IP Library Granted Patent US 12,120,145
Granted Patent B2
US 12,120,145 · App. 17/863,711 · Granted Oct 15, 2024

Threat intelligence system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
H04L63/1441H04L63/1408H04L67/02H04L67/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,145
App. No.
17/863,711
Granted
Oct 15, 2024
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions. The plurality of raw threat data definitions are processed, thus generating a plurality of processed threat data definitions. The plurality of processed threat data definitions are processed to form a master threat data definition. The master threat data definition is provided to one or more client electronic devices.

Claims (78)

1. A computer-implemented method, executed on a computing device, comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein processing the plurality of raw threat data definitions includes:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

determining a category for each of the plurality of raw threat data definitions; and

determining a source for each of the plurality of raw threat data definitions;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with one or more client electronic devices; and

providing the master threat data definition to the one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

2. The computer-implemented method of claim 1 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

3. The computer-implemented method of claim 1 wherein processing the plurality of raw threat data definitions includes one or more of:

converting the plurality of raw threat data definitions into a common format;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

4. The computer-implemented method of claim 1 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

5. The computer-implemented method of claim 1 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

6. The computer-implemented method of claim 1 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers;

social network trader sources; and

open source threat feeds.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein processing the plurality of raw threat data definitions includes:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

determining a category for each of the plurality of raw threat data definitions; and

determining a source for each of the plurality of raw threat data definitions;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with one or more client electronic devices; and

providing the master threat data definition to the one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

8. The computer program product of claim 7 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

9. The computer program product of claim 7 wherein processing the plurality of raw threat data definitions includes one or more of:

converting the plurality of raw threat data definitions into a common format;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

10. The computer program product of claim 7 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

11. The computer program product of claim 7 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

12. The computer program product of claim 7 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers;

social network trader sources; and

open source threat feeds.

13. A computing system including a processor and memory configured to perform operations comprising:

importing threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions;

processing the plurality of raw threat data definitions, thus generating a plurality of processed threat data definitions, wherein processing the plurality of raw threat data definitions includes:

deduplicating the plurality of raw threat data definitions;

cleaning the plurality of raw threat data definitions to remove false positives;

determining a category for each of the plurality of raw threat data definitions; and

determining a source for each of the plurality of raw threat data definitions;

processing the plurality of processed threat data definitions to form a master threat data definition;

formatting the master threat data definition into a format that is compatible with one or more client electronic devices; and

providing the master threat data definition to the one or more client electronic devices to enable the one or more client electronic devices to detect one or more threats.

14. The computing system of claim 13 wherein importing threat data from a plurality of threat data sources includes one or more of:

receiving the plurality of raw threat data definitions; and

storing the plurality of raw threat data definitions into one or more database tables.

15. The computing system of claim 13 wherein processing the plurality of raw threat data definitions includes one or more of:

converting the plurality of raw threat data definitions into a common format;

determining the trust level for each of the plurality of raw threat data definitions; and

determining the age level for each of the plurality of raw threat data definitions.

16. The computing system of claim 13 wherein processing the plurality of processed threat data definitions to form a master threat data definition includes one or more of:

combining the plurality of processed threat data definitions to form the master threat data definition.

17. The computing system of claim 13 wherein providing the master threat data definition to one or more client electronic devices includes:

providing at least a portion of the master threat data definition to the one or more client electronic devices using one or more of a Hypertext Markup Language (HTML) report and a pre-formatted data export.

18. The computing system of claim 13 wherein the plurality of threat data sources includes one or more of:

public honeypot servers;

private honeypot servers;

social network trader sources; and

open source threat feeds.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: MURPHY, BRIAN P.; PARTLOW, JOE
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 068043/0465 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
Continuity (4)
Continuation 16552693 · Aug 27, 2019
Continuation 15202213 · Jul 5, 2016
Provisional Application 62187922 · Jul 2, 2015
Related Publication 20220353291A1 · Nov 3, 2022