IP Library › Granted Patent US 12,592,938
Granted Patent B2
US 12,592,938 · App. 18/769,267 · Granted Mar 31, 2026

Security integration for cloud services

Inventors: Biju Balakrishnan Nair (Bangalore, IN); Brian Steven Vysocky, Jr. (Hudson, NH)
Assignee: Sophos Limited
H04L63/1408G06F21/53G06F21/567H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,938
App. No.
18/769,267
Filed
Jul 10, 2024
Granted
Mar 31, 2026
Kind
B2
Art Unit
2498
USPC
726/25
Abstract

A threat management facility for an enterprise network integrates native threat management capabilities with threat data from a cloud service provider used by the enterprise. By properly authenticating to the cloud service and mapping data feeds from the cloud service to a native threat management environment, the threat management facility can extend threat detection and management capabilities beyond endpoint-centric techniques.

Claims (50)

1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

receiving, at a threat management facility, a first event stream of local threat data from a plurality of local security agents executing on a plurality of compute instances associated with an enterprise network;

storing the first event stream in a data lake according to a threat schema for the threat management facility;

authenticating the threat management facility to a cloud service provider that provides cloud computing facilities to users of the plurality of compute instances associated with the enterprise network;

receiving security data for the plurality of compute instances from the cloud service provider;

mapping the security data from the cloud service provider into a second event stream for the enterprise network, the second event stream conforming to the threat schema for the threat management facility used to store the first event stream of local threat data from the plurality of local security agents executing on the plurality of compute instances;

storing the second event stream in the data lake;

calculating a threat score for one of the plurality of compute instances based on data from the first event stream and the second event stream stored in the data lake; and

initiating a remediation of the one of the plurality of compute instances when the threat score meets a predetermined criterion; and

displaying the threat score in a user interface.

2 . The computer program product of claim 1 , wherein mapping the security data includes converting a data blob in the security data from the cloud service provider into a plurality of risk items in the threat schema.

3 . The computer program product of claim 1 , wherein the cloud service provider includes a cloud computing service hosting virtual compute instances for the enterprise network.

4 . The computer program product of claim 1 , wherein the cloud service provider includes an identity provider providing identity management and authentication services for the users of the plurality of compute instances associated with the enterprise network.

5 . The computer program product of claim 1 , wherein the cloud service provider includes a third party network security service for the users of the plurality of compute instances associated with the enterprise network.

6 . The computer program product of claim 1 , wherein the cloud service provider includes an electronic mail service provider for the users of the plurality of compute instances associated with the enterprise network.

7 . The computer program product of claim 1 , wherein the cloud service provider includes an application hosting provider for the users of the plurality of compute instances associated with the enterprise network.

8 . A method comprising:

receiving a first event stream of events based on local threat data from a plurality of compute instances in an enterprise network;

storing the first event stream in a data lake according to a threat schema;

authenticating to a cloud service provider for the plurality of compute instances in the enterprise network;

receiving security data for the plurality of compute instances from the cloud service provider;

mapping the security data from the cloud service provider into a second event stream for the enterprise network, the second event stream conforming to the threat schema used to store the first event stream based on local threat data from the plurality of compute instances;

storing the second event stream in the data lake;

calculating a threat score for one of the plurality of compute instances based on data from the first event stream and the second event stream stored in the data lake;

initiating a remediation of the one of the plurality of compute instances when the threat score meets a predetermined criterion; and

displaying the threat score in an administrative console of a threat management facility for the enterprise network.

9 . The method of claim 8 , wherein mapping the security data includes scaling one or more quantitative threat scores in the security data to a threat score range for the threat schema.

10 . The method of claim 8 , wherein mapping security data includes converting one or more threat types in the security data to a threat category for the threat schema.

11 . The method of claim 8 , wherein mapping security data includes transforming risk metadata in the security data into one or more context descriptors for the threat schema.

12 . The method of claim 8 , further comprising:

calculating a plurality of threat scores for a plurality of the compute instances based on the first event stream and the second event stream, and displaying one or more of the plurality of threat scores in the administrative console in an order ranked according to threat severity.

13 . The method of claim 8 , wherein the cloud service provider hosts one or more of an electronic mail application, a cloud storage service, a cloud computing service, a virtualization platform, and an authentication service.

14 . The method of claim 8 , further comprising augmenting the second event stream with additional security data from one or more third party security data providers.

15 . The method of claim 8 , wherein the second event stream includes contextual data for a suspected threat, the contextual data including one or more of classification information for the suspected threat, a network location associated with the suspected threat, a path for the suspected threat, a filename for the suspected threat, a process name for the suspected threat, and a machine identifier for the suspected threat.

16 . The method of claim 8 , wherein the cloud service provider hosts one or more of a web application, a zero trust network access resource, and a network monitor executing on a third-party firewall.

17 . The method of claim 8 , further comprising receiving contextual information for a suspected threat from a remote data source, the contextual information including one or more of classification information for the suspected threat, a network location associated with the suspected threat, and geolocation data for the suspected threat.

18 . A system comprising:

a plurality of compute instances associated with an enterprise network, each executing a local security agent that provides event data to a first event stream; and

a threat management facility for the enterprise network, the threat management facility implemented by at least one hardware processor and configured to:

receive the first event stream of event data from local security agents executing on the plurality of compute instances;

store the first event stream in a data lake according to a threat schema for the threat management facility;

authenticate to a cloud service provider that provides cloud computing facilities to users of the plurality of compute instances;

receive security data for the plurality of compute instances from the cloud service provider;

map the security data from the cloud service provider into a second event stream for the enterprise network, the second event stream conforming to the threat schema used by the threat management facility to store the first event stream based on local threat data from the plurality of compute instances, wherein mapping the security data includes scaling one or more quantitative threat scores in the security data to a threat score range for the threat schema, converting one or more threat types in the security data to a threat category for the threat schema, and transforming risk metadata in the security data into one or more context descriptors for the threat schema;

store the second event stream in the data lake;

calculate a composite threat score indicative of a security risk of one of the plurality of compute instances based on data from the first event stream and the second event stream stored in the data lake;

initiate a remediation of the one of the plurality of compute instances when the composite threat score meets a predetermined criterion; and

display the composite threat score in a user interface.

19 . The system of claim 18 , wherein the cloud service provider includes one or more of an application hosting platform, a communication platform, an identity management platform, and a remote security services platform.

20 . The system of claim 18 , wherein mapping the security data includes converting a data blob in the security data from the cloud service provider into a plurality of risk items in the threat schema.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2024
From: NAIR, BIJU BALAKRISHNAN; VYSOCKY, BRIAN STEVEN, JR
To: SOPHOS LIMITED
Reel/Frame 067988/0843 →
Continuity (4)
Continuation 17825120 · May 26, 2022
Continuation PCTUS2022030859 · May 25, 2022
Provisional Application 63254368 · Oct 11, 2021
Related Publication 20250039190A1 · Jan 30, 2025
References Cited (88)
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8595789B2 · Warn et al. · 2013 [cited by applicant]
US 8713633B2 · Thomas · 2014 [cited by examiner]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8769676B1 · Kashyap · 2014 [cited by examiner]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9503472B2 · Laidlaw et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9589245B2 · Coden et al. · 2017 [cited by applicant]
US 9697352B1 · Armstrong · 2017 [cited by applicant]
US 9721296B1 · Chrapko · 2017 [cited by applicant]
US 10063654B2 · Kirti et al. · 2018 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10587647B1 · Khalid et al. · 2020 [cited by applicant]
US 10902114B1 · Trost et al. · 2021 [cited by applicant]
US 10984122B2 · Thomas · 2021 [cited by examiner]
US 11089047B1 · Kaushal · 2021 [cited by examiner]
US 11552974B1 · Bagga et al. · 2023 [cited by applicant]
US 11558401B1 · Vashisht et al. · 2023 [cited by applicant]
US 11651313B1 · Fridakis · 2023 [cited by applicant]
US 11777992B1 · Cross et al. · 2023 [cited by applicant]
US 12019754B2 · Tineo · 2024 [cited by applicant]
US 20130191919A1 · Basavapatna · 2013 [cited by examiner]
US 20130347052A1 · Choudrie · 2013 [cited by examiner]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160173509A1 · Ray · 2016 [cited by examiner]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20170171231A1 · Reybok, Jr. et al. · 2017 [cited by applicant]
US 20180004948A1 · Martin et al. · 2018 [cited by applicant]
US 20180124098A1 · Carver et al. · 2018 [cited by applicant]
US 20190034641A1 · Gil et al. · 2019 [cited by applicant]
US 20190081968A1 · Wang et al. · 2019 [cited by applicant]
US 20190318109A1 · Thomas · 2019 [cited by examiner]
US 20190319945A1 · Levy · 2019 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20190373008A1 · Brandwine · 2019 [cited by examiner]
US 20200007586A1 · Seeber et al. · 2020 [cited by applicant]
US 20200074360A1 · Humphries et al. · 2020 [cited by applicant]
US 20200076835A1 · Ladnai et al. · 2020 [cited by applicant]
US 20200220885A1 · Will et al. · 2020 [cited by applicant]
US 20200302058A1 · Kenyon et al. · 2020 [cited by applicant]
US 20200327223A1 · Sanchez et al. · 2020 [cited by applicant]
US 20200329066A1 · Kirti · 2020 [cited by examiner]
US 20200356666A1 · Reybok et al. · 2020 [cited by applicant]
US 20200358807A1 · Connell · 2020 [cited by examiner]
US 20210250366A1 · Ladnai · 2021 [cited by examiner]
US 20210294901A1 · Agarwwal et al. · 2021 [cited by applicant]
US 20210377313A1 · Murphy et al. · 2021 [cited by applicant]
US 20220053011A1 · Rao et al. · 2022 [cited by applicant]
US 20220094705A1 · Tineo · 2022 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230111304A1 · Thomas et al. · 2023 [cited by applicant]
US 20230111864A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113375A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113621A1 · Griffin et al. · 2023 [cited by applicant]
US 20230114719A1 · Thomas et al. · 2023 [cited by applicant]
US 20230114821A1 · Thomas et al. · 2023 [cited by applicant]
US 20230275917A1 · Karmali · 2023 [cited by examiner]
US 20240414174A1 · Thomas et al. · 2024 [cited by applicant]
US 20250047686A1 · Thomas et al. · 2025 [cited by applicant]
US 20260046294A1 · Thomas et al. · 2026 [cited by applicant]
WO WO2016195985 · 2016 [cited by applicant]
WO WO2019200317 · 2019 [cited by applicant]
WO WO2022129085 · 2022 [cited by applicant]
WO WO2022208045 · 2022 [cited by applicant]
WO WO2023064007 · 2023 [cited by applicant]
“U.S. Appl. No. 17/825,056 Final Office Action mailed Dec. 30, 2024”, NPL-1161 , 14 pages. [cited by applicant]
“U.S. Appl. No. 17/825,056 Non-Final Office Action mailed Jul. 18, 2024”, NPL-1130 , 13 pages. [cited by applicant]
“U.S. Appl. No. 17/825,056 Notice of Allowance mailed Apr. 9, 2025”, NPL-1191 , 7 pages. [cited by applicant]
“U.S. Appl. No. 17/825,070 Notice of Allowance mailed Apr. 9, 2024”, NPL-1114 , 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825,083 Notice of Allowance mailed Apr. 9, 2024”, NPL-1115 , 13 pages. [cited by applicant]
“U.S. Appl. No. 17/825,098 Notice of Allowance mailed Apr. 8, 2024”, NPL-1116 , 19 pages. [cited by applicant]
“U.S. Appl. No. 17/825,120 Notice of Allowance mailed Mar. 6, 2024”, NPL-1090 , 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825,135 Final Office Action mailed Feb. 27, 2025”, NPL-1192 , 31 pages. [cited by applicant]
“U.S. Appl. No. 17/825,135 Non-Final Office Action mailed Sep. 9, 2024”, NPL-1140 , 25 pages. [cited by applicant]
“U.S. Appl. No. 17/825,146 Notice of Allowance mailed Mar. 11, 2024”, NPL-1091 , 20 pages. [cited by applicant]
WIPO, , “PCT Application No. PCT/US22/30859 International Preliminary Report on Patentability mailed Apr. 25, 2024”, NPL-1117 , 15 pages. [cited by applicant]
ISA/EP, , “PCT Application No. PCT/US22/30859 International Search Report and Written Opinion mailed Nov. 7, 2022”, NPL-905 , 21 pages. [cited by applicant]
ISA/EP, , “PCT Application No. PCT/US22/30859 Invitation to Pay Additional Fees mailed Sep. 14, 2022”, NPL-906 , 17 pages. [cited by applicant]
“U.S. Appl. No. 17/825,135 Notice of Allowance mailed Jun. 25, 2025”, NPL-1208 , 33 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/811,256 Non-Final Office Action mailed Jan. 21, 2026”, 10 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/811,488 Notice of Allowance mailed Jan. 22, 2026”, NPL-1245, 25 pages. [cited by applicant]