IP Library Granted Patent US 10,791,141
Granted Patent B2
US 10,791,141 · App. 16/541,036 · Granted Sep 29, 2020

Anonymized network data collection and network threat assessment and monitoring systems and methods

Inventors: William Peteroy (Redmond, WA); Josh Carlson (Carnation, WA)
Assignee: icebrg Inc.
H04L63/1441H04L63/0421H04L63/0471H04L69/08H04L69/22H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,791,141
App. No.
16/541,036
Granted
Sep 29, 2020
Kind
B2
Abstract

Systems and methods for data collection and processing in a network, including one or more sensors disposed in a network interface and configured to collect raw signal traffic data where each sensor is further configured to parse the raw signal traffic data into network protocols; split the network protocols into content data and metadata; derive contextual metadata from the content data; compile the metadata and the derived metadata to produce anonymized metadata; encrypt the anonymized metadata; and transmit to the encrypted anonymized metadata to a unified data server.

Claims (89)

1. A computer implemented method comprising:

obtaining a plurality of encrypted anonymized network communications from a first network, the plurality of encrypted anonymized network communications including encrypted anonymized network metadata and contextual metadata derived from network communications traffic associated with the first network;

decrypting the first plurality of encrypted anonymized network communications to obtain a plurality of anonymized network communications from the first network, including a first anonymized network communication; and

generating a network security assessment associated with the first network based at least partially on the first anonymized network communication.

2. The method of claim 1 , further comprising generating a network security assessment of a second network based at least partially on the first anonymized network communication.

3. The method of claim 1 , comprising:

obtaining a security alert relating to an attacking network element and the first network;

generating a network entity having a graph representation of the attacking network element, the network entity being at least partially based on information related to the first anonymized network communication;

providing a displayable version the network entity;

generating a threat entity using information in the data store, the threat entity: being at least partially based on information related to the first anonymized network communication, having a graph representation, and describing a customer

context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the threat entity.

4. The method of claim 3 wherein the customer context includes information regarding a compromised network element in the first network and network communications between the compromised network element and the attacking network element.

5. The method of claim 3 , comprising:

obtaining a plurality of encrypted anonymized network communications from a second network, decrypting the plurality of encrypted anonymized network communications from the second network, thereby obtaining a plurality of anonymized network communications from the second network, including a second anonymized network communication; providing the second anonymized network communication to the data store; and generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on information related to the first anonymized network communication and the second anonymized network communication, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

6. The method of claim 3 , comprising:

applying analytics to the threat entity and information in the data store, identifying a network relationship between the attacking network element and an unknown network element;

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the network relationship, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element and the unknown network element; and

providing a displayable version of the updated threat entity.

7. The method of claim 3 , comprising:

obtaining external network security information from an external source, providing the network security information to the data store; and

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the external network security information, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

8. A non-transitory computer-readable medium have contents, execution of which in a processing system cause the processing system to perform a method comprising:

identifying a communication protocol related to a first network communication of a plurality of network communications of a network;

identifying a network metadata portion of the first network communication, based at least partially on the communication protocol;

identifying a data portion of the first network communication based at least partially on the communication protocol;

generating anonymized contextual metadata based on the data portion; and

combining the network metadata and the anonymized contextual metadata into a first anonymized network communication.

9. The non-transitory computer-readable medium of claim 8 wherein the method includes generating an encrypted version of the first anonymized network communications, and providing the plurality of encrypted anonymized network communications to a remote server.

10. The non-transitory computer-readable medium of claim 9 wherein the contextual metadata is derived from characteristics of the first network communication including authorization traffic, HTTP flow, encryption, VPN activity, encryption certificates, passive fingerprints and application traffic.

11. A non-transitory computer-readable medium have contents that configure a processing system to perform a process comprising:

obtaining a plurality of encrypted anonymized network communications from a first network, the plurality of encrypted anonymized network communications including encrypted anonymized network metadata and contextual metadata derived from network communications traffic associated with the first network;

decrypting the first plurality of encrypted anonymized network communications to obtain a plurality of anonymized network communications from the first network, including a first anonymized network communication; and

generating a network security assessment associated with the first network based at least partially on the first anonymized network communication.

12. The non-transitory computer-readable medium of claim 11 , the process further comprising generating a network security assessment of a second network based at least partially on the first anonymized network communication.

13. The non-transitory computer-readable medium of claim 11 , the process comprising:

obtaining a security alert relating to an attacking network element and the first network;

generating a network entity having a graph representation of the attacking network element using information in the data store, the network entity being at least partially based on information related to the first anonymized network communication;

providing a displayable version the network entity;

generating a threat entity using information in the data store, the threat entity: being at least partially based on information related to the first anonymized network communication, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the threat entity.

14. The non-transitory computer-readable medium of claim 13 wherein the customer context includes information regarding a compromised network element in the first network and network communications between the compromised network element and the attacking network element.

15. The non-transitory computer-readable medium of claim 13 , the process comprising:

obtaining a plurality of encrypted anonymized network communications from a second network, decrypting the plurality of encrypted anonymized network communications from the second network, thereby obtaining a plurality of anonymized network communications from the second network, including a second anonymized network communication; providing the second anonymized network communication to the data store; and generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on information related to the first anonymized network communication and the second anonymized network communication, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

16. The non-transitory computer-readable medium of claim 13 , the process comprising:

applying analytics to the threat entity and information in the data store, identifying a network relationship between the attacking network element and an unknown network element;

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the network relationship, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element and the unknown network element; and

providing a displayable version of the updated threat entity.

17. The non-transitory computer-readable medium of claim 13 , the process comprising:

obtaining external network security information from an external source, providing the network security information to the data store; and

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the external network security information, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

18. A system comprising:

a memory; and

processing circuitry coupled to the memory, wherein the processing circuitry, when in operation, controls a process that includes:

obtaining a plurality of encrypted anonymized network communications from a first network, the plurality of encrypted anonymized network communications including encrypted anonymized network metadata and contextual metadata derived from network communications traffic associated with the first network;

decrypting the first plurality of encrypted anonymized network communications, to obtain a plurality of anonymized network communications from the first network, including a first anonymized network communication; and

generating a network security assessment associated with the first network based at least partially on the first anonymized network communication.

19. The system of claim 18 , the process further comprising generating a network security assessment of a second network based at least partially on the first anonymized network communication.

20. The system of claim 18 , the process comprising:

obtaining a security alert relating to an attacking network element and the first network;

generating a network entity having a graph representation of the attacking network element using information in the data store, the network entity being at least partially based on information related to the first anonymized network communication;

providing a displayable version the network entity;

generating a threat entity using information in the data store, the threat entity: being at least partially based on information related to the first anonymized network communication, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the threat entity.

21. The system of claim 20 wherein the customer context includes information regarding a compromised network element in the first network and network communications between the compromised network element and the attacking network element.

22. The system of claim 20 , the process comprising:

obtaining a plurality of encrypted anonymized network communications from a second network, decrypting the plurality of encrypted anonymized network communications from the second network, thereby obtaining a plurality of anonymized network communications from the second network, including a second anonymized network communication; providing the second anonymized network communication to the data store; and generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on information related to the first anonymized network communication and the second anonymized network communication, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

23. The system of claim 20 , the process comprising:

applying analytics to the threat entity and information in the data store, identifying a network relationship between the attacking network element and an unknown network element;

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the network relationship, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element and the unknown network element; and

providing a displayable version of the updated threat entity.

24. The system of claim 20 , the process comprising:

obtaining external network security information from an external source, providing the network security information to the data store; and

generating an updated threat entity using information in the data store, the updated threat entity:

being at least partially based on the external network security information, having a graph representation, and describing a customer context, a global context, and a network context related to the attacking network element; and

providing a displayable version of the updated threat entity.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: PETEROY, WILLIAM; CARLSON, JOSH
To: ICEBRG INC.
Reel/Frame 065770/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: PETEROY, WILLIAM; CARLSON, JOSH
To: ICEBRG INC.
Reel/Frame 065771/0617 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2023
From: ICEBRG LLC
To: FORTINET, INC.
Reel/Frame 062364/0854 →
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2022
From: JEFFERIES FINANCE LLC
To: ICEBRG LLC
Reel/Frame 062194/0522 →
ENTITY CONVERSION Recorded Dec 2, 2022
From: ICEBRG INC.
To: ICEBRG LLC
Reel/Frame 062048/0167 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
Continuity (4)
Continuation 15877162 · Jan 22, 2018
Continuation 14838279 · Aug 27, 2015
Provisional Application 62042726 · Aug 27, 2014
Related Publication 20190373014A1 · Dec 5, 2019
Cited By (2)
US 12,381,845 US 12,585,784