IP Library Granted Patent US 8,931,095
Granted Patent B2
US 8,931,095 · App. 14/046,161 · Granted Jan 6, 2015

System and method for assessing whether a communication contains an attack

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,931,095
App. No.
14/046,161
Granted
Jan 6, 2015
Kind
B2
Abstract

Communications can be processed with multiple countermeasures to identify attacks. Each countermeasure can compute a probability of a communication containing an attack and an accompanying confidence score indicating confidence in the probability. Combining the probabilities can produce a composite probability and associated confidence of the communication containing an attack. The composite probability and confidence scores can be produced from a weighted combination of the individual countermeasure probabilities and confidence scores. Weighting factors can be generated or obtained from a database that stores profiles of confirmed attacks.

Claims (41)

1. A method for assessing whether a communication contains an attack, the method comprising:

computing, at an attack detection device, a first probability that the communication contains an attack and a first confidence in the first probability in response to conducting a first counter-measure assessment on the communication;

computing a second probability that the communication contains an attack and a second confidence in the second probability in response to conducting a second countermeasure assessment on the communication; and

producing a third probability that the communication contains an attack and a third confidence in the third probability based on the first probability, the first confidence, the second probability, the second confidence, and hierarchical parameters aggregated from locations remote from the attack detection device, wherein the locations utilize an attack detection system of a common vendor, wherein the producing the third probability comprises computing the third probability from a weighted combination of the first and second probabilities, the weighted combination comprising using weights determined by reference to at least two characteristics of the communication to a database of historical attack characteristics.

2. The method of claim 1 , wherein the weighted combination of the first and second probabilities comprises weights based on at least one of industry, client, site, and device of the communication.

3. The method of claim 1 , wherein the communication comprises a network transmission.

4. The method of claim 1 , wherein the communication comprises a log message.

5. The method of claim 1 , further comprising:

determining whether the third probability and the third confidence meet a predetermined criterion; and

adding attack profile data to a database in response to the determining.

6. The method of claim 1 , further comprising:

determining whether the third probability exceeds a first threshold and the third confidence exceeds a second threshold; and

adding attack profile data to a database in response to determining that the third probability exceeds the first threshold and the third confidence exceeds the second threshold.

7. The method of claim 6 , further comprising:

determining whether the third probability exceeds a third threshold and the third confidence exceeds a fourth threshold; and

transmitting an alert signal in response to determining that the third probability exceeds the third threshold and the third confidence exceeds the fourth threshold, wherein the third threshold is different than the first threshold, and the fourth threshold is different than the second threshold.

8. A non-transitory computer-readable medium including code for performing a method, the method comprising:

computing a first probability that a communication contains an attack and a first confidence in the first probability in response to conducting a first counter-measure assessment on the communication;

computing a second probability that the communication contains an attack and a second confidence in the second probability in response to conducting a second countermeasure assessment on the communication; and

producing a third probability that the communication contains an attack and a third confidence in the third probability based on the first probability, the first confidence, the second probability, the second confidence, and hierarchical parameters aggregated from locations remote from the attack detection device, wherein the locations utilize an attack detection system of a common vendor, wherein the producing the third probability comprises computing the third probability from a weighted combination of the first and second probabilities, the weighted combination comprising using weights determined by reference to at least two characteristics of the communication to a database of historical attack characteristics.

9. The computer-readable medium of claim 8 , wherein the weighted combination of the first and second probabilities comprises weights based on at least one of industry, client, site, and device of the communication.

10. The computer-readable medium of claim 8 , wherein the communication comprises a network transmission.

11. The computer-readable medium of claim 8 , wherein the communication comprises a log message.

12. The computer-readable medium of claim 8 , further comprising:

determining whether the third probability and the third confidence meet a predetermined criterion; and

adding attack profile data to a database in response to the determining.

13. The computer-readable medium of claim 8 , further comprising:

determining whether the third probability exceeds a first threshold and the third confidence exceeds a second threshold;

adding attack profile data to a database in response to determining that the third probability exceeds the first threshold and the third confidence exceeds the second threshold;

determining whether the third probability exceeds a third threshold and the third confidence exceeds a fourth threshold; and

transmitting an alert signal in response to determining that the third probability exceeds the third threshold and the third confidence exceeds the fourth threshold, wherein the third threshold is different than the first threshold, and the fourth threshold is different than the second threshold.

14. An attack detection device comprising:

a memory for storing machine-executable code; and

a processor operable to:

conduct a first counter-measure assessment on a communication;

compute a first probability that the communication contains an attack and a first confidence in the first probability in response to the first counter-measure assessment;

conduct a second counter-measure assessment on a communication;

compute a second probability that the communication contains an attack and a second confidence in the second probability in response to the second countermeasure assessment; and

produce a third probability that the communication contains an attack and a third confidence in the third probability based on the first probability, the first confidence, the second probability, the second confidence, and hierarchical parameters aggregated from locations remote from the attack detection device, wherein the locations utilize an attack detection system of a common vendor, wherein in producing the third probability, the processor is further operable to compute the third probability from a weighted combination of the first and second probabilities, the weighted combination comprising using weights determined by reference to at least two characteristics of the communication to a database of historical attack characteristics.

15. The attack detection device of claim 14 ,

wherein the weighted combination of the first and second probabilities further comprises weights based on at least one of industry, client, site, and device of the communication.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2025
From: RAMSEY, JON R.; VARMA, JYOTHISH S.; THOMAS, ASHLEY; SCHMIDT, KEVIN J.; STEWART, JOSEPH NEAL; RISTICH, RUDY ALEXANDER; PEPIN, JOAN
To: SECUREWORKS, INC.
Reel/Frame 072808/0791 →
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
ENTITY CONVERSION WITH NAME CHANGE Recorded Dec 8, 2015
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 037243/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2015
From: DELL PRODUCTS L.P.
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 036262/0417 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0490 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0509 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0525 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →