IP Library Granted Patent US 10,243,991
Granted Patent B2
US 10,243,991 · App. 15/878,611 · Granted Mar 26, 2019

Methods and systems for generating dashboards for displaying threat insight information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,991
App. No.
15/878,611
Granted
Mar 26, 2019
Kind
B2
Abstract

Dashboards for displaying threat insight information are provided herein, as well as systems and methods for generating the same. According to some embodiments, methods for providing a threat dashboard include locating metrics regarding a malicious attack against a targeted resource; the metrics indicating instances where users were exposed to the malicious attack or instances where a cloud-based threat detection system prevented the user from being exposed to the malicious attack. The method may also include rendering a threat dashboard for a web browser application of a client device, where the threat dashboard includes the located metrics.

Claims (40)

1. A method for providing a threat dashboard via a cloud-based threat detection system, the cloud-based threat detection system comprising a Central Processing Unit (CPU) and a memory, the method comprising the steps of:

determining metrics regarding a particular malicious attack against a targeted resource, the metrics indicating:

instances where users actuated the particular malicious attack, and

instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated;

rendering a threat dashboard for a web browser application of a client device via a graphics display, the threat dashboard comprising the metrics for the instances where the users actuated the particular malicious attack and the instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated, the threat dashboard further comprising a slider for categorizing attacks being configured to indicate whether the particular malicious attack was targeted to a particular resource or less discriminative; and

indicating, via the slider, on the threat dashboard whether the particular malicious attack was targeted to a particular group of the users or widespread.

2. The method of claim 1 , wherein the slider has a targeted end and a widespread end.

3. The method of claim 1 , wherein the metrics further indicate instances where the users were exposed to the particular malicious attack or instances where the cloud-based threat detection system prevented the users from being exposed to the particular malicious attack.

4. The method of claim 3 , wherein the rendering includes graphing a timeline of the metrics to illustrate both:

(a) the instances where the cloud-based threat detection system prevented the users from being exposed to the particular malicious attack; and

(b) the instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated;

the rendering further including graphing the timeline of the metrics to further indicate:

(c) the instances where the users were exposed to the particular malicious attack; and

(d) the instances where the users actuated the particular malicious attack.

5. The method of claim 4 , wherein the graph has a vertical axis defined by exposures and a horizontal axis defined by a period of time, the timeline being populated with the (a) instances and the (c) instances.

6. The method of claim 4 , wherein the graph has a vertical axis defined by actuations and a horizontal axis defined by a period of time, the timeline being populated with the (b) instances and the (d) instances.

7. The method of claim 4 , further comprising locating a threat neutralization indicator on the timeline, the threat neutralization indicator illustrating a point in time where the cloud-based threat detection system neutralized an actuated malicious attack.

8. The method of claim 1 , wherein the rendering includes populating the threat dashboard with a list of threat instances where the users encountered the particular malicious attack or actuated the particular malicious attack, wherein the list is organized such that the threat instances where the users actuated the particular malicious attack are displayed above the threat instances where the users encountered but did not actuate the particular malicious attack.

9. The method of claim 1 , wherein the rendering includes assembling a threat source list comprising a ranked listing of malicious attacks arranged according to exposure or actuation success.

10. A cloud-based threat detection system for providing a threat dashboard, the system comprising:

a processor; and

a memory for storing logic, the logic being executed by the processor to execute operations comprising:

determining metrics regarding a particular malicious attack against a targeted resource, the metrics indicating:

instances where users actuated the particular malicious attack, and

instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated;

rendering a threat dashboard for a web browser application of a client device via a graphics display, the threat dashboard comprising the metrics for the instances where the users actuated the particular malicious attack and the instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated, the threat dashboard further comprising a slider for categorizing attacks being configured to indicate whether the particular malicious attack was targeted to a particular resource or less discriminative; and

indicating, via the slider, on the threat dashboard whether the particular malicious attack was targeted to a particular group of the users or widespread.

11. The system of claim 10 , wherein the processor further executes the logic to perform an operation of rendering a view of the targeted resource within the threat dashboard.

12. The system of claim 10 , wherein the processor further executes the logic to perform an operation graphing a timeline of the metrics to illustrate:

(a) instances where the users were exposed to the particular malicious attack;

(b) instances where the cloud-based threat detection system prevented the users from being exposed to the particular malicious attack;

(c) the instances where the users actuated the particular malicious attack; and

(d) the instances where the cloud-based threat detection system prevented the particular malicious attack from being actuated.

13. The system of claim 12 , wherein graphing the timeline comprises generating a two dimensional graph having a vertical axis defined by exposures and a horizontal axis defined by a period of time, the timeline being populated with the (a) instances and the (b) instances.

14. The system of claim 13 , wherein the processor further executes the logic to perform an operation of assigning a different hue to each of the (a) instances and the (b) instances so as to visually distinguish the (a) and the (b) instances.

15. The system of claim 12 , wherein graphing the timeline comprises generating a two dimensional graph having a vertical axis defined by actuations and a horizontal axis defined by a period of time, the timeline being populated with the (c) instances and the (d) instances.

16. The system of claim 15 , further comprising assigning a different hue to each of the (c) instances and the (d) instances so as to visually distinguish the (c) and the (d) instances.

17. The system of claim 12 , wherein the processor further executes the logic to perform an operation of locating a threat neutralization indicator on the timeline, the threat neutralization indicator illustrating a point in time where the cloud-based threat detection system neutralized an actuated malicious attack.

18. The system of claim 10 , wherein the processor further executes the logic to perform an operation of populating the threat dashboard with a list of threat instances where the users encountered the particular malicious attack or the threat instances where the users actuated the particular malicious attack, wherein the list is organized such that the threat instances where the users actuated the particular malicious attack are displayed above the threat instances where the users encountered but did not actuate the particular malicious attack.

19. The system of claim 10 , wherein the targeted resource and the client device are not the same device.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2018
From: HAGAR, DAVID ERIC; EDDY, STEVE
To: PROOFPOINT, INC.
Reel/Frame 047460/0706 →