IP Library Granted Patent US 10,367,829
Granted Patent B2
US 10,367,829 · App. 14/946,088 · Granted Jul 30, 2019

Protecting threat indicators from third party abuse

Inventors: Wei Huang (Los Altos Hills, CA); Yizheng Zhou (Cupertino, CA); Hugh Njemanze (Redwood City, CA)
Assignee: Anomali Incorporated
H04L63/1416G06F21/554G06F21/577H04L63/06H04L63/1433G06F2221/2101G06F2221/2115H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,829
App. No.
14/946,088
Filed
Nov 19, 2015
Granted
Jul 30, 2019
Kind
B2
Art Unit
2437
USPC
726/23
Abstract

A threat analytics system expends significant resources to acquire, structure, and filter the threat indicators provided to the client-side monitoring systems. To protect the threat indicators from misuse, the threat analytics system only provides enough information about the threat indicators to the client-side systems to allow the client-side systems to detect past and ongoing threats. Specifically, the threat analytics system provides obfuscated threat indicators to the client-side monitoring systems. The obfuscated threat indicators enable the client-side systems to detect threats while protecting the threat indicators from misuse or malicious actors.

Claims (37)

1. A computer-based method for detecting threats based on obfuscated threat indicators, the method comprising:

receiving, from a server, an obfuscated threat indicator associated with an identified cyber-threat that was determined by the server to be above a threshold level of quality, the obfuscated threat indicator having been generated by the server responsive to determining that the identified-cyber-threat is above the threshold level of quality by: including a threat data source of a threat indicator and excluding raw information of the threat indicator;

identifying one or more client-side events occurring within a third-party system, each client-side event identified by an entity identifier indicating an entity to which the client-side event is attributed;

determining that the third-party system experienced a cyber-threat when the obfuscated threat indicator matches at least one entity identifier; and

in response to determining that the third-party system experienced the cyber-threat:

generating descriptive information associated with the obfuscated threat indicator; and

transmitting the descriptive information to the third-party system.

2. The computer-based method of claim 1 , further comprising obfuscating the entity identifier by excluding raw information related to the entity.

3. The computer-based method of claim 1 , further comprising reporting the cyber-threat to the third-party system when the obfuscated threat indicator matches at least one obfuscated entity identifier.

4. The computer-based method of claim 1 , wherein generating the descriptive information comprises de-obfuscating the obfuscated threat indicator using a decryption key.

5. The computer-based method of claim 1 , wherein the threat data source is not a client.

6. The computer-based method of claim 1 , wherein the obfuscated threat indicator was generated using a hashing algorithm.

7. The computer-based method of claim 1 , wherein the obfuscated threat indicator was generated using an encryption algorithm.

8. The computer-based method of claim 1 , further comprising:

purging the obfuscated threat indicator when the obfuscated threat indicator expires, and

subsequently receiving a second obfuscated threat indicator associated with the identified cyber-threat, the second obfuscated threat indicator being different from the obfuscated threat indicator.

9. A computer program product for detecting threats based on obfuscated threat indicators, the computer program product comprising a non-transitory computer-readable storage medium containing computer program code for:

receiving, from a server, an obfuscated threat indicator associated with an identified cyber-threat that was determined by the server to be above a threshold level of quality, the obfuscated threat indicator having been generated by the server responsive to determining that the identified cyber-threat is above the threshold level of quality by: including a threat data source of a threat indicator and excluding raw information of the threat indicator;

identifying one or more client-side events occurring within a third-party system, each client-side event identified by an entity identifier indicating an entity to which the client-side event is attributed;

obfuscating the entity identifier by excluding raw information related to the entity;

determining that the third-party system experienced a cyber-threat when the obfuscated threat indicator matches at least one obfuscated entity identifier; and

in response to determining that the third-party system experienced the cyber-threat:

generating descriptive information associated with the obfuscated threat indicator; and

transmitting the descriptive information to the third-party system.

10. The computer program product of claim 9 , further comprising reporting the cyber-threat to the third-party system when the obfuscated threat indicator matches at least one obfuscated entity identifier.

11. The computer program product of claim 9 , wherein generating the descriptive information comprises de-obfuscating the obfuscated threat indicator using a decryption key.

12. The computer program product of claim 9 , wherein the threat data source is not a client.

13. The computer program product of claim 9 , further comprising:

purging the obfuscated threat indicator when the obfuscated threat indicator expires, and

subsequently receiving a second obfuscated threat indicator associated with the identified cyber-threat, the second obfuscated threat indicator being different from the obfuscated threat indicator.

14. A computer-based method for transmitting threat information to client modules, the method comprising:

generating, at a server, obfuscated threat indicators associated with identified cyber-threats that are determined to be above a threshold level of quality, each respective obfuscated threat indicator having been generated responsive to determining that a respective cyber-threat is above the threshold level of quality by: including a threat data source of a threat indicator and excluding raw information of the threat indicator;

determining, by the server, that the obfuscated threat indicators are available for transmission to a client module;

determining, by the server, whether a threat detection report associated with the obfuscated threat indicators was received from the client module; and

transmitting, by the server, the obfuscated threat indicators to the client module in response to determining that the threat detection report was received from the client module.

15. The computer-based method of claim 14 , further comprising process the threat detection report to evaluate a relevance between the obfuscated threat indicators and a client system associated with the client module.

16. The computer-based method of claim 14 , wherein transmitting the obfuscated threat indicators comprises obfuscating the additional threat indicators prior to transmission and transmitting the obfuscated threat indicators to the client module.

Assignments (2)
CHANGE OF NAME Recorded Mar 30, 2016
From: THREAT STREAM INC.
To: ANOMALI INCORPORATED
Reel/Frame 038310/0753 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2016
From: HUANG, WEI; ZHOU, YIZHENG; NJEMANZE, HUGH
To: THREAT STREAM, INC.
Reel/Frame 038073/0664 →
Continuity (1)
Related Publication 20170149802A1 · May 25, 2017
Cited By (51)
US 12,204,921 US 12,206,708 US 12,224,992 US 12,225,042 US 12,225,055 US 12,229,837 US 12,236,172 US 12,267,347 US 12,267,369 US 12,284,221 US 12,301,626 US 12,335,310 US 12,335,317 US 12,355,809 US 12,401,627 US 12,406,310 US 12,407,735 US 12,438,851 US 12,438,906 US 12,438,916 US 12,443,999 US 12,452,284 US 12,452,307 US 12,457,223 US 12,462,016 US 12,483,599 US 12,489,791 US 12,493,914 US 12,494,916 US 12,500,767 US 12,500,823 US 12,500,920 US 12,500,929 US 12,500,938 US 12,500,941 US 12,506,715 US 12,506,754 US 12,536,593 US 12,556,523 US 12,598,197 US 12,621,311 US 12,634,345 US 12,641,123 US 12,641,127 US 12,671,715 US 12,695,733 US 12,701,106 US 12,712,916 US 12,719,932 US 12,719,933 US 12,726,521