IP Library Patent Application 18621695
Patent Application
App. No. 18/621,695

GLOBAL BLOCKLIST CURATION BASED ON CROWDSOURCED INDICATORS OF COMPROMISE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/621,695
Abstract

Systems and methods are described herein for global blocklist curation based on crowdsourced indicators of compromise (IoC). One or more servers store the messages reported as suspicious into a message collection system. The server(s) classify he messages as one of clean, spam or threat. The server(s)) tag the messages responsive to the classification and determine a plurality of IoC from the messages classified and tagged as a threat. The server(s) determine one or more metrics for each of the plurality of IoC and selected, based at least on the one or more metrics, one or more of the plurality of IoC as blocklist entry (BLE) candidates.

Claims (31)

1 . A method comprising:

receiving, by one or more servers, messages that have been reported by users of one or more organizations, the one or more servers storing the messages into a message collection system;

classifying, by the one or more servers, the messages as one of clean, spam or threat, the one or more servers tagging the messages responsive to the classification;

determining, by the one or more servers, a plurality of indicators of compromise from the messages classified and tagged as threat;

determining, by the one or more servers, one or more metrics for each of the plurality of indicators of compromise;

selecting, by the one or more servers based at least on the one or more metrics, one or more of the plurality of indicators of compromise as blocklist entry (BLE) candidates.

2 . The method of claim 1 , further comprising providing, by the one or more servers, the BLE candidates to a system administrator of an organization for selection to be included in a private blocklist.

3 . The method of claim 1 , further comprising removing, by the one or more servers, from the messages classified as a threat, messages with a timestamp of receipt in a reporting user's mailbox before a predetermined time period before the classification.

4 . The method of claim 1 , further comprising excluding, by the one or more servers, from the plurality of indicators of compromise any indicators of compromise on a BLE exclusion list.

5 . The method of claim 1 , further comprising determining, by the one or more servers, one or more metrics comprising a severity metric representing an extent of harm to an organization a message having an indicator of compromise can cause.

6 . The method of claim 1 , further comprising determining, by the one or more servers, one or more metrics comprising a breadth metric comprising a proportion of a number of organizations in which an indicator of comprise is included in the plurality of indicators of compromise from classified messages for a time period.

7 . The method of claim 1 , further comprising determining, by the one or more servers, one or more metrics comprising a prevalence metric comprising a count of a number of times an indicator of comprise is included in the plurality of indicators of compromise from classified messages for a time period.

8 . The method of claim 1 , further comprising excluding, by the one or more servers, as BLE candidates the plurality of indicators of compromise with one or more metrics below a threshold value for the respective metric, wherein the one or more metrics comprises a prevalence metric or a breadth metric.

9 . The method of claim 1 , further comprising determining, by an artificial intelligence model of the one or more servers, which of the BLE candidates are approved to be included in the blocklist, the artificial intelligence model being trained on previous BLE candidates.

10 . The method of claim 1 , further comprising outputting, by the one or more servers, as BLE candidates each of the selected plurality of indicators of compromise with the one or more metrics.

11 . A system comprising:

one or more servers configured to:

receive messages that have been reported by users of one or more organizations, the one or more servers storing the messages into a message collection system;

classify the messages as one of clean, spam or threat and tag the messages responsive to the classification;

determine a plurality of indicators of compromise from the messages classified and tagged as threat;

determine one or more metrics for each of the plurality of indicators of compromise;

select based at least on the one or more metrics, one or more of the plurality of indicators of compromise as blocklist entry (BLE) candidates.

12 . The system of claim 11 , wherein the one or more servers are further configured to provide the BLE candidates to a system administrator of an organization for selection to be included in a private blocklist.

13 . The system of claim 11 , wherein the one or more servers are further configured to remove from the messages classified as a threat, messages with a timestamp of receipt in a reporting user's mailbox before a predetermined time period before the classification.

14 . The system of claim 11 , wherein the one or more servers are further configured to exclude from the plurality of indicators of compromise any indicators of compromise on a BLE exclusion list.

15 . The system of claim 11 , wherein the one or more servers are further configured to determine one or more metrics comprising a severity metric representing an extent of harm to an organization a message having an indicator of compromise can cause.

16 . The system of claim 11 , wherein the one or more servers are further configured to determine one or more metrics comprising a breadth metric comprising a proportion of a number of organizations in which an indicator of compromise is included in the plurality of indicators of compromise from classified messages for a time period.

17 . The system of claim 11 , wherein the one or more servers are further configured to determine one or more metrics comprising a prevalence metric comprising a count of a number of times an indicator of comprise is included in the plurality of indicators of compromise from classified messages for a time period.

18 . The system of claim 11 , wherein the one or more servers are further configured to exclude as BLE candidates the plurality of indicators of compromise with one or more metrics below a threshold value for the respective metric, wherein the one or more metrics comprises a prevalence metric or a breadth metric.

19 . The system of claim 11 , wherein the one or more servers are further configured to determine via an artificial intelligence model, which of the BLE candidates are approved to be included in the blocklist, the artificial intelligence model being trained on previous BLE candidates.

20 . The system of claim 11 , wherein the one or more servers are further configured to output as BLE candidates each of the selected plurality of indicators of compromise with the one or more metrics.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2024
From: BODKE, ANAND DINKAR; PATTON, MARK WILLIAM; HOWES, ERIC; PERRY, STEFFAN
To: KNOWBE4, INC
Reel/Frame 066960/0240 →