The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 13, 2024

Filed:

Sep. 24, 2021
Applicant:

Exabeam, Inc., Foster City, CA (US);

Inventors:

Derek Lin, San Mateo, CA (US);

Domingo Mihovilovic, Menlo Park, CA (US);

Sylvain Gil, San Francisco, CA (US);

Assignee:

Exabeam, Inc., Foster City, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 16/901 (2019.01); H04L 41/0631 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 16/9024 (2019.01); H04L 41/064 (2013.01); H04L 41/065 (2013.01);
Abstract

The present disclosure relates to a system, method, and computer program for graph-based multi-stage attack detection in which alerts are displayed in the context of tactics in an attack framework, such as the MITRE ATT&CK framework. The method enables the detection of cybersecurity threats that span multiple users and sessions and provides for the display of threat information in the context of a framework of attack tactics. Alerts spanning an analysis window are grouped into tactic blocks. Each tactic block is associated with an attack tactic and a time window. A graph is created of the tactic blocks, and threat scenarios are identified from independent clusters of directionally connected tactic blocks in the graph. The threat information is presented in the context of a sequence of attack tactics in the attack framework.


Find Patent Forward Citations

Loading…