-
公开(公告)号:US20180004941A1
公开(公告)日:2018-01-04
申请号:US15201186
申请日:2016-07-01
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Philipp Reinecke , Marco Casassa Mont , Yolanta Beresna
CPC classification number: G06F21/55 , G06F17/30979 , G06F21/56 , G06F21/566 , G06F21/577 , G06F2221/034 , G06N5/02 , H04L63/1408 , H04L63/1416 , H04L63/1425
Abstract: Examples relate to model-based computer attack analytics orchestration. In one example, a computing device may: generate, using an attack model that specifies behavior of a particular attack on a computing system, a hypothesis for the particular attack, the hypothesis specifying, for a particular state of the particular attack, at least one attack action; identify, using the hypothesis, at least one analytics function for determining whether the at least one attack action specified by the hypothesis occurred on the computing system; provide an analytics device with instructions to execute the at least one analytics function on the computing system; receive analytics results from the analytics device; and update a state of the attack model based on the analytics results.
-
公开(公告)号:US20180139224A1
公开(公告)日:2018-05-17
申请号:US15577865
申请日:2015-08-31
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Simon Ian Arnell , Marco Casassa Mont , Yolanta Beresna
CPC classification number: H04L63/1425 , G06F21/552 , H04L12/22 , H04L29/06 , H04L41/12 , H04L61/1511 , H04L61/6009 , H04L63/1408 , H04L63/145
Abstract: Examples relate to collecting domain name system traffic. In one example, a computing device may: receive, from a first intermediary network device, a DNS query packet that was sent by a client computing device operating on a private network, the DNS query packet specifying i) a query domain name, and ii) a source address that specifies the client computing device; store, in a data storage device, a query record specifying the query domain name and the source address specified by the DNS query packet; receive, from a second intermediary network device, a DNS response packet; determine that the DNS response packet specifies a response domain name that matches the query domain name; in response to the determination, extract, from the DNS response packet, a resolved address that corresponds to the response domain name; and store, in the query record, the resolved address specified by the DNS response packet.
-
公开(公告)号:US10764393B2
公开(公告)日:2020-09-01
申请号:US16061998
申请日:2016-04-21
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Marco Casassa Mont , Yolanta Beresna , Simon Ian Arnell , Nipun Balan Thekkummal
Abstract: The present disclosure relates to a network device that determines a persistent network identity for a networked device. Specifically, the network device receives a service request that includes an identifier for a second network device in a sub-network among a plurality of sub-networks. The identifier uniquely corresponds to the second network device during a limited period of time. At least one sub-networks are unreachable by the service request. The network device aggregates partial networked device profiles corresponding to the second network device received from other network devices in at least the at least one sub-networks to generate a networked device profile. Moreover, the network device searches at least one caches to obtain the networked device profile based on the identifier in the service request, and correlates the identifier to a persistent network identity corresponding to the second network device based on the networked device profile.
-
公开(公告)号:US10666672B2
公开(公告)日:2020-05-26
申请号:US15577865
申请日:2015-08-31
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Simon Ian Arnell , Marco Casassa Mont , Yolanta Beresna
Abstract: Examples relate to collecting domain name system traffic. In one example, a computing device may: receive, from a first intermediary network device, a DNS query packet that was sent by a client computing device operating on a private network, the DNS query packet specifying i) a query domain name, and ii) a source address that specifies the client computing device; store, in a data storage device, a query record specifying the query domain name and the source address specified by the DNS query packet; receive, from a second intermediary network device, a DNS response packet; determine that the DNS response packet specifies a response domain name that matches the query domain name; in response to the determination, extract, from the DNS response packet, a resolved address that corresponds to the response domain name; and store, in the query record, the resolved address specified by the DNS response packet.
-
公开(公告)号:US20180375953A1
公开(公告)日:2018-12-27
申请号:US16061998
申请日:2016-04-21
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Marco Casassa Mont , Yolanta Beresna , Simon Ian Amell , Nipun Balan Thekkummal
CPC classification number: H04L67/303 , H04L12/28 , H04L12/4625 , H04L41/0213 , H04L61/1588 , H04L61/2015 , H04L61/2053 , H04L61/6022
Abstract: The present disclosure relates to a network device that determines a persistent network identity for a networked device. Specifically, the network device receives a service request that includes an identifier for a second network device in a sub-network among a plurality of sub-networks. The identifier uniquely corresponds to the second network device during a limited period of time. At least one sub-networks are unreachable by the service request. The network device aggregates partial networked device profiles corresponding to the second network device received from other network devices in at least the at least one sub-networks to generate a networked device profile. Moreover, the network device searches at least one caches to obtain the networked device profile based on the identifier in the service request, and correlates the identifier to a persistent network identity corresponding to the second network device based on the networked device profile.
-
公开(公告)号:US10749895B2
公开(公告)日:2020-08-18
申请号:US15777185
申请日:2015-11-17
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Simon Ian Arnell , Marco Casassa Mont , Yolanta Beresna , Theofrastos Koulouris , Jon Potter
Abstract: Examples relate to handling network threats. In one example, a computing device may: receive, from a threat detector, threat data associated with a particular network device included in a plurality of network devices; identify, based on the threat data, a particular analytics operation for assisting with remediation of a threat associated with the threat data; identify, based on the threat data, additional data for performing the particular analytics operation; cause reconfiguration of at least one of the plurality of network devices, the reconfiguration causing each of the reconfigured network devices to i) collect the additional data, and ii) provide the additional data to an analytics device; and receive, from the analytics device, particular analytics results of the particular analytics operation.
-
公开(公告)号:US10262132B2
公开(公告)日:2019-04-16
申请号:US15201186
申请日:2016-07-01
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Philipp Reinecke , Marco Casassa Mont , Yolanta Beresna
IPC: G06F11/00 , G06F21/55 , G06F16/903 , G06F21/56 , H04L29/06 , G06F17/30 , G06F21/57 , G06N5/02 , G06F12/14
Abstract: Examples relate to model-based computer attack analytics orchestration. In one example, a computing device may: generate, using an attack model that specifies behavior of a particular attack on a computing system, a hypothesis for the particular attack, the hypothesis specifying, for a particular state of the particular attack, at least one attack action; identify, using the hypothesis, at least one analytics function for determining whether the at least one attack action specified by the hypothesis occurred on the computing system; provide an analytics device with instructions to execute the at least one analytics function on the computing system; receive analytics results from the analytics device; and update a state of the attack model based on the analytics results.
-
公开(公告)号:US20180219884A1
公开(公告)日:2018-08-02
申请号:US15418458
申请日:2017-01-27
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Yolanta Beresna , Marco Casassa Mont , Philipp Reinecke
IPC: H04L29/06
CPC classification number: H04L63/1425 , G06F21/55
Abstract: Example implementations relate to changing deployment statuses. An example implementation includes updating a data source data store comprising descriptors of available data sources, a pre-processor data store comprising descriptors of available pre-processors, or an analytic data store comprising descriptors of available analytics. A change request may be initiated responsive to a change in the data source data, pre-processor data, or analytic data and a deployment status of a pre-processor or an analytic may be changed responsive to the change request.
-
公开(公告)号:US20180004958A1
公开(公告)日:2018-01-04
申请号:US15201171
申请日:2016-07-01
Applicant: Hewlett Packard Enterprise Development LP
Inventor: Philipp Reinecke , Marco Casassa Mont , Yolanta Beresna
IPC: G06F21/57
CPC classification number: G06F21/577 , G06F21/566 , G06F2221/034 , H04L63/145 , H04L2463/144
Abstract: Examples relate to computer attack model management. In one example, a computing device may: identify a first set of attack models, each attack model in the first set specifying behavior of a particular attack on a computing system; obtain, for each attack model in the first set, performance data that indicates at least one measure of attack model performance for a previous use of the attack model in determining whether the particular attack occurred on the computing system; and update the first set of attack models based on the performance data.
-
-
-
-
-
-
-
-