and , Approximately real-time processing of model updates by various components of the system; as well as analysis visualization, monitoring, and updates to dashboards; large amounts of network flow data, packet (PCAP) data files, system log data , External threat data, and other interest data can be processed.
Typical actions in a cyber environment are analyzing cyber analysis data, building behavioral models, scoring behavioral models, updating behavioral models, sending alerts, evaluating alerts, sending commands. Includes things, control and mitigation actions, real-time visualization, and manipulating the emphasis framework.
System architecture FIG. 1 is a system diagram showing a cyber security framework according to an embodiment of the present disclosure. Figure 1 shows the sensor 102 (also referred to here as the cyber sensor), the ingestor actor 104, the distributed analytics platform 106, the scoring engine 108, the real-time analytics engine (RTAE) 110, the visualization engine 112, the control plane engine 114, and , Decentralized Enterprise Service Bus (ESB) 116. In certain embodiments of the present disclosure, the sensor 102 and the scoring engine 108 are combined into a single integrated application. Figure 1 shows endpoints 120, data planes 122, servers and workstations 126, cyber operations (ops) staff and cyber analysts 128, third-party applications, third-party applications, sources and devices 130, and firewalls, switches. And additional system components, including router 132, are also shown.
Each of the elements of FIG. 1 will be described in more detail below. In short, sensor 102 captures and processes data from the enterprise data plane 122 and passes the data to ESB116, where the data is routed for further processing. The data plane 122 is from various devices on the enterprise network, including from endpoints 120, servers and workstations 126, and firewalls, switches and routers 132, and to various devices on the enterprise network. Send data. The control plane engine 114 receives the processed data from the ESB 116 and configures the network device including the switch, router and fire wall 132, and the reconfiguring scoring engine 108 receives the data from the ESB 116 and is in the stream. For each individual event, process using one or more analytical models and include scores, outputGenerates information, warnings and messages, as well as relevant information. The ingestor actor 104 captures and processes data from third-party applications, sources and devices and sends the data to the ESB, where the data is routed for further processing. The distributed analysis platform 106 (also referred to as the analysis cloud) is a distributed computer platform that can be used to analyze large amounts of data and generate various analysis results. The decentralized analysis platform 106 receives and sends data from the ESB116, the ingestion actor 104, the RTAE110, and the visualization engine 112. The RTAE110 receives data from ESB116 and the distributed analysis platform 106, performs near real-time calculations using distributed memory and dedicated processors such as GPUs, creates near real-time visualizations, and multiple scores. Create near real-time decisions about mitigation actions by processing data from attachment engine 108 and other sources. The visualization engine, dashboard and monitor 112 receive data from ESB116, RTAE110 and analysis engine 106 and send data to them, giving cyber ops and analysts 128 a visible representation of the other elements shown in Figure 1. I will provide a. The visualization engine, dashboard and monitor 112 provide a user-configurable dashboard, provide real-time information, support real-time queries from RTAE110, and provide analysis results using the distributed analysis platform 106. It can provide visualization as well as the ability to interact with entities, warnings, events, PCAP data, flow data, and graphs to query.
As shown in FIG. 2, in certain embodiments of the present disclosure, the cybersecurity framework can be implemented across three networks. FIG. 2 shows the enterprise data plane 122, the enterprise control plane 204, and the out-of-band system network 206. In certain embodiments of the present disclosure, the enterprise service bus 116 is deployed over an out-of-band system network. Out-of-band system network 206 connects cybersensor 102, distributed analytics platform 106, RTAE110, scoring engine 108, control plane engine 114, and mitigation agent 210. In one embodiment, two or more of the following components communicate with other components of the out-of-band network via ESB116. Cybersensor 102, Distributed Analysis Platform 106, RTAE110, Scoring Engine 108, Control Plane Engine 114, and Mitigation Agent 210.
In certain embodiments, the control plane engine 114 may send a mitigation message to the mitigation agent 210 via the enterprise control plane 204. The mitigation agent 210 can be embedded within the control plane engine 114, or can be embedded or integrated in other components of the system or in other devices or components of the enterprise. For example, the mitigation agent 210 can be integrated with the control plane engine 114 to send a message to the enterprise control plane to close the port or block IP. The mitigation agent 210 sends a mitigation action to the control plane, which then takes action, such as modifying a table in the router or switch. Mitigation actions include resulting modifications such as closing ports, separating end devices, servers or network services, and separating subnets. Another example is that the mitigation agent 210 may send a mitigation action that modifies a packet or modifies the transmission of a packet or flow to a network device on the enterprise data plane.
In one embodiment, the sensor 102 (also referred to herein as a cyber sensor) is located on the enterprise data plane 122. As described in more detail below, the sensor 102 collects and processes data on the enterprise data plane 122 and transmits the processed data to the out-of-band system network 206. In certain embodiments, the cyber sensor 102 may be directly connected to the scoring engine 108 (eg, rather than connected via the ESB116) or may be integrated with the scoring engine 108.
As shown in FIG. 2, the enterprise network functions as a data plane 122 and carries most of the data that passes across the enterprise network. In addition, some enterprises may use the control plane 204 to communicate control information to switches, routers, firewalls 132, and other network devices. The control plane 204 and the data plane 122 are logically independent and may or may not share the same physical network. In certain embodiments of the present disclosure, there is also an out-of-band system network 206 that system components use for communication. In this disclosure, out-of-band refers to a physical network that is independent of the enterprise data plane 122 and control plane 204.
In certain embodiments of the present disclosure, the out-of-band system network 206 has a higher capacity than the enterprise data plane 122. For example, if the enterprise data plane is a 10G network, the out-of-band system network may be a 40G network. If the enterprise data plane is a 40G network, then the out-of-band system network is a 100G network.
In one embodiment, the components shown at the top of FIG. 1 are located within the same network. For example, in one embodiment, the enterprise plane 122 and control plane 204 are in the same network as the distributed analytics platform 106, scoring engine 108, real-time analytics engine (RTAE) 110, visualization engine 112, and control plane engine 114. It is in.
In certain embodiments of the present disclosure, the cybersecurity systems described herein, eg, FIG. 1, may be deployed in multiple physical or logical arrangements. Each deployed cybersecurity system may be configured to exchange selected threat information messages with one or more of the cybersecurity systems. In certain embodiments, the selected threat information message is encrypted to provide a confidential mechanism for transmitting the information. In certain embodiments, the transmitted information in the selected threat information message exposes sensitive internal information about the cyber security system being transmitted, such as specific internal devices at risk or specific internal IPs under attack. It does not, but instead includes information about the type of attack, external IP, etc.
In certain embodiments of the present disclosure, the cybersecurity systems described herein may be configured to exchange external threat information messages with compatible third party systems. External threat information messages can be encrypted to provide a sensitive mechanism for transmitting information. In certain embodiments, the information in the external threat information message does not expose sensitive inside information about a third party, such as a particular internal device at risk or a particular internal IP to be attacked, but of the attack. Includes information about types, external IPs, etc. instead. External threat information messages can be formatted by a common model information format for behavioral models understood by scoring engines, distributed analysis platforms, and real-time analysis engines.
Both FIGS. 1 and 2 will be taken up and described in more detail below.
Enterprise Service Bus 116, Messages and Topics In some embodiments of the present disclosure, the out-of-band system network uses a distributed enterprise service bus (ESB) 116 for communication. Decentralized ESB116 is language and platform independent, AMQP, NSQ, ZeroMQ, RabbitMQ, adeptia ESB Suite, IBM WebSphere ESB, Microsoft BizTalk Server, and Oracle Enterprise Service. It may include any enterprise service bus, including but not limited to Bus. The ESB116 delivers messages reliably and, in most embodiments, has very high throughput. In general, enterprise service buses monitor, route, and further disassemble communications from various devices. The device may include endpoint 120 and data plane 122. Endpoints include workstation servers, personal computers, and end-user devices 120, such as mobile devices such as mobile phones and tablets. The data plane 122 includes devices that carry network traffic, such as firewalls, switches and routers 132. In addition, control plane traffic to firewalls, switches, routers 132, and other devices that are part of the control plane is also passed to the out-of-band system network.
In one embodiment, the messages on the ESB116 are often referred to as topics, each divided into independent streams, each with its own queue, so messages related to one topic are related to another topic. Does not interfere with messages related to. This disclosure of the exemplary implementation uses topics to form independent queues within the ESB116, which allows different types of events to be processed by the scoring engine, messages passed to different system components, and different types of. TIM and the like all have different queues.
Data is passed to the out-of-band system network via two main methods for processing, analysis and visualization: the sensor 102 and the ingestor actor 104. The sensor 102 and the ingestion actor 104 will be described in more detail below. Data processing and analysis results in additional records and (threat information messages) TIMs, which are passed to the out-of-band ESB, and data processing and analysis results in real-time visualization and various reports. To form. All of them will be described in more detail below.
Sensor 102 One way data enters the system is through sensors. The sensor 102 captures and processes data from the enterprise data plane 122 and the enterprise control plane 204 and passes the data to the out-of-band system network for further processing. The network tap, which is part of sensor 102, is inserted at key points for network visibility and network traffic mirroring to support real-time processing. The sensor 102 will be described in more detail below in the description accompanying FIGS. 7 and 9. In short, sensor 102 processes the packet and builds records and flows associated with the processed packet.
In some embodiments, there are at least three ports. Received data port, outgoing data port, and monitor port. All or any of the selected data determined by the sensor is mirrored on the monitor port. The data on the monitor port is processed to produce a record that is passed to the out-of-band ESB116 described below. In some embodiments of the system, there is also a fourth port that provides command and control information to the sensors and taps. The fourth port can be used to change what data is being collected and processed, and to take some mitigation actions, such as not passing a packet to the outgoing port. For example, packets associated with a particular IP, port, extracted data, or computational characteristics can be blocked.
FIG. 3 is a system diagram showing network taps inserted in various parts of a corporate network according to an embodiment of the present disclosure. I<sub>0</sub>302 is a network tap 314 on the corporate gateway between the corporate network and the external internet 320. I<sub>0</sub>302 is a visibility point on network tap 314, in front of firewall 312, which can be located on external switch 310. I<sub>0</sub>302 is the external facing interface of the customer infrastructure, the first opportunity to use statistical and analytical models, as well as probing, intrusion, network reconnaissance, attacks on enterprises, and other behaviors due to harmful factors. Represents other techniques for detecting, initiating the processing of an attribute (eg, identifying the subject behind a threatening behavior), and deploying an appropriate response to stop or constrain the impact of the behavior. Conventionally, I<sub>0</sub>The 302 interface is the boundary between the outside and the inside of the information infrastructure. Usually this is the external facing interface of the entire enterprise, but for these purposes I<sub>0</sub>302 can be any information infrastructure, namely the outer boundary interface of an entity, container, cloud or workgroup, or the outer facing interface. I<sub>0</sub>302 is the point at which customers outline and implement first-stage protection, typically using router access control lists (ACLs) or commercial firewall solutions. These devices typically implement conservative (usually constrained) access control policies and represent key protection points for the infrastructure. For many sites, I<sub>0</sub>The 302 interface is also Network Address Translation (NAT), which modifies the packet address to minimize the exposure of the infrastructure identifier to external entities. I<sub>0</sub>The types of bad actors found in include: 1) Remote attempt to discover and penetrate external defenses; 2) External but local strategies that penetrate the outer infrastructure; 3) Insider-mediated external access changes; 4) Internally promoted external access; 5) Traditional cyber development; and 6) Infrastructure rootkit-based development.
I<sub>1</sub>304 and I<sub>2</sub>Reference numeral 306 is an internal face-to-face interface inside the enterprise, and anomalous cyber activity inside the enterprise is referred to herein as an internal attack. I<sub>1</sub>304 is located between the Enterprise Firewall 312 and the rest of the Internal Enterprise Network. Sensor application I<sub>2</sub>The 306 allows visibility into lateral network traffic within the enterprise. I<sub>2</sub>Network tap 306 is located on internal switch 316 and can see traffic to devices such as web servers, enterprise servers, workstations, desktops, and other such devices. I<sub>3</sub>The 308 is a network device that can process data on the enterprise control plane. In general, in many deployments of the system, except for the simplest networks, type I<sub>2</sub>306 and I<sub>3</sub>There are 308 multiplex sensors. Type I for some complex networks<sub>0</sub>302 and I<sub>1</sub>There can be 304 multiplex sensors.
In one embodiment, I<sub>0</sub>302, I<sub>1</sub>304, I<sub>2</sub>306 and I<sub>3</sub>Data and activity from 308 are continuously correlated and stored, commanding and controlling all enterprise networks and components via the control plane interface. The scoring engine 108 and the sensors 102 and RTAE110 that work with the behavior model generate a TIM, which is passed along the ESB116 and consumed by the enterprise and network components to support real-time commands and control actions. Includes mitigation and TIM model update messages. Examples of mitigation TIMs and model update TIMs used in certain embodiments of the present disclosure will be described below. In short, an example of a mitigation TIM of an embodiment of the present disclosure is a message that closes a particular port or isolates a particular device. An example of a model update TIM of an embodiment of the present disclosure is to lower the warning threshold in a post-processing element of a behavior model workflow based on behavior within a corporate network. More specifically, the scoring engine 108 analyzes the model update TIM to identify the appropriate components of the PFA document to be updated, such as the thresholds within the appropriate PFA elements in this example, and further determines the current value of the threshold. , Replace with the new threshold provided in the model update TIM. Another example of the model update TIM of one embodiment of the present disclosure is to modify the coefficients of the analytical model, i.e. the coefficients of the pre- or post-processed PFA components of the analytical model.
Ingestion Actor 104 The second way data enters the system is via the ingestion actor 104. Ingestion actor 104 may be designed to process data from third party applications (apps), sources and devices 130. Third-party applications (apps), sources and devices 130 are generated by other system components, other computer devices on workstations, servers, and corporate networks, and other security applications, including host-based security systems. Information streams and sources of external third-party data, including information about threats, IP reputation, response policy zone (RPZ) information and related information, and in other geographically dispersed locations of the same entity. Other systems with the same architecture, either associated with or associated with other entities, as well as others with different architectures that follow an agreed format for exchanging information. The system and can be included.
The ingestion actor 104 receives input data to be processed from one of the aforementioned sources or directly from the ESB. After processing, the ingestor actor 104 delivers the processed event back to ESB116 for further processing by other system components. Ingestion Actor 104 receives data to be processed from third party applications (apps), sources and devices 130 so that input data can be transmitted to ESB116, RTAE110, or distributed analysis platform 106 for further processing. Perform the data processing and conversion required by. In certain embodiments, processing in the ingestion actor 104 comprises retrieving the input data and converting the input data into a format suitable for ESB116, RTAE110, or distributed analysis platform 106.
Scoring engine 108 The scoring engine 108 is a module that can import analytical models (or analytical workflows) and retrieve data from networks and from other system modules. Once the analytic model is imported, the scoring engine can read the stream of data, process the events with one or more analytic models for each event in the stream, and score, Produce output, including warnings and messages, as well as relevant information. The scoring engine 108 and the data flow associated with the scoring engine 108 will be described in more detail below with reference to FIGS. 7, 9 and 4.
As mentioned above, the scoring engine 108 is a module that can score data at network speed with a model of statistics and behavior. Models can be built offline from historical data or streaming data. In certain embodiments, the scoring engine 108 may issue a scoring engine message, including metadata data and a score, such as a warning. In one embodiment, the scoring engine is PFA compliant, as described in detail below. The scoring engine 108 may score data using statistical, predictive, and data mining models such as cluster models, baseline models, Bayesian networks, or regression and classification trees. The model can be built offline based on historical data. The model may be a streaming analysis model, as described in detail below.
FIG. 4 is a block diagram showing a scoring engine according to an embodiment of the present disclosure. FIG. 4 shows inputs 402 to the scoring engine, PFA document 404, PFA execution engine 406, stored state information 408 for analytical models, model update TIM410, and output 412. The input 402 to the scoring engine may be a stream of events and, more generally, a data record. The scoring engine 108 processes the input 402 with the PFA execution engine 406. PFA is a language that describes how inputs for analysis are transformed and integrated to produce analytical outputs. The PFA execution engine takes the input into the scoring engine and produces an output within the PFA document 404 that follows the process and procedure (referred to herein as the analysis workflow). For example, PFA document 404 may describe a classification and regression tree. The PFA execution engine 406 takes inputs into the classification and regression tree and produces the output of the classification and regression tree. The scoring engine 108 includes the stored state information and updates this state information as specified in the PFA document 404. In one embodiment, the scoring engine 108 imports a new PFA document 404 to update the analysis process.
In certain embodiments of the present disclosure, the analysis process within the scoring engine 108 may also be updated by sending one or more model update TIMs to the scoring engine 108, the model update TIM being a model update. Update the appropriate components of the PFA document as identified by TIM. As mentioned above, the update may include changes to the thresholds or to the coefficients of the algorithm that are part of the analytical model. This type of update, referred to herein as a minor update, can be applied by the scoring engine to a stream of data midstreams without stopping the processing of the data by the scoring engine. Larger updates are possible, such as switching out the entire PFA document 404.
More generally, the scoring engine 108 of certain embodiments of the present disclosure can be based on a model interchange format. The illustrated model interchange format is a specification that allows the model to update data records at the same time as scoring data records, as provided by the read-copy update policy supported by cells and pools in the PFA specification. based on. The read-copy update policy allows the PFA document 404 to be read by the scoring engine at the same time as the component with the document is updated. As described in certain embodiments herein, near real-time scoring relates to supporting simultaneous scoring of data using models with simultaneous model updates. More generally, the exemplary model interchange format for the present disclosure is by transforming and integrating, transforming and integrating, transforming and integrating other analytical models into inputs that support passing the output of the analytical model. Based on the analytical model and specifications that describe the analytical processing of the data.
Decentralized analytics platform 106 The distributed analysis platform 106 or analysis cloud is a distributed computer platform that can be used to analyze large amounts of data and generate various analysis results. The distributed analysis platform 106 uses both distributed file systems such as Hadoop and MapR, and non-relational (eg NoSQL) databases such as HBase, Accumulo, and MapR-DB for large quantities for analysis. Data can be retained. In certain embodiments of the present disclosure, the distributed analysis platform 106 is a distributed computer platform that includes support for MapReduce and iterative MapReduce calculations, such as those supported by Spark. The distributed analysis platform 106 of an embodiment of the present disclosure further adds support for performing iterative calculations with data, either on-disk, in-memory, or both on-disk and in-memory. It also includes support for NoSQL databases and for other specialized applications and tools that work with distributed data in the system, such as Hadoop, MapR, Spark, or other distributed computer platforms. Decentralized analytics platform 106 also includes REST-based APIs This allows the various system components to uniformly and uniformly in the distributed analysis platform 106, independent of the particular analysis, processing or component within the distributed analysis platform that generated the data or information. You can access the information.
The distributed analysis platform 106 receives data from the sensor 102 and the ingestion actor 104 via the distributed ESB 116. In certain embodiments of the present disclosure, the distributed analysis platform 106 also receives data directly from the ingestion actor 104.
There are multiple types of output from the distributed analysis platform 106. Includes: Threat information message (TIM) sent to ESB116 and sent from ESB116 to control plane engine 114; sent to RTAE110 (as described in more detail below) and sent from RTAE110 to visualization engine, dashboard and monitor 112. Data and data structures that describe the visualization of the data that is made; in addition to other languages that can be used to describe the analytical model for the scoring engine 108, for analysis (as described in detail below). An analysis workflow, including an analysis model, described in Portable Format (PFA).
The distributed analysis platform 106 is from a large collection of flow data (eg, network flow streams and data files), packet data (eg, PCAP files), and log files from network devices, servers, and other devices. Collect, clean, integrate, and build behavioral models. The environment is designed for machine-based learning algorithms that can take minutes to hours or longer to run. The output is an analytical workflow, which may include a behavioral model, and a decentralized analytical platform TIM (also referred to herein as an analytical platform message). In one embodiment, the analysis workflow comprises a number of segmented models, each of which is associated with a logical segment. In certain embodiments, the analytical workflow comprises a number of segmented workflows, each of which is associated with a logical segment. In one embodiment, this environment is designed for data scientists and support discovery of new threats, as well as for the generation of analytical models for other environments.
The distributed analytics platform 106 may also include a virtual machine infrastructure, which may include virtual machines for containment of potential malware. Malware can be run on a virtual machine, which is separated from the cybersecurity framework. In certain embodiments, the virtual machine comprises a Linax® container.
Real-time analysis engine 110 The RTAE110 receives data from the ESB116 and the distributed analysis platform 106 and performs multiple functions. These features use distributed memory and dedicated processors such as GPUs to perform near real-time calculations of derived, aggregated, and transformed data, network activity, enterprise entities and users. To form near real-time visualizations of and flow behavior, potential threats, correlated behavior, etc., and to process data from multiple scoring engines and other sources to make near real-time decisions about mitigation. Including forming. Forming near real-time decisions about mitigation actions is discussed in the description accompanying Figures 10 and 11. In certain embodiments, the data received from the distributed analysis platform 106 includes an analysis workflow and a distributed analysis message. In certain embodiments, the RTAE110 is an analysis workflow and event from at least one of the scoring engine messages from the scoring engine, the distributed analysis platform, the user-configured settings, and the results of a third-party analysis system. The processing rule is also received. The near real-time visualization is passed to the visualization engine, dashboard, and monitor 112 for display. In one embodiment, near real-time decisions about mitigation events are constructed in command and control (C2) messages (eg, mitigation TIM) and passed to ESB116, which are processed by control plane engine 114, followed by: Take various mitigation events or actions such as. Closing ports, modifying packets, blocking subnets, blocking one or more Internet Protocol (IP) or IP ranges, one or more internal or external IPs. Blocking, controlling the transmission of packets or flows, of servers and workstations Take at least one offline, form at least one of the new visualization server and new visualization workstation from the protected image, block actions associated with at least one of the server and workstation , And so on. In certain embodiments, the mitigation action may also include removing permissions and access to the entity associated with the anomalous activity. Removing permissions and access means blocking network access, blocking access to network devices, blocking access to servers, blocking access to workstations, and others. It may include at least one of blocking access to a computer device. In certain embodiments, the RTAE110 is integrated into a single application with one or more scoring engines.
In one embodiment, the RTAE110 provides a GPU-based environment that manages a large number of parallel computer threads for real-time analysis. The RTAE database can also be used by all computer actors running large-scale data processing tasks in near real time for sophisticated analysis. The RTAE110 processes a visualization engine, a real-time statistical engine that summarizes the status of the enterprise on the dashboard and monitor 112, and TIMs from multiple sensors 102, calculates appropriate mitigation actions, if any, and (scores). Includes a real-time engine, which sends appropriate TIMs (including warnings, updates, mitigation actions, etc.). The RTAE110 also includes a REST-based API that allows various system components to uniformly transform the data or information into the RTAE110's data and information, regardless of the particular analysis, processing or component within the RTAE110 that generated the data or information. Can be accessed. Depending on the amount of data and the required substantially real-time calculations, a dedicated processor capable of processing large amounts of data in parallel, such as the GPU used in certain embodiments of the present disclosure, will be used in the RTAE110.
The RTAE110 may also send commands and control (C2) messages, called threat information messages (TIMs), to other components of the cybersecurity framework. For example, the RTAE110 performs a wide range of event-based actions such as updating analysis, visualizations and alerts, mitigation actions for control plane and distributed sensor updates. Flow agents managed by RTAE110 also provide publication and subscription requests, as well as information for a wide variety of agents that enable which metachannels are associated with a particular topic, type, and concept. To do.
In certain embodiments of the present disclosure, the RTAE110 produces a mitigation TIM transmitted from one or more behavioral models. In one embodiment, the TIM is sent by the scoring engine 108 to the ESB116. Various TIMs are collected, processed, integrated, and input to another model by RTAE110, which can result in mitigation depending on the results from the new model. In certain embodiments, the RTAE110 communicates the mitigation TIM to one or more mitigation agents 210 over the ESB116, which comprises an instruction to take a specific mitigation action, such as closing a port.
FIG. 5 is a flowchart showing a method of processing and transmitting a message by a real-time analysis engine according to an embodiment of the present disclosure.
With reference to step 502, the first one or more messages, such as TIM, are received by the RTAE110 from one or more scoring engines, distributed analysis platforms or other system components. As described in more detail herein, the first message may include a TIM generated by a scoring engine or distributed analysis platform. The TIM may contain warnings or making minor modifications to the PFA document and related data. The RTAE110 may also receive analysis workflows from distributed analysis engines and analysis workflows, as well as event handling rules. In certain embodiments, the analytical workflow and event handling rules may identify thresholds associated with the analytical model or analytical workflow. For example, analytical workflows and event handling rules may identify that all activities associated with an analytical workflow whose score exceeds a certain threshold are classified as anomalous activities. As described herein, anomalous activity can include reconnaissance, means of exploiting security weaknesses, intrusions, information leaks, insider threats, and attacks.
With reference to step 504, the RTAE110 processes the received TIM using the analysis workflow as well as the analysis workflow and event handling rules. In one embodiment, entity information is retrieved from the TIM, related status information is retrieved from the RTAE110, and status information is updated with information extracted from the received TIM. In certain embodiments, the stored state information is associated with a message previously received from at least one of a sensor, a scoring engine, and a distributed analysis platform.
With reference to step 506, the RTAE110 may take the following actions based on the process: i) To carry a broadcast message. ii) If the RTAE110 determines that the updated model can improve the detection rate or reduce the false positive rate of the current model, transmit the model update to the scoring engine. iii) If the RTAE110 determines that the received TIM indicates intrusion or presumed intrusion, or other anomalous activity, transmit the mitigation action using the control plane engine and mitigation agent. iv) Transmit the analytical model when the analytical workflow changes exceed the threshold. v) Wait to receive more TIMs. In certain embodiments, the processing of RTAE110 may also include analyzing updated state information to determine if any action should be taken. In one embodiment, the RTAE110 is one of a broadcast message, a mitigation message, and a model update message after first receiving a first output from a scoring engine, a distributed analysis platform, and multiple sensors. Can be sent. In certain embodiments, the RTAE110 receives multiple outputs from a scoring engine, a distributed analysis platform, and multiple sensors prior to sending one of the mitigation messages and model update messages. stand by.
As mentioned above, the RTAE110 may transmit one of the relaxation TIMs, model update TIMs, and analytical models based on the process. For example, a TIM received by an RTAE110 that indicates an estimated intrusion at a port, detected by a sensor and scoring engine associated with the port, can result in a TIM being transmitted, which closes the port. At the same time, the RTAE110 may send to all scoring engines a model update that modifies the parameters in the scoring engine, based on the same received TIM, which better describes the intrusion or the effect on the intrusion. If the RTAE110 determines that the scoring engine or other system component requires a change that is more important than the threshold amount of change, the RTAE110 may send the updated behavior model instead of the model update. In certain embodiments, the RTAE110 may also transmit a broadcast message, which broadcast message may include at least one of a cyber vent message and a warning message.
Control plane engine 114 The control plane engine 114 relates to monitoring, configuring, and reconfiguring network devices, including switches, routers, and firewalls. The control plane engine 114 can take mitigation actions, communicate with mitigation agents, send alerts about the control plane, and the visualization engine, dashboard, and monitor 112 can provide status awareness of the control plane infrastructure. Responsible for supplying the data. Situational awareness in this context includes a summary of entities in the control plane, current traffic on the control plane, normal traffic on the control plane, deviations between current traffic and normal traffic, if any, and Information that provides other information about normal activity, potentially bad actor activity, or related behavior. In one embodiment, the control plane engine 114 obtains a mitigation TIM from the RTAE110, the scoring engine 108, and the distributed analysis platform 106.
The control plane engine 114 includes C2 compute actors that generate real-time commands and control messages. Pre-planned actions are managed across the control and data planes, such as blocking specific IPs, isolating suspicious workstations, or redirecting packet flows.
Control plane engine 114 includes DNS, DHCP, and IP Address Management (DDI) 140. The DDI module 140 includes a global device graph, a trust protocol ID inside the control flow, and a device and flow finger print. The global device graph includes a visual display of all network devices and activities. The trust protocol ID inside the control flow contains the encrypted string inside the packet. Devices and flow finger prints are managed by the control plane and utilize Dynamic Host Configuration Protocol (DHCP) to uniquely finger print all devices on the network.
Other system components Other system components include a registry (not shown) that is accessible to all components. In certain embodiments, the registry contains highly available data, data structures, message formats, and other information that simplifies the development and operation of the system for commonly used services.
Behavior modeling and real-time scoring In certain embodiments of the disclosure, the behavioral model is the potential for cyber intrusion, the presence of bad actors (either external actors or "insiders"), and whether by cyber analysts manual testing or automated action of mitigation devices. It is used to quantify other behaviors that guarantee action.
In the present disclosure, a behavioral model is a statistic, data mining, or other type of algorithm that takes an input (or "event") and processes the input to calculate its characteristics. Then process the characteristics to calculate the output (score). The events described herein are typically streams of temporarily ordered inputs that are processed one at a time.
6A-6C, 7 and 8A-8C are system diagrams showing various ways in which an event can be represented by a behavioral model, according to an embodiment of the present disclosure.
For real-time analysis or near real-time analysis, events are represented on an event-by-event basis and scored on an event-by-event basis to produce output in various ways. FIG. 6A is a flowchart directly showing the processing of an input or event according to an embodiment of the present invention. Data attribute 602 is used to generate characteristic 604. In some embodiments, property 604 is formed by transforming or integrating data attributes. For example, if the data attribute corresponds to a flow record, then if the flow is a short-term flow, the example property may contain a binary variable equal to 1, otherwise the example property may contain a binary property equal to 0. obtain. Property 604 is then processed by model 606 to produce model output 608. FIG. 6B is a flow chart showing the association of one or more characteristic vectors (also referred to herein as state vectors) with an individual event according to an embodiment of the present disclosure. The event is received (610) and the data attributes are determined for the event (612). Data attributes are used to generate characteristics for an event (614). When a new event is processed, the associated stored characteristic vector or characteristic vector is persistent from event to event, retrieved and updated with data from the new event (616). After the characteristic vector has been updated (618), it is used as an input to the behavior model (620) to produce an output (622). An example of a characteristic vector that is updated with an individual event is the flow of normalized numbers in a window at a particular time (eg, within a 10 second travel time window). FIG. 6C is a flowchart showing pre-processing 638 and post-processing 640 of the analytical model according to an embodiment of the present disclosure. The data preprocessing 638 transforms or integrates the data, creates a characteristic vector, and performs other processing as desired before passing the data to the analytical model 630. Post-processing 640 is converted and integrated to further out It calculates the output and then performs other processing as desired. As an example of post-processing, the post-processing module collects and evaluates various statistics to determine if the model has seen enough events that are considered statistically valid. If statistically valid, the score will be sent. Otherwise, the score will be suppressed. A number of models are available for the methods shown in FIGS. 6A, 6B and 6C, one or more, as described in more detail below in the description accompanying FIGS. 8A, 8B and 8C. The output of the above model is used as the input of one or more other models.
For batch processing of data in an analysis, the inputs are aggregated into a file or into a number of files, which are processed to produce the output associated with the analytical model. As mentioned above, for the size of data typical of cyber applications, distributed analytics platforms are used for analytical processing.
The model itself used to process events and produce output can also be generated in a variety of ways. In FIGS. 7 and 9, as shown below, the distributed analysis platform 106 can be used to process the inputs to the model to generate an analytical model. In certain embodiments of the present disclosure, the model is represented in a model exchange format, such as PFA, and the model in the model exchange format is batched using a distributed analysis platform or streamed using a scoring engine. In a way, it can be used for scoring events. In one of the embodiments of the present disclosure, the PFA model can also be generated by two other system components, namely the RTAE and the scoring engine itself.
FIG. 7 is a system diagram showing the processing of network traffic for generating an analytical model according to an embodiment of the present disclosure. Figure 7 shows network traffic 702, event record and file builder 704, PFA model repository 706, packet processor 708, score 710, insights 712 from batch analysis of event data, event 720, imported PFA model 722, enhanced network. The flow and PCAP file 724, the exported PFA model 726, the sensor 102, the distributed analysis platform 106, and the scoring engine 108 are shown.
Network traffic 702 is collected by sensor 102. The sensor 102 includes a packet processor 708, which is designed to process packet data at line speed (ie, the speed at which data is moving over the network). The packet processor 708 can process packet data at line speeds using a highly optimized software stack and, in certain embodiments of the present disclosure, dedicated hardware. In certain embodiments, zero-copy technology is used to improve packet processing execution. Packet processing is the extraction of packet attributes, such as destination and source port and IP, protocol flags, and other attributes such as TCP packets, UDP packets, etc., and the attributes extracted to identify a specific protocol. Includes examining combinations of, as well as enhancing the information with other data, such as Dynamic Host Configuration Protocol (DHCP) data, geolocation data, and so on. Information from multiple packets corresponding to the same source and destination IP and port is processed by the event record and file builder 704 to generate a flow record that is passed to the scoring engine 108 via ESB116. In certain embodiments of the present disclosure, information from a single packet or multiple packets is processed to generate other types of events that are passed to the scoring engine 108 via ESB116. For example, in certain embodiments of the present disclosure, individual packets may be individually scored by the scoring engine 108. Selected packets, or other attributes or characteristics, such as those corresponding to one or more protocol types, may be scored. Alternatively, the packet combination may be processed by the scoring engine 108. The large number of packets is also processed by the event record and file builder 704 and is passed to the distributed analysis platform 106 as a file of packets ( Generate a PCAP file). In certain embodiments of the present disclosure, the sensor 102, the sensor 102, processes data in collaboration with an entity engine. The role of the entity engine is to enhance flow events and PCAP files with unique entity identifiers as IP addresses often change within the corporate environment using DHCP.
Sensor 102 transmits event 720 to scoring engine 108 over ESB116 for real-time scoring. In one embodiment, the scoring engine 108 includes describing a large number of models, preprocessing inputs to the model, post-processing the output of the model, sending events to a segmented model, and so on. , Read PFA file 722 from PFA model repository 706. In certain embodiments, the imported PFA file 722 can represent an analytical workflow. In certain embodiments, the analytical workflow includes a number of segmented analytical workflows, each associated with a logical segment. For example, FIG. 8A shows how the outputs of many analytical models can be combined to produce a single output, and FIG. 8B shows two or more outputs of an analytical model. It shows how it can be used as an input to other analytical models. Analytical models include cluster models, baseline models, classification and regression models, neural networks, random forests, Bayesian models, and any of the other statistical and machine learning analytical models well known to experts in the field. Not limited to them. The scoring engine 108 translates the scores of individual events to create many types of TIMs, including TIMs containing scores, event or warning notifications, model update TIMs, and mitigation TIM710s. In certain embodiments, the scoring engine 108 may construct additional event characteristics from the received event information. In certain embodiments, the sensor 102 is controlled by the RTAE110, which may change the type of packets and flows collected, the way events and flows are processed by the sensor.
Sensor 102 also transmits the network flow record and PCAP file 724 to the distributed analysis platform 106. The data transmitted by the sensors includes data and metadata about the observed entities, data and metadata about network traffic, data and metadata about users, data and metadata about workstations and servers, routers and switches. Data and metadata, data and metadata about external network entities, and data and metadata about internal and external devices that interact with the network can be enhanced by adding at least one of them. The distributed analysis platform 106 processes the received information in a number of ways, including using statistical algorithms, machine learning algorithms, and other algorithms that build analytical models that can be performed by scoring engines. .. An example of processing received information in a number of ways as described above is batch processing of event data, flow data, and other data referred to in any of the present disclosures. Analysis of the data processed in this way can provide insights into cyber behavior 712, such as the presence of anomalous or suspicious behavior. These models can be exported as a model exchange format, eg, PFA models to PFA model repository 706. The PFA model is received by the scoring engine 108 and is added to the existing collection of PFA models, which modifies the collection of PFA documents accessed by the scoring engine 108 to handle the event. The distributed analysis platform 106 can also score events within batch 712.
In certain embodiments of the present disclosure, the input is from a network flow record generated by sensor 102, a packet record generated by sensor 102, a log file from a network device, workstation, server, or other system by sensor 102. It may be a record to be extracted, or a record to be extracted through some other mechanism.
In certain embodiments of the present disclosure, an input is an event associated with an entity, such as a network device, user, etc., and the input is one or more state vectors that store persistent information for that entity. It is processed by searching, updating the state vector with the information from the event, and then using the updated state vector as input to the model.
In one embodiment of the disclosure, as described above with respect to FIG. 2, one or more sensors 102 collect and process data from the protected entity to generate event-based records, event-based. The record of is passed to the ESB116 of the system, and one or more scoring engines 108 read the event-based record from the ESB116 and process the event-based record to produce various outputs.
In certain embodiments of the present disclosure, an analytical model is deployed within the scoring engine 108 to detect cyber behavior at line speeds as network data is processed, and changes in cyber behavior. The analytical model deployed within the scoring engine 108 can be utilized for a number of different use cases within a cyber network. For example, the analytical model in the scoring engine 108 can be used to detect unexpected changes in network devices, workstations, servers, etc. Unexpected changes can be defined in multiple ways, including, for example, due to changes in the communication patterns (communities of interest) of devices on the network. In this case, various types of models, including baseline models, can be used to detect changes. Using a baseline model to detect changes can also be employed to detect insider or lateral movement threats. The scoring engine 108 can also be used to accumulate suspicious behavior across sources. For example, a flow can occur from a country at night. If some of these flows are also found to be associated with failed login attempts, the risks associated with all of these flows are increased. If the risk score passes the threshold, a warning will be sent.
In certain embodiments of the present disclosure, a large number of models exist and can be combined in various ways. FIG. 8A shows a model of an embodiment of the present disclosure.<u style="single">ensemble</u>It is a system diagram which shows. Analytical models 1-n (802-804) are combined to give a single output score of 806. Analytical models can be combined using averaging, voting, or any method of combining models. For example, voting is used to combine the outputs of categories from a large number of models (corresponding to a single input), in which case the most frequently occurring category as the output of the model is selected as the output of the ensemble. Will be done. FIG. 8B is a system diagram showing the synthesis or chaining of models according to an embodiment of the present disclosure. Analytical model 1 (810) is supplied as input to analytical model 2a (812) and analytical model 2b (814). The outputs of analytic model 2a (812) and analytic model 2b (814) can be used as inputs to analytic model 3 (816). In certain embodiments, Analytical Model 1 (810), Analytical Model 2a (812), Analytical Model 2b (814) and Analytical Model 3 (816) can be any model. For example, the model is not limited to a particular subset of the model. Models can be chained together in any configuration. FIG. 8C is a system diagram showing a segmented model according to an embodiment of the present disclosure. The individual models 820 ... 822 are associated with a unique key that identifies the indicator. Since models are generally different between different compartments, the same input event produces a number of different outputs corresponding to different different models in relation to different compartments.
In certain embodiments of the present disclosure, a portable format (PFA) for analysis is used. Other model exchange formats (MIFs), such as the Predictive Model Markup Language, support only a limited type of model synthesis, for example, because they support three types of the many models mentioned above. Does not support any co-chaining of the output of one or more models to the input of one or more other models, as supported by PFA.
In one embodiment of the disclosure, a modeler is used to export MIF documents that are imported into one or more scoring engines. In some embodiments of the system, the MIF document is transmitted to the scoring engine 108 across the ESB116, and in some embodiments the MIF document comprises an out-of-band network linking the distributed analysis platform 106 to the scoring engine 108. , Loaded into the scoring engine 108 via another mechanism. In some embodiments, the MIF document is a PFA document.
In certain embodiments of the present disclosure, there are several different types of TIMs that are the output of the model. these are, i) Scores associated with input events stored for future potential analysis, ii) Scores associated with input events stored for further processing, iii) Model update TIM and iv) Relaxation TIM including.
Updating the behavior model FIG. 9 is a flowchart illustrating the flow of data between components within a cybersecurity framework according to an embodiment of the present disclosure.
The RTAE110, as well as the control plane engine modules and agents, may take mitigation actions, as briefly described earlier and in more detail below. For example, the analytical model in the scoring engine 108 can be updated in one of four ways. First, a new analytical model can be created in a batch analysis job and exported to model exchange format 902. In one embodiment of the disclosure, the batch analysis job runs within the distributed analysis platform 106 and is exported as a PFA. The batch analysis job uses data from sensor 102 as inputs, such as network flow data, PCAP data, and data from other systems and sensors. Second, new analytical models can be created using RTAE in near real time and exported in model exchange format 904. In certain embodiments of the present disclosure, RTAE110 exports the model as PFA. Third, changes to the model itself can be made via model update TIM410. Model update TIM410 may include specific values, variables, and information such that PFA elements within a PFA document can be updated without replacing the entire PFA document. Due to the large size of PFA documents, the ability to update specific values and elements using the model update TIM, which is the result of processing TIM and other information by RTAE110, contributes to the speed at which the data is processed. Is. Fourth, when the event is processed (908) the parameters (for state information related to the entity) or other components of the model 914 are updated, if the model is a streaming model, the parameters of the analytical model itself Will be updated. A streaming model in this context is an analytical model constructed from data that is processed only once as it passes through a scoring engine. This is in contrast to the analytical model constructed by batch analysis as described above, in which batch analysis
As mentioned above, in certain embodiments, sensor 102 receives an input event from network traffic. Types of input events can include events from network packets, events from network flows, events from monitoring systems, events from log files, and events from other systems and applications. Further, as mentioned above, the output of the scoring engine 108 may include TIM. In certain embodiments, the TIM is a score associated with an event stored for future potential analysis, a score associated with an event sent for further dynamic processing, a model update TIM, and a mitigation TIM. Can be included.
An element of the disclosure is that a large number of scoring engines 108, a large number of sensors 102, or other components of the system can send messages to the ESB116 at the same time, and the scoring engine 108 can be updated at the same time. In one embodiment of the present disclosure, there is a large number of scoring engines 108, the large number of scoring engines 108 reading the model update TIM. In other words, a large number of sensors 102 are used and a model update TIM can be transmitted over the ESB116 to update the scoring engine 108 simultaneously; a single sensor 102 sends a model update TIM to a large number of scoring engines 108. Can be updated simultaneously; or a large number of sensors and a large number of scoring engines 108 can send a model update TIM and a large number of sensors 102 can be used to update a large number of scoring engines 108 simultaneously. In certain embodiments, the system described herein includes only one scoring engine 108 that connects to a large number of sensors 102.
In one embodiment of the disclosure, the model update TIM is processed at the same time as the scoring engine scores the event so that it is not necessary to stop the scoring engine to update it (PFA document) with the model update TIM. In addition, the scoring engine 108 is designed. Since the PFA standard includes language components that support simultaneity as described above, this ability exists for the scoring engine 108 to handle changes to the PFA document at the same time it scores the event. In certain embodiments of the present disclosure, the implementation of the scoring engine 108 supports various simultaneous elements supported by the PFA standard.
The RTAE110 processes TIMs and events from the scoring engine 108 and other system modules to determine mitigation actions. A TIM containing a mitigation action is sent to the mitigation agent, which performs the mitigation action, and in some embodiments, the mitigation agent uses the control plane to modify control network devices such as routers and switches. .. In certain embodiments, the RTAE110, scoring engine, and associated system modules reside on the ESB116 running over an out-of-band system network.
The components of this disclosure are support for analytical frameworks that can use a large number of models that can be combined in various ways. Various methods include: i) Separated model. In the segmented model, inputs are sent to one or more of the individual models, and the individual models are associated with one or more constraints, such as a particular time period, a particular network segment, and so on. ii) Ensemble. In the ensemble, the inputs to the model are common and two or more outputs are combined into a single output. iii) Model configuration. In this configuration, one or more outputs are used as inputs for another model.
In certain embodiments, the model needs to be periodically reconstructed or retrained to take into account changed conditions, such as new behavior or improvements in model technology. When a new model is created, the new model can be contrasted with the current model to pick the winner (eg, using the Champion-Challenger method).
In certain embodiments, the process is human readable and audible. The model is also updated over time. This allows the model to move to generation and be constructed from raw data rather than waiting for training data with a sufficiently valid and appropriate history.
In addition to the types of TIMs already mentioned, a key component of this disclosure is the use of external TIMs. The external TIM is either an instance of the system or an instance of another system that produces an interoperable TIM with the TIM used by the systems described in this disclosure. , A TIM generated outside the entity by another entity.
The external TIM works as described above, with the following exceptions. External TIMs that correspond to other instances of the systems described in this disclosure do not contain the identification information of the entity that generated them, and instead, two or more entities operating the systems described in this disclosure. Includes information such as information about external IPs, new thresholds and components for PFA documents, new post-processing rules, etc. that can be shared between.
In one embodiment of the disclosure, the external TIM is created by RTAE110 of the first entity, encrypted before being passed from the first entity to the second entity, and by the second entity. It is decrypted and passed to the second entity, RTAE110. After being received by the second entity RTAE110, the external TIM is processed in the same way that the internal TIM is processed.
External TIMs can be processed automatically by the entity RTAE110 that receives them and, unlike other types of threat information shared between entities, are not designed to be processed manually.
In certain embodiments of the present disclosure, the external TIM can be generated by other systems using conventions and standards implemented by various entities sharing the external TIM. For example, the TIM may include information that changes the threshold for certain types of warnings, such as those associated with lateral movement within the entity, or withdrawal of data from the entity. If one entity that accepts and sends an external TIM detects one of these types of threats, it (one entity) can be sent to another entity that accepts and sends an external TIM. An external TIM can be automatically generated, which other entity can subsequently process the external TIM and take action to lower the threshold for attacks observed by the first entity.
Stream analysis In one embodiment of the present disclosure, stream analysis is used within the model parameters, model, as opposed to being used within the scoring engine 108 and updating only the states associated with the entities scored by the model. Update the characteristics to be used, or the structure of the model itself. In one embodiment of the present disclosure, when the first score is received in post-processing, various statistics are accumulated and evaluated and the model sees enough events to be considered statistically valid. Determine if. If it is statistically valid, the score will be sent out, otherwise the score will be suppressed.
For example, variables or other statistical attributes for the distribution associated with one or more properties in the model can be calculated, and if these statistics fall below the threshold, the score can be emitted by the model.
Microsegments for cyber analytics In certain embodiments, the venture can be subdivided into logical segments that can be independently modeled, monitored and mitigated, including internal and external entities that interact with the venture. The logical segment is also referred to herein as a micro cyber segment. As described below, the individual logical segments are i) At least one of an analytical model, a set of analytical models, or an analytical workflow; ii) One or more sources of input (eg, tap points); and iii) A set of actions to mitigate the impact of anomalous activity that occurs inside a logical segment Can be related.
In certain embodiments, the present disclosure utilizes thousands to hundreds of thousands or more of micro-cyber segments. In certain embodiments of the present disclosure, various methods of dividing the enterprise into micro-cyber segments are used, analytical models are used, and mitigation is used, depending on the behavior of the cyber of interest. In other words, in one embodiment, various, often overlapping, micro-cyber segments are used simultaneously.
The micro-cyber segment is defined by dividing the venture with one or more dimensions. Dimensions are network attributes, including IP and network segments; modeled device attributes, including device type, etc .; the number of flows during a particular time window, and when one device communicates with another. Network or device characteristics, such as the density of graphs formed in; Device-related flow characteristics, such as the type of protocol used; Internals that interact with the network, including user types, user roles, etc. Attribute and characteristics of and external entities; time dimensions such as time, day, etc.
A micro-cyber segment uses one dimension and divides the dimension into different regions to form different segments; or takes the product of two or more dimensions and divides the individual dimensions. It can be formed by forming a multi-dimension segment.
When the division is made into various segments, an independent analytical model is calculated for the data associated with the entities in that segment. To do this, one embodiment collects and processes data using sensors that monitor relevant data for entities, users, or flows associated with that segment.
In addition to monitoring and modeling the micro-cyber segment, one or more mitigation actions for that segment are defined. The mitigation action is to blacklist the entities associated with that segment and the ports associated with that segment so that switches and routers no longer send data to the entities in that segment; Modifying the data flowing to or from the segment; redirecting traffic to or from the segment; restarting the entity associated with the segment's device from a clean installation; to increase the security of the entity Includes the use of visualization technology or the movement of target technology.
One of the criteria for determining the appropriate segmentation is to form a segment whose segments are sufficiently uniform in their cyber analytical behavior that can be modeled by analytical models. For example, a segment can be divided until one or more characteristics of the model within the segment or variables or other statistical attributes about the distribution associated with other components fall below the threshold and stabilize over time. In certain embodiments, the partitioning includes network partitioning, traffic partitioning on the network, user partitioning on the network, device partitioning on the network, partitioning based on other data, including third-party data, and networks, networks. The above traffic, users on the network, devices on the network, and third-party data may include data associated with at least one of the plurality of divisions involved. In some embodiments, one or more divisions may overlap with another division.
In one embodiment of the disclosure, the analytical model associated with an individual micro-cyber segment is represented in a model exchange format such as PFA, where the micro-cyber segment is monitored at line speed for mitigation events and events by a scoring engine. A scoring engine is used so that it can be scored and delivered in near real time.
Move target defenses using virtual environment In one embodiment, the RTAE110 includes a virtual defense module (VDM) that integrates with the micro cyber segment to create, manage, and dismantle a virtual environment that includes a corresponding virtual network. The virtual network is shown in Fig. 3 as described above.<sub>0</sub>And I<sub>1</sub>From I<sub>2</sub>Associated with these virtual environments, including route information to. Virtual Defense Module 150 is IDI<sub>0</sub>And IDI<sub>1</sub>To receive. As mentioned above, IDI<sub>0</sub>Contains data received outside the firewall, IDI<sub>1</sub>Contains data received inside the firewall. In certain embodiments, the ID is an encrypted, immutable, globally unique ID for all networks and data packets within the cybersecurity framework, which allows the machine to move from "suspicious" activity. You can uniquely separate "allowed" activities. The ID parallelizes the real world environment and the virtual world environment, and in addition to managing, visualizing, analyzing, and warning them, they can operate at the same time. The identity allows unique baselines and analysis to be based on the overall history of all packets that enter the cybersecurity framework throughout the processing and usage history of all packets. In one embodiment, the event triggers enabled for machine speed are pre-planned mitigation (eg, lateral movement, unauthorized infrastructure changes, unauthorized) when ID packets are detected. VPN, spoof, etc.).
In one embodiment, the virtual execution module 150 utilizes a secure virtual machine or virtual container with an identity and is both "trusted" and "untrusted" physical for dynamic complexity. And form and manage virtual environments. Thus, a "virtual attack surface" can be formed to identify suspicious activity. This forces an attacker to distinguish between hundreds to tens of thousands (untrusted) virtual environments of real (trusted) enterprise data and processing, which in turn attacks. It dramatically reduces a person's chances of success and increases their chances of detection and mitigation. DDI infrastructure can also be used to manipulate packet flow and interconnection within and between virtual and real-world networks and components. The virtual defense module 150 can dynamically reorient from suspicious activity in the control plane to a particular virtual environment for pre-planned actions triggered by the scoring engine. Trust relationships are feasible between the container, its contents, and the framework, which provides policy-based access control to all data and machine processes within the cybersecurity framework. , Extends its use for identity access management (IDAM) and attribute-based access control (ABAC).
Illustrative detection and mitigation FIG. 10 is a system diagram showing the response of the cyber security framework to an external threat according to an embodiment of the present disclosure. The process is that a bad external actor 1006 launches an attack, sensor 102 / scoring engine 1 1002 detects a threat and issues TIM1005, RTAE110 receives a message to determine mitigation and issues it to ESB116. That the control plane engine 114 receives the mitigation action (MA) 1003 within the range of the mitigation TIM 1008, the sensor 102 and the scoring engine 2 1004 receive the model update TIM 906 to update the state, and the control plane. Includes that engine 114 takes action to close the port. The scoring engine 1 1002 and the scoring engine 2 1004 have similar functions to the scoring engine 108 described herein.
At step 1011, an attack initiated by an external bad actor 1006 bypasses the IDS and firewall access control lists (ACLs) and passes through firewall 132.
In step 1012, sensor 102 processes packets and flows from external threat 1006. The scoring engine 1 1002 will generate a TIM 1005 when it detects a threat event. The scoring engine 1 1002 publishes threat events and TIM 1005 to the distributed ESB 116.
In step 1013, RTAE110 receives the threat event and TIM transmitted by ESB116. RTAE110 processes TIM1005 from scoring engine 1 1002 and RTAE110 determines for mitigation based on TIM1005.
In step 1014, RTAE110 determines with respect to mitigation. RTAE110 issues one of model update TIM906 and mitigation TIM1008 to all connecting elements on ESB116.
In step 1015, the control plane engine 114 receives the mitigation TIM1008 associated with the IP reputation change, resulting in actions such as blocking IPs and ports and warning of anomalous activity analysis. The control plane engine 114 takes mitigation action 1003 by closing the port used by the external actor 1006.
In step 1016, the scoring engine 2 1004, and other scoring engines connected on the ESB116, receive model update TIM906 from RTAE110 and modify their scoring behavior to adopt similar behavior. Detect actors better.
FIG. 11 is a system diagram showing the response of the cyber security framework to an internal threat according to an embodiment of the present disclosure. The process determines that the internal bad actor 1106 launches an attack, the sensor 102 / scoring engine 1 1002 detects the threat and issues a TIM 1005, the RTAE 110 receives a message, and the RTAE 110 determines about mitigation ESB116. The control plane engine 114 receives the mitigation TIM1008, the sensor 102 and the scoring engine 2 1004 receive the model update TIM906 to update the state, and the control plane engine 114 closes the port. Including taking. The scoring engine 1 1002 and the scoring engine 2 1004 have similar functions to the scoring engine 108 described herein.
At step 1111 the bad internal actor 1106 initiates network reconnaissance (eg, critical spy reconnaissance) within the corporate network.
In step 1112, sensor 102 processes packets and flows associated with internal threats. The scoring engine 1102 forms an event from packets and flows and sends TIM1005 to ESB116.
In step 1113, RTAE110 receives the TIM transmitted by ESB116. RTAE110 determines mitigation based on TIM. The RTAE110 takes the mitigation TIM1008 across the ESB116 to the control plane engine 114 and within the data plane 122, such as firewalls, routers, switches 132, or endpoints 120 such as workstations, servers or mobile devices. Issue to all entities affiliated with mitigation actions.
At step 1114, the mitigation TIM is sent to ESB116.
In step 1115, control plane engine 114 receives mitigation TIM1008. The control plane engine 114 takes action by closing the port used by the internal actor 1106.
In step 1116, the scoring engine 2 1004 (and any other scoring engine on ESB116) receives model update TIM906 from RTAE110 and modifies their scoring behavior to achieve similar behavior. Better detect the accompanying bad actors.
The gist of the invention described herein is in digital electronic circuits, or in computer software, firmware, or hardware, including the structures disclosed herein and their structural equivalents, or them. Can be implemented in combination of. The gist of the invention described herein is expressly embodied in an information carrier (eg, a machine-readable storage device) or executed by a data processing device (eg, a programmable processor, computer, or multiple computer). It can be implemented as one or more computer program products, such as one or more computer programs that are implemented or control their behavior, embodied in propagated signals. Computer programs (also known as programs, software, software applications, or code) can be written in any form of programming language, including compilation and interpreter languages, as stand-alone programs, or as modules. Can be deployed in any format, including, as a component, or as another unit suitable for use in a computer environment. Computer programs do not necessarily have to deal with files. A program is a portion of a file that holds other programs or data, either as a single file dedicated to this program, or as a number of integrated files (eg, one or more modules, subprograms, or The code portion can be stored in the file). Computer programs can be deployed to run on one computer, in one location, or on multiple computers distributed over multiple locations and interconnected by communication networks. ..
The processing and logic flows described herein, including the method steps of the gist of the invention described herein, are described herein by operating on input data and producing outputs. It may be performed by one or more programmable processors that execute one or more computer programs that perform the function of the purpose of. For example, processing and logic flow can be performed by dedicated logic circuits such as FPGA (Field Programmable Gate Array) and ASIC (Application Specific Integrated Circuit), and the books described in this specification as those dedicated logic circuits. The device to the effect of the invention can be implemented.
Processors suitable for running computer programs include both general purpose and dedicated microprocessors, such as GPUs, and also include any one or more processors of any type of digital computer. In general, the processor receives instructions and data from read-only memory, random access memory, or both. The essential elements of a computer are a processor that executes instructions and one or more memory devices that store instructions and data. In general, a computer includes one or more mass storage devices that store data, such as magnetic disks, magneto-optical disks, or optical disks, or receives or receives data from those mass storage devices. Freely combine to send data to. Suitable information carriers for embodying computer program instructions and data include all types of non-volatile memory, eg semiconductor memory devices (eg EPROM, EEPROM, and flash memory devices); magnetic disks (eg internal hard disks). And removable discs); include magneto-optical discs and optical discs (eg, CD and DVD discs). The processor and memory can be complemented or combined with dedicated logic circuits.
In order to provide interaction with the user, the gist of the present invention described herein can be implemented on a computer, which displays information to the user, eg, an LCD (Light Display). It has display devices such as LEDs (Light Emitting Diodes), OLEDs (Organic Light Emitting Diodes), or CRTs (Brown Tubes), as well as keyboard and pointing devices (eg, mice or trackballs) that allow the user to provide input to the computer. .. Other types of devices can also be used to provide interaction with the user. For example, the food bag provided to the user may be any form of perceptual feedback (eg, visual feedback, auditory feedback, or tactile feedback), and the input from the user includes acoustic, audio, or tactile input. , May be received in any format.
The gist of the present invention described herein can be implemented in a computer system, which is one or more backend components (eg, data servers), middleware components (eg, application servers). Or front-end components (eg, client computers with graphic user interfaces or web browsers through which the user can interact with implementations of the present invention described herein), or their back-ends, middle-class. It includes any combination of wear and front-end components, either on physical hardware, in a virtual environment, or using container-based technology to deploy applications such as Linux containers. is there. The components of the system may be interconnected by digital data communication of any form or medium, eg, a communication network. Examples of communication networks include local area networks (LANs) and, for example, wide area networks (WANs) such as the Internet.
As a matter of course, the gist of the invention of the present disclosure is not limited to the details of the configuration and the arrangement of components described in the following description or shown in the drawings in its use. The gist of the invention of the present disclosure may be in other embodiments and may be implemented and treated in various ways. Moreover, as a matter of course, the expressions and terms used herein are for the purpose of description and should not be taken as a limitation.
Thus, it will be appreciated by those skilled in the art that the ideas on which the present disclosure relies can be readily used as the basis for the design of other structures, methods, and methods that practice the plurality of objectives of the invention of the present disclosure. It will be obvious. Therefore, it is important to note that the claims should be considered to include such equivalent construction, as long as the claims do not deviate from the spirit and scope of the invention of the present disclosure.
Although the gist of the invention of the present disclosure has been described and shown in the above-exemplified embodiments, as a matter of course, the present disclosure has been made only as an example, and in the details of the implementation of the gist of the invention of the present disclosure. Numerous changes can be made without departing from the spirit and scope of the gist of the invention of the present disclosure, and the gist of the invention of the present disclosure is limited only by the following claims.
102 ... Sensor, 106 ... Distributed Analysis Platform, 108 ... Scoring Engine, 116 ... Distributed Enterprise Service Bus (ESB) 116.
15 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US20120072983A1 | Cites | United States of America |
22 members in 12 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 201462066769 | United States of America | P | |
| 201462066769 | United States of America | P | |
| 62066769 | United States of America | – | |
| 2015056082 | United States of America | W | |
| 2015056082 | United States of America | W | |
| 62066769 | – | – | – |
| US201462066769P | – | – | – |
| US2015056082 | – | – | – |
| WO2015US56082 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| US9306965B1 | United States of America | B1 | |
| US2016112443A1 | United States of America | A1 | |
| WO2016109005A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CA2934311A1 | Canada | A1 | |
| WO2016109005A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP3095034A2 | European Patent Office (EPO) | A2 | |
| CN106170772A | China | A | |
| SG11201703164RA | Singapore | A | |
| CA2934311C | Canada | C | |
| JP2017516411A | Japan | A | |
| IL251719A0 | Israel | A0 | |
| EP3095034A4 | European Patent Office (EPO) | A4 | |
| HK1225475A | Hong Kong, China | A | |
| HK1225475A1 | Hong Kong, China | A1 | |
| JP6196397B2This record | Japan | B2 | |
| CN106170772B | China | B | |
| EP3095034B1 | European Patent Office (EPO) | B1 | |
| IL251719A | Israel | A | |
| IL251719B | Israel | B | |
| LT3095034T | Lithuania | T | |
| PL3095034T3 | Poland | T3 | |
| ES2736099T3 | Spain | T3 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on accelerated examinationJAPANESE INTERMEDIATE CODE: A971005A975 | A975 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Explanation of circumstances concerning accelerated examinationJAPANESE INTERMEDIATE CODE: A871A871 | A871 |
Numbers
- Publication
- 6196397
- Publication, DOCDB
- 6196397
- Publication, EPODOC
- JP6196397B
- Application
- 2016567760
- Application, DOCDB
- 2016567760
- Application, EPODOC
- JP20160567760
Titles2
- Japanese
- サイバーセキュリティシステム
- English
- Cyber security system
Classification
- CPC, 3
- H04L63/1416
- H04L63/1425
- H04L63/1441
- IPC, 2
- H04L12 66
- G06F21 55
