IP Library Granted Patent US 10,601,853
Granted Patent B2
US 10,601,853 · App. 15/245,458 · Granted Mar 24, 2020

Generation of cyber-attacks investigation policies

Inventor: Avi Chesla (Tel-Aviv, IL)
Assignee: Empow Cyber Security Ltd.
H04L63/1433H04L63/1416H04L63/1425H04L63/20H04L63/1441H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,601,853
App. No.
15/245,458
Granted
Mar 24, 2020
Kind
B2
Abstract

A system and method for generating policies for investigating cyber-security attacks are provided. The method includes selecting at least one entity of interest (EoI); determining at least one detection event associated with the at least one EoI; processing the at least one detection event to create a plurality of investigation rules, wherein each of the plurality of investigation rules includes a set of filters utilized to identify malicious activity related the at least one EoI; and defining an investigation policy for the EoI, wherein the defined investigation policy includes the plurality of investigation rules.

Claims (54)

1. A method for generating policies for investigating cyber-security attacks, comprising:

selecting at least one security product as a source for attack logs input to at least one investigator security engine, wherein the selection is based on a performance score of the at least one security product;

generating a risk chain for a multivector attack based on information received from the at least one security product;

determining a risk level for the risk chain;

selecting at least one entity of interest (EoI) designated in the risk-chain representing a potential cyber-attack;

determining at least one detection event associated with the at least one EoI;

processing the at least one detection event to create a plurality of investigation rules, wherein each of the plurality of investigation rules includes a set of filters utilized to identify malicious activity against the at least one EoI; and

defining an investigation policy for the EoI, wherein the defined investigation policy includes the plurality of investigation rules.

2. The method of claim 1 , wherein selecting the at least one EoI further comprises: selecting an entity designated in an event that triggered an investigation function.

3. The method of claim 2 , wherein the at least one detection event is any one of: an event that causes the inclusion of the at least one EoI in the risk-chain, and the event that triggered an investigation function.

4. The method of claim 1 , further comprising:

defining at least one filter for each of the plurality of investigation rules.

5. The method of claim 4 , wherein the at least one filter for each of the plurality of investigation rules is based on any one of: a source entity, a destination entity, a time, and application path.

6. The method of claim 1 , wherein processing the at least one detection event to create the plurality of investigation rules further comprises:

identifying a detector security engine responsible for causing generation of the at least one detection event; and

determining the at least one investigator security engine.

7. The method of claim 6 , further comprising:

configuring the at least one investigator security engine and the detector security engine to carry out the investigation policy.

8. The method of claim 6 , wherein the at least one investigator security engine and the detector security engine are any of: the same security engine, and different security engines, wherein each of the at least one investigator security engine and the detector security engine is configured to detect and investigate threats by processing attack logs generated by the at least one security product communicatively connected thereto.

9. The method of claim 8 , further comprising:

normalizing the attack logs into a unified data structure, wherein the unified data structure is processed by the at least one investigator security engine.

10. The method of claim 1 , wherein the malicious activity related to the at least one EoI comprises at least one of: past malicious activity performed against at the least one EoI, past malicious activity performed by the at least one EoI, future malicious activity to be performed by the at least one EoI, and future malicious activity performed against at least one EoI.

11. A non-transitory computer readable medium having stored thereon instructions for causing one or more processing units to execute a method, the method comprising:

selecting at least one security product as a source for attack logs input to at least one investigator security engine, wherein the selection is based on a performance score of the at least one security product;

generating a risk chain for a multivector attack based on information received from the at least one security product;

determining a risk level for the risk chain;

selecting at least one entity of interest (EoI) designated in the risk-chain representing a potential cyber-attack;

determining at least one detection event associated with the at least one EoI;

processing the at least one detection event to create a plurality of investigation rules, wherein each of the plurality of investigation rules includes a set of filters utilized to identify malicious activity against the at least one EoI; and

defining an investigation policy for the EoI, wherein the defined investigation policy includes the plurality of investigation rules.

12. A system for generating policies for investigating cyber-security attacks, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

select at least one security product as a source for attack logs input to at least one investigator security engine, wherein the selection is based on a performance score of the at least one security product;

generate a risk chain for a multivector attack based on information received from the at least one security product;

determine a risk level for the risk chain;

select at least one entity of interest (EoI) designated in the risk-chain representing a potential cyber-attack;

determine at least one detection event associated with the at least one EoI;

process the at least one detection event to create a plurality of investigation rules, wherein each of the plurality of investigation rules includes a set of filters utilized to identify malicious activity against the at least one EoI; and

define an investigation policy for the EoI, wherein the defined investigation policy includes the plurality of investigation rules.

13. The system of claim 12 , wherein the system is further configured to select an entity designated in an event that triggered an investigation function.

14. The system of claim 13 , wherein the at least one detection event is any one of: an event that causes the inclusion of the at least one EoI in the risk-chain, and the event that triggered an investigation function.

15. The system of claim 12 , wherein the system is further configured to:

define at least one filter for each of the plurality of investigation rules.

16. The system of claim 15 , wherein the at least one filter for each of the plurality of investigation rules is based on any one of: a source entity, a destination entity, a time, and application path.

17. The system of claim 12 , wherein processing the at least one detection event to create the plurality of investigation rules further comprises:

identifying a detector security engine responsible for causing generation of the at least one detection event; and

determining the at least one investigator security engine.

18. The system of claim 17 , wherein the system is further configured to:

configure the at least one investigator security engine and the detector security engine to carry out the investigation policy.

19. The system of claim 17 , wherein the at least one investigator security engine and the detector security engine are any of: the same security engine, and different security engines, wherein each of the at least one investigator security engine and the detector security engine is configured to detect and investigate threats by processing attack logs generated by at least one security product communicatively connected thereto.

20. The system of claim 19 , wherein the system is further configured to:

normalize the attack logs into a unified data structure, wherein the unified data structure is processed by the at least one investigator security engine.

21. The system of claim 12 , wherein the malicious activity related to the at least one EoI comprises at least one of: past malicious activity performed against at the least one EoI, past malicious activity performed by the at least one EoI, future malicious activity to be performed by the at least one EoI, and future malicious activity performed against at least one EoI.

Assignments (8)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: EMPOW CYBER SECURITY LTD.; EMPOW CYBER SECURITY INC.
To: CYBEREASON INC.
Reel/Frame 056792/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2016
From: CHESLA, AVI
To: EMPOW CYBER SECURITY LTD
Reel/Frame 039522/0175 →
Cited By (1)
US 12,615,270