- Patent Title: Method and system for automated cybersecurity incident and artifact visualization and correlation for security operation centers and computer emergency response teams
-
Application No.: US14521328Application Date: 2014-10-22
-
Publication No.: US10412117B2Publication Date: 2019-09-10
- Inventor: Dario V. Forte , Michele Zambelli
- Applicant: Dario V. Forte , Michele Zambelli
- Applicant Address: IT Milan
- Assignee: DFLABS S.P.A.
- Current Assignee: DFLABS S.P.A.
- Current Assignee Address: IT Milan
- Agency: Browdy and Neimark, P.L.L.C.
- Main IPC: G06F16/901
- IPC: G06F16/901 ; G06F16/904 ; G06F9/451 ; G06F16/954 ; G06F3/0481 ; G06F3/0482 ; G06F3/0484 ; H04L12/24 ; H04L29/06 ; G06F16/9538

Abstract:
A method and system is provided for visualizing and navigating cybersecurity information. A hypertree is displayed on a display device of a computerized system. The hypertree includes a plurality of nodes linked by edges, one or more of the nodes representing cybersecurity incidents, and one or more of the nodes representing elements or artifacts of cybersecurity incidents, the edges representing a specific relationship between the nodes linked by the edges. The computerized system displays an interactive navigation aid to enable a user to navigate the hypertree, and receives a navigation command from the user through the interactive navigation aid. The computerized system modifies the displayed hypertree in response to the navigation command. The navigation command comprises selective elimination or restoration of edges or nodes on the hypertree so as to enable the user to readily visualize interrelationships between the displayed nodes that are significant to a cybersecurity investigation or response.
Public/Granted literature
Information query