IP Library Granted Patent US 12,200,494
Granted Patent B2
US 12,200,494 · App. 17/571,142 · Granted Jan 14, 2025

AI cybersecurity system monitoring wireless data transmissions

Inventor: Simon David Lincoln Fellows (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04W12/122H04L41/16H04L41/22H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,494
App. No.
17/571,142
Granted
Jan 14, 2025
Kind
B2
Abstract

A coordinator module, a cyber threat analyst module, and AI models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain cooperate with a combination of wireless sensors with RF protocol adapters to monitor and analyze wireless activity and probes to monitor activity in the second domain in order to analyze an anomaly of interest in a wider view of another domain's activity. These modules and models understand and assess the wireless activity and the activity from the second domain in light of the AI models modelling the pattern of life for entities in a wireless domain and/or a in the second domain in order to detect a cyber threat indicated by at least by the anomaly of interest. A formatting model generates an alert and/or a report.

Claims (68)

1. An Artificial Intelligence based cyber security system, comprising:

a coordinator module, a cyber threat analyst module, and one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain are configured to cooperate with a combination of 1) wireless sensors with one or more Radio Frequency protocol adapters to monitor and analyze wireless activity, including wireless transmissions transmitted through airspace in the wireless domain, and 2) probes to monitor activity in the second domain, which includes any of i) an Information Technology network, ii) an Operational Technology network, iii) a Cloud service, iv) a SaaS service, v) an endpoint device, and vi) an email domain in order to analyze at least an anomaly of interest in one of 1) the wireless activity from the wireless sensors in view of the activity in the second domain from the probes, 2) the activity from the second domain from the probes in view of the wireless activity in the wireless domain from the wireless sensors, and 3) and any combination of both in order for the coordinator module, the cyber threat analyst module, and the one or more Artificial Intelligence models to cooperate to analyse the anomaly of interest in a wider view of another domain's activity;

where the coordinator module and the cyber threat analyst module are configured to cooperate to understand and assess the wireless activity from the wireless sensors as well as the activity from the second domain from the probes from the second domain in light of the one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain in order to detect a cyber threat indicated by at least by the anomaly of interest, where the coordinator module and the cyber threat analyst module are implemented in hardware electronic components, software components, and any combination of both;

a formatting model is configured to generate at least one of i) an alert to a user and ii) a report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user when a possibility of the cyber threat is above a threshold based upon input from the cyber threat analyst module, where the formatting model is configured to deliver the alert and/or the report via a medium of at least one of 1) a printable report, 2) presented digitally on a graphical user interface, 3) presented digitally in an email on a display, 4) presented digitally in a message on the display, and 5) in a machine readable format for further reinforcement of machine learning, where the Artificial Intelligence models and the formatting model are implemented in hardware electronic components, software components, and any combination of both;

where the anomaly of interest is a suspicious wireless transmission from a wireless transmission source;

where a portable hunter device is configured to have one or more wireless receivers, one or more antennas, one or more Radio Frequency protocol adapters, a battery, a directional indicator to the wireless transmission source as well as a signal strength of the suspicious wireless transmission that is the anomaly of interest from the wireless transmission source; and

where the portable hunter device is configured to factor in at least one of i) an increase of signal strength of the suspicious wireless transmission, ii) a decrease of signal strength of the suspicious wireless transmission that is the anomaly of interest from the wireless transmission source, and iii) any combination of both in determining a physical location of the wireless transmission source.

2. The Artificial Intelligence based cyber security system of claim 1 , further comprising:

where the anomaly of interest is a suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain, and 2) transmitted in a frequency range not within frequency ranges associated with WiFi protocol standards known by the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain; and

a portable hunter device having one or more wireless receivers configured to allow an operator to physically move with the portable hunter device to determine a physical location of the wireless transmission source.

3. An Artificial Intelligence based cyber security system, comprising:

a coordinator module, a cyber threat analyst module, and one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain are configured to cooperate with a combination of 1) wireless sensors with one or more Radio Frequency protocol adapters to monitor and analyze wireless activity, including wireless transmissions transmitted through airspace in the wireless domain, and 2) probes to monitor activity in the second domain, which includes any of i) an Information Technology network, ii) an Operational Technology network, iii) a Cloud service, iv) a SaaS service, v) an endpoint device, and vi) an email domain in order to analyze at least an anomaly of interest in one of 1) the wireless activity from the wireless sensors in view of the activity in the second domain from the probes, 2) the activity from the second domain from the probes in view of the wireless activity in the wireless domain from the wireless sensors, and 3) and any combination of both in order for the coordinator module, the cyber threat analyst module, and the one or more Artificial Intelligence models to cooperate to analyse the anomaly of interest in a wider view of another domain's activity;

where the coordinator module and the cyber threat analyst module are configured to cooperate to understand and assess the wireless activity from the wireless sensors as well as the activity from the second domain from the probes from the second domain in light of the one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain in order to detect a cyber threat indicated by at least by the anomaly of interest, where the coordinator module and the cyber threat analyst module are implemented in hardware electronic components, software components, and any combination of both;

a formatting model is configured to generate at least one of i) an alert to a user and ii) a report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user when a possibility of the cyber threat is above a threshold based upon input from the cyber threat analyst module, where the formatting model is configured to deliver the alert and/or the report via a medium of at least one of 1) a printable report, 2) presented digitally on a graphical user interface, 3) presented digitally in an email on a display, 4) presented digitally in a message on the display, and 5) in a machine readable format for further reinforcement of machine learning, where the Artificial Intelligence models and the formatting model are implemented in hardware electronic components, software components, and any combination of both;

where the anomaly of interest is a suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain, where the Artificial Intelligence models are configured to use at least an unsupervised machine learning algorithm to update a training data for the Artificial Intelligence models trained to model a normal pattern of life in light of the wireless activity supplied by the wireless sensors, and 2) transmitted from a known wireless transmitter device, which is known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, but is interacting with a wireless network that is not normally part of the wireless domain being protected by the cyber security system; and

where a portable hunter device having one or more wireless receivers is configured to cooperate with the one or more wireless sensors to find a physical location of the wireless transmitter device, where the portable hunter device is configured to use 1) a location of a wireless sensor closest to the suspicious wireless transmission in the airspace that is the anomaly of interest and 2) identifying details of the suspicious wireless transmission in the airspace that is the anomaly of interest in order to indicate a general geographical area of a source of the suspicious wireless could be in order to assist the portable hunter device in finding an exact physical location of the wireless transmitter device.

4. The Artificial Intelligence based cyber security system of claim 1 , where the coordinator module, the cyber threat analyst module, the formatting module, and the one or more Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain and the normal pattern of life for entities in the second domain are located in a cyber security appliance,

where the formatting module is configured to generate the alert to the user on a user interface of the cyber security appliance and/or a device associated with the user whenever the anomaly of interest is a suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, and 2) transmitted from a known wireless transmitter device, which is known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, but is interacting with a wireless network that is not normally part of the wireless domain being protected by the cyber security system; as well as

where the coordinator module is configured to determine how links exist between the wireless activities that include alerts, events and the suspicious wireless transmission, from the wireless domain to the activities that include alerts and events from the second domain supplied by the probes.

5. The Artificial Intelligence based cyber security system of claim 1 , further comprising:

where the cyber threat analyst module is further configured to cooperate with one or more AI models trained on how human cyber security analysts conduct cyber investigations to conduct initial investigations regarding at least the anomaly of interest, and then to collect additional information to form a chain of potentially related information under analysis from either prior wireless transmissions and/or activity from the second domain that have a probability above a threshold of a logical nexus to the anomaly of interest, where the cyber threat analyst module is configured to cooperate with the one or more Al models trained on how the human cyber security analysts conduct cyber investigations to form one or more hypotheses on potential cyber threats that could have this chain of potentially related information under analysis, where the cyber threat analyst module is configured to perform additional rounds of gathering additional information in order to refute or to support each of the one or more hypotheses to re-check cyber threat indications for the chain of potentially related information under analysis until the one or more hypotheses on potential cyber threats are one of refuted, supported, or included in the report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user, and that also conveys at least a first hypothesis is neither supported or refuted; and thus, needs a human to further investigate the anomaly of interest.

6. The Artificial Intelligence based cyber security system of claim 1 , further comprising:

where the cyber threat analyst module is further configured to cooperate with a first Artificial Intelligence model trained to model the normal pattern of life for entities in the wireless domain supplied by the wireless sensors as well as a second Artificial Intelligence model trained to model the normal pattern of life for entities in the second domain from the probes from the second domain in order to autonomously investigate a combined activity from the wireless domain and activity from the second domain in order to support or refute one or more cyber threat hypotheses on whether the cyber threat has been detected, where the coordinator module is configured to assess activity including events occurring in the second domain compared to activity occurring in the wireless domain, where the first Artificial Intelligence model and the second Artificial Intelligence model are part of the one or more Artificial Intelligence models; and

where the cyber threat analyst module is configured to form and investigate the cyber threat hypotheses on what are a possible set of cyber threats, where the cyber threat analyst module is also configured to cooperate with one or more Al models trained on how human cyber security analysts conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, one or more scripts outlining how to conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, one or more rules based models on an investigation on a possible set of cyber threats hypotheses how to conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, and any combination of these, where the anomaly of interest was identified through cooperation with one or more Al models trained with machine learning on the normal pattern of life in the wireless domain.

7. The Artificial Intelligence based cyber security system of claim 1 , further comprising:

where a first wireless sensor is configured to have two or more Radio Frequency protocol adapters in order to be able to monitor the wireless transmissions in the airspace in the wireless domain consisting of various types of wireless transmissions both 1) a first type of wireless transmissions in a first known radio frequency protocol at a standard frequency range dictated by that first Radio Frequency protocol through to 2) a second known radio frequency protocol at a standard frequency range dictated by that second Radio Frequency protocol.

8. The Artificial Intelligence based cyber security system of claim 7 , where the two or more Radio Frequency protocol adapters are configured to include two or more Radio Frequency protocols from i) a WiFi protocol transmitted on 2.4 GHz channel, ii) a WiFi protocol transmitted on and 5 GHz channel, iii) a ZigBee or other mesh network protocol transmitted on a 2.4 GHz channel, iv) a ZigBee or other mesh network protocol transmitted on a 900 MHz channel, v) a ZigBee or other mesh network protocol transmitted on an 868 MHz channel; vi) a 4G protocol transmitted on a 600 MHz channel, vii) a 4G protocol transmitted on a 700 MHz channel, viii) a 4G protocol transmitted on a 1.7 GHZ channel, ix) a 4G protocol transmitted on a 2.1 GHz channel, x) a 4G protocol transmitted on a 2.3 GHZ channel, xi) a 4G protocol transmitted on a 2.5 GHz channel; xii) a 5G protocol in a first frequency range from 450 MHz to 6 GHZ, xiii) a 5G protocol in a second frequency range from 24.25 GHz to 52.6 GHZ, as well as xiv) a Z-Wave protocol transmitted on an 800-900 MHz frequency range, and

where each different radio frequency protocol adapter is configured both i) to understand one or more particular radio frequency protocols and ii) to have one or more frequency filters, where a first radio frequency protocol adapter is configured to cooperate with one or more antennas in the first wireless sensor to capture the wireless transmissions in the one or more particular radio frequency protocols.

9. The Artificial Intelligence based cyber security system of claim 1 , further comprising:

where a first wireless sensor has one or more radio frequency adapters that have wireless receivers configured to pull down raw data information from a first wireless transmission in the airspace in the wireless domain as well as one or more algorithms, a memory, and one or more processors, configured to then make an initial meta data analysis of the first wireless transmission in the airspace in the wireless domain.

10. A method for an Artificial Intelligence based cyber security system, comprising:

configuring a coordinator module, a cyber threat analyst module, and one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain to cooperate with a combination of 1) wireless sensors with one or more Radio Frequency protocol adapters to monitor and analyze wireless activity, including wireless transmissions transmitted through airspace in the wireless domain, and 2) probes to monitor activity in the second domain, which includes any of i) an Information Technology network, ii) an Operational Technology network, iii) a Cloud service, iv) a SaaS service, v) an endpoint device, and vi) an email domain in order to analyze at least an anomaly of interest in one of 1) the wireless activity from the wireless sensors in view of the activity in the second domain from the probes, 2) the activity from the second domain from the probes in view of the wireless activity in the wireless domain from the wireless sensors, and 3) and any combination of both in order for the coordinator module, the cyber threat analyst module, and the one or more Artificial Intelligence models to cooperate to analyse the anomaly of interest in a wider view of another domain's activity;

configuring the coordinator module and the cyber threat analyst module to cooperate to understand and assess the wireless activity from the wireless sensors as well as the activity from the second domain from the probes from the second domain in light of the one or more Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain and a normal pattern of life for entities in a second domain in order to detect a cyber threat indicated by at least by the anomaly of interest, where the coordinator module and the cyber threat analyst module are implemented in hardware electronic components, software components, and any combination of both;

configuring a formatting model to generate at least one of i) an alert to a user and ii) a report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user when a possibility of the cyber threat is above a threshold based upon input from the cyber threat analyst module, where the formatting model is configured to deliver at least one of the alert and the report via a medium of at least one of 1) a printable report, 2) presented digitally on a graphical user interface, 3) presented digitally in an email on a display, 4) presented digitally in a message on the display, and 5) in a machine readable format for further reinforcement of machine learning, where the Artificial Intelligence models and the formatting model are implemented in hardware electronic components, software components, and any combination of both;

configuring where the coordinator module, the cyber threat analyst module, the formatting module, and the one or more Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain and the normal pattern of life for entities in the second domain to be located in a cyber security appliance;

configuring the formatting module to generate the alert to the user on a user interface of at least one of the cyber security appliance and a device associated with the user, whenever the anomaly of interest is a suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, and 2) transmitted from a known wireless transmitter device, which is known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, but is interacting with a wireless network that is not normally part of the wireless domain being protected by the cyber security system; as well as

configuring the coordinator module to determine how links exist between the wireless activities that include alerts, events and the suspicious wireless transmission, from the wireless domain to the activities that include alerts and events from the second domain supplied by the probes.

11. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

where the anomaly of interest is the suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain, and 2) transmitted in a frequency range not within frequency ranges associated with WiFi protocol standards known by the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain; and

configuring a portable hunter device having one or more wireless receivers to allow an operator to physically move with the portable hunter device to determine a physical location of a wireless transmission source of the suspicious wireless transmission.

12. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

configuring the Artificial Intelligence models to use at least an unsupervised machine learning algorithm to update a training data for the Artificial Intelligence models trained to model a normal pattern of life in light of the wireless activity supplied by the wireless sensors;

where the anomaly of interest is a suspicious wireless transmission in the airspace from at least one of 1) transmitted from a wireless transmitter device, which was not known previously to the Artificial Intelligence models trained to model a normal pattern of life for entities in the wireless domain, and 2) transmitted from a known wireless transmitter device, which is known previously to the Artificial Intelligence models trained to model the normal pattern of life for entities in the wireless domain, but is interacting with a wireless network that is not normally part of the wireless domain being protected by the cyber security system;

configuring a portable hunter device having one or more wireless receivers to cooperate with the one or more wireless sensors to find a physical location of the wireless transmitter device; and

configuring the portable hunter device to use 1) a location of a wireless sensor closest to the suspicious wireless transmission in the airspace that is the anomaly of interest and 2) identifying details of the suspicious wireless transmission in the airspace that is the anomaly of interest in order to indicate a general geographical area of where a wireless transmission source of the suspicious wireless transmission could be in order to assist the portable hunter device in finding an exact physical location of the wireless transmitter device.

13. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

where the anomaly of interest is a suspicious wireless transmission from a wireless transmission source;

configuring a portable hunter device to have one or more wireless receivers, one or more antennas, one or more Radio Frequency protocol adapters, a battery, a directional indicator to the wireless transmission source as well as a signal strength of the suspicious wireless transmission that is the anomaly of interest from the wireless transmission source; and

configuring the portable hunter device to factor in at least one of i) an increase of signal strength of the suspicious wireless transmission, ii) a decrease of signal strength of the suspicious wireless transmission that is the anomaly of interest from the wireless transmission source, and iii) any combination of both in determining a physical location of the wireless transmission source.

14. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

configuring the cyber threat analyst module to cooperate with one or more Al models trained on how human cyber security analysts conduct cyber investigations to conduct initial investigations regarding at least the anomaly of interest, and then to collect additional information to form a chain of potentially related information under analysis from either prior wireless transmissions and/or activity from the second domain that have a probability above a threshold of a logical nexus to the anomaly of interest;

configuring the cyber threat analyst module to cooperate with the one or more Al models trained on how the human cyber security analysts conduct cyber investigations to form one or more hypotheses on potential cyber threats that could have this chain of potentially related information under analysis; and

configuring the cyber threat analyst module to perform additional rounds of gathering additional information in order to refute or to support each of the one or more hypotheses to re-check cyber threat indications for the chain of potentially related information under analysis until the one or more hypotheses on potential cyber threats are one of refuted, supported, or included in the report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user but that also conveys at least a first hypothesis is neither supported or refuted; and thus, needs a human to further investigate the anomaly of interest.

15. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

configuring the cyber threat analyst module to cooperate with a first Artificial Intelligence model trained to model the normal pattern of life for entities in the wireless domain supplied by the wireless sensors as well as a second Artificial Intelligence model trained to model the normal pattern of life for entities in the second domain from the probes from the second domain in order to autonomously investigate a combined activity from the wireless domain and activity from the second domain in order to support or refute one or more cyber threat hypotheses on whether the cyber threat has been detected, where the first Artificial Intelligence model and the second Artificial Intelligence model are part of the one or more Artificial Intelligence models;

configuring where the coordinator module to assess activity including events occurring in the second domain compared to activity occurring in the wireless domain; and

configuring the cyber threat analyst module to form and investigate the cyber threat hypotheses on what are a possible set of cyber threats, where the cyber threat analyst module is also configured to cooperate with one or more Al models trained on how human cyber security analysts conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, one or more scripts outlining how to conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, one or more rules based models on an investigation on a possible set of cyber threats hypotheses how to conduct an investigation on a possible set of cyber threats hypotheses that would include at least the anomaly of interest, and any combination of these, where the anomaly of interest was identified through cooperation with one or more Al models trained with machine learning on the normal pattern of life in the wireless domain.

16. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

configuring a first wireless sensor to have two or more Radio Frequency protocol adapters in order to be able to monitor the wireless transmissions in the airspace in the wireless domain consisting of various types of wireless transmissions both 1) a first type of wireless transmissions in a first known radio frequency protocol at a standard frequency range dictated by that first Radio Frequency protocol through to 2) a second known radio frequency protocol at a standard frequency range dictated by that second Radio Frequency protocol.

17. The method for the Artificial Intelligence based cyber security system of claim 10 , further comprising:

configuring a first wireless sensor to have one or more radio frequency adapters that have wireless receivers configured to pull down raw data information from a first wireless transmission in the airspace in the wireless domain as well as one or more algorithms, a memory, and one or more processors, configured to then make an initial meta data analysis of the first wireless transmission in the airspace in the wireless domain.

18. A machine readable medium configured to store instructions and data to be executed by one or more processors, where the instructions when executed cause a cyber security appliance to perform steps as follows, comprising:

causing a coordinator module, a cyber threat analyst module, and one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain to cooperate with a combination of 1) wireless sensors with one or more Radio Frequency protocol adapters to monitor and analyze wireless activity, including wireless transmissions transmitted through airspace in the wireless domain, and 2) probes to monitor activity in the second domain, which includes any of i) an Information Technology network, ii) an Operational Technology network, iii) a Cloud service, iv) a SaaS service, v) an endpoint device, and vi) an email domain in order to analyze at least an anomaly of interest in one of 1) the wireless activity from the wireless sensors in view of the activity in the second domain from the probes, 2) the activity from the second domain from the probes in view of the wireless activity in the wireless domain from the wireless sensors, and 3) and any combination of both in order for the coordinator module, the cyber threat analyst module, and the one or more Artificial Intelligence models to cooperate to analyse the anomaly of interest in a wider view of another domain's activity;

causing the coordinator module and the cyber threat analyst module to cooperate to understand and assess the wireless activity from the wireless sensors as well as the activity from the second domain from the probes from the second domain in light of the one or more Artificial Intelligence models trained to model a normal pattern of life for entities in a wireless domain and a normal pattern of life for entities in a second domain in order to detect a cyber threat indicated by at least by the anomaly of interest, where the coordinator module and the cyber threat analyst module are implemented in hardware electronic components, software components, and any combination of both;

causing a formatting model to generate at least one of i) an alert to a user and ii) a report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user when a possibility of the cyber threat is above a threshold based upon input from the cyber threat analyst module, where the formatting model is configured to deliver at least one of the alert and the report via a medium of at least one of 1) a printable report, 2) presented digitally on a graphical user interface, 3) presented digitally in an email on a display, 4) presented digitally in a message on the display, and 5) in a machine readable format for further reinforcement of machine learning, where the Artificial Intelligence models and the formatting model are implemented in hardware electronic components, software components, and any combination of both;

causing a cyber threat analyst module to cooperate with one or more Al models trained on how human cyber security analysts conduct cyber investigations to conduct initial investigations regarding at least the anomaly of interest, and then to collect additional information to form a chain of potentially related information under analysis from either prior wireless transmissions and/or activity from the second domain that have a probability above a threshold of a logical nexus to the anomaly of interest;

causing the cyber threat analyst module to cooperate with the one or more Al models trained on how the human cyber security analysts conduct cyber investigations to form one or more hypotheses on potential cyber threats that could have this chain of potentially related information under analysis; and

causing the cyber threat analyst module to perform additional rounds of gathering additional information in order to refute or to support each of the one or more hypotheses to re-check cyber threat indications for the chain of potentially related information under analysis until the one or more hypotheses on potential cyber threats are one of refuted, supported, or included in the report that includes details of activities assessed to be relevant activities to the anomaly of interest to the user but that also conveys at least a first hypothesis is neither supported or refuted; and thus, needs a human to further investigate the anomaly of interest.

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2022
From: FELLOWS, SIMON DAVID LINCOLN
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 059039/0392 →
Continuity (2)
Provisional Application 63135394 · Jan 8, 2021
Related Publication 20220225101A1 · Jul 14, 2022
References Cited (119)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 7843322B2 · Zakrewski et al. · 2010 [cited by applicant]
US 7890869B1 · Mayer et al. · 2011 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8661538B2 · Cohen-Ganor et al. · 2014 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9348742B1 · Brezinski · 2016 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10237298B1 · Nguyen et al. · 2019 [cited by applicant]
US 10268821B2 · Stockdale et al. · 2019 [cited by applicant]
US 10419466B2 · Ferguson et al. · 2019 [cited by applicant]
US 10516693B2 · Stockdale et al. · 2019 [cited by applicant]
US 10701093B2 · Dean et al. · 2020 [cited by applicant]
US 20020174217A1 · Anderson et al. · 2002 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080077358A1 · Marvasti · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100107254A1 · Elland et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor · 2015 [cited by examiner]
US 20150319185A1 · Kirti · 2015 [cited by examiner]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160124071A1 · Baxley et al. · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170054745A1 · Zhang et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20190036948A1 · Appel et al. · 2019 [cited by applicant]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190199756A1 · Correnti · 2019 [cited by examiner]
US 20190251260A1 · Stockdale et al. · 2019 [cited by applicant]
US 20190260786A1 · Dunn · 2019 [cited by examiner]
US 20200159624A1 · Malkov · 2020 [cited by examiner]
US 20200280575A1 · Dean et al. · 2020 [cited by applicant]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210157919A1 · Stockdale et al. · 2021 [cited by applicant]
US 20220303796A1 · Zhang · 2022 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Fog Intelligence for Network Anomaly Detection, by Ma et al., published 2019. (Year: 2019). [cited by examiner]
Anomaly Detection in IP Networks, by Ji et al., published 2003. (Year: 2003). [cited by examiner]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
International Search Report and Written Opinion, PCT/US2022/011665, ISA:US, Apr. 8, 2022, 21 pp. [cited by applicant]
Cited By (1)
US 12,348,530