- Patent Title: Anomaly detection based on changes in an entity relationship graph
-
Application No.: US16883887Application Date: 2020-05-26
-
Publication No.: US11463464B2Publication Date: 2022-10-04
- Inventor: Joseph Auguste Zadeh , Rodolfo Soto , George Apostolopoulos , John Clifton Pierce
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Perkins Coie LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; H04L43/08 ; H04L43/045 ; H04L67/30 ; H04L61/45 ; H04L61/103 ; H04L61/5014 ; H04L43/106 ; H04L41/12 ; H04L61/5007 ; H04L101/622

Abstract:
Techniques are described for analyzing data regarding activity in an IT environment to determine information regarding the entities associated with the activity and using the information to detect anomalous activity that may be indicative of malicious activity. In an embodiment, a plurality of events reflecting activity by a plurality of entities in an IT environment are processed to resolve the identities of the entities, discover how the entities fit within a topology of the IT environment, and determine what the entities are. This information is then used to generate an entity relationship graph that includes nodes representing the entities in the IT environment and edges connecting the nodes representing interaction relationships between the entities. In some embodiments, baselines are established by monitoring the activity between entities. This baseline information can be represented in the entity relationship graph in the form of directionality applied to the edges. The entity relationship graph can then be monitored to detect anomalous activity.
Public/Granted literature
- US20200287927A1 ANOMALY DETECTION BASED ON CHANGES IN AN ENTITY RELATIONSHIP GRAPH Public/Granted day:2020-09-10
Information query