US 11,874,872 B2
System event detection system and method
Andrew Eggleton, Doha (QA); Alexandra Serenhov, Stockholm (SE); Ankit Shankar, San Francisco, CA (US); Brandon Helms, Arnold, MD (US); Brian Keohane, New York, NY (US); Darren Zhao, New York, NY (US); Elliot Colquhoun, Sydney (AU); Gautam Punukollu, New York, NY (US); Morten Kromann, Copenhagen (DK); Nikhil Seetharaman, Palo Alto, CA (US); Ranec Highet, Hertfordshire (GB); Raj Krishnan, Mumbai (IN); Xiao Tang, Singapore (SG); Sriram Krishnan, New York, NY (US); Simon Vahr, London (GB); Tareq Alkhatib, Richmond (CA); and Thomas Mathew, New York, NY (US)
Assigned to Palantir Technologies Inc., Denver, CO (US)
Filed by Palantir Technologies Inc., Denver, CO (US)
Filed on Oct. 22, 2019, as Appl. No. 16/660,217.
Claims priority of application No. 1914344 (GB), filed on Oct. 4, 2019.
Prior Publication US 2023/0394083 A1, Dec. 7, 2023
Int. Cl. G06F 21/00 (2013.01); G06F 16/901 (2019.01); H04L 9/40 (2022.01); G06F 21/55 (2013.01)
CPC G06F 16/9024 (2019.01) [G06F 21/552 (2013.01); G06F 21/554 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/1433 (2013.01); H04L 63/20 (2013.01)] 17 Claims
OG exemplary drawing
 
1. A method, performed by one or more processors, comprising:
receiving one or more event records;
generating, using the one or more event records, an event descriptor object descriptive of one or more potential suspicious system events indicative of a cybersecurity threat occurring in a networked system, wherein the event descriptor object comprises a plurality of event properties;
receiving one or more entity records;
generating, using the one or more entity records, an entity descriptor object descriptive of one or more entities relevant to a security of the networked system, wherein the entity descriptor object comprises a plurality of entity properties;
incorporating, into an object graph, the event descriptor object as a first node and the entity descriptor object as a second node;
in response to determining that a value of an entity property of the plurality of entity properties matches a value of an event property of the plurality of event properties, associating, in the object graph, the event descriptor object with the entity descriptor object; and
determining a course of action entity descriptor object descriptive of one or more actions for mitigating the cybersecurity threat, wherein the object graph comprises a link between the event descriptor object and the course of action entity descriptor object.