IP Library Granted Patent US 10,686,820
Granted Patent B1
US 10,686,820 · App. 15/635,450 · Granted Jun 16, 2020

Scoping cyber-attack incidents based on similarities, accessibility and network activity

Inventors: Tal Sheffer (Tel Aviv, IL); Ravid Circus (Kfar Saba, IL); Moshe Raab (Sde Varburg, IL); Lior Ben Naon (Nes Ziona, IL); Gideon David Cohen (Palo Alto, CA)
Assignee: SKYBOX SECURITY Ltd
H04L63/1433G06F21/552H04L63/145H04L63/1425G06F21/57H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,820
App. No.
15/635,450
Granted
Jun 16, 2020
Kind
B1
Abstract

A method for evaluating a scope of cyber-attack incidents, the method may include detecting original compromised assets and malicious external machines that are related to each of the cyber-attack incidents; classifying potentially compromised assets to different classes based on (a) similarities between the potentially compromised assets and the original compromised assets, (b) a level of accessibility from the original compromised assets and malicious external machines to the potentially compromised assets, and (c) volumes of traffic between the potentially compromised assets and each one of the malicious external machines and the original compromised assets; wherein the different classes comprise compromised and non-compromised; and generating an alert that is indicative of the compromised assets and of potentially compromised assets that were classified as compromised.

Claims (29)

1. A method for evaluating a scope of cyber-attack incidents, the method comprises:

detecting original compromised assets and malicious external machines that are related to each of the cyber-attack incidents; classifying potentially compromised assets to different classes based on (a) similarities between the potentially compromised assets and the original compromised assets, (b) a level of accessibility from the original compromised assets and the malicious external machines to the potentially compromised assets, and (c) volumes of traffic between the potentially compromised assets and each one of the malicious external machines and the original compromised assets; wherein the different classes comprise compromised and non-compromised; and

generating an alert that is indicative of the original compromised assets and of potentially compromised assets that were classified as compromised.

2. The method according to claim 1 wherein the different classes comprise a suspected asset that warrants further analysis.

3. The method according to claim 1 wherein the classifying of the potentially compromised assets comprises assigning a compromise score to each potentially compromised asset, wherein a compromise score of a given potentially compromised asset is responsive to (a) similarities between the given potentially compromised asset and each one of the original compromised assets, (b) a level of accessibility from the original compromised assets and the malicious external machines to the given potentially compromised assets, and (c) a volume of traffic between the given potentially compromised asset and each one of the malicious external machines and the original compromised assets.

4. The method according to claim 3 wherein a calculating of the compromise score of the given potentially compromised asset comprises calculating a similarity score that is based on weighted similarity values.

5. The method according to claim 4 wherein the calculating of the compromise score of the given potentially compromised asset is further based on upper bounds of the weighted similarity values.

6. The method according to claim 4 comprising calculating the weighted similarity values by multiplying similarity values that represent similarities between different parameters of the given potentially compromised asset and the original compromised assets by weights.

7. The method according to claim 6 comprising assigning a more significant weight to similarity of indicator of compromise than to an operating system similarity.

8. The method according to claim 6 wherein the different parameters comprises at least two out of an operating system, an operating system family, a common vulnerability, an indicator of compromise and malware instance.

9. The method according to claim 6 wherein the different parameters comprises an operating system, an operating system family, a common vulnerability, an indicator of compromise and malware instance.

10. The method according to claim 3 wherein a calculating of the compromise score of the given potentially compromised asset comprises calculating a similarity score that is responsive to a number of original compromised assets that are deemed to be similar to the given potentially compromised asset.

11. The method according to claim 3 comprising calculating the accessibility of the given potentially compromised asset from each one of the original compromised assets and the malicious external machines based on a number of ports of the given potentially compromised asset that are accessible to each one of the original compromised assets and the malicious external machines.

12. The method according to claim 3 comprising classifying each potentially compromised asset to different classes that comprises compromised, non-compromised and a suspected asset that warrants further analysis based on the compromise score of each potentially compromised asset.

13. A non-transitory computer readable medium that stores instructions that once executed by a computer causes the computer to evaluate a scope of cyber-attack incidents, by:

detecting original compromised assets and malicious external machines that are related to each of the cyber-attack incidents;

classifying potentially compromised assets to different classes based on (a) similarities between the potentially compromised assets and the original compromised assets, (b) a level of accessibility from the original compromised assets and the malicious external machines to the potentially compromised assets, and (c) volumes of traffic between the potentially compromised assets and each one of the malicious external machines and the original compromised assets; wherein the different classes comprise compromised and non-compromised; and

generating an alert that is indicative of the original compromised assets and of potentially compromised assets that were classified as compromised.

14. The non-transitory computer readable medium according to claim 13 wherein the different classes comprise a suspected asset that warrants further analysis.

15. The non-transitory computer readable medium according to claim 13 wherein the classifying of the potentially compromised assets comprises assigning a compromise score to each potentially compromised asset, wherein a compromise score of a given potentially compromised asset is responsive to (a) similarities between the given potentially compromised asset and each one of the original compromised assets, (b) a level of accessibility from the original compromised assets and the malicious external machines to the given potentially compromised assets, and (c) a volume of traffic between the given potentially compromised asset and each one of the malicious external machines and the original compromised assets.

16. The non-transitory computer readable medium according to claim 15 wherein a calculating of the compromise score of the given potentially compromised asset comprises calculating a similarity score that is based on weighted similarity values.

17. The non-transitory computer readable medium according to claim 16 wherein the calculating of the compromise score of the given potentially compromised asset is further based on upper bounds of the weighted similarity values.

18. The non-transitory computer readable medium according to claim 16 that stores instructions for calculating the weighted similarity values by multiplying similarity values that represent similarities between different parameters of the given potentially compromised asset and the original compromised assets by weights.

19. The non-transitory computer readable medium according to claim 18 that stores instructions for assigning a more significant weight to similarity of indicator of compromise than to an operating system similarity.

20. The non-transitory computer readable medium according to claim 18 wherein the different parameters comprises at least two out of an operating system, an operating system family, a common vulnerability, an indicator of compromise and malware instance.

21. The non-transitory computer readable medium according to claim 18 wherein the different parameters comprises an operating system, an operating system family, a common vulnerability, an indicator of compromise and malware instance.

22. The non-transitory computer readable medium according to claim 15 wherein a calculating of the compromise score of the given potentially compromised asset comprises calculating a similarity score that is responsive to a number of original compromised assets that are deemed to be similar to the given potentially compromised asset.

23. The non-transitory computer readable medium according to claim 15 that stores instructions for calculating the accessibility of the given potentially compromised asset from each one of the original compromised assets and the malicious external machines based on a number of ports of the given potentially compromised asset that are accessible to each one of the original compromised assets and the malicious external machines.

24. The non-transitory computer readable medium according to claim 15 that stores instructions for classifying each potentially compromised asset to different classes that comprises compromised, non-compromised and a suspected asset that warrants further analysis based on the compromise score of each potentially compromised asset.

Assignments (7)
PATENT SECURITY AGREEMENT Recorded May 30, 2025
From: SPEAR PARENT, INC.
To: TCG SENIOR FUNDING, L.L.C., AS COLLATERAL AGENT
Reel/Frame 071464/0732 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2025
From: SKYBOX SECURITY, INC.
To: SPEAR PARENT, INC.
Reel/Frame 071138/0372 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE PROPERTY LIST BY DELETING PATENT APPLICATION NO. 10/409,993 AND ADDING PATENT NO. 10,409,993 PREVIOUSLY RECORDED AT REEL: 61994 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Feb 25, 2025
From: SKYBOX SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070328/0572 →
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2025
From: JPMORGAN CHASE BANK, N.A.
To: SKYBOX SECURITY, INC.
Reel/Frame 070326/0871 →
SECURITY INTEREST Recorded Dec 6, 2022
From: SKYBOX SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 061994/0530 →
RELEASE OF SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Dec 1, 2022
From: ALLY BANK, AS AGENT
To: SKYBOX SECURITY, INC.
Reel/Frame 062034/0791 →
SUPPLEMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 28, 2020
From: SKYBOX SECURITY, INC.
To: ALLY BANK
Reel/Frame 052774/0132 →
Cited By (2)
US 12,231,443 US 12,621,331