IP Library Granted Patent US 11,704,405
Granted Patent B2
US 11,704,405 · App. 17/457,152 · Granted Jul 18, 2023

Techniques for sharing network security event information

Inventors: Richard Reybok (Fremont, CA); Andreas Seip Haugsnes (Mountain View, CA); Kurt Joseph Zettel, II (Nashville, TN); Jeffrey Rhines (San Antonio, TX); Henry Geddes (Corte Madera, CA); Volodymyr Osypov (Mountain View, CA); Scott Lewis (Sunnyvale, CA); Sean Brady (Bedford, NH); Mark Manning (Redwood City, CA)
Assignee: ServiceNow, Inc.
G06F21/552H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,704,405
App. No.
17/457,152
Granted
Jul 18, 2023
Kind
B2
Abstract

This disclosure provides techniques for pooling and searching network security events reported by multiple sources. As information representing a security event is received from one source, it is searched against a central or distributed database representing events reported from multiple, diverse sources (e.g., different client networks). Either the search or correlated results can be filtered and/or routed according at least one characteristic associated with the networks, for example, to limit correlation to events reported by what are presumed to be similarly situated networks. The disclosed techniques facilitate faster identification of high-relevancy security event information, and thereby help facilitate faster threat identification and mitigation. Various techniques can be implemented as standalone software (e.g., for use by a private network) or for a central pooling and/or query service. This disclosure also provides different examples of actions that can be taken in response to search results.

Claims (38)

1. A system, comprising:

a memory; and

a processor communicatively coupled to a first network device via a first network, wherein the processor is configured to:

generate a first notification, wherein the first notification comprises an event detail related to a threat to the first network device, wherein the event detail comprises a property of the first network device;

sanitize the first notification to remove an identity of the first network device, an identity of the first network, or both from the event detail;

transmit the first notification to a central service that determines that both the first notification and a previously received threat notification via a second network from a second network device relates to the property of the first network device and adjusts a threat ranking of the first notification responsive to the determination;

receive the adjusted threat ranking associated with the first notification from the central service; and

perform a remedial action in response to receiving the adjusted threat ranking.

2. The system of claim 1 , wherein sanitizing the first notification comprises removing a network address associated with the first network device, the first network, or both, from the event detail.

3. The system of claim 1 , wherein the remediation action comprises downloading an upgrade to the memory to mitigate security vulnerabilities associated with the threat.

4. The system of claim 1 , wherein the central service is configured to transmit the adjusted threat ranking to the second network device.

5. The system of claim 1 , wherein the property corresponds to an indication of an operating system.

6. The system of claim 1 , wherein the memory comprises remedial action data associating a respective remedial action to a respective threat ranking of a plurality of threat rankings.

7. The system of claim 1 , wherein the processor is configured to determine the remedial action from the first notification, wherein the first notification comprises an indication of the remedial action to be performed.

8. The system of claim 1 , wherein the property corresponds to an indication of a service provider associated with the first network device.

9. The system of claim 1 , wherein the adjusted threat ranking indicates the remedial action without including an identity of the second network, and wherein the central service is configured to transmit the adjusted threat ranking to the second network, the second network device, or both.

10. The system of claim 1 , wherein the processor is configured to generate the first notification as an alert in response to detecting the threat.

11. A method, comprising:

generating a first notification in response to detecting a threat to a first network, wherein the first notification comprises an event detail that includes a property associated with a first network device and an identity of the first network device, an identity of the first network, or both;

sanitizing the first notification to remove the identity of the first network device, the identity of the first network, or both from the event detail;

transmitting the first notification to a central service via a second network, wherein the central service is configured to determine that both the first notification and a previously received threat notification from a second network device relate to the property and adjust a threat ranking of the first notification responsive to the determination; and

receiving the adjusted threat ranking associated with the first notification from the central service via the second network.

12. The method of claim 11 , comprising performing a remedial action in response to receiving the adjusted threat ranking.

13. The method of claim 11 , comprising transmitting the adjusted threat ranking to a third network device, wherein the first network device is configured to couple to the third network device via the first network.

14. The method of claim 13 , wherein the first network is separated via a firewall from the second network.

15. The method of claim 11 , wherein the property corresponds to an indication of an operating system.

16. A non-transitory, tangible, computer-readable medium storing instructions that, when executed by a processor of a network device communicatively coupled to a central service via a first network, cause the network device to:

generate a notification, wherein the notification comprises an event detail related to a threat to the network device, wherein the event detail comprises a property of the network device;

sanitize the notification to remove an identity of the network device, an identity of a second network, or both from the event detail;

transmit the notification to the central service;

receive an adjusted threat ranking associated with the notification from the central service; and

perform a remedial action in response to receiving the adjusted threat ranking.

17. The non-transitory, tangible, computer-readable medium of claim 16 , wherein the instructions cause the network device to:

receive an additional notification from the central service comprising the adjusted threat ranking, wherein the additional notification is generated in response to the central service matching the notification to a previously received notification from another network device based on the property; and

identify a software version associated with the previously received notification based on the additional notification.

18. The non-transitory, tangible, computer-readable medium of claim 16 , wherein the instructions cause the network device to replace a previous threat ranking with the adjusted threat ranking in memory.

19. The non-transitory, tangible, computer-readable medium of claim 16 , wherein the instructions cause the network device to perform an assessment to predict theft or damage if an attack were to be completed, perform a vulnerability assessment, or both.

20. The non-transitory, tangible, computer-readable medium of claim 16 , wherein the instructions cause the network device to select the remedial action from a plurality of remedial actions indicated via the adjusted threat ranking based on a ranking of respective remedial actions of the plurality of remedial actions against each other.

Continuity (12)
Continuation 16827127 · Mar 23, 2020
Continuation 16151085 · Oct 3, 2018
Continuation 16042918 · Jul 23, 2018
Continuation 15651924 · Jul 17, 2017
Continuation 14615202 · Feb 5, 2015
Continuation In Part 14536386 · Nov 7, 2014
Continuation 13556553 · Jul 24, 2012
Continuation 13556524 · Jul 24, 2012
Provisional Application 62061111 · Oct 7, 2014
Provisional Application 62046431 · Sep 5, 2014
Provisional Application 61593853 · Feb 1, 2012
Related Publication 20220083653A1 · Mar 17, 2022