Conventional computer and network security intelligence processes and approaches typically process network architecture and security information independently of each other. Current approaches to managing security intelligence data often address both threat and malicious behavior at the individual computer level, tracked by the Internet Protocol (IP) address. For example, important facts, observed behavior, and other indications that are tracked by security organizations are only tracked with respect to individual IP addresses. Thus, descriptive information is only associated with a particular IP address, and the information does not relate to other network entities.
Systems, methods, and apparatus embodiments are described herein for managing security intelligence data in which security attributes, which may describe network elements, are associated with one or more network elements, bilaterally, in a hierarchical fashion. For example, the security attributes are inherited from parents to children and from children to parents in a computer network hierarchy. The computer network hierarchy may comprise various entities such as, for example, top level network entities, autonomous systems having autonomous system numbers (ASNs), devices having internet protocol (IP) addresses that are within individual blocks of address ranges, devices having specific IP addresses, and fully qualified domain names (FQDNs). Attributes may comprise security data such as, for example, reports, indicators, observed behaviors, characteristics, or the like.
In accordance with one embodiment, a bilateral inheritance model structure provides information concerning security intelligence data. The bilateral inheritance model structure comprises a hierarchy of data structures that are each disposed at a given layer of the hierarchy. The bilateral inheritance mode structure may comprise a first data structure disposed at a top layer of the hierarchy. The first data defines a parent data structure. The first data structure is associated with, for instance includes, attributes that are associated with a top level entity. In accordance with the example embodiment, a plurality of child data structures are disposed at respective layers of the hierarchy that are below the top layer. Each child data structure is associated with, for instance includes, attributes that are associated with entities that are part of the top level entity. A portion of the plurality of child data structures may have a relationship with lower data structures such that the portion of the plurality of child data structures also define parent data structures. Attributes that are associated with the parent data structures may be mapped to their respective child data structures such that inspection of the child data structures reveals the attributes associated with their respective parent data structures, and attributes that are associated with child data structures may be mapped to their respective parent data structures such that inspection of the parent data structures reveals the attributes associated with their respective child data structures.
In another example embodiment, a bilateral inheritance model structure provides information concerning security intelligence data, wherein the bilateral inheritance model structure comprises a hierarchy of data structures that are each disposed at a given layer of the hierarchy. The bilateral inheritance model structure is built by generating a first data structure that represents a top level entity. The first data structure is associated with attributes that are associated with the top level entity. The attributes are mapped to a plurality of child data structures disposed at respective layers of the hierarchy that are below the top layer such that the attributes associated with the first data structure are associated with each of the plurality of child data structures. It may be determined that a portion of the plurality of child data structures have a relationship with lower data structures such that the portion of the plurality of child data structures also define parent data structures. Attributes that are associated with the parent data structures may be mapped to their respective child data structures such that inspection of the child data structures reveals the attributes associated with their respective parent data structures. Attributes that are associated with the child data structures may be mapped to their respective parent data structures such that inspection of the parent data structures reveals the attributes associated with their respective child data structures.
A more detailed understanding may be had from the following description, given by way of example in conjunction with the accompanying drawings wherein:
The ensuing detailed description is provided to illustrate example embodiments and is not intended to limit the scope, applicability, or configuration of the invention. Various changes may be made in the function and arrangement of elements and steps without departing from the spirit and scope of the invention.
As further described herein, bilateral network inheritance generally refers to inheriting a variety of attributes from parents to children and from children to parents in a computer network hierarchy. The computer network hierarchy may comprise various entities such as, for example, top level entities, autonomous systems, address ranges, individual internet protocol (IP) addresses, and fully qualified domain names (FQDNs). Attributes may comprise security data such as, for example, reports, indicators, observed behaviors, characteristics, or the like. Bilateral network inheritance, as further described herein, may provide rich context when observing attributes of computer network elements, and facilitates deep analytic capabilities.
In accordance with one embodiment, a bilateral inheritance model structure provides information concerning security intelligence data, and the bilateral inheritance model structure comprises a hierarchy of data structures that are each disposed at a given layer of the hierarchy. The bilateral inheritance model structure may comprise a first data structure disposed at a top layer of the hierarchy. The first data structure defines a parent data structure. The first data structure is associated with, for instance includes, attributes that are associated with a top level entity. In accordance with the example embodiment, a plurality of child data structures are disposed at respective layers of the hierarchy that are below the top layer. Each child data structure is associated with, for instance includes, attributes that are associated with entities that are part of the top level entity. Therefore, the top level entity attains attributes from the child data structures, and the child data structure attains certain attributes from the top level entity. A portion of the plurality of child data structures may have a relationship with lower data structures such that the portion of the plurality of child data structures also define parent data structures. Attributes that are associated with the parent data structures may be mapped to their respective child data structures such that inspection of the child data structures reveals the attributes associated with their respective parent data structures, and attributes that are associated with child data structures may be mapped to their respective parent data structures such that inspection of the parent data structures reveals the attributes associated with their respective child data structures.
Referring to
With continuing reference to
With continuing reference to
Referring now to
With continuing reference to
In accordance with the illustrated embodiment depicted in
The construction details of the embodiment illustrated in
For example, referring to
Thus, it may be determined at each level of the hierarchy if intelligence data should be applied. Such a determination may be made by inspecting the element at the level in the hierarchy, and inspecting the type and values contained within the intelligence data being inherited from another level in the hierarchy. It is possible that business logic determines that an attribution of intelligence data may be applied at more than one level of the hierarchy or skip levels in the hierarchy. As used herein, business logic may refer to one or more rules that determine how attributes are applied to data structures. One such example of business logic that skips levels is where a threat indicator that has been associated with a specific IP Address is attributed to a form of network infection. The network infection may be associated with, for instance spreads to, other IP Addresses (e.g., a cluster of IP addresses) in the same autonomous system. In this case, the threat indicator may be referred to as a “clustering IP botnet” threat indicator, and the business logic may apply the threat indicator at the autonomous system level rather than at a specific CIDR block level. Another example of business logic that skips levels is where a host server (e.g., top level entity) is assigned a threat indicator, which for purposes of example can be referred to as “Host infection A,” that was originally detected against a dynamically assigned IP address associated with the host. However, the IP address assignment to the host server may be temporal due to dynamic host configuration protocol (DHCP) assignment changes, and therefore the threat indicator continues to be associated with the host server after the IP address is no longer mapped to the host server.
By way of another example, a threat indicator 401 may be associated with an FQDN, such as www.abc.com for example. The 401 indicator is applied to the IP address associated with the FQDN at the time of the FQDN resolution, as it is a direct mapping between the threat indicator, FQDN, and IP address. Having the threat indicator inherit from the IP to CIDR should not occur because of the use of Dynamic Domain Services. By way of yet another example, a user wants to assign the tag “Point of Sales (POS)” to 7 different unannounced/29 CIDR blocks that represent an IP address range, to visually describe those networks. In accordance with the example, this tag (attribute) is not applied to the individual IP addresses in the address range, nor to the AS, as this is a specific descriptive tag meant only for the specific CIDR blocks.
Referring now to
In more detail, still referring to
In further detail, still referring to
Thus, a bilateral inheritance model structure may include a second data structure that is both a parent and a child data structure, and that is disposed at a second layer of the hierarchy. The second data structure may be associated with an autonomous system of the top level entity. The bilateral inheritance model may further include a third data structure that is both a parent and a child data structure, and the third data structure may be disposed at a third layer of the hierarchy. The third data structure may be associated with attributes that are associated with a range of internet protocol (IP) addresses such that inspection of the third data structure reveals attributes that are associated with the autonomous system and inspection of the second data structure reveals attributes that are associated with the range of IP addresses, wherein the range of (IP) addresses are representative of devices that are part of the autonomous system. The bilateral inheritance model structure may further include a fourth data structure that is a child data structure and that is disposed at a fourth layer of the hierarchy. The fourth data structure may be associated with an individual IP address representative of a device such that inspection of the fourth data structure reveals attributes that are associated with the top level entity, the autonomous system, and the range of IP addresses, and the individual IP address within the range of IP addresses. The bilateral inheritance model may further include another second data structure disposed at the second layer and associated with attributes of another autonomous system of the top level entity, wherein a subset of attributes associated with the other second data structure are not associated with the second data structure, and wherein attributes that are associated with the first data structure are mapped to the other second data structure such that inspection of the other second data structures reveals the attributes mapped from the first data structure. Further, the bilateral inheritance model structure may include another third data structure disposed at the third layer and associated with attributes of another range of IP addresses representative of other devices that are part of the autonomous system, wherein a subset of attributes associated with the other third data structure are not associated with the third data structure, and wherein attributes that are associated with the second data structure are mapped to the other third data structure such that the inspection of the other third data structure reveals the attributes mapped from the second data structure.
Referring to
The inheritances described herein may allow for cross-flow of knowledge and awareness to related network elements and entities to significantly increase context while decreasing time to analyze. Thus, it will be understood that advantages of the various embodiments described herein may include, without limitation, the ability to create and utilize a system allowing the user to take in a wide variety of reports, intelligence, and indicators, often assigned to different network element types (autonomous system, network range, individual IP address). Building a model as described herein may allow a user to develop a richer knowledge and awareness of network activity, to find interrelationships in activities across broader network segments, and to discover non-obvious trends, security events, and other intelligence information.
In operation, in accordance with an example embodiment, a method of building a bilateral inheritance model structure for providing information concerning security intelligence data, wherein the bilateral inheritance model structure comprises a hierarchy of data structures that are each disposed at a given layer of the hierarchy, may comprise generating a first data structure that represents a top level entity and is associated with attributes that are associated with the top level entity. The method may further comprise mapping the attributes to a plurality of child data structures disposed at respective layers of the hierarchy that are below the top layer such that the attributes associated with the first data structure are associated with each of the plurality of child data structures; determining that a portion of the plurality of child data structures have a relationship with lower data structures such that the portion of the plurality of child data structures also define parent data structures; mapping attributes associated with the parent data structures to their respective child data structures such that inspection of the child data structures reveals the attributes associated with their respective parent data structures; and mapping attributes associated with the child data structures to their respective parent data structures such that inspection of the parent data structures reveals the attributes associated with their respective child data structures.
In accordance with another embodiment, a method of building a bilateral inheritance model structure may include generating a first data structure that represents a top level entity and is associated with attributes that are associated with the top level entity. The attributes are mapped to a plurality of child data structures disposed at respective layers of the hierarchy that are below the top layer such that the attributes associated with the first data structure are associated with each of the plurality of child data structures. The method may further include determining that a portion of the plurality of child data structures have a relationship with lower data structures such that the portion of the plurality of child data structures also define parent data structures. In an example embodiment, the attributes that are associated with the parent data structures are mapped to their respective child data structures such that inspection of the child data structures reveals the attributes associated with their respective parent data structures, and the attributes that are associated with the child data structures are mapped to their respective parent data structures such that inspection of the parent data structures reveals the attributes associated with their respective child data structures. In an example embodiment in which attributes are not mapped to every child or parent of a given data structure, the method includes mapping the attributes that are associated with the parent data structure to ones of the child data structures such that inspection of such child data structures reveals the attributes associated with the parent data structures from which such child data structures were mapped, and mapping the attributes that are associated with the child data structures to ones of the parent data structures such that inspection of such parent data structures reveals the attributes associated with the child data structures from which such parent data structures were mapped.
In another example embodiment, a method of building a bilateral inheritance model structure includes identifying a top level entity that includes one or more autonomous systems, each autonomous system including a set of devices; determining that a security attribute is associated with a select autonomous system of the one or more autonomous systems; associating the security attribute with a first data structure that is representative of the top level entity; and associating the security attribute in a second data structure that is representative of the select autonomous system.
By way of yet another example for purposes of illustration,
In Table 2, with respect to IP 4.1.2.1, the IP address does not have the criminal actors tag applied at the host level. This is an example of where business logic determined that the criminal actors tag did not apply to those hosts even though it was inherited down from the ASN to other systems in the same network address range. Thus, it will be understood that attributes can be inherited to select parents (e.g., not all parents) and to select children (e.g., not all children) in accordance with an example embodiment. For example, attributes that are associated with a parent data structure may be mapped to ones of the child data structures such that inspection of such child data structures reveals the attributes associated with the parent data structures from which such child data structures were mapped. Further, attributes that are associated with a child data structure may be mapped to ones of the parent data structures such that inspection of such parent data structures reveals the attributes associated with the child data structures from which such parent data structures were mapped.
In operation, CPU 91 fetches, decodes, and executes instructions, and transfers information to and from other resources via the computer's main data-transfer path, system bus 80. Such a system bus connects the components in computing system 90 and defines the medium for data exchange. System bus 80 typically includes data lines for sending data, address lines for sending addresses, and control lines for sending interrupts and for operating the system bus. An example of such a system bus 80 is the PCI (Peripheral Component Interconnect) bus.
Memory devices coupled to system bus 80 include random access memory (RAM) 82 and read only memory (ROM) 93. Such memories include circuitry that allows information to be stored and retrieved. ROMs 93 generally contain stored data that cannot easily be modified. Data stored in RAM 82 can be read or changed by CPU 91 or other hardware devices. Access to RAM 82 and/or ROM 93 may be controlled by memory controller 92. Memory controller 92 may provide an address translation function that translates virtual addresses into physical addresses as instructions are executed. Memory controller 92 may also provide a memory protection function that isolates processes within the system and isolates system processes from user processes. Thus, a program running in a first mode can access only memory mapped by its own process virtual address space; it cannot access memory within another process's virtual address space unless memory sharing between the processes has been set up.
In addition, computing system 90 may contain peripherals controller 83 responsible for communicating instructions from CPU 91 to peripherals, such as printer 94, keyboard 84, mouse 95, and disk drive 85.
Display 86, which is controlled by display controller 96, is used to display visual output generated by computing system 90. Such visual output may include text, graphics, animated graphics, and video. Display 86 may be implemented with a CRT-based video display, an LCD-based flat-panel display, gas plasma-based flat-panel display, or a touch-panel. Display controller 96 includes electronic components required to generate a video signal that is sent to display 86.
Further, computing system 90 may contain network adaptor 97 that may be used to connect computing system 90 to an external communications network.
The various techniques described herein can be implemented in connection with hardware or software or, where appropriate, with a combination of both. Thus, the methods and apparatuses of using and implementing a bilateral inheritance model structure may be implemented, or certain aspects or portions thereof, can take the form of program code (i.e., instructions) embodied in concrete, tangible, storage media having a concrete, tangible, physical structure. Examples of tangible storage media include floppy diskettes, CD-ROMs, DVDs, hard drives, or any other tangible machine-readable storage medium (computer-readable storage medium). Thus, a computer-readable storage medium is not a transient signal per se. Further, a computer-readable storage medium is not a propagating signal per se. A computer-readable storage medium as described herein is an article of manufacture. When the program code is loaded into and executed by a machine, such as a computer, the machine becomes an apparatus for implementing a bilateral inheritance as described herein. In the case of program code execution on programmable computers, the computing device will generally include a processor, a storage medium readable by the processor (including volatile and non-volatile memory and/or storage elements), at least one input device, and at least one output device. The program(s) can be implemented in assembly or machine language, if desired. The language can be a compiled or interpreted language, and combined with hardware implementations.
The methods and apparatuses for using and implementing a bilateral inheritance model structure as described herein also may be practiced via communications embodied in the form of program code that is transmitted over some transmission medium, such as over electrical wiring or cabling, through fiber optics, or via any other form of transmission, wherein, when the program code is received and loaded into and executed by a machine, such as an EPROM, a gate array, a programmable logic device (PLD), a client computer, or the like, the machine becomes an apparatus for implementing a bilateral inheritance model structure as described herein. When implemented on a general-purpose processor, the program code combines with the processor to provide a unique apparatus that operates to invoke the functionality of a bilateral inheritance model structure as described herein.
While the foregoing written description of the invention enables one of ordinary skill to make and use what is considered presently to be the best mode thereof, those of ordinary skill will understand and appreciate the existence of variations, combinations, and equivalents of the specific embodiment, method, and examples herein. The invention should therefore not be limited by the above described embodiment, method, and examples, but by all embodiments and methods within the scope and spirit of the invention.
This application is a continuation of U.S. patent application Ser. No. 14/176,461 filed Feb. 10, 2014, now U.S. Pat. No. 9,455,993, which claims the benefit of U.S. Provisional Application No. 61/779,549 filed Mar. 13, 2013, the disclosure of which is hereby incorporated by reference as if set forth in its entirety herein.
Number | Name | Date | Kind |
---|---|---|---|
7096502 | Fox | Aug 2006 | B1 |
8132260 | Mayer | Mar 2012 | B1 |
8301994 | Shah | Oct 2012 | B1 |
9455993 | Lewis | Sep 2016 | B2 |
20030046390 | Ball et al. | Mar 2003 | A1 |
20030097588 | Fischman | May 2003 | A1 |
20130081141 | Anurag | Mar 2013 | A1 |
Number | Date | Country | |
---|---|---|---|
20160359898 A1 | Dec 2016 | US |
Number | Date | Country | |
---|---|---|---|
61779549 | Mar 2013 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 14176461 | Feb 2014 | US |
Child | 15240765 | US |