Invention Publication
- Patent Title: System and Method for Cybersecurity Threat Monitoring Using Dynamically-Updated Semantic Graphs
-
Application No.: US18337785Application Date: 2023-06-20
-
Publication No.: US20240007495A1Publication Date: 2024-01-04
- Inventor: Scott Eric Coull , Jeffrey Thomas Johns
- Applicant: Google LLC
- Applicant Address: US CA Mountain View
- Assignee: Google LLC
- Current Assignee: Google LLC
- Current Assignee Address: US CA Mountain View
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/901

Abstract:
A method for performing cyber-security analysis includes generating a semantic graph in which each object is represented as a node, and each event associated with an object is represented as an edge. A cyber-threat related alert, with an associated alert type, is received from a source. A first object from the plurality of objects is modified based on the alert. A plurality of threat scores, each associated with an object, are calculated, substantially concurrently, based on the alert type. Subsequently, a plurality of modified threat scores are determined for each object, based on: (1) the threat score for that object, (2) a connectivity of that object to each of the remaining objects within the semantic graph; and (3) the threat score for each remaining object from the plurality of objects. A subgraph of the semantic graph is identified based on normalized versions of the modified threat scores.
Public/Granted literature
- US12074902B2 System and method for cybersecurity threat monitoring using dynamically-updated semantic graphs Public/Granted day:2024-08-27
Information query