IP Library Granted Patent US 11,418,536
Granted Patent B2
US 11,418,536 · App. 16/552,693 · Granted Aug 16, 2022

Threat intelligence system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
H04L63/1441H04L63/1408H04L67/02H04L67/2814
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,418,536
App. No.
16/552,693
Granted
Aug 16, 2022
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions. The plurality of raw threat data definitions are processed, thus generating a plurality of processed threat data definitions. The plurality of processed threat data definitions are processed to form a master threat data definition. The master threat data definition is provided to one or more client electronic devices.

Claims (75)

1. A computer-implemented method, executed on a computing device, comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions, wherein the plurality of threat data sources includes social network trader sources on which hackers/bad actors exchange information concerning their hacking experiences, expertise and insights, wherein importing threat data from a plurality of threat data sources includes defining a list of specific keywords and searching the social network trader sources for the specific keywords, wherein the list of keywords concern one or more of a specific type of attack, a specific company/organization targeted for an attack, and a specific known hacker;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein the plurality of raw threat data definitions include a plurality of data pieces with an age level;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with the one or more client electronic devices; and

providing the master threat data definition to one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

2. The computer-implemented method of claim 1 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

3. The computer-implemented method of claim 1 wherein processing the plurality of raw threat data definitions includes one or more of:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

converting the plurality of raw threat data definitions into a common format;

determining a category for each of the plurality of raw threat data definitions;

determining a source for each of the plurality of raw threat data definitions;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

4. The computer-implemented method of claim 1 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

5. The computer-implemented method of claim 1 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

6. The computer-implemented method of claim 1 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers; and

open source threat feeds.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions, wherein the plurality of threat data sources includes social network trader sources on which hackers/bad actors exchange information concerning their hacking experiences, expertise and insights, wherein importing threat data from a plurality of threat data sources includes defining a list of specific keywords and searching the social network trader sources for the specific keywords, wherein the list of keywords concern one or more of a specific type of attack, a specific company/organization targeted for an attack, and a specific known hacker;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein the plurality of raw threat data definitions include a plurality of data pieces with an age level;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with the one or more client electronic devices; and

providing the master threat data definition to one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

8. The computer program product of claim 7 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

9. The computer program product of claim 7 wherein processing the plurality of raw threat data definitions includes one or more of:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

converting the plurality of raw threat data definitions into a common format;

determining a category for each of the plurality of raw threat data definitions;

determining a source for each of the plurality of raw threat data definitions;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

10. The computer program product of claim 7 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

11. The computer program product of claim 7 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

12. The computer program product of claim 7 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers; and

open source threat feeds.

13. A computing system including a processor and memory configured to perform operations comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions, wherein the plurality of threat data sources includes social network trader sources on which hackers/bad actors exchange information concerning their hacking experiences, expertise and insights, wherein importing threat data from a plurality of threat data sources includes defining a list of specific keywords and searching the social network trader sources for the specific keywords, wherein the list of keywords concern one or more of a specific type of attack, a specific company/organization targeted for an attack, and a specific known hacker;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein the plurality of raw threat data definitions include a plurality of data pieces with an age level;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with the one or more client electronic devices; and

providing the master threat data definition to one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

14. The computing system of claim 13 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

15. The computing system of claim 13 wherein processing the plurality of raw threat data definitions includes one or more of:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

converting the plurality of raw threat data definitions into a common format;

determining a category for each of the plurality of raw threat data definitions;

determining a source for each of the plurality of raw threat data definitions;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

16. The computing system of claim 13 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

17. The computing system of claim 13 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

18. The computing system of claim 13 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers; and

open source threat feeds.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2019
From: MURPHY, BRIAN P; PARTLOW, JOE
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 050185/0403 →
Continuity (3)
Continuation 15202213 · Jul 5, 2016
Provisional Application 62187922 · Jul 2, 2015
Related Publication 20190394226A1 · Dec 26, 2019
Cited By (1)
US 12,627,692