IP Library Granted Patent US 10,027,705
Granted Patent B1
US 10,027,705 · App. 15/457,403 · Granted Jul 17, 2018

Apparatuses, methods and systems for a real-time cyber threat indicator verification mechanism

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,027,705
App. No.
15/457,403
Granted
Jul 17, 2018
Kind
B1
Abstract

The real-time cyber threat indicator verification mechanism technology (hereinafter “TIVM”) instantiates one or more virtual client emulators to access a source of a threat, in response to a received threat indicator, so as to evaluate validity and/or severity of the potential threat. In one embodiment, the TIVM may receive a cyber threat indicator having identifying information of a cyber threat source; instantiate, in response to the cyber threat indicator, a virtual client emulator; send a control message to cause the virtual client emulator to interact with the cyber threat source based on the identifying information; obtain a confidence indicator relating to the cyber threat indicator based on interaction between the virtual client emulator and the cyber threat source; and generate a cyber threat indicator confirmation report including the confidence indicator.

Claims (65)

1. A non-transitory processor-readable medium storing code representing processor-executable instructions, the code comprising code to cause a processor to:

receive information related to a cyber threat indicator of a type, the cyber threat indicator including identifying information of a target host and information related to malware behavior;

instantiate a virtual client emulator selected based on the type of the cyber threat indicator in response to receiving the information related to the cyber threat indicator, the virtual client emulator configured to emulate a client of the target host;

send an access request from the virtual client emulator to the target host based on the identifying information;

receive a response from the target host based on the access request; and

send a signal to a compute device based on the response such that the compute device performs a cyber threat mitigation action on compute devices within control of the compute device and associated with communications from the target host.

2. The non-transitory processor-readable medium of claim 1 , wherein the code to receive the response includes code to receive the response based on interaction between the virtual client emulator and the target host.

3. The non-transitory processor-readable medium of claim 1 , wherein:

the code to receive the response includes (1) code to receive malicious code from the target host in response to the access request and (2) code to receive information on the target host including retrievable malware instances and executable components from the target host.

4. The non-transitory processor-readable medium of claim 1 , wherein the code further includes code to:

generate a cyber threat confidence indicator based on the response, the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

5. The non-transitory processor-readable medium of claim 1 , wherein:

the code to receive the response includes (1) code to receive malicious code from the target host in response to the access request and (2) code to receive information on the target host including retrieve malware instances and executable components from the target host,

the code further includes code to:

generate a cyber threat confidence indicator based on the malicious code, the information on the retrievable malware instances, and the executable component,

the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

6. The non-transitory processor-readable medium of claim 1 , wherein the client is a first client, the virtual client emulator is a first virtual client emulator, the cyber threat indicator is a first cyber threat indicator, the code further includes code to:

receive information related to a second cyber threat indicator of a type different than the type of the first cyber threat indicator, the second cyber threat indicator including identifying information related to malware behavior; and

instantiate a second virtual client emulator selected based on the type of the second cyber threat indicator in response to receiving the information related to the second cyber threat indicator, the second virtual client emulator configured to emulate a second client different from the first client.

7. The non-transitory processor-readable medium of claim 6 , wherein the code to instantiate the first virtual client emulator and the code to instantiate the second virtual client emulator are implemented at a virtual client emulator controller of the processor.

8. The non-transitory processor-readable medium of claim 1 , wherein the access request is disguised as a request sent from a client of the target host.

9. The non-transitory processor-readable medium of claim 1 , wherein the access request is disguised as a request sent from a client of the target host that is at least one of a client terminal, a client application, a client operating system or a client operation.

10. A non-transitory processor-readable medium storing code representing processor-executable instructions, the code comprising code to cause a processor to:

receive information related to a cyber threat indicator of a type, the cyber threat indicator including identifying information of a target host and information related to malware behavior;

instantiate a virtual client emulator selected based on the type of the cyber threat indicator in response to receiving the information related to the cyber threat indicator;

send an access request from the virtual client emulator to the target host based on the identifying information;

receive a response from the target host based on the access request and based on an interaction that is between the virtual client emulator and the target host and that includes verifying presence of malicious code at the target host; and

send a signal to a compute device based on the response such that the compute device performs a cyber threat mitigation action on compute devices within control of the compute device and associated with communications with the target host.

11. The non-transitory processor-readable medium of claim 10 , wherein the interaction includes receiving, from the target host and in response to the access request, at least one of malicious code, information on retrievable malware instances, or executable components.

12. The non-transitory processor-readable medium of claim 10 , wherein the code further includes code to:

generate a cyber threat confidence indicator based on the response, the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

13. The non-transitory processor-readable medium of claim 10 , wherein:

the interaction includes receiving, from the target host and in response to the access request, at least one of malicious code, information on retrievable malware instances, or executable components,

the code further includes code to:

generate a cyber threat confidence indicator based on the at least one of malicious code, information on retrievable malware instances, or executable components, the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

14. The non-transitory processor-readable medium of claim 10 , wherein the client is a first client, the virtual client emulator is a first virtual client emulator, the cyber threat indicator is a first cyber threat indicator, the code further includes code to:

receive information related to a second cyber threat indicator of a type different than the type of the first cyber threat indicator, the second cyber threat indicator including identifying information related to malware behavior; and

instantiate a second virtual client emulator selected based on the type of the second cyber threat indicator in response to receiving the information related to the second cyber threat indicator, the second virtual client emulator configured to emulate a second client different from the first client.

15. The non-transitory processor-readable medium of claim 14 , wherein the code to instantiate the first virtual client emulator and the code to instantiate the second virtual client emulator are implemented at a virtual client emulator controller of the processor.

16. The non-transitory processor-readable medium of claim 10 , wherein the access request is disguised as a request sent from a client of the target host that is at least one of a client terminal, a client application, a client operating system or a client operation.

17. A non-transitory processor-readable medium storing code representing processor-executable instructions, the code comprising code to cause a processor to:

receive information related to a cyber threat indicator of a type, the cyber threat indicator including identifying information of a target host and information related to malware behavior;

instantiate a virtual client emulator selected based on the type of the cyber threat indicator in response to receiving the information related to the cyber threat indicator;

send an access request from the virtual client emulator to the target host based on the identifying information, the access request being disguised as a request sent from a client of the target host;

receive a malicious code from the target host in response to the access request; and

send a signal to a compute device based on receiving the malicious code such that the compute device performs a cyber threat mitigation action on compute devices within control of the compute device and associated with communications from the target host.

18. The non-transitory processor-readable medium of claim 17 , wherein the code to receive the malicious code includes code to receive the malicious code based on interaction between the virtual client emulator and the target host.

19. The non-transitory processor-readable medium of claim 17 , wherein the code to receive the malicious code includes code to receive information on the target host including retrievable malware instances and executable components from the target host.

20. The non-transitory processor-readable medium of claim 17 , wherein the code further includes code to:

generate a cyber threat confidence indicator based on receiving the malicious code, the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

21. The non-transitory processor-readable medium of claim 17 , wherein:

the code to receive the malicious code includes (1) code to receive malicious code from the target host in response to the access request and (2) code to receive information on the target host including retrievable malware instances and executable components from the target host,

the code further includes code to:

generate a cyber threat confidence indicator based on receiving the malicious code, the malware instances and executable components,

the cyber threat confidence indicator indicating at least one of existence of malware at the target host or malware behavior at the target host,

the code to send the signal including code to send the signal representing a cyber threat indicator confirmation report that includes the cyber threat confidence indicator.

22. The non-transitory processor-readable medium of claim 17 , wherein the client is a first client, the virtual client emulator is a first virtual client emulator, the cyber threat indicator is a first cyber threat indicator, the code further includes code to:

receive information related to a second cyber threat indicator of a type different than the type of the first cyber threat indicator, the second cyber threat indicator including identifying information related to malware behavior; and

instantiate a second virtual client emulator selected based on the type of the second cyber threat indicator in response to receiving the information related to the second cyber threat indicator, the second virtual client emulator configured to emulate a second client different from the first client.

23. The non-transitory processor-readable medium of claim 22 , wherein the code to instantiate the first virtual client emulator and the code to instantiate the second virtual client emulator are implemented at a virtual client emulator controller of the processor.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
CHANGE OF NAME Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 063821/0591 →
SECURITY INTEREST Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, LLC
To: STIFEL BANK
Reel/Frame 063829/0248 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062871/0797 →
SECURITY INTEREST Recorded May 11, 2022
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0264 →
SECURITY INTEREST Recorded Aug 24, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057275/0234 →
SECURITY INTEREST Recorded Jul 12, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056822/0787 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2017
From: COLEMAN, CHRISTOPHER D.; THOMSON, ALLAN; LEWIS, JASON A.
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 042457/0578 →
Cited By (2)
US 12,323,464 US 12,413,473