Analysis and mitigation of network security risks

    公开(公告)号:US11949702B1

    公开(公告)日:2024-04-02

    申请号:US18052030

    申请日:2022-11-02

    Applicant: Splunk Inc.

    CPC classification number: H04L63/1425 H04L65/61

    Abstract: A method comprises acquiring anomaly data including a plurality of anomalies detected from streaming data, wherein each of the anomalies relates to an entity on or associated with a computer network. The method determines a risk score of each of the anomalies, and adjusts the risk score of an anomaly according to a set of factors. The method further determines, for each of a plurality of sliding time windows of different lengths, an entity score of the entity in relation to the sliding time window, based on an aggregation of risk scores of all anomalies related to the entity that were detected within the sliding time window, where the entity score corresponds to a risk level associated with the entity. An action to prevent the entity from performing an operation can be determined and caused to occur based on the entity score.

    Cybersecurity risk analysis and mitigation

    公开(公告)号:US11552974B1

    公开(公告)日:2023-01-10

    申请号:US17086146

    申请日:2020-10-30

    Applicant: Splunk Inc.

    Abstract: A method comprises acquiring anomaly data including a plurality of anomalies detected from streaming data, wherein each of the anomalies relates to an entity on or associated with a computer network. The method determines a risk score of each of the anomalies, and adjusts the risk score of an anomaly according to a set of factors. The method further determines, for each of a plurality of sliding time windows of different lengths, an entity score of the entity in relation to the sliding time window, based on an aggregation of risk scores of all anomalies related to the entity that were detected within the sliding time window, where the entity score corresponds to a risk level associated with the entity. An action to prevent the entity from performing an operation can be determined and caused to occur based on the entity score.

    SYSTEMS DATA AVAILABILITY VALIDATION

    公开(公告)号:US20220247770A1

    公开(公告)日:2022-08-04

    申请号:US17680240

    申请日:2022-02-24

    Applicant: Splunk Inc.

    Abstract: A network connection between a server group of a data intake and query system and each of one or more source network nodes is established. Source data at the server group is received from at least one of the one or more source network nodes via the respective network connections and transformed, by the indexer server, to timestamped data entries of machine data. A model management server detects data constraints for a security model that include a data element used by the security model and an availability requirement set. Using the timestamped data entries, the data constraints are validated, and the validation used to determine a data availability assessment of the security model.

    Validation of systems data
    27.
    发明授权

    公开(公告)号:US11297087B2

    公开(公告)日:2022-04-05

    申请号:US16861031

    申请日:2020-04-28

    Applicant: Splunk Inc.

    Abstract: A network connection between a server group of a data intake and query system and each of one or more source network nodes is established. Source data at the server group is received from at least one of the one or more source network nodes via the respective network connections and transformed, by the indexer server, to timestamped entries of machine data. A model management server detects data constraints for a security model. Using the timestamped entries, the data constraints are validated to obtain a validation result, where validating the data constraints includes determining whether the timestamped entries satisfy the availability requirement set for the data element. The model management server determines a data availability assessment of the security model based on the validation result.

    SYSTEMS DATA VALIDATION
    28.
    发明申请

    公开(公告)号:US20190238574A1

    公开(公告)日:2019-08-01

    申请号:US15885485

    申请日:2018-01-31

    Applicant: Splunk, Inc.

    Abstract: A network connection between a server group of a data intake and query system and each of one or more source network nodes is established. The server group includes an indexer server and a model management server. Source data at the server group is received from at least one of the one or more source network nodes via the respective network connections and transformed, by the indexer server, to timestamped entries of machine data. A model management server detects data constraints for a security model. The data constraints include a data element used by the security model and an availability requirement set, the availability requirement set defining when the data element is available. Using the timestamped entries, the data constraints are validated to obtain a validation result, where validating the data constraints includes determining whether the timestamped entries satisfy the availability requirement set for the data element. The model management server determines a data availability assessment of the security model based on the validation result. The data availability assessment of the security model is stored in computer storage.

Patent Agency Ranking