IP Library Granted Patent US 10,951,645
Granted Patent B2
US 10,951,645 · App. 16/114,365 · Granted Mar 16, 2021

System and method for prevention of threat

Inventor: Bimodh Jo Mathew (Piscataway, NJ)
Assignee: Marlabs Innovations Private Limited
H04L63/1433G06F16/951H04L41/142H04L41/145H04L63/0263H04L63/1425H04L63/1441H04L63/205H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,951,645
App. No.
16/114,365
Granted
Mar 16, 2021
Kind
B2
Abstract

System and method for prevention of threat are disclosed. The system includes a processing subsystem. The processing subsystem includes a data extraction module configured to extract data from one or more internal sources such as a router, a firewall or a security solution and one or more external sources such as a deep, a dark and a surface web. The processing subsystem also includes an analysis module configured to analyse the data by using at least one threat analysis method for detection of the threat, a rule generation module configured to generate one or more rules to enable prevention of the threat detected, an implementation module configured to implement the one or more generated rules on at least one node associated with the one or more internal sources for prevention of the threat.

Claims (29)

1. A system for prevention of threat comprising:

a memory configured to store one or more generated rules associated with a threat;

a processing subsystem operatively coupled to the memory, wherein the processing subsystem comprises:

a data extraction module configured to extract data from one or more internal sources and one or more external sources through one or more web crawlers using one or more parameters, wherein the one or more parameters comprises at least one of a keyword, content of search and a search string; wherein the one or more external sources comprises at least one of a deep web, a dark web and a surface web;

an analysis module operatively coupled to the data extraction module, wherein the analysis module is configured to:

analyse one or more elements from extracted data by using at least one of a co-relation analysis technique, a behavioural analysis technique and a contextual analysis technique; and

determine a type of threat, one or more existing threats and one or more upcoming threats based on one or more analysed elements, wherein the type of threat, the one or more existing threats and the one or more upcoming threats are obtained from at least one of a specific environment, a specific geographical area or a specific sector of an organization;

a rule generation module operatively coupled to the analysis module, wherein the rule generation module is configured to:

generate one or more rules in real time by monitoring the type of the threat, the one or more existing threats and the one or more upcoming threats determined by the analysis module; and

evaluate every packet of the extracted data based on one or more generated rules; and

an implementation module operatively coupled to the rule generation module, wherein the implementation module is configured to:

implement the one or more generated rules on at least one node corresponding to at least one computer device indulged in malicious activities upon evaluation of every packet of the extracted data; and

generate a notification in real-time to alert a system administrator to take one or more actions for prevention of threat upon implementing the one or more generated rules.

2. The system as claimed in claim 1 , wherein the processing subsystem operatively coupled to the memory is stored on a remote storage.

3. The system as claimed in claim 1 , further comprising a representation module operatively coupled to the analysis module, and configured to present the threat in one or more forms, wherein the one or more forms comprises at least one of a report, a dashboard, a structured threat information expression and an application programming interface.

4. The system as claimed in claim 1 , wherein the one or more internal sources comprises at least one of a firewall, a router and a security solution.

5. The system as claimed in claim 1 , wherein the one or more elements comprises at least one of a context of the data, depth of the context of the data, relationship between the context and the one or more parameters, interaction or communication within the one or more internal sources and the one or more external sources.

6. The system as claimed in claim 1 , wherein the one or more actions comprises deny access of acquiring the data from the one or more internal sources and the one or more external sources, drop a detected malicious packet or cease or disrupt an attack.

7. A method for preventing a threat comprising:

extracting, by a data extraction module, data from one or more internal sources and one or more external sources through one or more web crawlers using one or more parameters, wherein the one or more parameters comprises at least one of a keyword, content of search and a search string,

wherein the one or more external sources comprises at least one of a deep web, a dark web and a surface web;

analysing, by an analysis module, one or more elements from extracted data by using at least one of a co-relation analysis technique, a behavioural analysis technique and a contextual analysis technique;

determining, by the analysis module, a type of the threat, one or more existing threats and one or more upcoming threats based on one or more analysed elements, wherein the type of threat, the one or more existing threats and the one or more upcoming threats are obtained from at least one of a specific environment, a specific geographical area or a specific sector of an organization;

generating, by a rule generation module, one or more rules in real time by monitoring the type of the threat, the one or more existing threats and the one or more upcoming threats determined by the analysis module;

evaluating, by the rule generation module, every packet of the extracted data based on one or more generated rules;

implementing, by an implementation module, the one or more generated rules on at least one node corresponding to at least one computer device indulged in malicious activities upon evaluation of every packet of the extracted data; and

generating, by the implementation module, a notification in real-time to alert a system administrator to take one or more actions for prevention of threat upon implementing the one or more generated rules.

8. The method as claimed in claim 7 , wherein storing the one or more generated rules associated to the threat comprises storing the one or more generated rules associated to the threat on a remote storage.

9. The method as claimed in claim 7 , further comprising presenting the data associated with the threat in one or more forms, wherein the one or more forms comprises at least one of a report, a dashboard, a structured threat information expression and an application programming interface.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Aug 6, 2025
From: FIFTH THIRD BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: MARLABS LLC
Reel/Frame 071951/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 20, 2022
From: MARLABS LLC
To: FIFTH THIRD BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 058785/0855 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2021
From: MARLABS INNOVATIONS PRIVATE LIMITED
To: MARLABS INCORPORATED
Reel/Frame 057856/0397 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2019
From: MATHEW, BIMODH JO
To: MARLABS INNOVATIONS PRIVATE LIMITED
Reel/Frame 050007/0156 →
Continuity (1)
Related Publication 20200076845A1 · Mar 5, 2020
Cited By (2)
US 12,261,864 US 12,328,295