Active extension of a threat intelligence sharing service
A cyber security appliance and computerized method for detecting and disabling malicious endpoints is described. Upon receiving information associated with one or more endpoints including a first endpoint, the cyber security appliance determines, based on conducting analytics on a portion of the information by a cyber security appliance, whether the first endpoint constitutes a malicious endpoint. In response to detecting the malicious endpoint, the cyber security appliance requests authorization to launch an offensive countermeasure against the malicious endpoint and, upon receiving the authorization, conducts the offensive countermeasure against the malicious endpoint by at least continuously disrupting or disabling communications over a network utilized by the malicious endpoint.
1 . A cyber security appliance for detecting and disabling malicious endpoints, comprising:
one or more input/output (I/O) ports to receive information associated with one or more endpoints including a first endpoint; and
a non-transitory memory storage device including software executable by one or more processors, the software comprises an artificial intelligence-based (AI-based) detect component and an inoculation module
wherein the AI-based detect component configured to receive the information and determine, based on a portion of the information, whether the first endpoint constitutes a malicious endpoint by being responsible for or associated with a cyber threat against an enterprise protected by the cyber security appliance, and
wherein the inoculation module in communication with the AI-based detect component, the inoculation module includes an inoculation extension, wherein the inoculation extension includes (1) a nomination module configured to request authorization to launch an offensive countermeasure against the malicious endpoint, (2) a disablement module to conduct the offensive countermeasure against the malicious endpoint to disable network communications by the malicious endpoint upon receiving the authorization, and (3) a confirmation module operating with a fingerprint module to generate a fingerprint in which content of the fingerprint is used to verify the malicious endpoint,
wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint, and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences.
2 . The cyber security appliance of claim 1 , wherein the disablement module of the inoculation module is configured to disable network communications for the malicious endpoint by at least disabling or continuously disrupting network connection availability by the malicious endpoint.
3 . The cyber security appliance of claim 2 , wherein the inoculation module is disabling or continuously disrupting network connection availability by the malicious endpoint by at least conducting a Denial-of-Service (DoS) attack by establishing communication sessions with the malicious endpoint and continuing to maintain the communication sessions in an attempt to exhaust all available sockets used by the malicious endpoint for network communications.
4 . The cyber security appliance of claim 3 , wherein the disablement module of the inoculation module includes a master component and a plurality of slave components, the master component is a software instance configured to receive and distribute network addressing information associate with the malicious endpoint to the plurality of slave components and each of the plurality of slave components is a software instance configured to establish a communication session of the communication sessions with a socket of the available sockets associated with the malicious endpoint.
5 . The cyber security appliance of claim 4 , wherein each slave component of the plurality of slave components is configured to maintain its communication session with the malicious endpoint through low-throughput data exchange with a maximum throughput of less than 500 kilobytes per second (kbps).
6 . The cyber security appliance of claim 4 , wherein each slave component of the plurality of slave components is configured to establish a communication session with the malicious endpoint via an anonymity server.
7 . The cyber security appliance of claim 1 , wherein the content of the fingerprint is used to verify the malicious endpoint operating as a malicious server as well as other servers related to the malicious server.
8 . The cyber security appliance of claim 1 , wherein the offensive countermeasure is an attempt to disable operability of a malicious server utilized to provide communications for a malicious endpoint used by a malicious actor, where the offensive countermeasure is a Denial-of-Service (DoS) attack on the malicious server by exhausting its available sockets.
9 . The cyber security appliance of claim 1 , wherein the fingerprint is delivered to other cyber security appliances associated with different domains to assist in disabling the malicious endpoint.
10 . The cyber security appliance of claim 1 , wherein the AI-based detect component comprises a cyber threat analyst module that operates in cooperation with AI models and AI classifiers to analyze the portion of the information associated with the first endpoint to determine that the first endpoint constitutes a malicious endpoint in response to detection of behaviors of the first endpoint that correlate with characteristics of a cyber threat recognized by at least one of the AI models.
11 . A non-transitory storage medium configured to store instructions that are configured, when executed, to detect and disable malicious endpoints, comprising:
an artificial intelligence-based (AI-based) detect component configured, when executed, to determine a cyber threat based on information sourced by a first endpoint and classify the first endpoint as a malicious endpoint; and
an inoculation module in communication with the AI-based detect component, the inoculation module includes an inoculation extension, wherein the inoculation extension includes (1) a nomination module configured to request authorization to launch an offensive countermeasure against the malicious endpoint, (2) a disablement module to coordinate the offensive countermeasure against the malicious endpoint to disable or continuously disrupt network connection availability for the malicious endpoint upon receiving the authorization, and (3) a confirmation module operating with a fingerprint module to generate a fingerprint in which content of the fingerprint is used to verify the malicious endpoint,
wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences.
12 . The non-transitory storage medium of claim 11 , wherein the disablement module of the inoculation module is configured to disable or continuously disrupt network connection availability by the malicious endpoint by conduct a Denial-of-Service (DoS) attack by establishing communication sessions with the malicious endpoint and continuing to maintain the communication sessions in an attempt to exhaust all available sockets used by the malicious endpoint for network communications.
13 . The non-transitory storage medium of claim 12 , wherein the disablement module of the inoculation module includes a master component and a plurality of slave components, the master component is a software instance configured to receive and distribute network addressing information associate with the malicious endpoint to the plurality of slave components and each of the plurality of slave components is a software instance configured to establish a communication session of the communication sessions with a socket of the available sockets associated with the malicious endpoint.
14 . The non-transitory storage medium of claim 13 , wherein each slave component of the plurality of slave components is configured to maintain its communication session with the malicious endpoint through low-throughput data exchange with a maximum throughput of less than 500 kilobytes per second (kbps).
15 . The non-transitory storage medium of claim 13 , wherein each slave component of the plurality of slave components is configured to establish a communication session with the malicious endpoint via an anonymity server.
16 . The non-transitory storage medium of claim 11 , wherein the AI-based detect component is configured to perform a plurality of levels of investigations on the information to determine the cyberthreat in which a first level of investigation is adapted to detect overt cyber threats over a first period of time and a second level of investigation is adapted to detect advanced persistent cyber threats through analysis of low-level anomalies over a second period of time greater than the first period of time.
17 . The non-transitory storage medium of claim 11 , wherein the fingerprint is delivered to other cyber security appliances associated with different domains to assist in disabling the malicious endpoint.
18 . The non-transitory storage medium of claim 11 , wherein the AI-based detect component comprises a cyber threat analyst module that operates in cooperation with AI models and AI classifiers to analyze a portion of the information associated with the first endpoint to determine that the first endpoint operates as a malicious endpoint in response to detection of behaviors of the first endpoint that correlate with characteristics of a cyber threat recognized by at least one of the AI modules.
19 . A computerized method for detecting and disabling malicious endpoints, comprising:
receiving information associated with one or more endpoints including a first endpoint;
determining, based on conducting analytics on a portion of the information by a cyber security appliance, whether the first endpoint constitutes a malicious endpoint by at least generating at least a fingerprint in which content of the fingerprint is used to verify the malicious endpoint, wherein the fingerprint is based on a hash result performed on at least (i) configuration parameters of the malicious endpoint and one or more of (ii) data obtained from full port scan of the malicious endpoint and (iii) infrequent or rare byte sequences; and
responsive to detecting the malicious endpoint,
request authorization to launch an offensive countermeasure against the malicious endpoint, and
conducting the offensive countermeasure against the malicious endpoint by at least continuously disrupting or disabling communications over a network utilized by the malicious endpoint upon receiving the authorization.