IP Library Granted Patent US 12,231,443
Granted Patent B2
US 12,231,443 · App. 18/121,543 · Granted Feb 18, 2025

Analysis of endpoint detect and response data

Inventors: Agustin Matias March (Cordoba, AR); Raul Osvaldo Robledo (Cordoba, AR); Alejandro Houspanossian (Cordoba, AR); Gabriel Infante Lopez (Cordoba, AR)
Assignee: Musaruba US LLC
H04L63/1416G06N20/00H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,443
App. No.
18/121,543
Granted
Feb 18, 2025
Kind
B2
Abstract

There is disclosed a system and method of detecting security threats for an enterprise, including: filtering a first set of endpoint metadata records to identify a subset of metadata records, wherein filtering includes identifying endpoint security metadata records that are uncommon in context of the enterprise; and designating the subset of metadata records as indicating a potential security threat including designating the subset of metadata records for human analysis.

Claims (38)

1. A method of detecting security threats for an enterprise, comprising:

computing commonality baseline metadata records based on multiple time windows;

filtering a first set of endpoint metadata records to identify a subset of metadata records, wherein filtering includes identifying, via machine learning, a delta between the first set of endpoint security metadata records and the commonality baseline metadata records;

based on the filtering designating the subset of metadata records as indicating a potential security threat, wherein designating includes designating the subset of metadata records for human analysis;

identifying command line operations within the endpoint metadata records; and

tokenizing the command line operations into a token, wherein the token is assigned a numerical value.

2. The method of claim 1 , wherein the first set of endpoint metadata records are an unfiltered set.

3. The method of claim 1 , wherein the subset of metadata records is less than one tenth a size of the first set of endpoint metadata records.

4. The method of claim 1 , further including providing the subset of metadata records to a security operations center for human analysis.

5. The method of claim 1 , further including receiving an instruction from a human actor to adjust a threshold for identifying uncommon security metadata records.

6. The method of claim 5 , further including providing a graphical user interface to receive the instruction from the human actor.

7. The method of claim 1 , further including using cooperative human/machine interaction to perform the human analysis.

8. The method of claim 1 , further including using a hash to filter the first set of endpoint metadata records.

9. The method of claim 8 , wherein the hash is a MinHash.

10. The method of claim 1 , further including performing locality-sensitive hashing to group the tokenized command line operations.

11. The method of claim 1 , wherein the numerical value is based on characters within the respective tokens.

12. The method of claim 1 , wherein the commonality baseline metadata records based on multiple time windows represent metadata that are common in context of the enterprise at different times.

13. One or more tangible, non-transitory computer-readable storage media having stored thereon executable instructions to instruct a processor circuit to:

compute baseline security records based on multiple time windows;

filter a first set of endpoint security records to identify a subset of security records, wherein filtering includes identifying, via machine learning, a delta between the first set of endpoint security records and the baseline security records;

based on the filtering, designating the subset of endpoint security records as indicating a potential security threat to an enterprise, wherein designating includes designating the subset of endpoint security records for human analysis;

identify command line operations within the endpoint metadata records; and

tokenize the command line operations into a token, wherein the token is assigned a numerical value.

14. The one or more tangible, non-transitory computer-readable storage media of claim 13 , wherein the subset of endpoint security records is less than one tenth a size of the first set of endpoint security records.

15. The one or more tangible, non-transitory computer-readable storage media of claim 13 , wherein the instructions are further to perform locality-sensitive hashing to group the tokenized command line operations.

16. The one or more tangible, non-transitory computer-readable storage media of claim 13 , wherein the numerical value is based on characters within the respective tokens.

17. A computing ecosystem including one or more computers, virtual machines, or containers, the computing system comprising:

at least one processor circuit;

at least one memory circuit;

instructions encoded within the at least one memory circuit to instruct the at least one processor circuit to:

compute baseline security records based on multiple time windows;

filter a first set of endpoint security records to identify a subset of security records, wherein filtering includes identifying, via machine learning, a delta between the first set of endpoint security records and the baseline security records;

based on the filtering, designating the subset of endpoint security records as indicating a potential security threat to an enterprise, wherein designating includes designating the subset of endpoint security records for human analysis;

identify command line operations within the endpoint metadata records; and

tokenize the command line operations into a token, wherein the token is assigned a numerical value.

18. The computing ecosystem of claim 17 , further including providing the subset of metadata records to a security operations center for human analysis.

19. The computing ecosystem of claim 17 , wherein the instructions are further to receive an instruction from a human actor to adjust a threshold for identifying uncommon endpoint security records.

20. The computing ecosystem of claim 17 , wherein the instructions are further to provide a cooperative human/machine interaction to perform the human analysis.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
Continuity (2)
Continuation 16586804 · Sep 27, 2019
Related Publication 20230216868A1 · Jul 6, 2023
References Cited (22)
US 10686820B1 · Sheffer et al. · 2020 [cited by applicant]
US 10878335B1 · Waugh · 2020 [cited by examiner]
US 11621956B2 · Franzi · 2023 [cited by applicant]
US 20100125594A1 · Li et al. · 2010 [cited by applicant]
US 20140379619A1 · Permeh · 2014 [cited by examiner]
US 20160080399A1 · Harris et al. · 2016 [cited by applicant]
US 20170078286A1 · Hunt et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170302665A1 · Zou et al. · 2017 [cited by applicant]
US 20180316691A1 · Strong · 2018 [cited by examiner]
US 20190260785A1 · Jenkinson · 2019 [cited by examiner]
US 20200287924A1 · Zhang · 2020 [cited by examiner]
US 20200314117A1 · Nguyen · 2020 [cited by examiner]
KR 101814368B1 · 2018 [cited by applicant]
Krebs, Rouven et al., “Architectural Concerns in Multi-Tenant SaaS Applications,” Proceedings of the 2nd International Conference on Cloud Computing and Services Science (Closer-2012) pp. 426-431. [cited by applicant]
International Searching Authority, “International Search Report,” issued in connection with International Patent Application No. PCT/US2020/052381, mailed on Dec. 30, 2020, 4 pages. [cited by applicant]
International Searching Authority, “Written Opinion of the International Searching Authority,” issued in connection with International Patent Application No. PCT/US2020/052381, mailed on Dec. 30, 2020, 7 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 16/586,804, dated Jan. 21, 2022, 11 pages. [cited by applicant]
International Bureau, “International Preliminary Report on Patentability,” issued in connection with International Patent Application No. PCT/US2020/052381, issued on Apr. 7, 2022, 9 pages. [cited by applicant]
United States Patent and Trademark Office, “Final Office Action,” issued in connection with U.S. Appl. No. 16/586,804, dated Aug. 19, 2022, 14 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 16/586,804, dated Nov. 23, 2022, 8 pages. [cited by applicant]
European Patent Office, “Extended European Search Report,” issued in connection with European Patent Application No. 20869497.6, dated Aug. 24, 2023, 7 pages. [cited by applicant]