IP Library Granted Patent US 10,341,367
Granted Patent B1
US 10,341,367 · App. 15/842,330 · Granted Jul 2, 2019

System and method for inquiring IOC information by P2P protocol

Inventor: Kihong Kim (Seoul, KR)
Assignee: Saint Security Inc.
H04L63/1416G06F21/552G06F21/554G06F21/577H04L63/1433H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,367
App. No.
15/842,330
Granted
Jul 2, 2019
Kind
B1
Abstract

Methods, systems, and devices are provided for inquiring and storing Indicator of Compromise (IoC) information. In one example, a method of inquiring and storing IoC information can include determining a target IoC information to be identified when an event occurs, requesting an encryption socket communication module of a first user terminal to request the target IoC information from an IoC information providing server, requesting a P2P socket communication module of the first user terminal to request the target IoC information from a P2P socket communication module of at least one other user terminal, and storing the target IoC information that is received first from either the IoC information providing server or the P2P socket communication module of the at least one other user terminal.

Claims (25)

1. A method of inquiring and storing Indicator of Compromise (IoC) information by at least first user terminal among a plurality of user terminals in an environment including the plurality of user terminals, each of the plurality of user terminals having at least an event processing module, an IoC inquiry agent module, an encryption socket communication module, and a P2P socket communication module; and the environment further including an IoC information providing server, the method comprising:

a first step of determining by the event processing module of the first user terminal a target IoC information to be identified when an event occurs based on the event;

a second step of requesting by the IoC inquiry agent module of the first user terminal that the encryption socket communication module and the P2P socket communication module of the first user terminal request the target IoC information;

a third step of requesting by the encription socket communication module of the first user terminal first a IoC information corresponding to the target IoC information from the IoC information providing server;

a fourth step of requesting by the P2P socket communication module of the first user terminal a second IoC information corresponding to the target IoC information from the P2P socket communication module of one or more of the plurality of user terminals other than the first user terminal;

a fifth step of storing by the first user terminal only one of the first IoC information or the second IoC information that is received first from either the IoC information providing server or the P2P socket communication module of one or more of the plurality of user terminal other than the first user terminal, and

a sixth step of a user accessing the first user terminal and responding to the event based on the first IoC information or the second IoC information stored on the first user terminal.

2. The method according to claim 1 , wherein at the fifth step the first IoC information or the second IoC information is stored in a cache memory of the first user terminal during a predetermined time period, the method further compromising, before the second step, a 2-1 step of analyzing by the IoC inquiry agent module any initial IoC information stored in the cache memory of the first user terminal to determine if the initial IoC information stored in the cache corresponds to the target IoC information, and if the initial IoC information stored in the cache memory does not correspond to the target IoC information, proceeding to the second step.

3. The method according to claim 1 , wherein the plurality of user terminals belong to a local internal network; and

wherein the fourth step includes requesting the second IoC information from the P2P socket communication module of one or more of the plurality of user terminals other than the first user terminal through UDP broadcasting by the P2P socket communication module of the first user terminal.

4. The method according to claim 2 , wherein the plurality of user terminals belong to a local internal network; and

wherein the fourth step includes requesting the second IoC information from the P2P socket communication module of one or more of the plurality of user terminals other than the first user terminal through UDP broadcasting by the P2P socket communication module of the first user terminal.

5. The method according to claim 1 , wherein the fourth step includes establishing a direct connection between the P2P socket communication module of the first user terminal and the P2P socket communication module of the one or more of the plurality of user terminals other than the first user terminal to request the second IoC information.

6. A method of inquiring and storing Indicator of Compromise (IoC) information, comprising:

determining by an event processing module of a first user terminal a desired target IoC information identified based on a security event that occurs on the first user terminal;

requesting by an encryption socket communication module of the first user terminal a first IoC information corresponding to the desired target IoC information from an IoC information providing server;

requesting by a P2P socket communication module of the first user terminal a second IoC information corresponding to the desired target IoC information from a P2P socket communication module of at least one other user terminal in communication with the first user terminal;

storing on the first user terminal only one of the first IoC information or the second IoC information that is received first from either the IoC information providing server or the P2P socket communication module of the at least one other user terminal; and

a sixth step of a user accessing the first user terminal and responding to the security event based on the first IoC information or the second IoC information stored on the first user terminal.

7. The method according to claim 6 , wherein the first user terminal stores either the first IoC information or the second IoC information in a cache memory of the first user terminal during a predetermined time period.

8. The method according to claim 6 , further comprising analyzing by an IoC inquiry agent module on the first user terminal any initial IoC information stored on the first user terminal to determine if the initial IoC information stored on the first user terminal corresponds to the desired target IoC information, and if the initial IoC information does not correspond to the target IoC information, requesting the first IoC information and the second IoC information.

9. The method according to claim 6 , further comprising, subsequent to storing the first IoC information or the second IoC information on the first user terminal, deleting the first IoC information or the second IoC information stored on the first user terminal after a predetermined time period.

10. The method according to claim 6 , further comprising, subsequent to storing the first IoC information or the second IoC information on the first user terminal, updating the first IoC information or the second IoC information stored on the first user terminal after a predetermined time period.

11. The method according to claim 6 , wherein the first user terminal and the at least one other user terminal belong to a local internal network; and

wherein requesting the second IoC information from the P2P socket communication module of the at least one other user terminal includes using UDP broadcasting by the P2P socket communication module of the first user terminal.

Assignments (2)
CHANGE OF NAME Recorded Apr 21, 2022
From: SAINT SECURITY INC.
To: SANDS LAB INC.
Reel/Frame 059747/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2017
From: KIM, KIHONG
To: SAINT SECURITY INC.
Reel/Frame 044400/0832 →
Priority Claims (1)
KR 10-2017-0167993 · Dec 8, 2017 · national