IP Library Granted Patent US 12,574,393
Granted Patent B2
US 12,574,393 · App. 17/859,841 · Granted Mar 10, 2026

Cyber security system utilizing interactions between detected and hypothesize cyber-incidents

Inventors: Simon David Lincoln Fellows (Cambridge, GB); Timothy Owen Bazalgette (Knebworth, GB); Marko Marsenic (Cambridge, GB); Dickon Murray Humphrey (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,393
App. No.
17/859,841
Granted
Mar 10, 2026
Kind
B2
Abstract

An apparatus may include a set of modules and artificial intelligence models to detect a cyber incident, a simulator to simulate an actual cyber attack of the cyber incident on a network including physical devices being protected by the set of modules and artificial intelligence models; and a feedback loop between i) the set of modules and artificial intelligence models and ii) the simulator, during an ongoing detected cyber incident. An attack path modeling module is configured to feed details of the detected incident by a cyber threat module into an input module of the simulator, and to run one or more hypothetical simulations of that detected incident in order to predict and control an autonomous response to the detected incident. Any software instructions forming part of the set of modules, the artificial intelligence models, and the simulator are stored in an executable form in memories and executed by processors.

Claims (42)

1 . An apparatus comprising:

a defined set of modules, including a cyber threat module and an autonomous response module, and one or more artificial intelligence models configured to detect and respond to a cyber incident, where the defined set of modules and the one or more artificial intelligence models are part of a cyber security appliance installed in a network, where the cyber threat module is configured to cooperate with the autonomous response module to cause one or more autonomous responses in response to be taken to counter a cyber threat that is part of the cyber incident, where the autonomous response module, rather than a human taking an action, is configured to cause the one or more autonomous responses in response to be taken to counter the cyber threat in the detected cyber incident;

a simulator configured to simulate an actual cyber attack of the cyber incident on the network, including physical devices, being protected by the set of modules and artificial intelligence models configured to detect the cyber incident;

a feedback loop between i) the set of modules and artificial intelligence models configured to detect the cyber incident and ii) the simulator configured to simulate the actual cyber attack of the cyber incident on the network including physical devices being protected by the set of modules and artificial intelligence models configured to detect the cyber incident during an ongoing detected cyber incident,

where an attack path modeling module is configured to feed details of the detected cyber incident by the cyber threat module into an input module of the simulator, where the simulator is configured to run one or more hypothetical simulations of that detected cyber incident and cooperate with the autonomous response module in order to predict and control the one or more autonomous responses to the detected cyber incident, and

where any software instructions forming part of the set of modules, the artificial intelligence models, and the simulator are stored in an executable form in one or more memories and executed by one or more processors.

2 . The apparatus of claim 1 ,

where the simulator is configured to construct a graph of a virtualized instance of the network including i) the physical devices connecting to the virtualized instance of the network as well as ii) connections and pathways through the virtualized instance of the network, and

where the set of modules in the cyber security appliance are configured to cooperate with the simulator to predict an initial autonomous response to the detected cyber incident and then how effectively the initial autonomous response performs in mitigating the detected cyber incident once the autonomous response module takes the initial autonomous response, where the initial autonomous response is visible to an attacker in the actual cyber attack, and the set of modules in the cyber security appliance are configured to cooperate with the simulator to predict how the attacker may possibly alter their plans in response to being detected and the initial autonomous response that is visible to the attacker.

3 . The apparatus of claim 2 , where the simulator is configured to run the one or more hypothetical simulations of the detected incident to calculate one or more paths of least resistance from the virtualized instance of a source device through to other virtualized instances of components of the network until reaching an end goal of each hypothetical simulation of the detected incident, but not calculate every theoretically possible path from the virtualized instance of the source device to the end goal of each hypothetical simulation of the detected incident.

4 . The apparatus of claim 1 , where the simulator is further configured to prioritize which devices connecting to a virtualized instance of the network should have a priority to allocate security resources to them based on results of the one or more hypothetical simulations of the detected incident, and

where the set of modules in the cyber security appliance are configured to cooperate with the simulator to predict an initial autonomous response to the detected cyber incident and then how effectively the initial autonomous response performs in mitigating the detected cyber incident once the autonomous response module takes the initial autonomous response, where the initial autonomous response is hidden to an attacker in the actual cyber attack.

5 . The apparatus of claim 2 , where the simulator is configured to construct the graph of the virtualized network, with its nets and subnets, where two or more of the devices connecting to the virtualized network are assigned with different weighting resistances to malicious compromise from the one or more hypothetical simulations based on the actual cyber attack of the cyber incident on the virtualized instance of the network.

6 . The apparatus of claim 1 , where the simulator is further configured to run a single hypothetical simulation based on the actual cyber attack of the cyber incident on a virtualized instance of the network in order to calculate a set of paths of possible cyber attack propagation in the network if no autonomous response action is taken in response to the actual cyber attack of the cyber incident.

7 . The apparatus of claim 6 , where the simulator is further configured to calculate, based at least in part on the results of the one or more hypothetical simulations, a risk score for each device, the risk score being indicative of a possible severity of a compromise if no autonomous response action is taken in response to the actual cyber attack of the cyber incident.

8 . The apparatus of claim 1 , where once the simulator runs the one or more hypothetical simulations, a pattern of life, conditions, and indicators in the network are recorded to show what indicators and level of detected cyber incident would have been needed to trigger the one or more autonomous responses.

9 . The apparatus of claim 1 , where the simulator is further configured to increase a risk score associated with a first device based at least in part on: a determination that the first device has been a target in past cyber attacks, the first device is in connection with a second device which is designated as essential to the network, and the first device is in connection with at least one device with a risk score over a pre-defined threshold risk score.

10 . The apparatus of claim 1 , where the simulator is configured to run the one or more hypothetical simulations of the detected incident to calculate one or more paths of least resistance for each hypothetical simulation to compromise 1) a virtualized instance of a source device, originally compromised by the cyber incident, 2) through to other virtualized instances of components of a virtualized network, 3) until reaching an end goal of that hypothetical simulation of the one or more hypothetical simulations in the virtualized network, all based on historic knowledge of connectivity and behavior patterns of users and devices within the network under analysis.

11 . A method for predicting one or more autonomous responses to a detected cyber incident, the method comprising:

configuring a defined set of modules, including a cyber threat module and an autonomous response module, and one or more artificial intelligence models configured to detect and respond to the cyber incident, where the defined set of modules and the one or more artificial intelligence models are part of a cyber security appliance installed in a network;

configuring the cyber threat module to cooperate with the autonomous response module to cause the one or more autonomous responses in response to be taken to counter a cyber threat that is part of the detected cyber incident, where the autonomous response module, rather than a human taking an action, is configured to cause the one or more autonomous responses in response to be taken to counter the cyber threat in the detected cyber incident;

configuring a simulator configured to simulate an actual cyber attack of the detected cyber incident on the network, including physical devices, being protected by the set of modules and artificial intelligence models configured to detect the cyber incident;

configuring a feedback loop between i) the set of modules and artificial intelligence models configured to detect the cyber incident and ii) the simulator configured to simulate the actual cyber attack of the cyber incident on the network including physical devices being protected by the set of modules and artificial intelligence models configured to detect the cyber incident during an ongoing detected cyber incident,

where an attack path modeling module is configured to feed details of the detected cyber incident by the cyber threat module into an input module of the simulator, where the simulator is configured to run one or more hypothetical simulations of that detected cyber incident and cooperate with the autonomous response module in order to predict and control the one or more autonomous responses to the detected cyber incident, and

where any software instructions forming part of the set of modules, the artificial intelligence models, and the simulator are stored in an executable form in one or more memories and executed by one or more processors.

12 . The method of claim 11 , further comprising

configuring the simulator to construct a graph of a virtualized instance of the network including i) the physical devices connecting to the virtualized instance of the network as well as ii) connections and pathways through the virtualized instance of the network.

13 . The method of claim 12 , further comprising

configuring the simulator to run the one or more hypothetical simulations of the detected incident to calculate one or more paths of least resistance from the virtualized instance of a source device through to other virtualized instances of components of the network until reaching an end goal of each hypothetical simulation of the detected incident, but not calculate every theoretically possible path from the virtualized instance of the source device to the end goal of each hypothetical simulation of the detected incident.

14 . The method of claim 11 , further comprising

configuring the simulator to prioritize which devices connecting to a virtualized instance of the network should have a priority to allocate security resources to them based on results of the one or more hypothetical simulations of the detected incident.

15 . The method of claim 12 , further comprising

configuring the simulator to construct the graph of the virtualized network, with its nets and subnets, where two or more of the devices connecting to the virtualized network are assigned with different weighting resistances to malicious compromise from the one or more hypothetical simulations based on the actual cyber attack of the cyber incident on the virtualized instance of the network; and

running a single hypothetical simulation based on the actual cyber attack of the cyber incident on the virtualized instance of the network in order to calculate a set of paths of possible cyber attack propagation in the network if no autonomous response action is taken in response to the actual cyber attack of the cyber incident.

16 . The method of claim 15 , further comprising

configuring the simulator to calculate, based at least in part on the results of the one or more hypothetical simulations, a risk score for each device, the risk score being indicative of a possible severity of the compromise if no autonomous response action is taken in response to the actual cyber attack of the cyber incident.

17 . The method of claim 11 , where once the simulator runs the one or more hypothetical simulations, a pattern of life, conditions, and indicators in the network are recorded to show what indicators and level of detected cyber incident would have been needed to trigger the autonomous response action.

18 . The method of claim 11 , further comprising

configuring the simulator to increase a risk score associated with a first device based at least in part on: a determination that the first device has been a target in past cyber attacks, the first device is in connection with a second device which is designated as essential to the network, and the first device is in connection with at least one device with the risk score over a pre-defined threshold risk score.

19 . The method of claim 11 , further comprising

configuring the simulator to run the one or more hypothetical simulations of the detected incident to calculate one or more paths of least resistance for each hypothetical simulation to compromise 1) a virtualized instance of a source device, originally compromised by the cyber incident, 2) through to other virtualized instances of components of a virtualized network, 3) until reaching an end goal of that hypothetical simulation of the one or more hypothetical simulations in the virtualized network, all based on historic knowledge of connectivity and behavior patterns of users and devices within the network under analysis.

20 . A non-transitory computer readable medium in an apparatus, comprising one or more computer readable codes operable, when executed by one or more processors, to instruct the apparatus to perform the method of claim 11 .

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2023
From: FELLOWS, SIMON DAVID LINCOLN; MARSENIC, MARKO; HUMPHREY, DICKON MURRAY; BAZALGETTE, TIMOTHY OWEN
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 062302/0809 →
Continuity (8)
Continuation In Part 17187373 · Feb 26, 2021
Continuation In Part 17004392 · Aug 27, 2020
Provisional Application 63219026 · Jul 7, 2021
Provisional Application 63274376 · Nov 1, 2021
Provisional Application 63317157 · Mar 7, 2022
Provisional Application 62893350 · Aug 29, 2019
Provisional Application 62983307 · Feb 28, 2020
Related Publication 20220360597A1 · Nov 10, 2022
References Cited (284)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 7890869B1 · Mayer et al. · 2011 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8387116B2 · Deguchi · 2013 [cited by applicant]
US 8407798B1 · Lotem · 2013 [cited by examiner]
US 8484741B1 · Chapman · 2013 [cited by applicant]
US 8621614B2 · Vaithilingam · 2013 [cited by examiner]
US 8661538B2 · Cohen-Ganor et al. · 2014 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8881288B1 · Levy · 2014 [cited by examiner]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9176951B2 · Patrudu · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9239908B1 · Constantine · 2016 [cited by examiner]
US 9292695B1 · Bassett · 2016 [cited by examiner]
US 9344444B2 · Lippmann · 2016 [cited by applicant]
US 9348742B1 · Brezinski · 2016 [cited by applicant]
US 9369484B1 · Lacerte · 2016 [cited by examiner]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9680855B2 · Schultz · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 9742803B1 · Kras · 2017 [cited by examiner]
US 9749360B1 · Irimie · 2017 [cited by applicant]
US 9954884B2 · Hassell · 2018 [cited by applicant]
US 9971973B1 · Smith · 2018 [cited by applicant]
US 10237298B1 · Nguyen et al. · 2019 [cited by applicant]
US 10268821B2 · Stockdale et al. · 2019 [cited by applicant]
US 10320713B2 · Alsup et al. · 2019 [cited by applicant]
US 10320813B1 · Ahmed · 2019 [cited by examiner]
US 10382473B1 · Ashkenazy · 2019 [cited by examiner]
US 10419466B2 · Ferguson et al. · 2019 [cited by applicant]
US 10516693B2 · Stockdale et al. · 2019 [cited by applicant]
US 10601865B1 · Mesdaq · 2020 [cited by examiner]
US 10659335B1 · Morris · 2020 [cited by examiner]
US 10701093B2 · Dean et al. · 2020 [cited by applicant]
US 10754959B1 · Rajasooriya · 2020 [cited by examiner]
US 10812521B1 · Sharifi Mehr · 2020 [cited by applicant]
US 10848512B2 · Murphy · 2020 [cited by examiner]
US 10848515B1 · Pokhrel · 2020 [cited by examiner]
US 11228612B2 · Vajipayajula · 2022 [cited by examiner]
US 11310268B2 · Bowditch · 2022 [cited by examiner]
US 11316875B2 · Frey · 2022 [cited by applicant]
US 11587177B2 · Sankar · 2023 [cited by applicant]
US 11687825B2 · Khan · 2023 [cited by applicant]
US 11902321B2 · Beck · 2024 [cited by examiner]
US 12041082B2 · Lam · 2024 [cited by applicant]
US 20020174217A1 · Anderson et al. · 2002 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030051026A1 · Carter · 2003 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20050193430A1 · Cohen · 2005 [cited by applicant]
US 20060021044A1 · Cook · 2006 [cited by examiner]
US 20060021046A1 · Cook · 2006 [cited by examiner]
US 20060021047A1 · Cook · 2006 [cited by examiner]
US 20060021048A1 · Cook · 2006 [cited by examiner]
US 20060021050A1 · Cook · 2006 [cited by examiner]
US 20060191010A1 · Benjamin · 2006 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070192855A1 · Hulten · 2007 [cited by examiner]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080077358A1 · Marvasti · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20080167920A1 · Schmidt · 2008 [cited by examiner]
US 20090007270A1 · Futoransky · 2009 [cited by applicant]
US 20090077666A1 · Chen · 2009 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100058456A1 · Jajodia · 2010 [cited by examiner]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100107254A1 · Eiland et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100138925A1 · Barai · 2010 [cited by applicant]
US 20100192195A1 · Dunagan · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130055404A1 · Khalili · 2013 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130198846A1 · Chapman · 2013 [cited by examiner]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20130297375A1 · Chapman · 2013 [cited by applicant]
US 20130312101A1 · Lotem · 2013 [cited by examiner]
US 20130318616A1 · Christodorescu · 2013 [cited by examiner]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140007241A1 · Gula · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140223562A1 · Liu · 2014 [cited by examiner]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150058993A1 · Choi · 2015 [cited by examiner]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150287336A1 · Scheeres · 2015 [cited by examiner]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20160044059A1 · Fine · 2016 [cited by examiner]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160306980A1 · Kotler · 2016 [cited by applicant]
US 20160330238A1 · Hadnagy · 2016 [cited by examiner]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170026388A1 · Gatti · 2017 [cited by examiner]
US 20170046519A1 · Cam · 2017 [cited by examiner]
US 20170048266A1 · Hovor · 2017 [cited by examiner]
US 20170054745A1 · Zhang et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by examiner]
US 20170230323A1 · Jakobsson · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20170359359A1 · Jaladi · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180041537A1 · Bloxham · 2018 [cited by examiner]
US 20180052993A1 · Jou · 2018 [cited by applicant]
US 20180075243A1 · Thomas · 2018 [cited by examiner]
US 20180124108A1 · Irimie · 2018 [cited by examiner]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180219901A1 · Gorodissky · 2018 [cited by examiner]
US 20180234435A1 · Cohen · 2018 [cited by applicant]
US 20180288073A1 · Hopper · 2018 [cited by applicant]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20180324207A1 · Reybok · 2018 [cited by applicant]
US 20180359272A1 · Mizrachi · 2018 [cited by examiner]
US 20180367549A1 · Jang · 2018 [cited by examiner]
US 20190014141A1 · Segal · 2019 [cited by examiner]
US 20190014149A1 · Cleveland · 2019 [cited by examiner]
US 20190036948A1 · Appel et al. · 2019 [cited by applicant]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190114245A1 · Mermoud · 2019 [cited by examiner]
US 20190149572A1 · Gorodissky · 2019 [cited by applicant]
US 20190171984A1 · Irimie · 2019 [cited by examiner]
US 20190173917A1 · Sites · 2019 [cited by examiner]
US 20190173918A1 · Sites · 2019 [cited by examiner]
US 20190173919A1 · Irimie · 2019 [cited by examiner]
US 20190182266A1 · Doron · 2019 [cited by examiner]
US 20190199746A1 · Doron · 2019 [cited by examiner]
US 20190238571A1 · Adir · 2019 [cited by examiner]
US 20190245875A1 · Chen · 2019 [cited by examiner]
US 20190245883A1 · Gorodissky · 2019 [cited by examiner]
US 20190251260A1 · Stockdale et al. · 2019 [cited by applicant]
US 20190260783A1 · Humphrey · 2019 [cited by applicant]
US 20190297096A1 · Ahmed · 2019 [cited by examiner]
US 20190342307A1 · Gamble · 2019 [cited by examiner]
US 20190347578A1 · Bolding · 2019 [cited by examiner]
US 20190349400A1 · Bruss · 2019 [cited by examiner]
US 20200034752A1 · Luo · 2020 [cited by examiner]
US 20200067962A1 · Tan · 2020 [cited by applicant]
US 20200097597A1 · Lourentzou · 2020 [cited by applicant]
US 20200143053A1 · Gutierrez · 2020 [cited by examiner]
US 20200177615A1 · Grabois · 2020 [cited by examiner]
US 20200177617A1 · Hadar · 2020 [cited by examiner]
US 20200177618A1 · Hassanzadeh · 2020 [cited by examiner]
US 20200201992A1 · Hadar · 2020 [cited by examiner]
US 20200201997A1 · Hadar · 2020 [cited by applicant]
US 20200244673A1 · Stockdale · 2020 [cited by applicant]
US 20200267183A1 · Vishwanath · 2020 [cited by examiner]
US 20200280575A1 · Dean et al. · 2020 [cited by applicant]
US 20200351295A1 · Nhlabatsi · 2020 [cited by applicant]
US 20200358798A1 · Maylor · 2020 [cited by examiner]
US 20200379079A1 · Dupray · 2020 [cited by examiner]
US 20200382543A1 · Hoopes · 2020 [cited by applicant]
US 20200389486A1 · Jeyakumar · 2020 [cited by applicant]
US 20210012012A1 · Soroush · 2021 [cited by examiner]
US 20210014256A1 · Malhotra · 2021 [cited by examiner]
US 20210021612A1 · Higbee · 2021 [cited by applicant]
US 20210021629A1 · Dani · 2021 [cited by examiner]
US 20210029154A1 · Picard · 2021 [cited by examiner]
US 20210029164A1 · Albero · 2021 [cited by examiner]
US 20210092153A1 · Wei · 2021 [cited by examiner]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210157919A1 · Stockdale et al. · 2021 [cited by applicant]
US 20210194924A1 · Heinemeyer · 2021 [cited by applicant]
US 20210273958A1 · McLean · 2021 [cited by applicant]
US 20210281596A1 · Covell · 2021 [cited by examiner]
US 20210367962A1 · Kurowski · 2021 [cited by examiner]
US 20210409449A1 · Crabtree · 2021 [cited by examiner]
US 20220078210A1 · Crabtree · 2022 [cited by applicant]
US 20220086064A1 · Sivaraman · 2022 [cited by applicant]
US 20220210200A1 · Crabtree · 2022 [cited by examiner]
US 20220358607A1 · Guo · 2022 [cited by applicant]
US 20220360597A1 · Fellows · 2022 [cited by applicant]
US 20230315851A1 · Wei · 2023 [cited by applicant]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945 · 2008 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407 · 2013 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660 · 2016 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
WO 2019243579A1 · 2019 [cited by applicant]
WO 2020021100A1 · 2020 [cited by applicant]
Patent Cooperation Treaty, International Search Report, Dec. 6, 2022, 2 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Aug. 3, 2023, 49 pages. [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
European Patent Office, Extended European Search Report for Application No. 20193124.3, Jan. 22, 2021, 11 pages., Germany. [cited by applicant]
Stephen Moskal et al., Cyber threat assessment via attack scenario simulation using an integrated adversary and network modeling approach, The Journal of Defense Modeling and Simulation: Applications, Methodology, Techn… [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Sep. 29, 2022, 87 pages. [cited by applicant]
Gharan, Shayan Oveis, “Lecture 11: Clustering and the Spectral Partitioning Algorithm” May 2, 2016, 6pp. [cited by applicant]
Nikolystylfw, “Can Senseon beat Darktrace at its very own game with its ‘An I triangulation’ modern technology?” Dec. 22, 2018, nikolystylfw. [cited by applicant]
Lunden, Ingrid, “Senseon raises $6.4M to tackle cybersecurity threats with an AI ‘triangulation’ approach” Feb. 19, 2019, Tech Crunch. [cited by applicant]
Senseon Tech Ltd., “The State of Cyber Security SME Report 2019,” Jun. 3, 2019. [cited by applicant]
Senseon Tech Ltd., “Technology,”. [cited by applicant]
Senseon Tech Ltd., “Senseon & You,”. [cited by applicant]
Senseon Tech Ltd., “Technology Overview,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Enterprise,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Pro,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Reflex,”. [cited by applicant]
Israeli Patent Offce, Notice of Deficiencies for Patent Aplication 276972 ; 4 pp. Aug. 22, 2021. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Feb. 1, 2024 45 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, Aug. 22, 2024, 28 pages. [cited by applicant]
Moskal Stephen et al: “Context Model Fusion for Multistage Network Attack Simulation”, 2014 IEEE Military Communications Conference, IEEE, Oct. 6, 2014 (Oct. 6, 2014), pp. 158-163, XP032686457, DOI: 10.1109/MILCOM.2014.… [cited by applicant]
European Patent Office, Communication Pursuant to Article 94(3) EPC, 36 pp, dated Nov. 21, 2024. [cited by applicant]
Darktrace, “Darktrace Attack Path Modeling: Utilizing Graph Theory to derive multi-domain, risk-prioritized attack paths within computer networks,” Feb. 23, 2022, 11 pages, Darktrace, Cambridge, United Kingdom. [cited by applicant]
Darktrace, “Darktrace Releases Attack Path Modeling Research,” Feb. 23, 2022, 2 pages, Darktrace, Cambridge, United Kingdom. [cited by applicant]
Robbins, “BloodHound: How Graphs Changed the Way Hackers Attack,” GraphConnect, Oct. 2017, 10 pages, New York City. [cited by applicant]
TrendMicro, “Online Phishing: How to Stay Out of the Hackers' Nets,” Nov. 20, 2019, 10 pages, TrendMicro. [cited by applicant]
Fugue et al., “The State of Cloud Security 2021,” 2021, 19 pages. [cited by applicant]
IBM, “X-Force Threat Intelligence Index,” 2021, 50 pages. [cited by applicant]
Krebs, “‘Blackhole’ Exploit Kit Author Gets 7 Years,” Apr. 14, 2016, 3 pages, KrebsonSecurity. [cited by applicant]
Dijkstra, “A Note on Two Problems in Connexion with Graphs,” 1959, Numerische Mathematik 1, pp. 269-271, Amsterdam. [cited by applicant]
International Search Authority, International Search Report and Written Opinion, 12pages. [cited by applicant]
John Seymour et al: “Generative Models for Spear Phishing Posts on Social Media”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, Feb. 14, 2018 (Feb. 14, 2018), XP081222023. [cited by applicant]
Caithness, Neil, “Supervised/unsupervised cross-over method for autonomous anomaly classification,” Oct. 25, 2019, CAMLIS 2019. [cited by applicant]
Marwan El-Gendi, “Red teaming 101: An introduction to red teaming and how it improves your cyber security,” PwC United Kingdom, 8 pages. [cited by applicant]
Nist Computer Security Resource Center, “Red Team—Glossary”, 2 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, dated Aug. 3, 2023, 49 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Feb. 28, 2025 61 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, May 29, 2025 28 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Sep. 3, 2025, 9 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Sep. 16, 2024, 27 pages. [cited by applicant]
European Patent Office, Supplementary European Search Report, 16pp., Oct. 12, 2024. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, dated Apr. 11, 2025, 32 pages. [cited by applicant]
Patent Cooperation Treaty, International Search Report, Dec. 6, 2022, 2pp. [cited by applicant]