IP Library Granted Patent US 11,836,664
Granted Patent B2
US 11,836,664 · App. 16/896,676 · Granted Dec 5, 2023

Enterprise network threat detection

Inventors: Karl Ackerman (Topsfield, MA); Russell Humphries (Surrey, GB); Mark Anthony Russo (Belle Mead, NJ); Andrew J. Thomas (Oxfordshire, GB)
Assignee: Sophos Limited
G06Q10/0635G06F9/542G06F11/079G06F16/955G06F17/18G06F18/214G06F18/2178G06F18/23213G06F18/24143G06F21/554G06F21/56G06F21/562G06F21/565G06N5/01G06N5/022G06N5/04G06N5/046G06N7/00G06N20/00G06N20/20G06Q10/06395G06V20/52H04L63/0227H04L63/0263H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20G06Q30/0185G06Q30/0283
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,836,664
App. No.
16/896,676
Filed
Jun 9, 2020
Granted
Dec 5, 2023
Kind
B2
Art Unit
2178
USPC
706/12
Abstract

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.

Claims (36)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

identifying a file within an enterprise network with an identifier based on a hash of the file;

monitoring activity within the enterprise network to obtain a record of activities for one or more instances of the file, the record including a history of execution for the file and information for identifying compute instances where the file was executed, and the record further including a number of locations of the file within the enterprise network and mapping a presence or absence of features in the file to one or more corresponding features from a set of similar safe samples and a set of similar unsafe samples;

storing the record in a database along with the identifier for the file;

detecting a suspicious activity associated with the file, the suspicious activity indicating a reputation of the file between safe and malicious;

presenting the identifier of the file to an analyst in a user interface, the user interface configured to present a list of suspicious files to the analyst and support investigation of the file by presenting to the analyst the mapping of the presence or absence of features in the file to one or more corresponding features from the set of similar safe samples and the set of similar unsafe samples;

receiving a disposition of the file as malicious or non-malicious from the analyst; and

in response to the disposition, removing the file from the list of suspicious files.

2. The computer program product of claim 1 further comprising code that performs the step of, when the analyst disposes of the file by indicating that the file is malicious, remediating a first location of execution of the file in the history of execution.

3. The computer program product of claim 1 further comprising code that performs the step of, when the analyst disposes of the file by indicating that the file is malicious, remediating each of the number of locations of the file stored in the record.

4. The computer program product of claim 1 wherein the number of locations include a machine and a path for each of the one or more instances of the file.

5. The computer program product of claim 1 wherein the history of execution includes a time and place of a first execution of the file in the enterprise network.

6. The computer program product of claim 1 wherein the record includes one or more network connections associated with the file.

7. The computer program product of claim 6 wherein the one or more network connections include at least one connection created by a process executing from the file.

8. The computer program product of claim 6 wherein the one or more network connections include at least one connection used to transfer the file to a location within the enterprise network.

9. The computer program product of claim 1 further comprising code that performs the step of aging the record out of the database after a predetermined interval.

10. The computer program product of claim 1 further comprising code that performs the step of returning the file to the list of suspicious files upon a detection of a second suspicious activity by the file occurring after the disposition.

11. The computer program product of claim 10 further comprising code that performs the step of presenting a history of dispositions and one or more associated analysts in the user interface.

12. The computer program product of claim 11 further comprising code that performs the step of receiving an override of the disposition by a second analyst.

13. A method comprising:

identifying a file within an enterprise network;

monitoring activity within the enterprise network to obtain a record of activities for the file, the record including a history of execution for the file and information for identifying compute instances where the file was executed, and the record further including a number of locations of the file within the enterprise network and mapping a presence or absence of features in the file to one or more corresponding features from a set of similar safe samples and a set of similar unsafe samples;

detecting a suspicious activity associated with the file;

presenting an identifier of the file to an analyst in a user interface, the user interface configured to present a list of suspicious files to the analyst and support investigation of the file by presenting to the analyst the mapping of the presence or absence of features in the file to one or more corresponding features from the set of similar safe samples and the set of similar unsafe samples;

receiving a disposition of the file as malicious or non-malicious from the analyst; and

in response to the disposition, removing the file from the list of suspicious files.

14. The method of claim 13 wherein the number of locations include a machine and a path for each instance of the file.

15. The method of claim 13 wherein the history of execution includes a time and place of a first execution of the file in the enterprise network.

16. The method of claim 13 further comprising monitoring one or more network connections associated with the file.

17. The method of claim 13 further comprising aging the record out of a database of monitored files after a predetermined interval.

18. The method of claim 13 further comprising returning the file to the list of suspicious files upon detection of a second suspicious activity by the file occurring after the disposition.

19. The method of claim 13 further comprising receiving an override of the disposition by a second analyst.

20. A system comprising:

a plurality of compute instances;

an enterprise network coupling the plurality of compute instances in a communicating relationship; and

a threat management facility for the enterprise network, the threat management facility including a processor and a memory storing code that, when executing on the processor, performs the steps of identifying a file within the enterprise network, monitoring activity within the enterprise network to obtain a record of activities for the file, the record including a history of execution for the file and information for identifying compute instances where the file was executed, mapping a presence or absence of features in the file to one or more corresponding features from a set of similar safe samples and a set of similar unsafe samples, detecting a suspicious activity associated with the file, presenting an identifier of the file to an analyst in a user interface, the user interface configured to present a list of suspicious files to the analyst and support investigation of the file by presenting to the analyst the mapping of the presence or absence of features in the file to one or more corresponding features from the set of similar safe samples and the set of similar unsafe samples, receiving a disposition of the file as malicious or non-malicious from the analyst, and in response to the disposition, removing the file from the list of suspicious files.

Assignments (2)
SECURITY INTEREST Recorded Mar 15, 2021
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 055593/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2020
From: ACKERMAN, KARL; HUMPHRIES, RUSSELL; RUSSO, MARK ANTHONY; THOMAS, ANDREW J.
To: SOPHOS LIMITED
Reel/Frame 054060/0452 →
Continuity (10)
Continuation PCTUS2019046316 · Aug 13, 2019
Continuation 16128953 · Sep 12, 2018
Continuation 16128984 · Sep 12, 2018
Continuation 16129087 · Sep 12, 2018
Continuation 16129113 · Sep 12, 2018
Continuation 16129143 · Sep 12, 2018
Continuation 16129183 · Sep 12, 2018
Provisional Application 62726174 · Aug 31, 2018
Provisional Application 62874758 · Jul 16, 2019
Related Publication 20200304528A1 · Sep 24, 2020
Cited By (9)
US 12,272,448 US 12,301,627 US 12,301,628 US 12,339,986 US 12,438,826 US 12,519,738 US 12,524,531 US 12,568,104 US 12,695,709