IP Library Granted Patent US 11,601,444
Granted Patent B1
US 11,601,444 · App. 16/726,723 · Granted Mar 7, 2023

Automated system for triage of customer issues

Inventors: Sai Vashisht (Morgan Hill, CA); Rahul Khul (Pune, IN)
Assignee: FireEye Security Holdings US LLC
H04L63/1416G06F40/205H04L63/1441G06F11/3664
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,444
App. No.
16/726,723
Granted
Mar 7, 2023
Kind
B1
Abstract

A device for verifying previous determinations from cybersecurity devices comprising a processor and a storage device communicatively coupled to the processor. The storage device comprises submission analysis logic including object parsing logic to receive submission message data and then parse the submission message data into object data, along with workflow selector logic to receive the object data and process the object data to select at least one analyzer within analyzer logic. The analyzer logic can generate at least one analyzer based on the selected analyzer within the workflow selector logic, analyze the object data for potential threats and embedded object data, generate results data based on that analysis, and pass the embedded object data back to the workflow selector for further analysis. Finally, the submission analysis logic comprises triage ticket generation logic to generate triage tickets for analyst review and alert logic to generate automatic alerts.

Claims (39)

1. An electronic device for automated triaging of cybersecurity threats, the electronic device comprising:

a processor; and

a non-transitory storage medium communicatively coupled to the processor, the non-transitory storage medium comprises submission analysis logic configured to receive and process a submission message from a submitter and triage the submission message data associated with the submission message by utilizing:

an object parsing logic configured to receive the submission message data and parse the submission message data into object data and context data;

a workflow selector logic configured to receive object data and process the object data to select at least one analyzer;

an analyzer logic configured to (i) utilize at least one analyzer based on the selected analyzer within the workflow selector logic, (ii) analyze the object data for maliciousness, and (iii) generate results data;

a correlation logic configured to receive the results data and generate score data based on the received results data; and

a triage ticket generation logic configured to receive the score data and generate triage data, wherein, in response to the triage data surpassing a pre-determined threshold, a triage ticket is generated.

2. The electronic device of claim 1 , wherein the workflow selector logic is configured to select the at least one analyzer within the analyzer logic in response to both the object data and the context data.

3. The electronic device of claim 1 , wherein the workflow selector logic is further configured to receive the object data and the context data.

4. The electronic device of claim 1 , wherein the correlation logic further receives results data and the context data and wherein the score data is generated in response to both the results data and the context data.

5. The electronic device of claim 1 , wherein the at least one analyzer, generated by the analyzer logic, emulates at least one computing environment with a plurality of computing environment settings.

6. The electronic device of claim 1 , wherein the at least one analyzer, generated by the analyzer logic, emulates at least one software program with a specified software version with a plurality of software settings.

7. The electronic device of claim 6 , wherein the context data comprises data relating to at least one of: computing environment, software version, software settings, computing environment settings, prior threat analysis methods, and prior threat analysis results.

8. The electronic device of claim 7 , wherein the selection of the at least one analyzer by the workflow selector logic comprises selecting an analyzer with different computing environment settings than the computer environment settings in the context data.

9. The electronic device of claim 7 , wherein the selection of the at least one analyzer by the workflow selector logic comprises selecting an analyzer with different software settings than the software settings in the context data.

10. The electronic device of claim 1 , wherein the submission analysis logic further comprises an alert logic, being processed by the processor, to receive the triage data and, in response to surpassing a pre-determined threshold, automatically generate at least one alert to the submitter.

11. The electronic device of claim 1 , wherein the analyzer logic utilizes at least one pre-generated analyzer.

12. The electronic device of claim 1 , wherein the analyzer logic further comprises passing embedded object data to the workflow selector for further analysis.

13. A method for automated triaging of cybersecurity threats, the method comprising:

parsing data associated with a received submission message into object data and context data;

generating at least one analyzer based, at least in part, on the parsed object data;

analyzing the object data within at least one analyzer for potential threats;

generating results data based on the analyzed object data;

generating score data based on the results data;

generating triage data based on the score data;

generating a triage report in response to the triage data surpassing a first pre-determined threshold; and

generating an alert to a submitter based on the triage data surpassing a second pre-determined threshold.

14. The method of claim 13 , wherein the alert is generated automatically in response to the triage data not surpassing the first pre-determined threshold.

15. The method of claim 13 , wherein the selecting of at least one analyzer is further based on the parsed context data.

16. The method of claim 13 , wherein the generating of the score data is further based on the parsed context data.

17. The method of claim 13 , wherein the at least one analyzer emulates at least one computing environment with a plurality of computing environment settings.

18. The method of claim 13 , wherein the at least one analyzer emulates at least one software program with a specified software version with a plurality of software settings.

19. The method of claim 18 , wherein the context data comprises data relating to at least one of: computing environment, software version, software settings, computing environment settings, prior threat analysis methods, and prior threat analysis results.

20. The method of claim 19 , wherein the selecting of the at least one analyzer comprises selecting an analyzer with different software settings than the software settings in the context data.

21. The method of claim 13 further comprising:

analyzing the object data within the at least one analyzer for embedded object data;

selecting an analyzer for the embedded object data; and

analyzing the embedded object data.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
CHANGE OF NAME Recorded Oct 26, 2022
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 061784/0289 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 061783/0950 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2020
From: VASHISHT, SAI; KHUL, RAHUL
To: FIREEYE, INC.
Reel/Frame 051880/0336 →
Cited By (1)
US 12,682,249