IP Library Granted Patent US 12,225,045
Granted Patent B2
US 12,225,045 · App. 18/213,123 · Granted Feb 11, 2025

Incorporating software-as-a-service data into a cyber threat defense system

Inventors: Jacob Araiza (Monmouth, GB); Andrew Woodford (Cheltenham, GB); David Palmer (Cheltenham, GB)
Assignee: Darktrace Holdings Limited
H04L63/1441G06F3/04842G06F3/0486G06F16/2455G06F18/23G06F18/232G06F21/36G06F21/554G06F21/556G06F40/40G06N20/00G06N20/10H04L41/22H04L43/045H04L51/212H04L51/224H04L51/42H04L63/0209H04L63/0428H04L63/101H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1483H04L63/20G06N20/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,045
App. No.
18/213,123
Granted
Feb 11, 2025
Kind
B2
Abstract

A cyber threat defense system can incorporate data from a Software-as-a-Service (SaaS) application hosted by a third-party operator platform to identify cyber threats related to that SaaS application. The cyber threat defense module can have a SaaS module to collect third-party event data from the third-party operator platform. The cyber threat defense system can have a comparison module to compare third-party event data for a network entity to at least one machine-learning model of a network entity using a normal behavior benchmark to spot behavior deviating from normal benign behavior. The comparison module can identify whether the network entity is in a breach state. The cyber threat defense system can have a cyber threat module to identify whether the breach state and a chain of relevant behavioral parameters correspond to a cyber threat. An autonomous response module can execute an autonomous response in response to the cyber threat.

Claims (46)

1. A method for a cyber threat defense system incorporating data from a Software-as-a-Service (SaaS) application hosted by a third-party operator platform to identify cyber threats related to the SaaS application, comprising:

collecting, with a SaaS module from one or more connectors deployed to a network entity representing at least one of a user and a network device that utilizes the SaaS application, third-party event data describing an administrative event of the SaaS application hosted by the third-party operator platform;

comparing the third-party event data, received from the one or more connectors, to one or more machine-learning models trained on a normal benign behavior of that network entity using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity for that network entity to spot behavior on the network deviating from the normal benign behavior;

identifying whether the network entity that utilized the SaaS application is in a breach state of the normal behavior benchmark;

causing the SaaS module to cooperate with i) the one or more connectors to supply the event data describing the administrative event once it is observed from the SaaS application hosted by the third-party operator platform; ii) the third-party operator platform hosting the SaaS application to keep a connection open until an event is observed and the event data describing the administrative event is returned to the SaaS module, and iii) any combination of these two; and

executing an autonomous response in response to the cyber threat using an autonomous response module to mitigate the identified cyber threat.

2. The method for the cyber threat defense system of claim 1 , further comprising:

directing the one or more connectors to send a Hypertext Transfer Protocol Secure event request to the third-party SaaS application to request the administrative event from an audit log of the third-party SaaS application.

3. The method for the cyber threat defense system of claim 1 , further comprising:

identifying whether the breach state and a chain of relevant behavioral parameters deviating from the normal benign behavior of that network entity correspond to a cyber threat.

4. The method for the cyber threat defense system of claim 1 , further comprising:

using the autonomous response module to tag a specific user to have a lower threshold for the autonomous response, depending on circumstances of the cyber threat.

5. The method for the cyber threat defense system of claim 1 , further comprising: using the autonomous response module to tag a specific user so that no more SaaS activities successfully occurs for that specific user until a human has verified that unusual behavior that deviated from the normal benign behavior is allowed or blocked indefinitely.

6. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a cyber threat defense system to instruct a computing device to perform a method for a cyber threat defense system incorporating data from a Software-as-a-Service (SaaS) application hosted by a third-party operator platform to identify cyber threats related to that SaaS application, comprising:

collecting, with a SaaS module from one or more connectors deployed to a network entity representing at least one of a user and a network device that utilizes the SaaS application, third-party event data describing an administrative event of the SaaS application hosted by the third-party operator platform;

comparing the third-party event data, received from the one or more connectors, to one or more machine-learning models trained on a normal benign behavior of that network entity using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity for that network entity to spot behavior on the network deviating from the normal benign behavior;

identifying whether the network entity that utilized the SaaS application is in a breach state of the normal behavior benchmark;

causing the SaaS module to cooperate with i) the one or more connectors to supply the event data describing the administrative event once it is observed from the SaaS application hosted by the third-party operator platform; ii) the third-party operator platform hosting the SaaS application to keep a connection open until an event is observed and the event data describing the administrative event is returned to the SaaS module, and iii) any combination of these two; and

executing an autonomous response in response to the cyber threat using an autonomous response module to mitigate the identified cyber threat.

7. The method for the cyber threat defense system of claim 6 , further comprising:

where the executing of the autonomous response module to take the autonomous response to the cyber threat includes one or more of

executing at least one of alerting an internal system administrator of the cyber threat and a suggested action to counter the cyber threat, alerting the third-party operator platform of the cyber threat and a suggested action to counter the cyber threat, autonomously reducing permissions of the network entity in the breach state of the normal behavior benchmark, and autonomously disabling a user account of the network entity in the breach state of the normal behavior benchmark, based on a threat risk parameter corresponding to aspects of the cyber threat.

8. The method for the cyber threat defense system of claim 6 , further comprising:

harvesting metadata from a data rich description and then using the metadata in the comparison of the normal behavior benchmark describing parameters corresponding to the normal pattern of activity for that network entity to spot behavior on a network deviating from the normal benign behavior; and

directing the one or more connectors to request the third-party operator platform to delete an event report.

9. The method for the cyber threat defense system of claim 6 , further comprising:

collecting network traffic in addition to the collected data from the SaaS application used by the network entity in order to analyze both to contextualize and understand the breach state and a chain of relevant behavioral parameters deviating from the normal benign behavior of that network entity in order to accurately correspond to the breach state and the chain of relevant behavioral parameters to the cyber threat.

10. The method for the cyber threat defense system of claim 6 , further comprising:

collecting, from one or more probes deployed to the network entity, probe data describing network-administrated activity, external to the SaaS application, by the network entity to analyze the probe data and the third-party event data in context to accurately associate the breach state and a chain of relevant behavioral parameters with the cyber threat.

11. An apparatus for a cyber threat defense system, comprising:

one or more input ports configured to connect to one or more connectors deployed to a network entity representing at least one of a user and a network device that utilizes a software-as-a-service (SaaS) application hosted by a third-party operator platform;

a SaaS module configured to collect from the one or more connectors deployed to the network entity that utilizes the SaaS application, third-party event data describing an administrative event of the SaaS application;

a comparison module configured to execute a comparison the third-party event data, received from the one or more connectors, to one or more machine-learning models trained on a normal benign behavior of that network entity using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity for that network entity to spot behavior on the network deviating from the normal benign behavior;

a cyber threat module configured to identify whether the network entity that utilized the SaaS application is in a breach state of the normal behavior benchmark provided by the one or more machine-learning models trained on the normal benign behavior in order to identify a cyber threat;

where the SaaS module is further configured to cooperate with i) the one or more connectors to supply the event data describing the administrative event once it is observed from the SaaS application hosted by the third-party operator platform; ii) the third-party operator platform hosting the SaaS application to keep a connection open until an event is observed and the event data describing the administrative event is returned to the SaaS module, and iii) any combination of these two;

an autonomous response module configured to execute at least one autonomous response in response to the identified cyber threat to mitigate the identified cyber threat; and

one or more processors communicatively coupled to one or more memories to execute software instructions associated with the SaaS module, the comparison module, the cyber threat module, and the autonomous response module.

12. The apparatus for the cyber threat defense system of claim 11 , wherein the SaaS module is configured to harvest metadata of the administrative event.

13. The apparatus for the cyber threat defense system of claim 11 , wherein the SaaS module is configured to anonymize metadata to remove any personally identifiable information for a third-party operator and the network entity from the metadata.

14. The apparatus for the cyber threat defense system of claim 11 , wherein the cyber threat module is further configured to identify whether the breach state identified by the comparison module and a chain of relevant behavioral parameters deviating from the normal benign behavior of that network entity corresponds to the cyber threat.

15. The apparatus for the cyber threat defense system of claim 11 , wherein the SaaS connector is configured to direct the one or more connectors to request that event data describing the administrative event to be sent as a push notification upon an occurrence of the event.

16. The apparatus for the cyber threat defense system of claim 11 , wherein the SaaS module is configured to receive the third-party event data describing an administrative event from the one or more connectors as a push notification, and then place the push notification received from the one or more connectors in a quarantine to scan for a deviant characteristic prior to analysis.

17. The apparatus for the cyber threat defense system of claim 11 , wherein the cyber threat module is configured to identify at least one of a login, a failed login, a resource creation, a resource view, a resource modification, a resource deletion, a file upload, a file download, a resource share, and an administrative action in the third-party event data.

18. The apparatus for the cyber threat defense system of claim 11 , wherein the autonomous response module is configured to at least one 1) reduce permissions of the network entity and 2) disable a user account of the network entity in response to the cyber threat.

19. The apparatus for the cyber threat defense system of claim 11 , wherein the one or more connectors interact with the SaaS application by at least one of an application programming interface interaction, a logging access tool, a Hypertext Transfer Protocol Secure protocol request, and any combination of these, and then feed information about user behavior back to the SaaS module, the comparison module, the cyber threat module, and the autonomous response module.

20. The apparatus for the cyber threat defense system of claim 11 , wherein the cyber threat defense system is configured to leverage containing the cyber threat to minimize an amount of processing unit cycles, memory space, and power consumed by the cyber threat in the network protected by the cyber threat defense system.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (3)
Continuation 16278991 · Feb 19, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20240064168A1 · Feb 22, 2024
References Cited (117)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey et al. · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9367877B1 · Gallaway et al. · 2016 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9679125B2 · Bailor et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10686792B1 · Keefer et al. · 2020 [cited by applicant]
US 11075917B2 · Dani et al. · 2021 [cited by applicant]
US 11496519B1 · Gupta · 2022 [cited by examiner]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130212680A1 · Winn · 2013 [cited by examiner]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160308895A1 · Kotler · 2016 [cited by examiner]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160364163A1 · Kamble · 2016 [cited by examiner]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170163666A1 · Venkatramani et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20170295181A1 · Parimi · 2017 [cited by examiner]
US 20170339174A1 · Mounaguruswamy · 2017 [cited by examiner]
US 20180018204A1 · Zhang et al. · 2018 [cited by applicant]
US 20180019932A1 · Giura · 2018 [cited by examiner]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180260843A1 · Hiranandani et al. · 2018 [cited by applicant]
US 20190036788A1 · Gupta et al. · 2019 [cited by applicant]
US 20190089809A1 · Theebaprakasam · 2019 [cited by examiner]
US 20210344707A1 · Ackerman · 2021 [cited by examiner]
CN 108055256A · 2018 [cited by applicant]
EP 2922268A1 · 2015 [cited by applicant]
EP 3262815B1 · 2019 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Singh et al “Hybrid Two-Tier Framework for Improved Security in Cloud Environment”, IEEE, 2016 3rd International Conference on Computing for Sustainable Global Development (INDIACom), Mar. 16-18, 2016) (Year: 2016). [cited by examiner]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Dec. 24, 2021, 41 pages, US. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Oct. 21, 2022, 30pages, US. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, Jun. 9, 2022, 31pages, US. [cited by applicant]