IP Library Granted Patent US 12,189,768
Granted Patent B2
US 12,189,768 · App. 18/414,373 · Granted Jan 7, 2025

Cross-network security evaluation

Inventors: Christopher Ahlberg (Watertown, MA); Bill Ladd (Watertown, MA); Sanil Chohan (Somerville, MA); Adrian Mata (Medford, MA); Michael Tran (Cambridge, MA)
Assignee: Recorded Future, Inc.
G06F21/56G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,768
App. No.
18/414,373
Granted
Jan 7, 2025
Kind
B2
Abstract

A computer security monitoring system and method are disclosed that feature, in one general aspect, monitoring on an ongoing basis for evidence of the presence of infected systems in one or more networks that are each associated with a monitored organizational entity possessing digital assets, continuously updating risk profiles for the entities based on information about intrusion features from the monitoring, aggregating risk scores for the entities, and electronically reporting the aggregated risk score to an end user. In another general aspect, a method is disclosed that includes acquiring and storing data relating to interactions with malware controllers over a public network, acquiring and storing a map of relationships between networks connected to the public network, extracting risk data from the stored interaction data and the stored relationship map by cross-referencing the acquired interaction data against the map of relationships, and issuing security alerts based the extracted risk data.

Claims (28)

1. A computer security monitoring method, including:

monitoring on an ongoing basis for evidence of the presence of infected systems in one or more third-party organizational networks that are each associated with a different third-party monitored organizational entity possessing digital assets, by externally observing network communication information about the third-party organizational networks,

providing an ontology that associates different subsets of the observed communication information to each of a plurality of third-party organizational entities possessing digital assets,

continuously updating machine-readable risk profiles for the third-party monitored organizational entities based on the information from the monitoring,

aggregating machine-readable risk scores for the third-party monitored organizational entities, wherein the aggregating the risk scores aggregates the risk scores for each of the third-party monitored organizational entities based on the associations in the ontology to derive an aggregated risk score,

electronically reporting the aggregated risk scores to an end user, wherein the electronically reporting the aggregated risk score to an end user reports a score that is based on evidence of the presence of infected systems and other risks, and wherein the electronically reporting the aggregated risk score provides a user interface and wherein the user interface is responsive to user actuation that allows the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

2. The method of claim 1 wherein the electronically reporting includes automatically issuing alerts to one or more related ones of a first of the monitored networks upon detection of an intrusion feature in traffic with the first of the monitored networks.

3. The method of claim 2 wherein the monitoring for intrusion features includes monitoring communications with one or more known or suspected malware controller machines.

4. The method of claim 1 wherein the aggregating risk scores includes combining information about intrusion features with information about other risks for the first of the networks.

5. The method of claim 1 further including responding to user requests to explore ontological relationships that led to the aggregated organizational risk score.

6. The method of claim 1 further including determining whether the aggregated organizational risk score meets a predetermined criteria, and wherein the electronically reporting includes electronically issuing an alert in response to the meeting of the predetermined criteria.

7. The method of claim 1 wherein the electronically reporting includes issuing a report that includes the aggregated organizational entity risk score.

8. The method of claim 7 wherein the issuing a report includes issuing a report that further includes a plurality of visual elements that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score.

9. The method of claim 7 wherein the issuing a report includes issuing an interactive report that includes a plurality of controls that allow the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

10. The method of claim 7 wherein the issuing a report includes issuing an interactive report that includes a plurality of visual elements that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score, and wherein the visual elements are responsive to user actuation to allow the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

11. The method of claim 10 wherein the presenting visual elements presents the visual elements as a series of textual links that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score, and wherein the links can be actuated to further explore the ontological relationships that lead to the aggregated organizational entity risk score.

12. The method of claim 1 further including continuously updating the ontological relationships using an ongoing ontology maintenance process.

13. The method of claim 1 wherein the ontological relationships include relationships between different organizational entities.

14. The method of claim 13 wherein the ontological relationships include relationships between organizational entities and their subsidiaries and contractors.

15. The method of claim 1 wherein the ontological relationships include relationships between organizational entities and network identifiers.

16. The method of claim 1 wherein the ontological relationships include relationships between organizational entities and types of technology.

17. The method of claim 1 wherein the ontological relationships can be expressed as a directed acyclic graph.

18. A computer security monitoring system, including:

a network traffic monitoring interface operative to detect on an ongoing basis evidence of the presence of infected systems in one or more third-party organizational networks that are each associated with a different third-party monitored organizational entity possessing digital assets, by externally observing network communication information about the third-party organizational networks,

memory operative to store an ontology that associates different subsets of the observed communication information to each of a plurality of third-party organizational entities possessing digital assets,

risk profile generation logic responsive to the traffic monitoring interface and operative to continuously update machine-readable risk profiles for the third-party monitored organizational entities based on the information from the monitoring interface,

aggregation logic operative to aggregate machine-readable risk scores for the scored entities for each of the third-party monitored organizational entities, wherein the aggregation logic is operative to aggregate the risk scores for each of the third-party monitored organizational entities based on the associations in the ontology to derive an aggregated risk score, and

a reporting interface operative to electronically report the aggregated risk scores to an end user, wherein the reporting interface is operative to report a score to an end user that is based on evidence of the presence of infected systems and other risks, wherein the reporting interface provides a user interface, and wherein the user interface is responsive to user actuation that allows the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2024
From: ALTER DOMUS (US) LLC
To: RECORDED FUTURE, INC; SECURITYTRAILS, LLC
Reel/Frame 069665/0398 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2024
From: AHLBERG, CHRISTOPHER; LADD, BILL; CHOHAN, SANIL; MATA, ADRIAN TIRADOS; TRAN, MICHAEL; TRUVÉ, STAFFAN
To: RECORDED FUTURE, INC.
Reel/Frame 069416/0393 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 28, 2024
From: RECORDED FUTURE, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 067964/0413 →
Continuity (4)
Continuation 18087686 · Dec 22, 2022
Division 16823282 · Mar 18, 2020
Provisional Application 62819906 · Mar 18, 2019
Related Publication 20240346138A1 · Oct 17, 2024
References Cited (6)
US 8429748B2 · Suit · 2013 [cited by examiner]
US 9166999B1 · Kulkarni · 2015 [cited by examiner]
US 10230767B2 · Singaraju · 2019 [cited by examiner]
US 20160226905A1 · Baikalov · 2016 [cited by examiner]
US 20180004948A1 · Martin · 2018 [cited by examiner]
US 20190188616A1 · Urban · 2019 [cited by examiner]