IP Library Granted Patent US 12,095,803
Granted Patent B2
US 12,095,803 · App. 17/241,364 · Granted Sep 17, 2024

Peer device protection

Inventor: Paul Barnes (Derby, GB)
Assignee: OPEN TEXT INC.
H04L63/1441H04L41/12H04L43/04H04L63/1416H04L63/1425H04L63/1433H04L63/304H04L63/306H04L67/104H04L67/30H04L67/303H04W12/68H04W4/70H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,803
App. No.
17/241,364
Granted
Sep 17, 2024
Kind
B2
Abstract

Peer device protection enables a first device comprising a digital security agent to remedy security issues on (or associated with) a set of devices visible to the first device. In aspects, a first device comprising a digital security agent may identify a set of devices visible to the first device. The first device may monitor the set of devices to collect data, such as types of communications and data points of interest. The digital security agent may apply threat detection to the collected data to identify anomalous network behavior. When anomalous network behavior is detected, the first device may cause an indicator of compromise (IOC) to be generated. Based on the IOC, the first device may facilitate remediation of the anomalous network behavior and/or apply security to one or more devices in the set of devices.

Claims (65)

1. A computer-readable storage medium encoding computer executable instructions for:

detecting a first peer device on a network;

detecting a second peer device on the network;

monitoring, by a security device, the first peer device to generate first monitored data and second monitored data;

monitoring, by the security device, the second peer device to generate third monitored data and fourth monitored data, wherein the security device is a peer of the first peer device and the second peer device, wherein the security device comprises a security solution;

generating, by the security device and using the first monitored data, a first behavior profile specific only to the first peer device;

generating, by the security device and using the third monitored data, a second behavior profile specific only to the second peer device;

applying, by the security device, threat detection to the second monitored data to identify anomalous behavior of the first peer device, the threat detection including comparing the second monitored data to the first behavior profile;

applying, by the security device, threat detection to the fourth monitored data to identify anomalous behavior of the second peer device, the threat detection including comparing the fourth monitored data to the second behavior profile;

generating a first indicator of compromise corresponding to the identified anomalous behavior of the first peer device;

generating a second indicator of compromise corresponding to the identified anomalous behavior of the second peer device;

based on the first indicator of compromise, using the security device to remediate the identified anomalous behavior of the first peer device; and

based on the second indicator of compromise, using the security device to remediate the identified anomalous behavior of the second peer device.

2. The computer-readable storage medium of claim 1 , wherein the first behavior profile represents an expected behavior of the first peer device.

3. The computer-readable storage medium of claim 1 , wherein the first behavior profile represents an expected device state of the first peer device.

4. The computer-readable storage medium of claim 1 , wherein the first behavior profile represents an expected network state for the first peer device.

5. The computer-readable storage medium of claim 1 , wherein the monitoring the first peer device comprises passively monitoring communications between the first peer device and the second peer device.

6. The computer-readable storage medium of claim 1 , wherein the monitoring the first peer device comprises passively monitoring communications between the first peer device and a remote device external to the network.

7. The computer-readable storage medium of claim 1 , wherein the monitoring comprises using an active monitoring mode, wherein the active monitoring mode enables the security device to request data packets and information from the first peer device.

8. The computer-readable storage medium of claim 1 , wherein applying threat detection comprises:

parsing the second monitored data to generate or identify a set of behavior features;

using the set of behavior features to construct a feature vector; and

evaluating the feature vector against the first behavior profile.

9. The computer-readable storage medium of claim 8 , wherein applying threat detection comprises applying the feature vector to a behavior model that generates a threat value for each behavior feature in the set of behavior features to generate a set of threat values and generates an overall threat score using the set of threat values.

10. The computer-readable storage medium of claim 1 , wherein the first indicator of compromise comprises an executable script.

11. A method for peer device protection, the method comprising:

detecting a first peer device on a network;

detecting a second peer device on the network;

monitoring, by a security device, the first peer device to generate first monitored data and second monitored data;

monitoring, by the security device, the second peer device to generate third monitored data and fourth monitored data, wherein the security device is a peer of the first peer device and the second peer device, wherein the security device comprises a security solution;

generating, by the security device and using the first monitored data, a first behavior profile specific only to the first peer device;

generating, by the security device and using the third monitored data, a second behavior profile specific only to the second peer device;

applying, by the security device, threat detection to the second monitored data to identify anomalous behavior of the first peer device, the threat detection including comparing the second monitored data to the first behavior profile;

applying, by the security device, threat detection to the fourth monitored data to identify anomalous behavior of the second peer device, the threat detection including comparing the fourth monitored data to the second behavior profile;

generating a first indicator of compromise corresponding to the identified anomalous behavior of the first peer device;

generating a second indicator of compromise corresponding to the identified anomalous behavior of the second peer device;

based on the first indicator of compromise, using the security device to remediate the identified anomalous behavior of the first peer device; and

based on the second indicator of compromise, using the security device to remediate the identified anomalous behavior of the second peer device.

12. The method of claim 11 , wherein the first behavior profile represents an expected behavior of the first peer device.

13. The method of claim 11 , wherein the first behavior profile represents an expected device state of the first peer device.

14. The method of claim 11 , wherein the first behavior profile represents an expected network state for the first peer device.

15. The method of claim 11 , wherein the monitoring the first peer device comprises passively monitoring communications between the first peer device and the second peer device.

16. The method of claim 11 , wherein the monitoring the first peer device comprises passively monitoring communications between the first peer device and a remote device external to the network.

17. The method of claim 11 , wherein the monitoring comprises using an active monitoring mode, wherein the active monitoring mode enables the security device to request data packets and information from the first peer device.

18. The method of claim 11 , wherein applying threat detection comprises:

parsing the second monitored data to generate or identify a set of behavior features;

using the set of behavior features to construct a feature vector; and

evaluating the feature vector against the first behavior profile.

19. The method of claim 18 , wherein applying threat detection comprises applying the feature vector to a behavior model that generates a threat value for each behavior feature in the set of behavior features to generate a set of threat values and generates an overall threat score using the set of threat values.

20. The method of claim 11 , wherein the first indicator of compromise comprises an executable script.

21. A system comprising:

a processor;

a memory coupled to the processor, the memory comprising computer executable instructions that, when executed by the processor, performs a method for peer device protection, the method comprising:

detecting a first peer device on a network;

detecting a second peer device on the network;

monitoring, by a security device, the first peer device to generate first monitored data and second monitored data;

monitoring, by the security device, the second peer device to generate third monitored data and fourth monitored data, wherein the security device is a peer of the first peer device and the second peer device, wherein the security device comprises a security solution;

generating, by the security device and using the first monitored data, a first behavior profile specific only to the first peer device;

generating, by the security device and using the third monitored data, a second behavior profile specific only to the second peer device;

applying, by the security device, threat detection to the second monitored data to identify anomalous behavior of the first peer device, the threat detection including comparing the second monitored data to the first behavior profile;

applying, by the security device, threat detection to the fourth monitored data to identify anomalous behavior of the second peer device, the threat detection including comparing the fourth monitored data to the second behavior profile;

generating a first indicator of compromise corresponding to the identified anomalous behavior of the first peer device;

generating a second indicator of compromise corresponding to the identified anomalous behavior of the second peer device;

based on the first indicator of compromise, using the security device to remediate the identified anomalous behavior of the first peer device; and

based on the second indicator of compromise, using the security device to remediate the identified anomalous behavior of the second peer device.

Assignments (5)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY TO REMOVE THE SECOND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 056150 FRAME: 0240. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jun 13, 2021
From: BARNES, PAUL
To: WEBROOT INC.
Reel/Frame 056557/0714 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2021
From: BARNES, PAUL; HOWE, RYAN
To: WEBROOT INC.
Reel/Frame 056150/0240 →
Continuity (3)
Continuation 16018156 · Jun 26, 2018
Provisional Application 62526573 · Jun 29, 2017
Related Publication 20210250372A1 · Aug 12, 2021