IP Library Granted Patent US 10,681,071
Granted Patent B1
US 10,681,071 · App. 15/667,303 · Granted Jun 9, 2020

Enrichment and analysis of cybersecurity threat intelligence and orchestrating application of threat intelligence to selected network security events

Inventors: Andrew Pendergast (Columbia, MD); Andrew Gidwani (Jessup, MD); Daniel Cole (Fairfax, VA); Jason Spies (Clifton, VA); Bhaskar Karambelkar (Ashburn, VA); Christopher Johnson (Matthews, NC); Danny Tineo (Charlotte, NC)
Assignee: ThreatConnect, Inc.
H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,681,071
App. No.
15/667,303
Granted
Jun 9, 2020
Kind
B1
Abstract

Techniques are disclosed which can provide an orchestrated response to a cybersecurity threat. This orchestrated response may be based upon, at least in part, a reputation score. Threat model(s) may be received that identify cybersecurity threat(s). An indication of observations, false positives, and/or page views for the threat may be obtained. Data feeds may be received including known good data feeds, known bad data feeds, and enrichment data feeds. The data feeds may provide information about one or more indicators of compromise (IOC). For each IOC, a weighted criticality score may be determined. The weighted criticality score may be mapped to a corresponding point value. An aggregated score may be determined based upon at least the corresponding point value. A reputation score may be computed, and in some configurations, provided to a user.

Claims (51)

1. A system, comprising:

a non-transitory memory configured to store at least threat model data; and

one or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising:

collecting a plurality of threat models used to score and classify new potential threat models, each threat model identifying a prior identified cybersecurity threat;

obtaining data of a potential cybersecurity threat, the data of the potential cybersecurity threat including a number of observations, a number of false positives, and a number of page views for the potential cybersecurity threat, the potential cybersecurity threat being identified in the based on at least one threat model of the plurality of threat models that identifies a prior identified cybersecurity threat;

receiving, over a communications network, a plurality of data feeds, the plurality of data feeds including one or more of a known bad data feed that constitute known cybersecurity threats, one or more known good data feed that do not constitute known cybersecurity threats, and one or more enrichment data feeds, wherein the plurality of data feeds comprise a plurality of indicators of compromise (IOC);

computing, for each known bad data feed, a deprecated confidence value which deprecates over time;

determining, for each IOC, a weighted criticality score of the potential cybersecurity threat based on the data of the potential cybersecurity threat;

mapping the weighted criticality score of the potential cybersecurity threat to a corresponding point value;

determining an aggregated score comprising at least the corresponding point value;

determining a reputation score of the potential cybersecurity threat as the product of a scale factor and the aggregated score, divided by a maximum point total; and

performing a network countermeasure response based upon the reputation score of the potential cybersecurity threat.

2. The system of claim 1 , wherein the deprecated confidence value is set to zero when a time period cut-off is exceeded.

3. The system of claim 1 , further comprising:

determining that an indicator in one of the plurality of data feeds is deprecated based upon the deprecated confidence value.

4. The system of claim 1 , wherein the corresponding point value has a maximum threshold value.

5. The system of claim 1 , wherein the aggregated score comprises additional points when the IOC is present in more than one of the plurality of bad data feeds.

6. The system of claim 1 , wherein the aggregated score comprises points computed for each of observations of the potential cybersecurity threat, false positives of the potential cybersecurity threat, and page views of the potential cybersecurity threat.

7. The system of claim 1 , wherein performing the network countermeasure response based upon the reputation score includes generating an alert for an analyst.

8. The system of claim 1 , further comprising:

determining whether the reputation score is above a trigger value to initiate the network countermeasure response.

9. A computer-implemented method, comprising:

collecting a plurality of threat models used to score and classify new potential threat models, each threat model identifying a prior identified cybersecurity threat;

obtaining data of a potential cybersecurity threat, the data of the potential cybersecurity threat including a number of observations, a number of false positives, and a number of page views for the potential cybersecurity threat, the potential cybersecurity threat being identified in the based on at least one threat model of the plurality of threat models that identifies a prior identified cybersecurity threat;

receiving, over a communications network, a plurality of data feeds, the plurality of data feeds including one or more of a known bad data feed that constitute known cybersecurity threats, one or more known good data feed that do not constitute known cybersecurity threats, and one or more enrichment data feeds, wherein the plurality of data feeds comprise a plurality of indicators of compromise (IOC);

computing, for each known bad data feed, a deprecated confidence value which deprecates over time;

determining, for each IOC, a weighted criticality score of the potential cybersecurity threat based on the data of the potential cybersecurity threat;

mapping the weighted criticality score of the potential cybersecurity threat to a corresponding point value;

determining an aggregated score comprising at least the corresponding point value;

determining a reputation score of the potential cybersecurity threat as the product of a scale factor and the aggregated score, divided by a maximum point total; and

performing a network countermeasure response based upon the reputation score of the potential cybersecurity threat.

10. The computer-implemented method of claim 9 , wherein the deprecated confidence value is set to zero when a time period cut-off is exceeded.

11. The computer-implemented method of claim 9 , further comprising:

determining that an indicator in one of the plurality of data feeds is deprecated based upon the deprecated confidence value.

12. The computer-implemented method of claim 9 , wherein the corresponding point value has a maximum threshold value.

13. The computer-implemented method of claim 9 , wherein the aggregated score comprises additional points when the IOC is present in more than one of the plurality of bad data feeds.

14. The computer-implemented method of claim 9 , wherein the aggregated score comprises points computed for each of observations of the potential cybersecurity threat, false positives of the potential cybersecurity threat, and page views of the potential cybersecurity threat.

15. The computer-implemented method of claim 9 , wherein performing the network countermeasure response based upon the reputation score includes generating an alert for an analyst.

16. The computer-implemented method of claim 9 , further comprising:

determining whether the reputation score is above a trigger value to initiate the network countermeasure response.

17. A non-transitory computer readable medium having stored thereon computer readable instructions that are executable to cause one or more processors to perform operations, comprising:

collecting a plurality of threat models used to score and classify new potential threat models, each threat model identifying a prior identified cybersecurity threat;

obtaining data of a potential cybersecurity threat, the data of the potential cybersecurity threat including a number of observations, a number of false positives, and a number of page views for the potential cybersecurity threat, the potential cybersecurity threat being identified in the based on at least one threat model of the plurality of threat models that identifies a prior identified cybersecurity threat;

receiving, over a communications network, a plurality of data feeds, the plurality of data feeds including one or more of a known bad data feed that constitute known cybersecurity threats, one or more known good data feed that do not constitute known cybersecurity threats, and one or more enrichment data feeds, wherein the plurality of data feeds comprise a plurality of indicators of compromise (IOC);

computing, for each known bad data feed, a deprecated confidence value which deprecates over time;

determining, for each IOC, a weighted criticality score of the potential cybersecurity threat based on the data of the potential cybersecurity threat;

mapping the weighted criticality score of the potential cybersecurity threat to a corresponding point value;

determining an aggregated score comprising at least the corresponding point value;

determining a reputation score of the potential cybersecurity threat as the product of a scale factor and the aggregated score, divided by a maximum point total; and

performing a network countermeasure response based upon the reputation score of the potential cybersecurity threat.

18. The non-transitory computer readable medium of claim 17 , wherein performing the network countermeasure response based upon the reputation score includes generating an alert for an analyst.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNMENT PREVIOUSLY RECORDED AT REEL: 044019 FRAME: 0429. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 24, 2020
From: PENDERGAST, ANDREW; GIDWANI, ANDREW; COLE, DANIEL; SPIES, JASON; KARAMBELKAR, BHASKAR; JOHNSON, CHRISTOPHER; TINEO, DANNY
To: THREATCONNECT, INC.
Reel/Frame 052487/0261 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY INTEREST Recorded Jun 20, 2019
From: SILICON VALLEY BANK
To: THREATCONNECT, INC.
Reel/Frame 049550/0659 →
SECURITY AGREEMENT Recorded May 31, 2019
From: THREATCONNECT, INC., AS A GRANTOR
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 049334/0221 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Sep 6, 2018
From: THREATCONNECT, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 047025/0334 →
SECURITY INTEREST Recorded Aug 29, 2018
From: THREATCONNECT, INC.
To: SILICON VALLEY BANK
Reel/Frame 046735/0854 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2017
From: PENDERGAST, ANDREW; GIDWANI, ANDREW; COLE, DANIEL; SPIES, JASON; KARAMBELKAR, BHASKAR; JOHNSON, CHRISTOPHER; TINEO, DANNY
To: THREATCONNECT, INC.
Reel/Frame 044019/0429 →
Continuity (2)
Provisional Application 62370219 · Aug 2, 2016
Provisional Application 62446255 · Jan 13, 2017
Cited By (3)
US 12,224,919 US 12,229,647 US 12,244,612