IP Library Granted Patent US 10,902,114
Granted Patent B1
US 10,902,114 · App. 16/208,531 · Granted Jan 26, 2021

Automated cybersecurity threat detection with aggregation and analysis

Inventors: Ryan Trost (Vienna, VA); Leon Ward (Reading, GB)
Assignee: THREATQUOTIENT, INC.
G06F21/552G06F16/22G06F16/26G06F16/288G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,902,114
App. No.
16/208,531
Filed
Dec 3, 2018
Granted
Jan 26, 2021
Kind
B1
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/25
Abstract

The systems and methods described herein generally relate to techniques for automated detection, aggregation, and integration of cybersecurity threats. The system ingests multiple data feeds which can be in one or numerous different formats. The system evaluates information based on defined scores to display to users threats and risks associated with them. The system also calculates decay rates for expiration of threats and indicators through various methods.

Claims (49)

1. A method for collecting, processing, and displaying cybersecurity threat intelligence information, comprising:

collecting threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parsing the collected threat intelligence information into a common format;

storing the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

storing the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of a threat indicator;

receiving the parsed threat intelligence information comprising threat indicators from the database;

storing the parsed threat intelligence information in a first threat data container object;

receiving investigation information relating to an active threat investigation, wherein the investigation information is one or more of: an event type, attack vector, indicator of compromise, adversary attribution, or file, and wherein the investigation information is associated with a threat indicator;

storing the investigation information in a second threat data container object;

identifying a common relation between the first threat data container object and the second threat data container object based on the respective threat indicators of the first threat data container object and the second threat data container object;

displaying the first threat data container object, the second threat data container object and a graphical indication of the common relation between the first threat data container object and the second threat data container object;

exporting formatted threat intelligence information, wherein the formatted threat intelligence information includes indicators, sources, and dates for input to a set visualization process; and

calculating a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of: a trend analysis, analysis based on date constraints, side-by-side comparison, or time series analysis.

2. The method of claim 1 , further comprising:

identifying multiple common relations between multiple threat data container objects;

assigning multiple subsets of common relations to multiple respective layers; and

selecting one of the multiple layers for display to a user such that the non-selected layers are not displayed.

3. The method of claim 2 , wherein at least one layer is associated with a level of access or an individual user.

4. The method of claim 1 , further comprising:

recording in association with a threat data container object an indication that a user has taken an action with respect to the threat data container object;

recording in association with the threat data container object a time associated with the action taken with respect to the threat data container object; and

displaying the threat data container object, a representation of the action taken, and the time associated with the action taken on the threat data container object.

5. The method of claim 1 , wherein the adversary attribution indicates one or more of a foreign intelligence actor, crimeware, hacktivist, or professional hacker.

6. The method of claim 1 , wherein threat intelligence information in the first threat data container object is a file hash, and the second threat data container contains at least one file hash, and further comprising:

comparing the file hashes in the first threat data container object and the second threat data container object to detect equality; and

if the file hashes are equal, then identifying a common relation between the first threat data container object and the second threat data container object, then identifying a file corresponding to the file hashes detected to be equal and transmitting that file to an external integration for threat analysis.

7. A method for collecting, processing, and displaying cybersecurity threat intelligence information, comprising:

collecting threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parsing the collected threat intelligence information into a common format;

storing the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

storing the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of a threat indicator;

receiving the parsed threat intelligence information comprising threat indicators from the database;

storing the parsed threat intelligence information in a first threat data container object;

receiving investigation information relating to an active threat investigation, wherein the investigation information is one or more of: an event type, attack vector, indicator of compromise, adversary attribution, or file, and wherein the investigation information is associated with a threat indicator;

storing the investigation information in a second threat data container object;

identifying a common relation between the first threat data container object and the second threat data container object based on the respective threat indicators of the first threat data container object and the second threat data container object; and

displaying the first threat data container object, the second threat data container object and a graphical indication of the common relation between the first threat data container object and the second threat data container object.

8. The method of claim 7 , further comprising:

identifying multiple common relations between multiple threat data container objects;

assigning multiple subsets of common relations to multiple respective layers; and

selecting one of the multiple layers for display to a user such that the non-selected layers are not displayed.

9. The method of claim 8 , wherein at least one layer is associated with a level of access or an individual user.

10. The method of claim 7 , further comprising:

recording in association with a threat data container object an indication that a user has taken an action with respect to the threat data container object;

recording in association with the threat data container object a time associated with the action taken with respect to the threat data container object; and

displaying the threat data container object, a representation of the action taken, and the time associated with the action taken on the threat data container object.

11. The method of claim 7 , wherein the adversary attribution indicates one or more of a foreign intelligence actor, crimeware, hacktivist, or professional hacker.

12. The method of claim 7 , wherein threat intelligence information in the first threat data container object is a file hash, and the second threat data container contains at least one file hash, and further comprising comparing the file hashes in the first threat data container object and the second threat data container object to detect equality, and if the file hashes are equal, then identifying a common relation between the first threat data container object and the second threat data container object.

13. The method of claim 12 , further comprising identifying a file corresponding to the file hashes detected to be equal, and transmitting that file to an external integration for threat analysis.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: THREATQUOTIENT, INC.
To: SECURONIX, INC.
Reel/Frame 071908/0453 →
SECURITY INTEREST Recorded Jul 31, 2025
From: THREATQUOTIENT, INC.
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 071891/0963 →
RELEASE OF SECURITY INTEREST Recorded Jun 10, 2025
From: AVENUE CAPITAL MANAGEMENT II, L.P.
To: THREATQUOTIENT, INC.
Reel/Frame 071379/0059 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT RECORDED AT REEL 052629 FRAME 0901 Recorded Apr 9, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: THREATQUOTIENT, INC.
Reel/Frame 070793/0021 →
SECURITY INTEREST Recorded Jul 28, 2023
From: THREATQUOTIENT, INC.
To: AVENUE CAPITAL MANAGEMENT II, L.P.
Reel/Frame 064420/0634 →
SECURITY INTEREST Recorded May 11, 2020
From: THREATQUOTIENT, INC.
To: SILICON VALLEY BANK
Reel/Frame 052629/0901 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2019
From: TROST, RYAN; WARD, LEON
To: THREATQUOTIENT, INC.,
Reel/Frame 048916/0504 →
Continuity (4)
Continuation In Part 15261867 · Sep 9, 2016
Provisional Application 62631695 · Feb 17, 2018
Provisional Application 62594014 · Dec 3, 2017
Provisional Application 62215777 · Sep 9, 2015
Cited By (11)
US 12,368,730 US 12,381,739 US 12,395,499 US 12,400,233 US 12,452,257 US 12,475,220 US 12,587,534 US 12,592,938 US 12,609,940 US 12,683,980 US 12,688,305