IP Library Granted Patent US 9,210,185
Granted Patent B1
US 9,210,185 · App. 14/562,623 · Granted Dec 8, 2015

Cyber threat monitor and control apparatuses, methods and systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,210,185
App. No.
14/562,623
Granted
Dec 8, 2015
Kind
B1
Abstract

The cyber threat monitor and control apparatuses, methods and systems (hereinafter “CTMC”) determines risk across a global Internet network graph model for various virtual or physical network elements. In one embodiment, the CTMC defines a factor mechanism representing interactions among the set of network elements, the factor mechanism including a factor indicative of a correlation between a pair of network elements from the set of network elements, and dynamically calculate the probabilistic network security measure for each network element in the global Internet graph model based at least in part on the factor mechanism and any observed threat indicators related to the global Internet graph model.

Claims (40)

1. A non-transitory processor-readable medium storing code representing processor-executable instructions, the code comprising code to cause the processor to:

obtain information of a data model graph having a plurality of nodes and a plurality of edges connecting the plurality of nodes,

a node from the plurality of nodes representing a virtual element or a physical element in a network,

the node having a probabilistic network security measure indicative of potential security risk associated with the node,

an edge from the plurality of edges representing a relationship between two nodes connected by the edge and from the plurality of nodes;

obtain a threat indicator having a characteristic of a categorized assessment of network security risk;

define a factor matrix representing a set of joint threat and safety probabilities for the plurality of nodes based on the relationship for each edge from the plurality of edges, the factor matrix including a factor indicative of a correlation between a pair of nodes from the plurality of nodes;

determine an influence path for the threat indicator in the data model graph based on the factor matrix;

propagate the threat indicator along the influence path to assess influence of the threat indicator on each node in the influence path;

calculate a first updated probabilistic network security measure for a first node on the influence path based at least in part on the characteristic of the threat indicator;

calculate a second updated probabilistic network security measure for a second node on the influence path based at least in part on the first updated probabilistic network security measure and the factor matrix;

dynamically update the data model graph with the first updated probabilistic network security measure and the second updated probabilistic network security measure; and

send a signal to generate a user interface having a user interface widget representing the first updated probabilistic network security measure and the second updated probabilistic network security measure.

2. The medium of claim 1 , wherein the factor has a degrading correlation strength over time based on a historical degradation of the interaction between the pair of nodes.

3. The medium of claim 1 , wherein the code further comprises code to cause the processor to perform one of:

calculate the first updated probabilistic network security measure for the first node individually; or

calculate the first updated probabilistic network security measure for the first node based on a respective probabilistic network security measure associated with a set that contains the first node.

4. The medium of claim 1 , wherein the plurality of nodes include a number of nodes no less than one million.

5. A non-transitory processor-readable medium storing code representing processor-executable instructions, the code comprising code to cause the processor to:

obtain information of a data model graph having a plurality of nodes and a plurality of edges connecting the plurality of nodes,

each node from the plurality of nodes having a probabilistic network security measure indicative of potential security risk associated with that node,

each edge from the plurality of edges representing a relationship between two nodes connected by the edge and from the plurality of nodes;

receive a threat indicator having a characteristic of a categorized assessment of network security risk;

define a factor matrix representing a set of joint threat and safety probabilities for the plurality of nodes, the factor matrix including a factor indicative of a correlation between a pair of nodes from the plurality of nodes;

determine an influence path for the threat indicator in the network graph based on the factor matrix;

dynamically update probabilistic network security measures for each node on the influence path based on the characteristic and the factor matrix; and

send a signal to generate a user interface having a user interface widget representing the dynamically updated probabilistic network security measures.

6. The medium of claim 5 , wherein the probabilistic network security measures for each node on the influence path includes a probability value representing a probability that that node is unsafe to cyber threats.

7. The medium of claim 5 , wherein the probabilistic network security measures for each node on the influence path includes a user-defined default value.

8. The medium of claim 5 , wherein each node from the plurality of nodes includes any of an Internet protocol (IP) host, a classless inter-domain router (CIDR), a fully qualified domain name (FQDN), a autonomous system number (ASN), an application or application identifiers, a group sector, or a user.

9. The medium of claim 5 , wherein the characteristic includes at least one of: a threat indicator identifier, a threat classification, a threat criticality level, or a threat source.

10. The medium of claim 5 , wherein the characteristic includes a probabilistic threat indicator score indicative of a positive assessment of risk or a negative assessment of risk.

11. The medium of claim 5 , wherein the code further comprising code to cause the processor to:

propagate the threat indicator along the influence path to progressively assess influence of the threat indicator on each node in the influence path; and

calculate an updated probabilistic network security measure for each node from the plurality of nodes and along the influence path based at least in part on a probabilistic threat indicator score associated with the threat indicator.

12. The medium of claim 5 , wherein the code further comprising code to cause the processor to:

calculate an aggregated probabilistic network security measure for each node from the plurality of nodes and when that node is influenced by multiple threat indicators.

13. The medium of claim 5 , wherein the probabilistic network security measures are dynamically updated based on the characteristic, the factor matrix, and at least one of a positive indicator or a negative indicator.

14. The medium of claim 5 , wherein the plurality of nodes includes a set of child nodes and a parent node such that a first threat indicator that affects any child node from the set of child nodes propagates a first effect up to the parent node, and a second threat indicator on the parent node propagates down a second effect to the set of child nodes.

15. The medium of claim 5 , wherein probabilistic network security measures of the plurality of nodes in the network graph are dynamically calculated or updated in a horizontally-distributed manner by a number of distributed processors.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
CHANGE OF NAME Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 063821/0591 →
SECURITY INTEREST Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, LLC
To: STIFEL BANK
Reel/Frame 063829/0248 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062871/0797 →
SECURITY INTEREST Recorded May 11, 2022
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0264 →
SECURITY INTEREST Recorded Aug 24, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057275/0234 →
SECURITY INTEREST Recorded Jul 12, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056822/0787 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2015
From: PINNEY WOOD, CHRISTOPHER PAUL; HELMSEN, JOHN JOSEPH; THOMSON, ALLAN; COLEMAN, CHRISTOPHER D.
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 036517/0370 →