US 12,348,535 B2
Indicators of compromise of access
John Eugene Neystadt, Kfar-Saba (IL); and Liron Raveh, Pardes Hanna-Karkur (IL)
Assigned to VARONIS SYSTEMS, INC.
Filed by VARONIS SYSTEMS, INC., New York, NY (US)
Filed on Dec. 29, 2022, as Appl. No. 18/090,583.
Prior Publication US 2024/0223577 A1, Jul. 4, 2024
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 63/1441 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method of prioritizing and handling events in a network, comprising:
receiving notification of an event;
identifying an account that triggered the event;
determining a group to which the account belongs;
determining an account blast radius for each account in the group and a group blast radius for the group; wherein the account blast radius represents an exposure level of accounts belonging to the group to data in the network relative to data of other accounts in the network; and wherein the group blast radius is calculated by summing up the account blast radiuses of the accounts in the group;
applying rules to prioritize handling of the events taking into consideration the group and group blast radius.