IP Library Granted Patent US 11,863,581
Granted Patent B1
US 11,863,581 · App. 17/872,854 · Granted Jan 2, 2024

Subscription-based malware detection

Inventors: Mumtaz Siddiqui (Fremont, CA); Manju Radhakrishnan (San Jose, CA)
Assignee: Musarubra US LLC
H04L63/1433G06F21/105G06F21/629H04L41/5003H04L63/1408H04L67/52H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,581
App. No.
17/872,854
Granted
Jan 2, 2024
Kind
B1
Abstract

A computerized method is described for authenticating access to a subscription-based service to detect an attempted cyber-attack. More specifically, service policy level information is received by a cloud broker. The service policy level information includes an identifier of a sensor operating as a source of one or more objects for analysis and an identifier assigned to a customer associated with the sensor. Thereafter, a cluster of a plurality of clusters is selected by the cloud broker. The cloud broker is configured to (i) analyze whether one or more objects are associated with an attempted cyber-attack by at least analyzing the sensor identifier to select the cluster based on at least a geographical location of the sensor determined by the sensor identifier and (ii) establish a communication session between the sensor and the cluster via the cloud broker until termination of the communication session.

Claims (28)

1. A computerized method comprising:

receiving service policy level information by a cloud broker, the service policy level information includes an identifier of a sensor operating as a source of one or more objects for analysis and an identifier assigned to a customer associated with the sensor; and

selecting a cluster of a plurality of clusters by the cloud broker to determine whether one or more objects are associated with an attempted cyber-attack, the cloud broker is configured to (i) analyze the sensor identifier to select the cluster based on at least a geographical location of the sensor determined by the sensor identifier and (ii) establish a communication session between the sensor and the cluster via the cloud broker until termination of the communication session.

2. The computerized method of claim 1 , wherein the receiving of the service policy level information by the cloud broker is based on using the sensor identifier in retrieval of the service policy level information from one or more databases separate from the sensor and the cloud broker.

3. The computerized method of claim 1 , wherein the selecting of the cluster by the cloud broker is based on both the geographical location of the sensor and one or more attributes of the service policy level information that includes geographic restrictions in selecting one of the plurality of clusters as the cluster.

4. The computerized method of claim 1 further comprising:

receiving, by the cloud broker, information based on operational metadata, the operational metadata includes metadata that pertains to an operating state of at least the cluster of the plurality of clusters.

5. The computerized method of claim 4 , wherein the selecting of the cluster further comprises conducting an analysis by the cloud broker whether the information, based on the operational metadata, meets or exceeds one or more performance-based attributes of the service policy level information.

6. The computerized method of claim 4 , wherein the operational metadata includes a current rate of analysis supported by the cluster and the service policy level information includes a quality of service (QoS) attribute that identifies a minimum rate of analysis offered by a subscription level assigned to the customer.

7. The computerized method of claim 4 , wherein the operational metadata includes a guest image, including an operating system and one or more applications, supported by the cluster and the service policy level information includes an attribute that identifies a type of guest image supported by the cluster.

8. The computerized method of claim 1 , wherein the service policy level information includes the identifier assigned to the customer and the cloud broker being configured to use the identifier assigned to the customer to access one or more databases to access performance-based attributes used by the cloud broker to select the cluster of the plurality of clusters.

9. A non-transitory storage medium deployed within a cloud broker and including software that comprises an analysis selection service configured to perform operations, comprising:

receiving service policy level information including an identifier of a sensor operating as a source of one or more objects for analysis and an identifier assigned to a customer associated with the sensor; and

selecting a cluster of a plurality of clusters by the cloud broker to determine whether one or more objects are associated with an attempted cyber-attack by at least (i) analyzing the sensor identifier to select the cluster based on at least a geographical location of the sensor determined by the sensor identifier and (ii) establish a communication session between the sensor and the cluster via the cloud broker until termination of the communication session.

10. The non-transitory storage medium of claim 9 , wherein the analysis selection service is further configured to receive of the service policy level information based on receipt of the sensor identifier and using the sensor identifier in retrieval of the service policy level information from one or more databases separate from the sensor and the cloud broker.

11. The non-transitory storage medium of claim 9 , wherein the analysis selection service is further configured to select the cluster by the cloud broker based on both the geographical location of the sensor and one or more attributes of the service policy level information that includes geographic restrictions in selecting one of the plurality of clusters as the cluster.

12. The non-transitory storage medium of claim 9 , wherein the software further comprising an analysis monitoring service configured to receive information based on operational metadata, the operational metadata includes metadata that pertains to an operating state of at least the cluster of the plurality of clusters.

13. The non-transitory storage medium of claim 12 , wherein the analysis selection service of the software is configured to select the cluster by at least conducting an analysis whether the information based on the operational metadata meets or exceeds one or more performance-based attributes of the service policy level information.

14. The non-transitory storage medium of claim 12 , wherein the operational metadata includes a current rate of analysis supported by the cluster and the service policy level information includes a quality of service (QoS) attribute that identifies a minimum rate of analysis offered by a subscription level assigned to the customer.

15. The non-transitory storage medium of claim 12 , wherein the operational metadata includes a guest image, including an operating system and one or more applications, supported by the cluster and the service policy level information includes an attribute that identifies a type of guest image supported by the cluster.

16. A computerized method comprising:

receiving service policy level information by a cloud broker, the service policy level information includes an identifier of a sensor operating as a source of one or more objects for analysis;

receiving, by the cloud broker, information based on operational metadata, the operational metadata includes metadata that pertains to an operating state of each cluster of a plurality of clusters, the plurality of clusters are configured to conduct analytics of submitted objects; and

selecting, by the cloud broker, a cluster of the plurality of clusters to analyze whether the one or more objects are associated with an attempted cyber-attack by at least (i) analyzing the sensor identifier to select the cluster based on at least a geographical location of the sensor determined by the sensor identifier and (ii) establish a communication session between the sensor and the cluster via the cloud broker until termination of the communication session.

17. The computerized method of claim 16 , wherein the cloud broker is configured to select the cluster using of the identifier of the sensor based on both the geographical location of the sensor and one or more attributes of the service policy level information that includes geographic restrictions in selecting one of the plurality of clusters as the cluster.

18. The computerized method of claim 16 , wherein the cloud broker to select the cluster of the plurality of clusters by at least conducting an analysis by the cloud broker that the information based on the operational metadata meets or exceeds one or more performance-based attributes of the service policy level information.

19. The computerized method of claim 16 , wherein the operational metadata includes a current rate of analysis supported by the cluster and the service policy level information includes a quality of service (QoS) attribute that identifies a minimum rate of analysis offered by a subscription level assigned to the customer.

20. The computerized method of claim 16 , wherein the operational metadata includes a guest image, including an operating system and one or more applications, supported by the cluster and the service policy level information includes an attribute that identifies a type of guest image supported by the cluster.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2023
From: SIDDIQUI, MUMTAZ; RADHAKRISHNAN, MANJU
To: FIREEYE, INC.
Reel/Frame 065561/0863 →
MERGER Recorded Nov 14, 2023
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 065561/0946 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 065578/0776 →
CHANGE OF NAME Recorded Nov 14, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 065578/0802 →
Continuity (4)
Continuation 17035538 · Sep 28, 2020
Continuation 15940410 · Mar 29, 2018
Provisional Application 62479208 · Mar 30, 2017
Provisional Application 62523121 · Jun 21, 2017
Cited By (1)
US 12,278,834