US 12,113,822 B1
Graph analysis-based assessment to determine relative node significance
Wah-Kwan Lin, Milton, MA (US); and Paul Deardorff, San Francisco, CA (US)
Assigned to Rapid7, Inc., Boston, MA (US)
Filed by Rapid7, Inc., Boston, MA (US)
Filed on Oct. 28, 2021, as Appl. No. 17/512,753.
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) 20 Claims
OG exemplary drawing
 
1. A system, comprising:
one or more hardware processors with associated memory that implement a graph analysis-based assessment to determine relative node significance, wherein the one or more hardware processors are configured to:
obtain network traffic data associated with a network;
perform a graph analysis-based assessment of the network, including to:
determine, based at least in part on the network traffic data, network traffic paths between a plurality of nodes in the network; and
calculate, for each node of the plurality of nodes and based at least in part on the network traffic paths, a respective centrality value of a respective node indicative of a level of potential disruption to operations of the network if the respective node is attacked or damaged;
identify, based at least in part on the centrality values, at least one significant node in the network; and
determine to perform one or more actions to harden the at least one significant node identified in the network against damage or attack, wherein the one or more actions includes establishing an alert mechanism to trigger an alert responsive to particular conditions being satisfied for the at least one significant node.