IP Library › Granted Patent US 10,635,817
Granted Patent B2
US 10,635,817 · App. 14/764,670 · Granted Apr 28, 2020

Targeted security alerts

Inventors: William G Horne (Princeton, NJ); Tomas Sander (Princeton, NJ); Krishnamurthy Viswanathan (Palo Alto, CA); Anurag Singla (Sunnyvale, CA); Siva Raj Rajagopalan (Chandler, AZ)
Assignee: Micro Focus LLC
G06F21/57G06F21/577H04L63/1408H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,635,817
App. No.
14/764,670
Filed
Jul 30, 2015
Granted
Apr 28, 2020
Kind
B2
Art Unit
2495
USPC
726/25
Abstract

Providing a targeted security alert can include collecting participant data from a plurality of participants within a threat exchange community, calculating, using a threat exchange server, a threat relevancy score of a participant among the plurality of participants within the threat exchange community using the collected participant data, and providing, from the threat exchange server to the participant, the targeted security alert based on the calculated threat relevancy score via a communication link within the threat exchange community.

Claims (22)

1. A method for providing a targeted security alert, the method comprising:

collecting participant data from a plurality of participants within a threat exchange community, the collected participant data including characteristics of attackers in security attacks against the plurality of participants;

grouping the plurality of participants into a plurality of clusters based on the characteristics of the attackers in the security attacks against the plurality of participants;

calculating, using a threat exchange server, a threat relevancy score of a participant among the plurality of participants using the collected participant data and a cluster among the plurality of clusters; and

providing, from the threat exchange server to the participant, a targeted security alert based on the calculated threat relevancy score via a communication link within the threat exchange community.

2. The method of claim 1 , wherein calculating the threat relevancy score includes statistically modeling a probability that a security occurrence is relevant to the participant based on a subset of the collected participant data.

3. The method of claim 1 , wherein calculating the threat relevancy score includes statistically modeling a probability that the participant will be attacked by an exploit against a vulnerability.

4. The method of claim 1 , wherein the characteristics of the attackers include an internet protocol (IP) address used by an attacker in multiple security attacks.

5. The method of claim 1 , wherein the characteristics of the attackers include an attack tool used by an attacker in multiple security attacks.

6. A non-transitory computer-readable medium storing a set of instructions executable by a processing resource, wherein the set of instructions can be executed by the processing resource to:

collect characteristic data and security data from a plurality of participants within a threat exchange community, the collected security data including characteristics of attackers in security attacks against the plurality of participants;

group the plurality of participants into a plurality of clusters based on the characteristics of the attackers in the security attacks against the plurality of participants included in the collected security data;

calculate, using a threat exchange server, a threat relevancy score of a participant among the plurality of participants using security data from the participant and a cluster among the plurality of clusters; and

provide, from the threat exchange server to the participant, a targeted security alert based on the calculated threat relevancy score via a communication link within the threat exchange community.

7. The medium of claim 6 , wherein the characteristics of the attackers include an internet protocol (IP) address used by an attacker in multiple security attacks.

8. The medium of claim 6 , wherein the instructions executable by the processing resource to provide the targeted security alert include instructions to send the targeted security alert to the participant in response to the threat relevancy score being beyond a threshold score.

9. The medium of claim 6 , wherein the instructions executable by the processing resource to calculate the threat relevancy score of the participant include instructions to consider security context to identify a threat level.

10. The medium of claim 6 , wherein the instructions executable by the processing resource to provide the targeted security alert include instructions to provide supporting evidence in the targeted security alert.

11. The medium of claim 6 , wherein the instructions executable by the processing resource to calculate the threat relevancy score of the participant include instructions to determine a similarity of the participant to the cluster.

12. The medium of claim 6 , wherein the characteristics of the attackers include an attack tool used by an attacker in multiple security attacks.

13. The medium of claim 6 , wherein the characteristics of the attackers include an objective of an attacker in multiple security attacks.

14. The method of claim 1 , wherein the characteristics of the attackers include an objective of an attacker in multiple security attacks.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2015
From: HORNE, WILLIAM G; SANDER, THOMAS; VISWANATHAN, KRISHNAMURTHY; RAJAGOPALAN, SIVA RAJ; SINGLA, ANURAG
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 036216/0833 →
Continuity (1)
Related Publication 20150371044A1 · Dec 24, 2015