IP Library Granted Patent US 10,084,804
Granted Patent B2
US 10,084,804 · App. 15/889,243 · Granted Sep 25, 2018

Optimizing security analyses in SaaS environment

Inventors: Kaushal K. Kapadia (Pune, IN); Dhilung H. Kirat (White Plains, NY); Youngja Park (Princeton, NJ); Marc P. Stoecklin (White Plains, NY); Sulakshan Vajipayajula (Bangalore, IN)
Assignee: International Business Machines Corporation
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,804
App. No.
15/889,243
Granted
Sep 25, 2018
Kind
B2
Abstract

Embodiments of the present invention provide systems and methods for performing a security analysis on a set of observables by inferring malicious relationships. The method includes receiving a set of observables and structured and unstructured threat data. The method further includes analyzing the observables and the structured and unstructured threat data using cognitive computing, and creating and transferring a subgraph.

Claims (20)

1. A computer-implemented method comprising:

receiving, by one or more hardware processors, a set of observables from an interfacing entity, and one or more of: a set of structured threat data and a set of unstructured threat data;

analyzing, by the one or more hardware processors, at least one of the set of observables, the set of structured threat data, and the set of unstructured threat data, wherein at least one of an observable of the set of observables, the set of structured threat data, and the set of unstructured threat data is analyzed using cognitive computing;

creating, by the one or more hardware processors, a subgraph representing the set of observables, the set of structured threat data and the set of unstructured threat data, based, at least in part, on the analysis;

transferring, by the one or more hardware processors, the subgraph to the interfacing entity;

receiving, by the one or more hardware processors, an updated set of observables from the interfacing entity;

updating, by the one or more hardware processors, the subgraph, based, at least in part, on the updated set of observables;

receiving, by the one or more hardware processors, one or more of a second updated set of observables from a different interfacing entity, a second updated set of structured threat data, and a second updated set of unstructured threat data;

further analyzing, by the one or more hardware processors, at least one of the received second updated set of observables from the different interfacing entity, the second updated set of structured threat data, and the second updated set of unstructured threat data;

further updating, by the one or more hardware processors, the subgraph, based, at least in part, on the further analysis;

transferring, by the one or more hardware processors, the updated subgraph through intelligent traversals to the interfacing entity;

removing, by the one or more hardware processors, one or more of a set of redundant data from the subgraph;

determining, by the one or more hardware processors, connections to the received set of observables, including one or more of: a uniform resource locator (URL), an internet protocol (IP) address, a domain, a subdomain, a hash, and a file;

creating, by the one or more hardware processors, a mapping structure on the subgraph based, at least in part, on the determined connections to the received set of observables;

analyzing, by the one or more hardware processors, the set of observables, the set of structured threat data, and the set of unstructured threat data utilizing a server-less computing architecture,

wherein the subgraph provides a solution for at least one of: malicious software and a malicious connection to a Uniform Resource Locator (URL), an internet protocol (IP) address, a hash, or a computer file,

wherein the subgraph further provides the solution on a user interface in an interactive format for a user, and

wherein the solution comprises a link to a downloadable security patch and information detailing instructions to install the security patch;

displaying the subgraph on the user interface; and

responsive to the user interacting with the link, installing and initiating, by the one or more hardware processors, the security patch on the interfacing entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2018
From: KAPADIA, KAUSHAL K.; KIRAT, DHILUNG H.; PARK, YOUNGJA; STOECKLIN, MARC P.; VAJIPAYAJULA, SULAKSHAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044837/0370 →
Continuity (2)
Continuation 15414809 · Jan 25, 2017
Related Publication 20180212990A1 · Jul 26, 2018
Cited By (9)
US 12,231,461 US 12,284,200 US 12,289,336 US 12,335,296 US 12,348,552 US 12,355,798 US 12,470,591 US 12,476,994 US 12,554,996