- Patent Title: System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using provenance tags and customizable policy
-
Application No.: US16544401Application Date: 2019-08-19
-
Publication No.: US11601442B2Publication Date: 2023-03-07
- Inventor: Ramasubramanian Sekar , Junao Wang , Md Nahid Hossain , Sadegh M. Milajerdi , Birhanu Eshete , Rigel Gjomemo , V. N. Venkatakrishnan , Scott Stoller
- Applicant: The Research Foundation for the State University of New York , The University of Illinois at Chicago
- Applicant Address: US NY Albany; US IL Chicago
- Assignee: The Research Foundation for the State University of New York,The University of Illinois at Chicago
- Current Assignee: The Research Foundation for the State University of New York,The University of Illinois at Chicago
- Current Assignee Address: US NY Albany; US IL Chicago
- Agency: Hoffman & Baron, LLP
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path.
A corresponding method and computer-readable medium are also disclosed.
A corresponding method and computer-readable medium are also disclosed.
Public/Granted literature
Information query