IP Library Granted Patent US 12,341,787
Granted Patent B2
US 12,341,787 · App. 17/855,940 · Granted Jun 24, 2025

Method for automatic signatures generation from a plurality of sources

Inventors: Alexey Kleymenov (Massagno, CH); Moreno Carullo (Gavirate, IT); Andrea Carcano (San Francisco, CA)
Assignee: Nozomi Networks Sagl
H04L63/1416H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,787
App. No.
17/855,940
Granted
Jun 24, 2025
Kind
B2
Abstract

The present invention relates to a method for automatic signatures generation from a plurality of sources, comprising defining a plurality of identified sources of samples providers, collecting, by a computerized data processing unit, input samples from the sample providers, verifying, by the computerized data processing unit, the input samples defining verified input samples, generating, by the computerized data processing unit, verified signatures from the verified input samples, storing, in a verified signatures database operatively connected to the computerized data processing unit, the verified signatures, wherein the collecting comprises extracting raw IoCs from the input samples, wherein the verifying comprises evaluating the reputation of each of the raw IoCs according to predefined reputation rules and comparing each of the raw IoCs with a database of existing signatures operatively connected to the data processing unit to define allowable raw IoCs; and wherein the generating comprises creating the verified signatures from the verified input samples corresponding to the allowable raw IoCs.

Claims (20)

1. A method for automatic signatures generation from a plurality of sources, comprising:

defining a plurality of identified sources of samples providers;

collecting, by a computerized data processing unit, input samples from said sample providers;

extracting, by the computerized data processing unit, raw indicators of compromise (IoCs) from said input samples;

verifying, by said computerized data processing unit, said input samples defining verified input samples;

generating, by said computerized data processing unit, verified signatures from said verified input samples;

storing, in a verified signatures database operatively connected to said computerized data processing unit, said verified signatures;

wherein said collecting comprises extracting raw IoCs from said input samples;

wherein said verifying comprises evaluating the reputation of each of said raw IoCs according to predefined reputation rules and comparing each of said raw IoCs with a database of existing signatures operatively connected to said data processing unit to define allowable raw IoCs; and

wherein said generating comprises creating said verified signatures from said verified input samples corresponding to said allowable raw IoCs, by inserting each allowable raw IoC into a predefined structured format including associated metadata.

2. The method for automatic signatures generation from a plurality of sources according to claim 1 , wherein said verified signatures are structured in a STIX format.

3. The method for automatic signatures generation from a plurality of sources according to claim 1 , wherein said input samples comprises input IoCs and pre-existing threat detection signatures.

4. The method for automatic signatures generation from a plurality of sources according to claim 1 , wherein said verified signatures are created by inserting said allowable raw IoCs into a predefined structure coupled with associated metadata.

5. The method for automatic signatures generation from a plurality of sources according to claim 4 , wherein said predefined structure is an XML structure or a JSON structure.

6. The method for automatic signatures generation from a plurality of sources according to claim 4 , wherein said metadata comprises information relating to one or more of: date of creation, time of creation, malware category.

7. The method for automatic signatures generation from a plurality of sources according to claim 1 , wherein said method further comprises filtering said input samples after collecting said input samples;

wherein said collecting comprises extracting raw signatures from said input samples; and

wherein said filtering comprises identifying verified signatures by removing said raw signatures containing artifacts.

8. The method for automatic signatures generation from a plurality of sources according to claim 1 , wherein said method further comprises receiving telemetry data related to usage or performance of said verified signatures.

9. The method of claim 1 , wherein said raw indicators of compromise include one or more of: IP addresses, domain names, file hashes, email addresses, or URLs.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: KLEYMENOV, ALEXEY; CARULLO, MORENO; CARCANO, ANDREA
To: NOZOMI NETWORKS SAGL
Reel/Frame 060420/0239 →
Continuity (1)
Related Publication 20240007483A1 · Jan 4, 2024
References Cited (14)
US 20150326588A1 · Vissamsetty · 2015 [cited by examiner]
US 20160342477A1 · Swierk · 2016 [cited by examiner]
US 20170118245A1 · Tcherchian · 2017 [cited by examiner]
US 20180063163A1 · Pevny · 2018 [cited by examiner]
US 20180191747A1 · Nachenberg · 2018 [cited by examiner]
US 20190121977A1 · Gordeychik et al. · 2019 [cited by applicant]
US 20200382525A1 · Scheideler · 2020 [cited by examiner]
US 20210144178A1 · Bailey · 2021 [cited by examiner]
US 20220417259A1 · Kulaga · 2022 [cited by examiner]
WO 2017184189A1 · 2017 [cited by applicant]
WO 2018125903A1 · 2018 [cited by applicant]
Ivo Vacas et al., Detecting Network Threats using OSINT Knowledge-based IDS, IEEE (Year: 2018). [cited by examiner]
Lauren Rudman et al., A sharing platform for Indicators of Compromise, SATNAC (Year: 2016). [cited by examiner]
Tounsi, W. and Rais, H., “A Survey on Technical Threat Intelligence: Research Trends & Challenges,” Computers & Security, vol. 72, Jul. 2018, pp. 68-98, Elsevier Ltd., United Kingdom. [cited by applicant]