IP Library Granted Patent US 10,333,971
Granted Patent B2
US 10,333,971 · App. 15/628,917 · Granted Jun 25, 2019

Systems and methods for detecting and preventing cyber-threats

Inventors: Roy Stephan (Loring, VA); Vladimir Tereshkov (Loring, VA)
Assignee: ZenopZ LLC
H04L63/1466G06F16/254G06F16/283G06F21/552G06F21/6227G06F21/6254H04L63/02H04L63/1425H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,971
App. No.
15/628,917
Granted
Jun 25, 2019
Kind
B2
Abstract

A system ( 100 ) for detecting and preventing cyber-threats is disclosed. The system ( 100 ) can include an online-analytical-processing (OLAP) resource ( 102 ) coupled to a data mining engine ( 104 ), a reporting resource ( 106 ) and a processor ( 108 ). The processor ( 108 ) can run instructions stored within an extract-transform-load (ETL) module ( 112 ). The ETL module ( 112 ) can enable the processor ( 108 ) to extract one or more data tuples various data sources ( 110 ). The ETL module ( 112 ) can enable the processor to transform the extracted tuple(s).

Claims (38)

1. A system for detecting, evaluating and preventing cyber-threats, the system comprising:

at least one online-analytical-processing (OLAP) resource;

at least one cloud-based data mining engine coupled to the OLAP resource;

at least one reporting resource coupled to the OLAP resource; and

at least one processor coupled to the OLAP resource and coupled to at least one data source, the processor having at least one extract-transform-load (ETL) module associated therewith, the ETL module configured, upon execution by the at least one processor, to:

extract at least one data tuple from the data source;

transform the data tuple, wherein transforming the data tuple comprises normalizing the data tuple according to a predetermined policy and removing sensitive information from the at least one data tuple; and

load the transformed data tuple (TDT) to the OLAP resource, wherein the OLAP resource is configured to:

store the loaded TDT,

analyze the loaded TDT with reference to data acquired by the data mining engine and with reference to at least one previously stored TDT according to at least one predetermined algorithm wherein at least one measure of similarity between the loaded TDT and the previously stored TDT is a factor, the predetermined algorithm including a reliability score associated with the data source from which the TDT was extracted,

assign at least one threat score to the data source from which the TDT was extracted, according to the predetermined algorithm, and

upload the threat score to the at least one reporting resource; and

wherein the reporting resource is configured to collate and store the threat score for subsequent retrieval.

2. The system of claim 1 , wherein the data mining engine is coupled to an external network.

3. The system of claim 1 , wherein the ETL module is configured for interoperability with at least one firewall.

4. The system of claim 1 , wherein the sensitive information is stored locally to the data source.

5. The system of claim 1 , where the OLAP resource resides within a distributed network.

6. The system of claim 1 , wherein the OLAP resource is hosted by at least one web server.

7. The system of claim 1 , wherein the data source is assigned a unique identifier (ID), thereby making the data source anonymous with respect to at least one device which is external to the data source.

8. The system of claim 7 , wherein the unique ID is randomly assigned by an encryption algorithm.

9. The system of claim 1 , wherein the system utilizes a Domain Name System-modeled protocol to manage a hierarchical system of servers hosting the at least one data source, thereby enabling the system to operate in real-time or in near real-time.

10. A method of detecting, evaluating and preventing cyber-threats, the method comprising:

extracting, by at least one processor running at least one extract-transform-load (ETL) module, at least one data tuple from at least one data source;

transforming the data tuple, wherein transforming the data tuple comprises normalizing the data tuple according to a predetermined policy and removing sensitive information from the data tuple;

loading the transformed data tuple (TDT) to at least one OLAP resource;

storing the loaded TDT;

analyzing the loaded TDT with reference to data acquired by at least one cloud-based data mining engine and with reference to at least one previously stored TDT, according to at least one predetermined algorithm in which at least one measure of similarity between the loaded TDT and the previously stored TDT is a factor, the predetermined algorithm including a reliability score associated with the data source from which the TDT was extracted;

assigning at least one threat score to the data source from which the TDT was extracted, according to the predetermined algorithm; and

uploading the threat score to at least one reporting resource,

wherein the reporting resource is configured to collate and store the threat score for subsequent retrieval.

11. The method of claim 10 , wherein the data mining engine is coupled to an external network.

12. The method of claim 10 , wherein the ETL module is configured for interoperability with at least one firewall.

13. The method of claim 10 , wherein the sensitive information is stored locally to the data source.

14. The method of claim 10 , where the OLAP resource resides within a distributed network.

15. The method of claim 10 , wherein the OLAP resource is hosted by at least one web server.

16. The method of claim 10 , wherein the data source is assigned a unique identifier (ID), thereby making the data source anonymous with respect to at least one device which is external to the data source.

17. The method of claim 16 , wherein the unique ID is randomly assigned by an encryption algorithm.

18. The method of claim 10 , wherein the method utilizes a Domain Name System-modeled protocol to manage a hierarchical system of servers hosting the at least one data source, thereby enabling the method to operate in real-time or in near real-time.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2018
From: PIERCE GLOBAL THREAT INTELLIGENCE, D/B/A PIERCE MATRIX
To: ZENOPZ LLC
Reel/Frame 047765/0872 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2018
From: STEPHAN, ROY; TERESHKOV, VLADIMIR
To: PIERCE GLOBAL THREAT INTELLIGENCE, INC.
Reel/Frame 047356/0492 →
Continuity (3)
Continuation 14771114
Provisional Application 61851250 · Mar 5, 2013
Related Publication 20180109558A1 · Apr 19, 2018
Cited By (1)
US 12,363,176