IP Library Granted Patent US 10,873,603
Granted Patent B2
US 10,873,603 · App. 15/923,949 · Granted Dec 22, 2020

Cyber security sharing and identification system

Inventors: Jacob Albertson (New York, NY); Melody Hildebrandt (New York, NY); Harkirat Singh (New York, NY); Shyam Sankar (Palo Alto, CA); Rick Ducott (San Francisco, CA); Peter Maag (New York, NY); Marissa Kimball (New York, NY)
Assignee: Palantir Technologies Inc.
H04L63/20G06F21/50G06F21/55H04L63/14H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,873,603
App. No.
15/923,949
Granted
Dec 22, 2020
Kind
B2
Abstract

Systems and techniques for sharing security data are described herein. Security rules and/or attack data may be automatically shared, investigated, enabled, and/or used by entities. A security rule may be enabled on different entities comprising different computing systems to combat similar security threats and/or attacks. Security rules and/or attack data may be modified to redact sensitive information and/or configured through access controls for sharing.

Claims (65)

1. A computer implemented method comprising:

by a computer system comprising one or more computer hardware processors and one or more storage devices,

communicating with a plurality of entities;

receiving security attack data from a first entity of the plurality of entities, the security attack data comprising information regarding one or more first security attacks;

identifying, based on sharing rules associated with the first entity, one or more recipient entity of a subset of the plurality of entities that are authorized to access a ruleset from the first entity; and

facilitating sharing of the ruleset from the first entity to the one or more recipient entity,

wherein the ruleset (i) is determined by the first entity, and (ii) is associated with the security attack data,

wherein the ruleset comprises instructions selectably applicable by the one or more recipient entity to detect a potential security attack,

wherein the instructions are configured to:

in response to detecting the potential security attack, add data associated with the potential security attack to a cluster as a seed, wherein the cluster comprises a plurality of connected objects and a representation of the cluster is displayable in a user interface.

2. The computer implemented method of claim 1 , wherein the sharing rules associated with the first entity further exclude sharing ruleset data from the first entity to particular one or more entities.

3. The computer implemented method of claim 1 , wherein the ruleset further comprises second instructions configured to:

access one or more data objects associated with the one or more recipient entity, the one or more data objects comprising a plurality of network communications.

4. The computer implemented method of claim 3 , wherein the one or more data objects further comprise a first user login object and a second user login object, the first user login object comprising data indicating a first login for a particular user at a first time and a first location, the second user login object comprising data indicating a second login for the particular user at a second time and a second location, and wherein the ruleset further comprises third instructions configured to:

calculate, from first user login object and the second user login object, a duration of time between the first time for the first login and the second time for the second login;

calculate, from first user login object and the second user login object, a distance between the first location for the first login and the second location for the second login;

calculate a speed from the duration of time and the distance; and

determine the potential security attack where the speed is greater than a threshold value.

5. The computer implemented method of claim 4 , wherein the ruleset further comprises fourth instructions configured to:

in response to determining the potential security attack, generate an alert.

6. Non-transitory computer storage medium comprising instructions for causing one or more computing devices to perform operations comprising:

communicating with a plurality of entities;

receiving security attack data from a first entity of the plurality of entities, the security attack data comprising information regarding one or more first security attacks;

identifying, based on sharing rules associated with the first entity, one or more recipient entity of a subset of the plurality of entities that are authorized to access a ruleset from the first entity; and

transmitting at least a portion of a ruleset from the first entity to the one or more recipient entity,

wherein the ruleset (i) is determined by the first entity, and (ii) is associated with the security attack data,

wherein the ruleset comprises instructions selectably applicable by the one or more recipient entity to detect a potential security attack,

wherein the instructions are configured to:

in response to detecting the potential security attack, add data associated with the potential security attack to a cluster as a seed, wherein the cluster comprises a plurality of connected objects and a representation of the cluster is displayable in a user interface.

7. The non-transitory computer storage medium of claim 6 , wherein the sharing rules associated with the first entity further exclude sharing ruleset data from the first entity to particular one or more entities.

8. The non-transitory computer storage medium of claim 6 , wherein the ruleset further comprises second instructions configured to:

access one or more data objects associated with the one or more recipient entity, the one or more data objects comprising a plurality of network communications.

9. The non-transitory computer storage medium of claim 6 , wherein the ruleset further comprises second instructions configured to:

receive a user agent identifier for a first login;

perform, at the one or more recipient entity, a search for the user agent identifier, wherein performing the search further comprises:

determining that the user agent identifier is a new user agent identifier; and

in response to determining that the user agent identifier is a new user agent identifier, generate an alert.

10. A system for sharing security information, the system comprising:

one or more computer processors executing code instructions, to:

communicate with a plurality of entities;

receive security attack data from a first entity of the plurality of entities, the security attack data comprising information regarding one or more first security attacks;

identify, based on sharing rules associated with the first entity, one or more recipient entity of a subset of the plurality of entities that are authorized to access ruleset data from the first entity; and

facilitate sharing of at least a portion of a ruleset from the first entity to the one or more recipient entity,

wherein the ruleset (i) is determined by the first entity, and (ii) is associated with the security attack data,

wherein the ruleset comprises instructions selectably applicable by the one or more recipient entity to detect a potential security attack,

wherein the instructions are configured to:

in response to detecting the potential security attack, add data associated with the potential security attack to a cluster as a seed, wherein the cluster comprises a plurality of connected objects and a representation of the cluster is displayable in a user interface.

11. The system of claim 10 , wherein the ruleset further comprises second instructions configured to:

access one or more data objects associated with the one or more recipient entity, the one or more data objects comprising a plurality of network communications.

12. The system of claim 10 , wherein the ruleset further comprises second instructions configured to:

identify a first login for a particular user at a first time and a first location;

identify a second login for the particular user at a second time and a second location;

calculate a duration of time between the first time for the first login and the second time for the second login;

calculate a distance between the first location for the first login and the second location for the second login;

calculate a speed from the duration of time and the distance; and

determine the potential security attack where the speed is greater than a threshold value.

13. The system of claim 12 , wherein the ruleset further comprises third instructions configured to:

in response to determining the potential security attack, generate an alert.

14. The system of claim 10 , wherein the one or more computer processors execute further code instructions, to:

facilitate sharing of at least a portion of a second ruleset from the first entity, the second ruleset comprising second instructions different from the instructions of the ruleset.

15. The system of claim 14 , wherein the second instructions are configured to:

receive a user agent identifier for a first login;

perform, at the one or more recipient entity, a search for the user agent identifier, wherein performing the search further comprises:

determining that the user agent identifier is a new user agent identifier.

16. The system of claim 10 , where the seed comprises at least one of: (i) an IP address or (ii) a user login identifier for the particular user.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: ALBERTSON, JACOB; HILDEBRANDT, MELODY; SINGH, HARKIRAT; SANKAR, SHYAM; DUCOTT, RICK; MAAG, PETER; KIMBALL, MARISSA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 064819/0186 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →