IP Library Granted Patent US 10,033,754
Granted Patent B2
US 10,033,754 · App. 15/663,157 · Granted Jul 24, 2018

Cyber threat monitor and control apparatuses, methods and systems

Inventors: Christopher Paul Pinney Wood (Centreville, VA); John Joseph Helmsen (Rockville, MD); Allan Thomson (Pleasanton, CA); Christopher D. Coleman (Centreville, VA)
Assignee: Lookingglass Cyber Solutions, Inc.
H04L63/1433G06F17/30958G06F21/552G06F21/577H04L41/12H04L41/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,033,754
App. No.
15/663,157
Granted
Jul 24, 2018
Kind
B2
Abstract

The cyber threat monitor and control apparatuses, methods and systems (hereinafter “CTMC”) determines risk across a global Internet network graph model for various virtual or physical network elements. In one embodiment, the CTMC defines a factor mechanism representing interactions among the set of network elements, the factor mechanism including a factor indicative of a correlation between a pair of network elements from the set of network elements, and dynamically calculate the probabilistic network security measure for each network element in the global Internet graph model based at least in part on the factor mechanism and any observed threat indicators related to the global Internet graph model.

Claims (40)

1. A processor-implemented method, comprising:

sending a signal to cause a user interface to render a representation of a probabilistic network security measure of each network element from a set of network elements within a network security assessment graph;

receiving an indication via the user interface of a change related to the network security assessment graph;

determining a group of influenced network elements from the set of network elements in response to the change related to the network security assessment graph based on a factor matrix that represents a joint threat and safety probabilities for the set of network elements, the factor matrix including a factor indicative of a correlation between a pair of network elements from the set of network elements;

dynamically updating the factor matrix for the group of influenced network elements to produce an updated factor matrix;

dynamically updating the probabilistic network security measure for each network element from the set of network elements to produce an updated probabilistic network security measure for each network from the set of network elements based at least in part on the updated factor matrix and the change related to the network security assessment graph; and

sending a signal to cause the user interface to render a representation of the updated probabilistic network security measure for each network element from the set of network elements within the network security assessment graph.

2. The processor-implemented method of claim 1 , wherein the change related to the network security assessment graph is made via manual input from a user via the user interface.

3. The processor-implemented method of claim 1 , wherein the change related to the network security assessment graph includes influence degradation over time from the threat indicator.

4. The processor-implemented method of claim 1 , wherein the factor matrix or the network security assessment graph is dynamically updated in network elements from the set of network elements that are affected by the change related to the network security assessment graph.

5. The processor-implemented method of claim 1 , wherein the change related to the network security assessment graph includes a structural change of the network security assessment graph.

6. The processor-implemented method of claim 1 , wherein:

the change related to the network security assessment graph includes a transient change to the network security assessment graph or the factor matrix, and

an influence of the change related to the network security assessment graph degrades impact over time.

7. The processor-implemented method of claim 1 , wherein:

the change related to the network security assessment graph includes a user defined condition, and

the probabilistic network security measure of each network element from the set of network elements and in the network security assessment graph is dynamically updated based on the user defined condition.

8. The processor-implemented method of claim 1 , wherein the change related to the network security assessment graph includes a changed value of a characteristic associated with the threat indicator.

9. The processor-implemented method of claim 1 , wherein the set of network elements includes a number of network elements no less than one million.

10. The processor-implemented method of claim 1 , wherein each network element from a set of network elements includes any of an Internet protocol (IP) host, a classless inter-domain router (CIDR), a fully qualified domain name (FQDN), an autonomous system number (ASN), an application or application identifiers, a group sector, or a user.

11. An apparatus, comprising:

a processor; and

a memory operatively coupled to the processor, the memory storing processor-readable instructions executable by the processor to:

send a signal to cause a user interface to render a representation of a probabilistic network security measure of each network element from a set of network elements within a network security assessment graph;

receive an indication via the user interface of a change related to the network security assessment graph;

determine a group of influenced network elements from the set of network elements in response to the change related to the network security assessment graph based on a factor matrix that represents a joint threat and safety probabilities for the set of network elements, the factor matrix including a factor indicative of a correlation between a pair of network elements from the set of network elements;

dynamically update the factor matrix for the group of influenced network elements to produce an updated factor matrix;

dynamically update the probabilistic network security measure for each network element from the set of network elements to produce an updated probabilistic network security measure for each network from the set of network elements based at least in part on the updated factor matrix and the change related to the network security assessment graph; and

send a signal to cause the user interface to render a representation of the updated probabilistic network security measure for each network element from the set of network elements within the network security assessment graph.

12. The apparatus of claim 11 , wherein the change related to the network security assessment graph is made via manual input from a user via the user interface.

13. The apparatus of claim 11 , wherein the change related to the network security assessment graph includes influence degradation over time from the threat indicator.

14. The apparatus of claim 11 , wherein the factor matrix or the network security assessment graph is dynamically updated in network elements from the set of network elements that are affected by the change related to the network security assessment graph.

15. The apparatus of claim 11 , wherein the change related to the network security assessment graph includes a structural change of the network security assessment graph.

16. The apparatus of claim 11 , wherein:

the change related to the network security assessment graph includes a transient change to the network security assessment graph or the factor matrix, and an influence of the change related to the network security assessment graph degrades impact over time.

17. The apparatus of claim 11 , wherein:

the change related to the network security assessment graph includes a user defined condition, and the probabilistic network security measure of each network element from the set of network elements and in the network security assessment graph is dynamically updated based on the user defined condition.

18. The apparatus of claim 11 , wherein the change related to the network security assessment graph includes a changed value of a characteristic associated with the threat indicator.

19. The apparatus of claim 11 , wherein the set of network elements includes a number of network elements no less than one million.

20. The apparatus of claim 11 , wherein each network element from a set of network elements includes any of an Internet protocol (IP) host, a classless inter-domain router (CDR), a fully qualified domain name (FQDN), an autonomous system number (ASN), an application or application identifiers, a group sector, or a user.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 067429/0361 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0715 →
RELEASE OF SECURITY INTEREST Recorded Apr 17, 2024
From: EASTWARD FUND MANAGEMENT, LLC
To: LOOKINGGLASS CYBER SOLUTIONS, INC.; CLOUDSHIELD TECHNOLOGIES, LLC; CYVEILLANCE, INC.
Reel/Frame 067131/0803 →
CHANGE OF NAME Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: LOOKINGGLASS CYBER SOLUTIONS, LLC
Reel/Frame 063821/0591 →
SECURITY INTEREST Recorded Jun 1, 2023
From: LOOKINGGLASS CYBER SOLUTIONS, LLC
To: STIFEL BANK
Reel/Frame 063829/0248 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2023
From: SILICON VALLEY BANK
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 062871/0797 →
SECURITY INTEREST Recorded May 11, 2022
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT, LLC
Reel/Frame 059892/0264 →
SECURITY INTEREST Recorded Aug 24, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057275/0234 →
SECURITY INTEREST Recorded Jul 12, 2021
From: LOOKINGGLASS CYBER SOLUTIONS, INC.
To: EASTWARD FUND MANAGEMENT
Reel/Frame 056822/0787 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2017
From: PINNEY WOOD, CHRISTOPHER PAUL; HELMSEN, JOHN JOSEPH; THOMSON, ALLAN; COLEMAN, CHRISTOPHER D.
To: LOOKINGGLASS CYBER SOLUTIONS, INC.
Reel/Frame 043379/0293 →
Continuity (3)
Continuation 14945102 · Nov 18, 2015
Division 14562623 · Dec 5, 2014
Related Publication 20170331851A1 · Nov 16, 2017
Cited By (2)
US 12,244,629 US 12,592,952