IP Library Granted Patent US 12,634,300
Granted Patent B1
US 12,634,300 · App. 18/207,064 · Granted May 19, 2026

Active extension of a threat intelligence sharing service

Inventors: Carl Salji (Bedford, GB); Jake Lal (Cambridge, GB); John Boyer (Cambridge, GB); Andres Martin (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1416H04L41/16H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,300
App. No.
18/207,064
Filed
Jun 7, 2023
Granted
May 19, 2026
Kind
B1
Examiner
TRAN, NAM T
Art Unit
2455
USPC
726/22
Abstract

A cyber security appliance and computerized method for detecting and disabling malicious endpoints is described. Upon receiving information associated with one or more endpoints including a first endpoint, the cyber security appliance determines, based on conducting analytics on a portion of the information by a cyber security appliance, whether the first endpoint constitutes a malicious endpoint. In response to detecting the malicious endpoint, the cyber security appliance requests authorization to launch an offensive countermeasure against the malicious endpoint and, upon receiving the authorization, conducts the offensive countermeasure against the malicious endpoint by at least continuously disrupting or disabling communications over a network utilized by the malicious endpoint.

Claims (32)

1 . A cyber security appliance for detecting and disabling malicious endpoints, comprising:

one or more input/output (I/O) ports to receive information associated with one or more endpoints including a first endpoint; and

a non-transitory memory storage device including software executable by one or more processors, the software comprises an artificial intelligence-based (AI-based) detect component and an inoculation module

wherein the AI-based detect component configured to receive the information and determine, based on a portion of the information, whether the first endpoint constitutes a malicious endpoint by being responsible for or associated with a cyber threat against an enterprise protected by the cyber security appliance, and

wherein the inoculation module in communication with the AI-based detect component, the inoculation module includes an inoculation extension, wherein the inoculation extension includes (1) a nomination module configured to request authorization to launch an offensive countermeasure against the malicious endpoint, (2) a disablement module to conduct the offensive countermeasure against the malicious endpoint to disable network communications by the malicious endpoint upon receiving the authorization, and (3) a confirmation module operating with a fingerprint module to generate a fingerprint in which content of the fingerprint is used to verify the malicious endpoint,

wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint, and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences.

2 . The cyber security appliance of claim 1 , wherein the disablement module of the inoculation module is configured to disable network communications for the malicious endpoint by at least disabling or continuously disrupting network connection availability by the malicious endpoint.

3 . The cyber security appliance of claim 2 , wherein the inoculation module is disabling or continuously disrupting network connection availability by the malicious endpoint by at least conducting a Denial-of-Service (DoS) attack by establishing communication sessions with the malicious endpoint and continuing to maintain the communication sessions in an attempt to exhaust all available sockets used by the malicious endpoint for network communications.

4 . The cyber security appliance of claim 3 , wherein the disablement module of the inoculation module includes a master component and a plurality of slave components, the master component is a software instance configured to receive and distribute network addressing information associate with the malicious endpoint to the plurality of slave components and each of the plurality of slave components is a software instance configured to establish a communication session of the communication sessions with a socket of the available sockets associated with the malicious endpoint.

5 . The cyber security appliance of claim 4 , wherein each slave component of the plurality of slave components is configured to maintain its communication session with the malicious endpoint through low-throughput data exchange with a maximum throughput of less than 500 kilobytes per second (kbps).

6 . The cyber security appliance of claim 4 , wherein each slave component of the plurality of slave components is configured to establish a communication session with the malicious endpoint via an anonymity server.

7 . The cyber security appliance of claim 1 , wherein the content of the fingerprint is used to verify the malicious endpoint operating as a malicious server as well as other servers related to the malicious server.

8 . The cyber security appliance of claim 1 , wherein the offensive countermeasure is an attempt to disable operability of a malicious server utilized to provide communications for a malicious endpoint used by a malicious actor, where the offensive countermeasure is a Denial-of-Service (DoS) attack on the malicious server by exhausting its available sockets.

9 . The cyber security appliance of claim 1 , wherein the fingerprint is delivered to other cyber security appliances associated with different domains to assist in disabling the malicious endpoint.

10 . The cyber security appliance of claim 1 , wherein the AI-based detect component comprises a cyber threat analyst module that operates in cooperation with AI models and AI classifiers to analyze the portion of the information associated with the first endpoint to determine that the first endpoint constitutes a malicious endpoint in response to detection of behaviors of the first endpoint that correlate with characteristics of a cyber threat recognized by at least one of the AI models.

11 . A non-transitory storage medium configured to store instructions that are configured, when executed, to detect and disable malicious endpoints, comprising:

an artificial intelligence-based (AI-based) detect component configured, when executed, to determine a cyber threat based on information sourced by a first endpoint and classify the first endpoint as a malicious endpoint; and

an inoculation module in communication with the AI-based detect component, the inoculation module includes an inoculation extension, wherein the inoculation extension includes (1) a nomination module configured to request authorization to launch an offensive countermeasure against the malicious endpoint, (2) a disablement module to coordinate the offensive countermeasure against the malicious endpoint to disable or continuously disrupt network connection availability for the malicious endpoint upon receiving the authorization, and (3) a confirmation module operating with a fingerprint module to generate a fingerprint in which content of the fingerprint is used to verify the malicious endpoint,

wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences.

12 . The non-transitory storage medium of claim 11 , wherein the disablement module of the inoculation module is configured to disable or continuously disrupt network connection availability by the malicious endpoint by conduct a Denial-of-Service (DoS) attack by establishing communication sessions with the malicious endpoint and continuing to maintain the communication sessions in an attempt to exhaust all available sockets used by the malicious endpoint for network communications.

13 . The non-transitory storage medium of claim 12 , wherein the disablement module of the inoculation module includes a master component and a plurality of slave components, the master component is a software instance configured to receive and distribute network addressing information associate with the malicious endpoint to the plurality of slave components and each of the plurality of slave components is a software instance configured to establish a communication session of the communication sessions with a socket of the available sockets associated with the malicious endpoint.

14 . The non-transitory storage medium of claim 13 , wherein each slave component of the plurality of slave components is configured to maintain its communication session with the malicious endpoint through low-throughput data exchange with a maximum throughput of less than 500 kilobytes per second (kbps).

15 . The non-transitory storage medium of claim 13 , wherein each slave component of the plurality of slave components is configured to establish a communication session with the malicious endpoint via an anonymity server.

16 . The non-transitory storage medium of claim 11 , wherein the AI-based detect component is configured to perform a plurality of levels of investigations on the information to determine the cyberthreat in which a first level of investigation is adapted to detect overt cyber threats over a first period of time and a second level of investigation is adapted to detect advanced persistent cyber threats through analysis of low-level anomalies over a second period of time greater than the first period of time.

17 . The non-transitory storage medium of claim 11 , wherein the fingerprint is delivered to other cyber security appliances associated with different domains to assist in disabling the malicious endpoint.

18 . The non-transitory storage medium of claim 11 , wherein the AI-based detect component comprises a cyber threat analyst module that operates in cooperation with AI models and AI classifiers to analyze a portion of the information associated with the first endpoint to determine that the first endpoint operates as a malicious endpoint in response to detection of behaviors of the first endpoint that correlate with characteristics of a cyber threat recognized by at least one of the AI modules.

19 . A computerized method for detecting and disabling malicious endpoints, comprising:

receiving information associated with one or more endpoints including a first endpoint;

determining, based on conducting analytics on a portion of the information by a cyber security appliance, whether the first endpoint constitutes a malicious endpoint by at least generating at least a fingerprint in which content of the fingerprint is used to verify the malicious endpoint, wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences; and

responsive to detecting the malicious endpoint,

request authorization to launch an offensive countermeasure against the malicious endpoint, and

conducting the offensive countermeasure against the malicious endpoint by at least continuously disrupting or disabling communications over a network utilized by the malicious endpoint upon receiving the authorization.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (1)
Provisional Application 63350781 · Jun 9, 2022
References Cited (126)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 9807092B1 · Gutzmann · 2017 [cited by examiner]
US 10043006B2 · Puri et al. · 2018 [cited by applicant]
US 10237287B1 · Amidon · 2019 [cited by examiner]
US 10268821B2 · Stockdale et al. · 2019 [cited by applicant]
US 10419466B2 · Ferguson et al. · 2019 [cited by applicant]
US 10701093B2 · Dean et al. · 2020 [cited by applicant]
US 11057409B1 · Bisht · 2021 [cited by examiner]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040054925A1 · Etheridge · 2004 [cited by examiner]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100071054A1 · Hart · 2010 [cited by examiner]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120210434A1 · Curtis · 2012 [cited by examiner]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140283064A1 · Fraize · 2014 [cited by examiner]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160094427A1 · Talat · 2016 [cited by examiner]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160261621A1 · Srivastava et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170118236A1 · Devi Reddy · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170262633A1 · Miserendino et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20170279775A1 · Savolainen · 2017 [cited by examiner]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180052993A1 · Jou et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180234435A1 · Cohen et al. · 2018 [cited by applicant]
US 20180324207A1 · Reybok, Jr. et al. · 2018 [cited by applicant]
US 20180359264A1 · Sweet · 2018 [cited by examiner]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190124099A1 · Matselyukh · 2019 [cited by examiner]
US 20190260783A1 · Humphrey et al. · 2019 [cited by applicant]
US 20200244673A1 · Stockdale et al. · 2020 [cited by applicant]
US 20200358792A1 · Bazalgette · 2020 [cited by examiner]
US 20210127395A1 · Zhang et al. · 2021 [cited by applicant]
US 20220394058A1 · Meunier · 2022 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
The United States Patent Office, Non-Final Office Action, May 20, 2021, 27 pages. [cited by applicant]
The United States Patent Office, Non-Final Office Action, Sep. 22, 2022, 17 pages. [cited by applicant]
The United States Patent Office, Final Office Action, Mar. 18, 2022, 19 pages. [cited by applicant]
Li Zhou, et al: “Operational Security Log Analytics for Enterprise Breach detection”, 2016 IEEE Cybersecurity Development (Serdev) IEE, Nov. 3, 2016, p. 15-22. [cited by applicant]
European Patent Office, “European search Report,” 10 pages, Jul. 10, 2019. [cited by applicant]