IP Library Granted Patent US 10,095,866
Granted Patent B2
US 10,095,866 · App. 14/936,593 · Granted Oct 9, 2018

System and method for threat risk scoring of security threats

Inventors: Fengmin Gong (Livermore, CA); Frank Jas (Scotts Valley, CA); Druce MacFarlane (Aptos, CA)
Assignee: Cyphort Inc.
G06F21/561G06F21/564G06F21/577H04L63/145H04L63/1416H04L41/06H04L43/04H04L43/06H04L43/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,095,866
App. No.
14/936,593
Granted
Oct 9, 2018
Kind
B2
Abstract

A system configured to generate a risk score for a threat activity including a digital device. The digital device configured to extract one or more threat events on a network based on metadata for one or more targeted digital devices on the network. Further, the digital device is configured to detect one or more incidents based on a correlation between at least a first threat event of the one or more threat events and a second threat event of the one or more threat events. And, the digital device is configured to generate a risk score for each of said one or more incidents.

Claims (74)

1. A system comprising:

a device to:

inspect one or more network activities on a network;

generate metadata associated with malware activity based on inspecting the one or more network activities;

extract one or more threat events on the network based on the metadata;

detect one or more incidents based on a correlation between a first threat event, of the one or more threat events, and a second threat event of the one or more threat events,

the correlation being determined based on the metadata and a kill chain progression of the one or more threat events;

generate risk scores for the one or more incidents based on the kill chain progression,

the risk scores being based on one or more asset values for one or more targeted devices, and

a first score, associated with a first stage of the kill chain progression, of the risk scores being lower than a second score, associated with a second stage of the kill chain progression, of the risk scores; and

mitigate the one or more incidents based on the risk scores,

the mitigation including quarantining data associated with the one or more network activities.

2. The system of claim 1 , wherein the device, when inspecting the one or more network activities, is to:

inspect the one or more network activities using at least one of:

static analysis,

sandbox detonation, or

machine learning.

3. The system of claim 1 , wherein the device, when inspecting the one or more network activities, is to:

inspect one or more protocols.

4. The system of claim 1 , wherein the device, when inspecting the one or more network activities, is to:

inspect one or more applications; and

wherein the device, when generating the metadata, is to:

generate the metadata based on inspecting the one or more applications.

5. The system of claim 1 , wherein the one or more threat events are time stamped.

6. The system of claim 1 , wherein the device is further to:

correlate the one or more threat events based on a time stamp for each of the one or more threat events.

7. The system of claim 1 , wherein the device is further to:

correlate the one or more threat events based on an Internet protocol address for each of the one or more threat events.

8. The system of claim 1 , wherein the device is further to:

correlate the one or more threat events over a period of time.

9. The system of claim 1 , wherein the risk scores are based on a threat severity value associated with the one or more incidents.

10. The system of claim 1 , wherein the risk scores are based on a threat relevance value associated with the one or more incidents.

11. The system of claim 1 , where the device is further to:

process the data associated with the one or more network activities in an emulated environment.

12. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

inspect one or more network activities on a network;

generate metadata associated with malware activity based on inspecting the one or more network activities;

extract one or more threat events on the network from the metadata;

detect one or more incidents based on a correlation between a first threat event of the one or more threat events, and a second threat event of the one or more threat events,

the correlation being determined based on the metadata and a kill chain progression of the one or more threat events;

generate a risk score for each incident of the one or more incidents based on the kill chain progression,

the risk score being based on an asset value for a targeted device, and

a first score, associated with a first stage of the kill chain progression, being lower than a second score associated with a second stage of the kill chain progression; and

mitigate the one or more incidents based on the risk score,

the mitigation including quarantining data associated with the one or more network activities.

13. The non-transitory computer-readable medium of claim 12 , wherein, the one or more instructions, that cause the one or more processors to inspect the one or more network activities, cause the one or more processors to:

inspect the one or more network activities using at least one of:

a static analysis,

a sandbox detonation, or

machine learning.

14. The non-transitory computer-readable medium of claim 12 , wherein the one or more instructions, that cause the one or more processors to inspect the one or more network activities, cause the one or more processors to:

inspect one or more protocols.

15. The non-transitory computer-readable medium of claim 12 , wherein the one or more instructions, that cause the one or more processors to inspect the one or more network activities, cause the one or more processors to:

inspect one or more applications; and

where the one or more instructions, that cause the one or more processors to generate the metadata, cause the one or more processors to:

generate the metadata based on inspecting the one or more applications.

16. The non-transitory computer-readable medium of claim 12 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

correlate the one or more threat events over a period of time.

17. A method, comprising:

inspecting, by a device, one or more network activities on a network;

generating, by the device, metadata associated with malware activity based on inspecting the one or more network activities;

extracting, by the device, one or more threat events on the network from the metadata;

detecting, by the device, one or more incidents based on a correlation between a first threat event of the one or more threat events and a second threat event of the one or more threat events,

the correlation being determined based on a kill chain progression of the one or more threat events; and

generating, by the device, a risk score for each incident of the one or more incidents based on the kill chain progression,

the risk score being based on an asset value of a targeted device; and

mitigating, by the device, the one or more incidents based on the risk score,

the mitigating including quarantining data associated with the one or more network activities.

18. The method of claim 17 , wherein mitigating the one or more incidents comprises:

sending an alert to an administrator.

19. The method of claim 17 , wherein mitigating the one or more incidents comprises:

flag the data associated with the one or more network activities.

20. The method of claim 17 , wherein the risk score is determined in real time.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded May 6, 2026
From: CYPHORT INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 075513/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2017
From: GONG, FENGMIN; JAS, FRANK; MACFARLANE, DRUCE
To: CYPHORT INC.
Reel/Frame 043378/0737 →
Continuity (3)
Continuation In Part 14629444 · Feb 23, 2015
Provisional Application 61944006 · Feb 24, 2014
Related Publication 20160078229A1 · Mar 17, 2016
Cited By (8)
US 12,417,292 US 12,445,466 US 12,452,289 US 12,470,593 US 12,572,846 US 12,574,399 US 12,659,323 US 12,695,752