IP Library Granted Patent US 12,603,904
Granted Patent B1
US 12,603,904 · App. 17/855,272 · Granted Apr 14, 2026

Cyber-threat analyses using machine learning and prior observations

Inventors: Scott Eric Coull (Cary, NC); Jeffrey Thomas Johns (Leesburg, VA)
Assignee: GOOGLE LLC
H04L63/1425H04L41/16H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,904
App. No.
17/855,272
Granted
Apr 14, 2026
Kind
B1
Abstract

A cyber-security analysis method uses machine learning (ML) technology to classify cyber-threat indicators, for example, as malicious or benign, by generating a threat score. The method includes receiving, at a compute device, a cyber-threat indicator (IUE) and associated verdicts from a set of sources. Augmenting the verdicts associated with the IUE with verdicts associated with at least one related indicator having a defined relationship with the IUE. The relationship between the IUE and the at least one related indicator can be operational, e.g., based on an administrative domain, or functional, e.g., based on a protocol specification. The cyber-threat score is generated for the IUE based on the ML model and the combined verdicts of the IUE and the at least one related indicator.

Claims (36)

1 . A cyber-security analysis method, comprising:

receiving, at a compute device, a representation of a first threat indicator and an associated classification of the first threat indicator;

identifying, via the compute device and based on the classification of the first threat indicator, at least one vote from a source;

executing a trained machine-learning (ML) model to generate, via the compute device, a cyber-threat score for the first threat indicator based on (1) the at least one vote associated with the first threat indicator, and (2) at least one vote associated with a prior observation of a second threat indicator having a functional or operational relationship to the first threat indicator;

detecting, via the compute device, data drift of the trained ML model based on the cyber-threat score and the at least one vote; and

retraining, via the compute device, the trained ML model based on a comparison of the data drift to a predetermined threshold; and

in response to a plurality of sources failing to provide sufficient vote information associated with the first threat indicator, searching for the second threat indicator in one or more administrative domains that encompass the first threat indicator to gather at least one additional vote.

2 . The cyber-security analysis method of claim 1 , further comprising determining the relationship based on at least one of observation of the second threat indicator associated with observed network traffic, an observation of the second indicator during monitoring of a compute device operation, and an observation of the second indicator during analysis of stored events.

3 . The cyber-security analysis method of claim 1 , wherein the first and second threat indicators having an operational relationship based on a first administrative domain encapsulating the first threat indicator and a second administrative domain encapsulating the second threat indicator.

4 . The cyber-security analysis method of claim 3 , wherein the first and second administrative domains each comprises one of an IP neighborhood or a domain neighborhood where the first and second threat indicators correspond to IP addresses or to domain names, respectively.

5 . The cyber-security analysis method of claim 3 , wherein the administrative domains corresponding to the first and second threat indicators are under common ownership.

6 . The cyber-security analysis method of claim 1 , wherein the first and second threat indicators have an operational relationship comprising a common administrative domain.

7 . The cyber-security analysis method of claim 1 , wherein executing a trained ML model to generate the cyber-threat score for the first threat indicator comprises employing a threat score associated with the second threat indicator in generating the threat score for the first threat indicator.

8 . The cyber-security analysis method of claim 1 , further comprising receiving a plurality of verdicts with respect to the first threat indicator, each of the verdicts originating from an associated source of a plurality of sources and serving as a vote from the associated source.

9 . The cyber-security analysis method of claim 1 , wherein the first threat indicator comprises an IP address; and wherein searching for the second threat indicator comprises searching, for the second threat indicator in at least one of an IP subnet corresponding to the first threat indicator, an autonomous system corresponding to the first threat indicator, and an owning organization corresponding to the first threat indicator.

10 . The cyber-security analysis method of claim 1 , further comprising:

receiving a first verdict for the first threat indicator from each source of a first subset of sources of a plurality of sources,

receiving a second verdict for the second threat indicator from each source of a second subset of sources of the plurality of sources, where the second threat indicator is associated with a same administrative domain as the first threat indicator, each of the first and each of the second verdicts serving as a vote; and

generating a threat score based on a combination of the votes for the first and second indicators.

11 . The cyber-security analysis method of claim 1 , wherein the operational relationship is such that the first threat indicator and the second threat indicator have a common autonomous system.

12 . The cyber-security analysis method of claim 1 , wherein the operational relationship is such that the first threat indicator and the second threat indicator have a common associated subnet.

13 . The cyber-security analysis method of claim 1 , further comprising identifying the at least one prior observation of the second threat indicator based on meta data related to the first threat indicator received prior to the identifying the at least one prior observation of the second threat indicator.

14 . The cyber-security analysis method of claim 1 , further comprising identifying the prior observation of the second threat indicator based on an index of prior observations of a plurality of threat indicators stored in a memory of the compute device.

15 . A cyber-security analysis method, comprising:

receiving, at a compute device, a representation of a first threat indicator;

identifying at least one prior observation of a second threat indicator having a predefined operational relationship to the first threat indicator;

executing a trained machine-learning (ML) model to generate, via the compute device, a cyber-threat score for the first threat indicator based on (1) at least one available vote on the first threat indicator from a plurality of sources, and (2) at least one vote for the at least one prior observation of the second threat indicator;

detecting, via the compute device, data drift of the trained ML model based on the cyber-threat score and the at least one prior observation; and

retraining, via the compute device, the trained ML model based on a comparison of the data drift to a predetermined threshold; and

in response to a plurality of sources failing to provide sufficient vote information associated with the first threat indicator, searching for the second threat indicator in one or more administrative domains that encompass the first threat indicator to gather at least one additional vote.

16 . The cyber-security analysis method of claim 15 , wherein the at least one prior observation of the second threat indicator captures an event during operation of a computer system or flow of network traffic that signifies either a benign occurrence or a potential cyber-threat.

17 . The cyber-security analysis method of claim 15 , wherein executing the trained ML model to generate, via the compute device, the cyber-threat score includes obtaining a vote from at least one source based on the prior observation of the second threat indicator.

18 . The cyber-security analysis method of claim 15 , wherein the at least one vote from the plurality of sources includes a plurality of votes from a plurality of the sources; and executing the trained ML model to generate, via the compute device, the cyber-threat score includes combining the plurality of vote on the first threat indicator with the at least one vote for the at least one prior observation of the second threat indicator.

19 . The cyber-security analysis method of claim 15 , further comprising: determining, at the compute device, that a threshold number of votes from the plurality of sources on the first threat indicator has not been met; and identifying, via the compute device and in response to determining that the threshold number of votes has not been met, the at least one prior observation of the second threat indicator.

20 . The cyber-security analysis method of claim 15 , wherein the threshold is based on a number of sources of the plurality of sources casting votes on the first threat indicator.

21 . The cyber-security analysis method of claim 15 , further comprising: weighting the pre-existing votes on the second threat indicator based on at least a degree of proximity within the administrative domain between the first threat indicator and the second threat indicator to form weighted values; combining the weighted values in forming the cyber-threat score for the first threat indicator.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2023
From: MANDIANT, INC.
To: GOOGLE LLC
Reel/Frame 063323/0440 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: COULL, SCOTT ERIC; JOHNS, JEFFREY THOMAS
To: MANDIANT, INC.
Reel/Frame 061137/0618 →