IP Library Granted Patent US 11,165,801
Granted Patent B2
US 11,165,801 · App. 15/998,423 · Granted Nov 2, 2021

Social threat correlation

Inventors: Christopher B. Cullison (Westminster, MD); Michael Price (Baltimore, MD); James Foster (Baltimore, MD)
Assignee: ZeroFOX, Inc.
H04L63/1425H04L51/12H04L51/32H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,801
App. No.
15/998,423
Granted
Nov 2, 2021
Kind
B2
Abstract

A computer-implemented method includes scanning data maintained on multiple social networks, where, scanning includes identifying a first set of data that is associated with a protected social entity. Scanning data maintained on one or more additional platforms, where, scanning includes identifying a second set of data that is associated with the protected social entity. Scanning data is performed on a continuous basis without user initiation. One or more characteristics of the first set and second set of identified data are determined, and a reference to the identified data, that indicates the characteristic, is generated for each of the one or more characteristics. The one or more generated references of the first set of identified data is compared to the one or more generated references of the second set of identified data. A correlation score is determined based on the comparison, and a threat level indicator is generated based on the determined correlation score.

Claims (62)

1. A computer-implemented method comprising:

scanning data that is maintained on multiple social networks, wherein the data that is maintained on multiple social networks is known to be associated with a protected social entity, wherein scanning comprises identifying, by one or more processors, a first security threat that is associated with the protected social entity;

scanning data maintained on one or more additional platforms, wherein the data maintained on one or more additional platforms is known to be associated with the protected social entity, wherein scanning comprises identifying, by one or more processors, a second security threat that is associated with the protected social entity;

wherein, scanning data is performed on a continuous basis, without user initiation;

determining one or more characteristics of the first security threat and second security threat;

generating, for each of the one or more characteristics, a reference to the respective security threat that indicates the characteristic;

comparing the one or more generated references of the first security threat to the one or more generated references of the second security threat;

determining, based on the comparison, a correlation score that reflects a level of similarity between the first and second security threat; and

generating, based on the determined correlation score, a threat level indicator.

2. The method of claim 1 wherein scanning data maintained on one or more additional platforms, comprises scanning data maintained by an email service.

3. The method of claim 1 further comprising:

comparing the threat indicator level to a threshold; and

in response to the threat indicator level exceeding the threshold, initiating a security action.

4. The method of claim 3 wherein initiating the security action comprises:

generating an alert; and

providing the alert to the protected social entity.

5. The method of claim 4 wherein providing the alert to the protected social entity comprises providing a computer-based alert to the protected social entity.

6. The method of claim 5 wherein providing a computer-based alert to the protected social entity comprises emailing the protected social entity.

7. A system comprising:

one or more processing devices; and

one or more non-transitory computer-readable media coupled to the one or more processing devices having instructions stored thereon which, when executed by the one or more processing devices, cause the one or more processing devices to perform operations comprising:

scanning data that is maintained on multiple social networks, wherein the data that is maintained on multiple social networks is known to be associated with a protected social entity, wherein scanning comprises identifying, by one or more processors, a first security threat that is associated with the protected social entity;

scanning data maintained on one or more additional platforms, wherein the data maintained on one or more additional platforms is known to be associated with the protected social entity, wherein scanning comprises identifying, by one or more processors, a second security threat that is associated with the protected social entity;

wherein, scanning data is performed on a continuous basis, without user initiation;

determining one or more characteristics of the first security threat and second security threat;

generating, for each of the one or more characteristics, a reference to the respective security threat that indicates the characteristic;

comparing the one or more generated references of the first security threat to the one or more generated references of the second security threat;

determining, based on the comparison, a correlation score that reflects a level of similarity between the first and second security threat; and

generating, based on the determined correlation score, a threat level indicator.

8. The system of claim 7 further comprising storing one or more references to the respective security threats in one or more databases that are accessible to a security analysis engine.

9. The system of claim 7 further comprising:

comparing the threat indicator level to a threshold; and

in response to the threat indicator level exceeding the threshold, initiating a security action.

10. The system of claim 9 wherein initiating the security action comprises:

generating an alert; and

providing the alert to the protected social entity.

11. The system of claim 10 wherein providing the alert to the protected social entity comprises providing a computer-based alert to the protected social entity.

12. The system of claim 11 wherein providing a computer-based alert to the protected social entity comprises emailing the protected social entity.

13. A non-transitory computer-readable storage medium encoded with a computer program, the program comprising instructions that when executed by a data processing apparatus cause the data processing apparatus to perform operations comprising:

scanning data that is maintained on multiple social networks, wherein the data that is maintained on multiple social networks is known to be associated with a protected social entity, wherein scanning comprises identifying, by one or more processors, a first security threat that is associated with the protected social entity;

scanning data maintained on one or more additional platforms, wherein the data maintained on one or more additional platforms is known to be associated with the protected social entity, wherein scanning comprises identifying, by one or more processors, a second security threat that is associated with the protected social entity;

wherein, scanning data is performed on a continuous basis, without user initiation;

determining one or more characteristics of the first security threat and second security threat;

generating, for each of the one or more characteristics, a reference to the respective security threat that indicates the characteristic;

comparing the one or more generated references of the first security threat to the one or more generated references of the second security threat;

determining, based on the comparison, a correlation score that reflects a level of similarity between the first and second security threat; and

generating, based on the determined correlation score, a threat level indicator.

14. The non-transitory computer-readable storage medium of claim 13 further comprising:

comparing the threat indicator level to a threshold; and

initiating a security action if the threat indicator level exceeds the threshold.

15. The non-transitory computer-readable storage medium of claim 14 wherein initiating the security action comprises:

generating an alert; and

providing the alert to the protected social entity.

16. The non-transitory computer-readable storage medium of claim 15 wherein providing the alert to the protected social entity comprises providing a computer-based alert to the protected social entity.

17. The method of claim 1 further comprising:

scanning data that is maintained in a published disclosure file, wherein scanning comprises identifying, by one or more processors, a third security threat that is associated with a protected social entity;

determining one or more characteristics of the third security threat;

generating, for each of the one or more characteristics, a reference to the security threat that indicates the characteristic;

comparing the one or more generated references of the first security threat and second security threat to the one or more generated references of the third security threat;

determining, based on the comparison, a match;

generating, based on the determined match, an alert; and

providing the alert to the protected social entity.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: ZEROFOX, INC.
Reel/Frame 067429/0328 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: ZEROFOX, INC.
Reel/Frame 060821/0173 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: VIGILANTEATI, INC.
Reel/Frame 060821/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR AND ASSIGNEE'S INFORMATION ON THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 054878 FRAME: 0117. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 6, 2022
From: HERCULES CAPITAL, INC.
To: ZEROFOX, INC.
Reel/Frame 058652/0754 →
SECURITY INTEREST Recorded Jan 28, 2021
From: ZEROFOX, INC.
To: STIFEL BANK
Reel/Frame 055066/0916 →
SECURITY INTEREST Recorded Jan 13, 2021
From: ZEROFOX, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 054906/0449 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2021
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 054878/0117 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 26, 2019
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 049602/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2019
From: CULLISON, CHRISTOPHER B.; PRICE, MICHAEL; FOSTER, JAMES
To: ZEROFOX, INC.
Reel/Frame 048778/0190 →
Continuity (2)
Provisional Application 62545641 · Aug 15, 2017
Related Publication 20190058721A1 · Feb 21, 2019