IP Library Granted Patent US 12670455
Granted Patent B2
US 12670455 · App. 17/705,666 · Granted Jun 30, 2026

Dynamically updated user interface for threat investigation

Inventors: Joshua Daniel Saxe (Wichita, KS); Andrew J. Thomas (Oxfordshire, GB); Russell Humphries (Surrey, GB); Simon Neil Reed (Wokingham, GB); Kenneth D. Ray (Seattle, WA); Joseph H. Levy (Farmington, UT)
Assignee: Sophos Limited
G06Q10/0635G06F9/542G06F11/079G06F16/955G06F17/18G06F18/214G06F18/2178G06F18/23213G06F18/24143G06F21/554G06F21/56G06F21/562G06F21/565G06N5/01G06N5/022G06N5/04G06N5/046G06N7/00G06N20/00G06N20/20G06Q10/06395G06V20/52H04L63/0227H04L63/0263H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20G06Q30/0185G06Q30/0283
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12670455
App. No.
17/705,666
Granted
Jun 30, 2026
Kind
B2
Abstract

A technique for dynamically updating a user interface for threat investigation may include receiving a scheduled transmittal of events in an event stream from an endpoint at a threat management facility, processing the event stream at the threat management facility to detect an intermediate threat, in response to detecting the intermediate threat at the threat management facility, requesting a transmittal of supplemental information from a data recorder on the endpoint, receiving the supplemental information in a supplemental transmittal from the endpoint to the threat management facility, and displaying a description of the intermediate threat and the supplemental information in a user interface hosted by the threat management facility, where the user interface is configured for user investigation and disposition of the intermediate threat.

Claims (36)

1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

receiving a scheduled transmittal of events in an event stream pushed from an endpoint on a predetermined schedule at a threat management facility;

processing the event stream at the threat management facility to detect an intermediate threat associated with the endpoint;

in response to detecting the intermediate threat at the threat management facility, automatically requesting a transmittal of supplemental information pulled by the threat management facility from a data recorder on the endpoint to supplement the event stream pushed from the endpoint on the predetermined schedule with event data from a window of time preceding a detection by the threat management facility of the intermediate threat;

receiving the supplemental information in a supplemental transmittal from the endpoint to the threat management facility; and

displaying a description of the intermediate threat and the supplemental information in a user interface hosted by the threat management facility, the user interface configured for user investigation and disposition of the intermediate threat.

2 . The computer program product of claim 1 , wherein the description includes a threat sample associated with the intermediate threat.

3 . The computer program product of claim 1 , wherein the user interface displays a list of similar threat samples ranked according to a similarity to the intermediate threat.

4 . The computer program product of claim 3 , wherein the similarity includes at least one of similarity of executable code, similarity of behaviors, similarity of filenames, and similarity of URLs called.

5 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of transmitting a remediation of a malware threat detected on the endpoint based on the event stream from the endpoint and the supplemental transmittal from the endpoint.

6 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of transmitting a filter adjustment from the threat management facility to the endpoint for use by the endpoint in adjusting filtering of events in the event stream.

7 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of augmenting the description of the intermediate threat with a suspiciousness score based on an analysis of features of a threat sample associated with the intermediate threat.

8 . The computer program product of claim 1 , wherein the event stream includes a plurality of causally related events.

9 . The computer program product of claim 1 , wherein the event stream includes events based on at least one of a file read, a file write, and a file copy.

10 . The computer program product of claim 1 , wherein the event stream includes events based on at least one of a file encrypt and a file decrypt.

11 . The computer program product of claim 1 , wherein the event stream includes events based on at least one of a registry update, a software installation, a change in permissions, and a remote resource query.

12 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of displaying an augmented description of the intermediate threat with contextual information including one or more of users associated with the intermediate threat, processes related to the intermediate threat, data sources associated with the intermediate threat, files associated with the intermediate threat, a software update history associated with the intermediate threat, and a status of the endpoint.

13 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of displaying an augmented description of the intermediate threat with contextual information including one or more of a signature analysis of the intermediate threat and a behavioral analysis of the intermediate threat.

14 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of displaying an augmented description of the intermediate threat including quantitative data about one or more human-interpretable features of the intermediate threat.

15 . The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform the step of displaying an augmented description of the intermediate threat including at least one of a similar one of a number of safe threat samples and a similar one of a number of unsafe threat samples.

16 . A method comprising:

receiving, at a threat management facility, a scheduled transmittal of events in an event stream pushed from an endpoint on a predetermined schedule;

detecting an intermediate threat on the endpoint based on the event stream;

in response to detecting the intermediate threat, automatically requesting a transmittal of supplemental information pulled by the threat management facility from a data recorder on the endpoint to supplement the event stream pushed from the endpoint on the predetermined schedule with event data from a window of time preceding a detection by the threat management facility of the intermediate threat;

receiving the supplemental information; and

displaying the intermediate threat and the supplemental information in a user interface for user disposition of the intermediate threat.

17 . The method of claim 16 , further comprising displaying, in the user interface, a suspiciousness score based on a genetic analysis of features of the intermediate threat.

18 . The method of claim 16 , wherein the event stream includes a plurality of causally related events.

19 . The method of claim 16 , wherein the event stream includes events based on at least one of a file read, a file write, a file copy, a file encrypt, a file decrypt, a registry update, a software installation, a change in permissions, and a remote resource query.

20 . A system comprising:

an endpoint executing a data recorder to store an event stream of event data including a plurality of types of changes to a plurality of computing objects detected on the endpoint, the endpoint further executing a local agent configured to process the event stream with a filter into a filtered event stream, the local agent further configured to communicate a scheduled transmittal of the filtered event stream to a remote resource over a data network on a predetermined schedule; and

a threat management facility configured to:

receive the filtered event stream pushed from the endpoint;

process the filtered event stream to identify an intermediate threat;

in response to identifying the intermediate threat, automatically request a transmittal of supplemental information pulled by the threat management facility from the data recorder of the endpoint to supplement the event stream pushed from the endpoint on the predetermined schedule with event data from a window of time preceding a detection by the threat management facility of the intermediate threat; and

display the intermediate threat and the supplemental information in a user interface configured for user disposition of the intermediate threat.