IP Library Granted Patent US 12,231,441
Granted Patent B2
US 12,231,441 · App. 17/155,318 · Granted Feb 18, 2025

Threat intelligence on a data exchange layer

Inventors: Christopher Smith (Sherwood, OR); Edward T. McDonald (Hillsboro, OR); Don R. Hanson, II (Portland, OR)
Assignee: Musarubra US LLC
H04L63/1408H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,441
App. No.
17/155,318
Granted
Feb 18, 2025
Kind
B2
Abstract

In an example, a threat intelligence controller is configured to operate on a data exchange layer (DXL). The threat intelligence controller acts as a DXL consumer of reputation data for a network object, which may be reported in various different types and from various different sources. Of the devices authorized to act as reputation data producers, each may have its own trust level. As the threat intelligence controller aggregates data from various providers, it may weight the reputation reports according to trust level. The threat intelligence engine thus builds a composite reputation for the object. When it receives a DXL message requesting a reputation for the object, it publishes the composite reputation on the DXL bus.

Claims (48)

1. A computing apparatus, comprising:

a network interface to receive a message from an enterprise service bus, the message having a topic for an object, the topic associated with a first trust level; and

a hardware processor to at least:

access a notification of a subscription to the topic, the notification received from an endpoint;

publish an indication that the computing apparatus is subscribed to the topic, at least in part based on the notification, the computing apparatus having a second trust level greater than the first trust level;

determine that the endpoint is subscribed to the topic, at least in part based on the subscription;

distribute the message to the endpoint based on the second trust level being greater than the first trust level;

when the second trust level satisfies a trust threshold, update a composite reputation score for the object, at least in part based on the message;

perform a determination that an issue with the object has been encountered; and

publish a security instruction over the enterprise service bus to the endpoint, at least in part based on the determination.

2. The computing apparatus of claim 1 , wherein the issue includes at least one of a security event, a security alert, a designation of the object as malware, or a security breach.

3. The computing apparatus of claim 1 , wherein the hardware processor is to subscribe to a private topic for the endpoint.

4. The computing apparatus of claim 1 , wherein the security instruction represents an instruction to block the object, the security instruction being broadcast to a plurality of devices.

5. The computing apparatus of claim 1 , wherein the message is a first message, wherein the network interface is to:

receive a second message having a request topic for a reputation of the object; and

provide the composite reputation score via a third message having a response topic for the reputation of the object.

6. The computing apparatus of claim 1 , wherein the security instruction includes an expiration.

7. A non-transitory, computer-readable medium having stored thereon instructions that, when executed, cause a computing apparatus to at least:

access a message from an enterprise service bus, the message having a topic for an object, the topic associated with a first trust level;

access a notification of a subscription to the topic from an endpoint;

publish that the computing apparatus is subscribed to the topic, at least in part based on the notification, the computing apparatus having a second trust level greater than the first trust level;

determine that the endpoint is subscribed to the topic, at least in part based on the subscription;

distribute the message to the endpoint based on the second trust level being greater than the first trust level;

when the second trust level satisfies a trust threshold, update a composite reputation score for the object, at least in part based on the message;

perform a determination that an issue with the object has been encountered; and

publish a security instruction over the enterprise service bus to the endpoint, at least in part based on the determination.

8. The computer-readable medium of claim 7 , wherein the issue is a at least one of a security event, a security alert, a designation of the object as malware, or a security breach.

9. The computer-readable medium of claim 7 , wherein the instructions, when executed, cause the computing apparatus to subscribe to a private topic for the endpoint.

10. The computer-readable medium of claim 7 , wherein the security instruction represents a second instruction to block the object, the security instruction being broadcast to a plurality of devices.

11. The computer-readable medium of claim 7 , wherein the message is a first message, wherein the instructions, when executed, cause the computing apparatus to:

access a second message having a request topic for a reputation of the object; and

provide the composite reputation score via a third message having a response topic for the reputation of the object.

12. The computer-readable medium of claim 7 , wherein the security instruction includes an expiration.

13. A method implemented by a computing apparatus, the method comprising:

receiving a message from an enterprise service bus, the message having a topic for an object, the topic associated with a first trust level;

receiving a notification of a subscription to the topic from an endpoint;

publishing that the computing apparatus is subscribed to the topic, at least in part based on the notification, the computing apparatus having a second trust level greater than the first trust level;

determining that the endpoint is subscribed to the topic, at least in part based on the subscription;

distributing the message to the endpoint based on the second trust level being greater than the first trust level;

when the second trust level satisfies a trust threshold, updating a composite reputation score for the object, at least in part based on the message;

determining that an issue with the object has been encountered; and

publishing a security instruction over the enterprise service bus to the endpoint, at least in part based on the determination.

14. The method of claim 13 , wherein the issue is at least one of a security event, a security alert, a designation of the object as malware, or a security breach.

15. The method of claim 13 , further including subscribing to a private topic for the endpoint.

16. The method of claim 13 , wherein the security instruction represents an instruction to block the object, the security instruction being broadcast to a plurality of devices.

17. The method of claim 13 , wherein the message is a first message, further including:

receiving a second message having a request topic for a reputation of the object; and

providing the composite reputation score via a third message having a response topic for the reputation of the object.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059855/0807 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
Continuity (4)
Continuation 16684756 · Nov 15, 2019
Continuation 14912743
Provisional Application 61884100 · Sep 29, 2013
Related Publication 20210144157A1 · May 13, 2021
References Cited (66)
US 5987610A · Franczek et al. · 1999 [cited by applicant]
US 6073142A · Geiger et al. · 2000 [cited by applicant]
US 6460050B1 · Pace et al. · 2002 [cited by applicant]
US 7506155B1 · Stewart et al. · 2009 [cited by applicant]
US 7716297B1 · Wittel et al. · 2010 [cited by applicant]
US 8336100B1 · Glick et al. · 2012 [cited by applicant]
US 8510836B1 · Nachenberg · 2013 [cited by applicant]
US 8868654B2 · Guha · 2014 [cited by examiner]
US 9779392B1 · Prasad · 2017 [cited by examiner]
US 10275267B1 · de Kadt · 2019 [cited by examiner]
US 20020049785A1 · Bauchot · 2002 [cited by applicant]
US 20020165815A1 · Vincent · 2002 [cited by applicant]
US 20030182567A1 · Barton et al. · 2003 [cited by applicant]
US 20060253581A1 · Dixon et al. · 2006 [cited by applicant]
US 20070022589A1 · Ishizuka et al. · 2007 [cited by applicant]
US 20070130351A1 · Alperovitch et al. · 2007 [cited by applicant]
US 20070222589A1 · Gorman · 2007 [cited by applicant]
US 20080005223A1 · Flake et al. · 2008 [cited by applicant]
US 20080103798A1 · Domenikos · 2008 [cited by examiner]
US 20080133300A1 · Jalinous · 2008 [cited by examiner]
US 20080320552A1 · Kumar · 2008 [cited by examiner]
US 20100057835A1 · Little · 2010 [cited by applicant]
US 20100169148A1 · Oberhofer · 2010 [cited by examiner]
US 20100179832A1 · Deursen et al. · 2010 [cited by applicant]
US 20100192216A1 · Komatsu · 2010 [cited by applicant]
US 20100324942A1 · Rogers · 2010 [cited by examiner]
US 20110004693A1 · Rehfuss · 2011 [cited by applicant]
US 20110113105A1 · Eckardt · 2011 [cited by applicant]
US 20110196824A1 · Maes · 2011 [cited by applicant]
US 20110307474A1 · Hom et al. · 2011 [cited by applicant]
US 20120030293A1 · Bobotek · 2012 [cited by applicant]
US 20120072480A1 · Hays et al. · 2012 [cited by applicant]
US 20120197911A1 · Banka et al. · 2012 [cited by applicant]
US 20120210335A1 · Salt et al. · 2012 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20130254897A1 · Reedy et al. · 2013 [cited by applicant]
US 20130276089A1 · Tseitlin · 2013 [cited by examiner]
US 20140059683A1 · Ashley · 2014 [cited by applicant]
US 20140096251A1 · Doctor et al. · 2014 [cited by applicant]
US 20140109190A1 · Cam-Winget et al. · 2014 [cited by applicant]
US 20140150060A1 · Riley · 2014 [cited by applicant]
US 20140331119A1 · Dixon et al. · 2014 [cited by applicant]
US 20150067849A1 · Agrawal et al. · 2015 [cited by applicant]
US 20150207809A1 · Macaulay · 2015 [cited by applicant]
US 20160197941A1 · Smith et al. · 2016 [cited by applicant]
CN 101681400A · 2010 [cited by applicant]
WO 2015048687A1 · 2015 [cited by applicant]
Banavar G, Chandra T, Mukherjee B, Nagarajarao J, Strom RE, Sturman DC. “An efficient multicast protocol for content-based publish-subscribe systems”. In Proceedings. 19th IEEE International Conference on Distributed Co… [cited by examiner]
Non Final Office Action in U.S. Appl. No. 14/912,743 dated Dec. 11, 2017, 14 pages. [cited by applicant]
Non Final Office Action in U.S. Appl. No. 14/912,73 dated Dec. 13, 2018, 15 pages. [cited by applicant]
Non Final Office Action in U.S. Appl. No. 16/684,756 dated Jul. 24, 2020, 6 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 14/912,743 date Jul. 3, 2019, 19 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/684,756 dated Nov. 17, 2020, 8 pages. [cited by applicant]
“Survey on NoSQL Database,” Han, et al IEEE, 2011, pp. 363-366. [cited by applicant]
“Enterprise Service Bus—Wikipedia”, Anonymous, Sep. 28, 2013, retrieved from the Internet: https://en.wikipedia.org/w/index.php?title=Enterprise_service_bus&oldid=574913410. retrieved on Mar. 6, 2017. [cited by applicant]
Lyublena Antova, Konstantinos Krikellas, Florian M. Waas “Automatic Capture of Minimal, Portable, and Executable Bug Repros Using AMPERe”, 2012, ACM , 6 pages (Year: 2012). [cited by applicant]
International Searching Authority, “International Search Report,” issued in connection with International Application No. PCT/US2014/058130, mailed on Jan. 12, 2015, 4 pages. [cited by applicant]
International Searching Authority, “International Preliminary Report on Patentability,” issued in connection with International Application No. PCT/US2014/058130, issued on Mar. 29, 2016, 5 pages. [cited by applicant]
European Patent Office, “Extended European Search Report,” issued in connection with European Patent Application No. 14847338.2, dated Mar. 15, 2017, 7 pages. [cited by applicant]
European Patent Office, “Communication pursuant to Article 94(3) EPC,” issued in connection with European Patent Application No. 14847338.2, dated Feb. 22, 2018, 4 pages. [cited by applicant]
Chinese First Office Action in Chinese Patent Application No. 201480048617.9 dated May 8, 2018, 13 pages with translation. [cited by applicant]
European Patent Office, “Communication under Rule 71(3) EPC,” issued in connection with European Patent Application No. 14847338.2, dated Sep. 10, 2018, 8 pages. [cited by applicant]
European Patent Office, “Communication under Rule 71(3) EPC,” issued in connection with European Patent Application No. 14847338.2, dated Jan. 17, 2019, 8 pages. [cited by applicant]
European Patent Office, “Decision to Grant a European Patent,” issued in connection with European Patent Application No. 14847338.2, dated Feb. 14, 2019, 2 pages. [cited by applicant]
United States Patent and Trademark Office, “Advisory Action,” issued in connection with U.S. Appl. No. 14/912,743, dated Oct. 5, 2018, 3 pages. [cited by applicant]
United States Patent and Trademark Office, “Corrected Notice of Allowability,” issued in connection with U.S. Appl. No. 14/912,743, dated Sep. 6, 2019, 2 pages. [cited by applicant]