IP Library Patent Application 17187385
Patent Application
App. No. 17/187,385

APPARATUS AND METHOD FOR A CYBER-THREAT DEFENSE SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/187,385
Abstract

An apparatus comprising: one or more machine learning modules that are trained on a normal behavior of entities associated with a network and interactions between the entities; an interface configured to receive a signal from an external apparatus to request and trigger an artificial intelligence based analyst investigation; where the interface is configured to work with at least one of: artificial intelligence models trained on how to conduct an investigation; and scripts on how to conduct an investigation, in order to determine whether a chain of related low level abnormalities associated with one or more of the entities should be determined to be one or more incidents worthy of generating a notification to a human user for possible further investigation and/or worthy of being determined as an actual cyber-threat, and thus, trigger an autonomous response from an autonomous response module to mitigate the cyber-threat.

Claims (27)

1 . An apparatus comprising:

one or more machine learning modules that are trained on a normal behavior of entities associated with a network and interactions between the entities;

an interface configured to receive a signal from an external apparatus to request and trigger an artificial intelligence based analyst investigation, where the interface is configured to work with at least one of: artificial intelligence models trained on how to conduct an investigation; and scripts on how to conduct an investigation, in order to determine whether a chain of related low level abnormalities associated with one or more of the entities should be determined to be one or more incidents worthy of generating a notification to a human user for possible further investigation and/or worthy of being determined as an actual cyber-threat, and thus, trigger an autonomous response from an autonomous response module to mitigate the cyber-threat.

2 . An apparatus according to claim 1 wherein the signal from the external apparatus is provided by a manual user input.

3 . An apparatus according to claim 2 wherein the manual user input comprises investigation instructions comprising one or more of: a time period to be investigated, designation of the one or more entities to be investigated, and a particular investigation environment.

4 . An apparatus according to claim 1 wherein the signal from the external apparatus is provided by a third party threat intelligence component.

5 . An apparatus according to claim 4 wherein the third party threat intelligence component provides additional data relating to behavior of the one or more entities.

6 . An apparatus according to claim 1 further comprising:

an analyser module configured to, in response to the determination of one or more incidents, generate a directed graph, using graph theory, to map the one or more incidents onto the graph to detect anomalies potentially indicative of cyber threats.

7 . An apparatus according to claim 6 wherein the directed graph comprises a plurality of nodes, each node of the plurality of nodes corresponding to a respective entity of the entities, the plurality of nodes being connected by one or more edges corresponding to the one or more incidents.

8 . An apparatus according to claim 6 , wherein the analyser module is further configured to group the one or more incidents into a meta of incidents representing a compromise linking entities in the network affected by the one or more incidents.

9 . An apparatus according to claim 6 further comprising a formatting module configured to generate a visual representation of the directed graph for display.

10 . An apparatus according to claim 1 , wherein the autonomous response module is configurable to know when the response module should take the autonomous actions to mitigate the cyber-threat when one or more incidents are worth of being determined as a cyber-threat, where the autonomous response module has an administrative tool, configurable through the interface, to set what autonomous actions the autonomous response module can take, including types of actions and specific actions the autonomous response module is capable of.

11 . A method for a cyber-threat defense system, the method comprising:

using one or more machine learning models that are trained on a normal behavior of entities associated with a network and interactions between the entities;

receiving, at an interface, a signal from an external apparatus to request and trigger an artificial intelligence based analyst investigation;

the interface working with at least one of: artificial intelligence models trained on how to conduct an investigation; and scripts on how to conduct an investigation, and determining whether a chain of related low level abnormalities associated with one or more of the entities should be determined to be one or more incidents worthy of generating a notification to a human user for possible further investigation and/or worthy of being determined as an actual cyber-threat; and

triggering an autonomous response from an autonomous response module to mitigate the cyber-threat.

12 . A method according to claim 11 wherein the signal from the external apparatus is provided by a manual user input at the interface.

13 . A method according to claim 12 wherein the manual user input comprises investigation instructions comprising one or more of: a time period to be investigated, designation of the one or more entities to be investigated, and a particular investigation environment.

14 . A method according to claim 11 wherein the signal from the external apparatus is provided by a third party threat intelligence component.

15 . A method according to claim 14 wherein the third party threat intelligence component provides additional data relating to behavior of the one or more entities.

16 . A method according to claim 11 further comprising, in response to the determination of one or more incidents, generating a directed graph, using graph theory, to map the one or more incidents onto the graph to detect anomalies potentially indicative of cyber-threats.

17 . A method according to claim 16 wherein the directed graph comprises a plurality of nodes, each node of the plurality of nodes corresponding to a respective entity of the entities, the plurality of nodes being connected by one or more edges corresponding to the one or more incidents.

18 . A method according to claim 16 further comprising grouping the one or more incidents into a meta of incidents representing a compromise linking entities in the network affected by the one or more incidents.

19 . A method according to claim 16 further comprising generating a visual representation of the directed graph.

20 . A non-transitory computer-readable medium including executable instructions that, when executed with one or more processors, cause a cyber-threat defense system to perform the method of claim 11 .

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2021
From: HUMPHREY, DICKON MURRAY; BAZALGETTE, TIMOTHY OWEN
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 058010/0920 →