IP Library Granted Patent US 10,904,269
Granted Patent B2
US 10,904,269 · App. 16/684,756 · Granted Jan 26, 2021

Threat intelligence on a data exchange layer

Inventors: Christopher Smith (Sherwood, OR); Edward T. McDonald (Hillsboro, OR); Don R. Hanson, II (Portland, OR)
Assignee: McAfee, LLC
H04L63/1408H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,904,269
App. No.
16/684,756
Granted
Jan 26, 2021
Kind
B2
Abstract

There is disclosed in one example, a computing apparatus, including: a hardware platform including a processor and a memory; a network interface; a data exchange layer (DXL) application programming interface (API), the DXL API including instructions to communicatively couple the apparatus to a DXL bus and provide a DXL abstraction layer on top of a TCP/IP-based communication network; and a reputation engine including instructions encoded within memory to instruct the processor to: receive a plurality of DXL messages from a first DXL endpoint; compute a composite reputation for the first DXL endpoint; receive from a second DXL endpoint a DXL message requesting a reputation for the first DXL endpoint; establish a private topic on the DXL bus between the computing apparatus and the second DXL endpoint; and publish the composite reputation to the private topic.

Claims (49)

1. A computing apparatus, comprising:

a hardware platform comprising a processor and a memory;

a network interface;

a data exchange layer (DXL) application programming interface (API), the DXL API including instructions to communicatively couple the apparatus to a DXL bus and provide a DXL abstraction layer on top of a TCP/IP-based communication network; and

a reputation engine comprising instructions encoded within memory to instruct the processor to:

receive a plurality of DXL messages from a first DXL endpoint;

compute a composite reputation for the first DXL endpoint;

receive from a second DXL endpoint a DXL message requesting a reputation for the first DXL endpoint;

establish a private topic on the DXL bus between the computing apparatus and the second DXL endpoint; and

publish the composite reputation to the private topic.

2. The computing apparatus of claim 1 , wherein the reputation engine is further to instruct the processor to:

aggregate reputation data for a network object via a plurality of DXL messages;

compute a composite reputation for the network object;

receive from a DXL endpoint a DXL request message, via a private topic of the plurality of private topics, for a reputation for the network object; and

provide the composite reputation via a DXL message through the DXL broker and the one-to-many publish-subscribe fabric.

3. The computing apparatus of claim 2 , wherein the DXL message to provide the composite reputation has the same private topic as the DXL request message.

4. The computing apparatus of claim 2 , wherein the private topic belongs to a class of object reputation topics.

5. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object comprises:

querying a plurality of DXL endpoints;

identifying at least one of the queried DXL endpoints as being an authorized DXL reputation source; and

including, in the aggregating, reputation data from the at least one of the queried DXL endpoints identified as being an authorized DXL reputation source.

6. The computing apparatus of claim 5 , wherein aggregating the reputation data for the network object further comprises:

identifying at least one of the queried DXL endpoints as not being an authorized DXL reputation source; and

blocking object reputation data from the at least one queried DXL endpoint identified as not being an authorized DXL reputation source.

7. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object further comprises:

computing a weighted permission score for a scored DXL endpoint;

determining that the weighted permission score is sufficient to permit the scored DXL endpoint to act as a DXL reputation source; and

including, in the aggregation, reputation data from the scored DXL endpoint.

8. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object further comprises computing a reputation score for the network object based at least in part on a determination that a plurality of DXL endpoints have identified the network object as suspicious but not known malicious, and broadcasting a DXL message that the network object is to be blocked.

9. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object comprises computing a reputation score for the network object based at least in part on a determination that a plurality of DXL endpoints have identified the network object as suspicious but not known malicious, and broadcasting a DXL message that the network object is to be quarantined.

10. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object comprises computing a reputation score for the network object based at least in part on a determination that a plurality of DXL endpoints have identified the network object as suspicious but not known malicious, and broadcasting a DXL message that the network object is to be subjected to additional analysis.

11. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object comprises determining that at least one DXL endpoint has blocked the network object, and broadcasting a message that all DXL endpoints should block the network object.

12. The computing apparatus of claim 2 , wherein aggregating the reputation data for the network object comprises determining that the network object lacks a known reputation, and assigning a new reputation to the network object.

13. The computing apparatus of claim 12 , wherein assigning the new reputation comprises performing deep analysis on the object.

14. The computing apparatus of claim 12 , wherein assigning the new reputation comprises determining that the network object has been encountered multiple times within a time span, and assigning the network object a suspicious score.

15. The computing apparatus of claim 1 , further comprising a NoSQL-based reputation store.

16. One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to instruct a processor to:

overlay a data exchange layer (DXL) abstraction layer on a TCIP/IP network stack, the DXL abstraction layer to communicatively couple to a DXL bus;

receive via the DXL bus a DXL message from a first DXL endpoint requesting a reputation for an object, wherein the message comprises a private DXL topic for point-to-point communication;

compute a composite reputation for the object comprising aggregating reputation data from a plurality of other DXL endpoints; and

publish the composite reputation via a DXL message.

17. The one or more tangible, non-transitory computer-readable media of claim 16 , wherein publishing the composite reputation comprises publishing the composite reputation with the private DXL topic.

18. The one or more tangible, non-transitory computer-readable media of claim 16 , wherein publishing the composite reputation comprises publishing the composite reputation via a public DXL topic.

19. A method of providing a composite reputation on a data exchange layer (DXL), comprising:

communicatively coupling to a DXL bus, comprising providing an abstraction layer overlaid on a traditional internet protocol (IP) network;

receiving from a first DXL endpoint a first DXL message requesting a reputation for a network object;

computing a composite reputation for the second DXL endpoint comprising aggregating reputation data received via DXL messages from a plurality of DXL endpoints that have previously encountered the network object; and

providing the composite reputation to the first DXL endpoint.

20. The method of claim 19 , further comprising providing the composite reputation to a plurality of other DXL endpoints via a DXL public topic.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2019
From: SMITH, CHRISTOPHER; MCDONALD, EDWARD T.; HANSON, DON R., II
To: MCAFEE, LLC
Reel/Frame 051016/0746 →