IP Library Granted Patent US 12,483,600
Granted Patent B2
US 12,483,600 · App. 18/742,372 · Granted Nov 25, 2025

System and method for utilization of threat data for network security

Inventors: David Dubois (Erie, CO); Michael Benjamin (Broomfield, CO); Mark Dehus (Thornton, CO); Peter Brecl (Highlands Ranch, CO)
Assignee: Level 3 Communications, LLC
H04L63/20G08B21/18H04L63/0263H04L63/102H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,600
App. No.
18/742,372
Granted
Nov 25, 2025
Kind
B2
Abstract

Aspects of the present disclosure involve utilizing network threat information to manage one or more security devices or policies of a communication network. The security system may receive threat intelligence data or information associated with potential threats to a communications network and process the threat intelligence data to determine one or more configurations to apply to security devices of a network. The system may then generate a rule or action to respond to the identified attack, such as a firewall rule for a firewall device to block traffic from the source of the attack. The threat intelligence information may include a confidence score indicating a calculated confidence in the identification of the malicious communications, which may be utilized by the system to determine the type of action taken on the security devices of the network in response to the information or data.

Claims (41)

1 . A method for providing security services from a telecommunications network, the method comprising:

generating, at a computing device, a security infrastructure profile comprising a first network security device of a first network and a second network security device of a second network;

receiving, at the computing device, threat intelligence data comprising identification of a source computing device associated with a network threat and a risk score associated with communications originating from the source computing device;

transmitting, based on a comparison of the risk score of the threat intelligence data to a risk threshold value of a security trigger, information to configure the first network security device of the first network and the second network security device of the second network to apply a security policy to communications originating from the source computing device associated with the network threat;

providing, via a user interface, an interactive alert associated with the comparison of the risk score of the data to the risk threshold value of the security trigger; and

receiving, via the user interface and through the interactive alert, an authorization to transmit the information to configure the first network security device of the first network and the second network security device of the second network.

2 . The method of claim 1 , further comprising:

identifying a first plurality of network security devices of the first network and a second plurality of network security devices of the second network for inclusion in a security sub-system of security infrastructure profile; and

configuring the security sub-system based on the threat intelligence data.

3 . The method of claim 2 wherein the identifying of the first plurality of network security devices and the second plurality of network security devices in the security sub-system is based on a geographic location of the first plurality of network security devices and the second plurality of network security devices.

4 . The method of claim 2 wherein the identifying of the first plurality of network security devices and the second plurality of network security devices in the security sub-system is based on a type of network security device of the first plurality of network security devices and the second plurality of network security devices.

5 . The method of claim 2 wherein the security trigger is associated with the security sub-system of the security infrastructure profile.

6 . The method of claim 4 wherein altering the configuration of the first network security device is based a source identification associated with the first event matching the identification of the source computing device associated with the network threat.

7 . A network device comprising:

a processing device;

a communication port receiving threat intelligence data comprising identification of a source computing device associated with a threat to a network and a risk score associated with communications originating from the source computing device; and

a non-transitory computer-readable medium encoded with instructions, when executed by the processing device, cause the processing device to perform the operations of:

generating a security infrastructure profile comprising a first network security device of a first network and a second network security device of a second network;

transmitting, based on a comparison of the risk score of the threat intelligence data to a risk threshold value of a security trigger of a security policy for the first network security device, information to configure the first network security device of the first network and the second network security device of the second network to apply a security action on communications originating from the source computing device associated with the threat to the network;

transmitting, via the communication port, an interactive alert associated with the comparison of the risk score of the data to the risk threshold value of the security trigger; and

receiving, through the interactive alert, an authorization to transmit the information to configure the first network security device of the first network and the second network security device of the second network.

8 . The network device of claim 7 wherein the instructions further cause the processing device to perform the operations of:

identifying a first plurality of network security devices of the first network and a second plurality of network security devices of the second network for inclusion in a security sub-system of security infrastructure profile; and

configuring the security sub-system based on the threat intelligence data.

9 . The network device of claim 8 wherein the identifying of the first plurality of network security devices and the second plurality of network security devices in the security sub-system is based on a geographic location of the first plurality of network security devices and the second plurality of network security devices.

10 . The network device of claim 8 wherein the identifying of the first plurality of network security devices and the second plurality of network security devices in the security sub-system is based on a type of network security device of the first plurality of network security devices and the second plurality of network security devices.

11 . The network device of claim 8 wherein the security trigger is associated with the security sub-system of the security infrastructure profile.

12 . A network security system comprising:

a first plurality of network security devices of the first network and a second plurality of network security devices of the second network; and

a network security management device in communication with the first plurality of network security devices of the first network and a second plurality of network security devices of the second network, the network security management device comprising:

a processing device; and

a non-transitory computer-readable medium encoded with instructions, when executed by the processing device, cause the processing device to perform the operations of:

associating a security policy with a security infrastructure profile comprising the first plurality of network security devices of the first network and a second plurality of network security devices of the second network, the security policy comprising a security trigger parameter;

receiving threat intelligence data comprising identification of a source computing device associated with a network threat and a risk score associated with communications originating from the source computing device;

transmitting, based on a comparison of the risk score of the threat intelligence data to a risk threshold value of the security trigger parameter, information to configure at least a first network security device of the first network to apply a security action on communications originating from the source computing device associated with the threat to the network;

transmitting an interactive alert associated with the comparison of the risk score of the data to the risk threshold value of the security trigger; and

receiving, through the interactive alert, an authorization to transmit the information to configure the first network security device of the first network and the second network security device of the second network.

13 . The network system of claim 12 wherein the instructions further cause the processing device to perform the operations of:

identifying a security sub-system of security infrastructure profile, the security sub-system comprising a subset of the first plurality of network security devices and a subset of the second plurality of network security devices.

14 . The network system of claim 13 wherein the identifying of the subset of the first plurality of network security devices and the subset of the second plurality of network security devices in the security sub-system is based on a geographic location of the subset of the first plurality of network security devices and the subset of the second plurality of network security devices.

15 . The network system of claim 13 wherein the identifying of the subset of the first plurality of network security devices and the subset of the second plurality of network security devices in the security sub-system is based on a type of network security device of the first plurality of network security devices and the second plurality of network security devices.

Assignments (4)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: BENJAMIN, MICHAEL; DUBOIS, DAVID; DEHUS, MARK
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 067732/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: BRECL, PETER
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 067732/0741 →