IP Library Granted Patent US 10,484,398
Granted Patent B2
US 10,484,398 · App. 14/912,743 · Granted Nov 19, 2019

Threat intelligence on a data exchange layer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,398
App. No.
14/912,743
Granted
Nov 19, 2019
Kind
B2
Abstract

In an example, a threat intelligence controller is configured to operate on a data exchange layer (DXL). The threat intelligence controller acts as a DXL consumer of reputation data for a network object, which may be reported in various different types and from various different sources. Of the devices authorized to act as reputation data producers, each may have its own trust level. As the threat intelligence controller aggregates data from various providers, it may weight the reputation reports according to trust level. The threat intelligence engine thus builds a composite reputation for the object. When it receives a DXL message requesting a reputation for the object, it publishes the composite reputation on the DXL bus.

Claims (76)

1. A threat intelligence apparatus adapted for use on a data exchange layer (DXL), comprising:

a network interface;

a DXL client engine comprising a DXL application programming interface (API) operable for communicatively coupling the apparatus to a DXL via a DXL broker, wherein the DXL is a messaging bus configured to provide endpoint-to-endpoint communication, brokered by a DXL broker, between loosely-coupled dissimilar DXL endpoints, including the threat intelligence apparatus, on a one-to-many publish-subscribe fabric on which a plurality of private DXL topics are to be established between the dissimilar DXL endpoints; and

one or more logic elements comprising a threat intelligence engine operable for:

aggregating reputation data for a network object via a plurality of DXL messages;

computing a composite reputation for the network object;

receiving from a DXL endpoint a DXL request message, via a private topic of the plurality of private topics, for a reputation for the network object; and

providing the composite reputation via a DXL message through the DXL broker and the one-to-many publish-subscribe fabric.

2. The apparatus of claim 1 , wherein the DXL message for providing the composite reputation is a DXL response message directed to the private topic of the plurality of private topics.

3. The apparatus of claim 1 , wherein the DXL message for providing the composite reputation is a DXL message with an object reputation topic.

4. The apparatus of claim 3 , wherein the DXL message for providing the composite reputation comprises an expiry.

5. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining permissions for a DXL message source;

determining that the source has permission to act as a provider of object reputation data; and

permitting object reputation data from the source to be included in the aggregating.

6. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining permissions for a DXL message source;

determining that the source does not have permission to act as a provider of object reputation data; and

blocking object reputation data from the source from being included in the aggregating.

7. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining a weighted permission for a DXL message source;

determining that the weighted permission is sufficient for the source to act as a provider of object reputation data; and

permitting object reputation data from the source to be included in the aggregating, comprising weighting data provided by the source according to the weighted permission.

8. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

receiving a plurality of determinations that the network object is suspect but has not been blocked; and

assigning the composite reputation a score configured to block the network object on a network or subject the network object to additional scrutiny or deep analysis.

9. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

receiving a DXL message indicating that the network object has been blocked by a DXL endpoint; and

publishing a DXL message indicating that the network object should be blocked by all DXL endpoints on the DXL.

10. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

receiving a DXL message indicating that the network object has been blocked by a DXL endpoint; and

publishing a DXL message indicating that the network object should be blocked by a class of DXL endpoints on a network.

11. The apparatus of claim 1 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining that the network object is a new object on a network, and that the new object has been encountered multiple times in a designated time span; and

assigning the composite reputation a suspicious score.

12. The apparatus of claim 1 , further comprising a reputation store.

13. The apparatus of claim 12 , wherein the reputation store is a self-replicating NoSQL database.

14. One or more non-transitory computer-readable mediums having stored thereon executable instructions for providing a threat intelligence engine comprising a DXL application programming interface (API) operable for:

communicatively coupling to a data exchange layer (DXL) via a DXL broker, wherein the DXL is a messaging bus configured to provide endpoint-to-endpoint communication, brokered by a DXL broker, between loosely-coupled dissimilar DXL endpoints, including the threat intelligence apparatus, on a one-to-many publish-subscribe fabric on which a plurality of private DXL topics are to be established between the dissimilar DXL endpoints;

subscribing to a DXL object reputation topic;

aggregating reputation data for a network object via a plurality of object reputation DXL messages;

computing a composite reputation for the network object;

receiving from a DXL endpoint a DXL request message, via a private topic of the plurality of private topics, for a reputation for the network object; and

providing the composite reputation via a DXL message through the DXL broker and the one-to-many publish-subscribe fabric.

15. The one or more non-transitory computer-readable mediums of claim 14 , wherein the DXL message for providing the composite reputation is a DXL response message directed to the private topic of the DXL endpoint.

16. The one or more non-transitory computer-readable mediums of claim 14 , wherein the DXL message for providing the composite reputation is a DXL message with an object reputation topic.

17. The one or more non-transitory computer-readable mediums of claim 14 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining permissions for a DXL message source;

determining that the source has permission to act as a provider of object reputation data; and

permitting object reputation data from the source to be included in the aggregating.

18. The one or more non-transitory computer-readable mediums of claim 14 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining a weighted permission for a DXL message source;

determining that the weighted permission is sufficient for the source to act as a provider of object reputation data; and

permitting object reputation data from the source to be included in the aggregating, comprising weighting data provided by the source according to the weighted permission.

19. The one or more non-transitory computer-readable mediums of claim 14 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

receiving a plurality of determinations that the network object is suspect but has not been blocked; and

assigning the composite reputation a score configured to block the network object on a network or subject the network object to additional scrutiny or deep analysis.

20. The one or more non-transitory computer-readable mediums of claim 14 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

receiving a DXL message indicating that the network object has been blocked by a DXL endpoint; and

publishing a DXL message indicating that the network object should be blocked by all DXL endpoints on the DXL.

21. The one or more non-transitory computer-readable mediums of claim 14 , wherein aggregating reputation data for the network object via the plurality of DXL messages comprises:

determining that the network object is a new object on a network, and that the new object has been encountered multiple times in a designated time span; and

assigning the composite reputation a suspicious score.

22. The one or more non-transitory computer-readable mediums of claim 14 , further comprising a reputation store.

23. The one or more non-transitory computer-readable mediums of claim 22 , wherein the reputation store is a self-replicating NoSQL database.

24. A method of providing a server engine, comprising a DXL application programming interface (API) in a threat intelligence engine apparatus, and further comprising:

communicatively coupling to a data exchange layer (DXL) via a DXL broker, wherein the DXL is a messaging bus configured to provide endpoint-to-endpoint communication, brokered by a DXL broker, between loosely-coupled dissimilar DXL endpoints, including the threat intelligence apparatus, on a one-to-many publish-subscribe fabric on which a plurality of private DXL topics are to be established between the dissimilar DXL endpoints;

subscribing to a DXL object reputation topic;

aggregating reputation data for a network object via a plurality of object reputation DXL messages;

computing a composite reputation for the network object;

receiving from a DXL endpoint a DXL request message, via a private topic of the plurality of private topics, for a reputation for the network object; and

providing the composite reputation via a DXL message through the DXL broker and the one-to-many publish-subscribe fabric.

25. The method of claim 24 , further comprising:

determining permissions for a DXL message source;

determining that the source has permission to act as a provider of object reputation data; and

permitting object reputation data from the source to be included in the aggregating.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2016
From: SMITH, CHRISTOPHER; MCDONALD, EDWARD T.; HANSON, DON R., II
To: MCAFEE, INC.
Reel/Frame 037768/0129 →