IP Library Granted Patent US 11,899,790
Granted Patent B2
US 11,899,790 · App. 18/087,686 · Granted Feb 13, 2024

Cross-network security evaluation

Inventors: Christopher Ahlberg (Watertown, MA); Bill Ladd (Watertown, MA); Sanil Chohan (Stivichall, GB); Adrian Tirados Mata (Medford, MA); Michael Tran (Cambridge, MA); Staffan Truvé (Alingsås, SE)
Assignee: Recorded Future, Inc.
G06F21/56G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,899,790
App. No.
18/087,686
Granted
Feb 13, 2024
Kind
B2
Abstract

A computer security monitoring system and method are disclosed that feature, in one general aspect, monitoring on an ongoing basis for evidence of the presence of infected systems in one or more networks that are each associated with a monitored organizational entity possessing digital assets, continuously updating risk profiles for the entities based on information about intrusion features from the monitoring, aggregating risk scores for the entities, and electronically reporting the aggregated risk score to an end user. In another general aspect, a method is disclosed that includes acquiring and storing data relating to interactions with malware controllers over a public network, acquiring and storing a map of relationships between networks connected to the public network, extracting risk data from the stored interaction data and the stored relationship map by cross-referencing the acquired interaction data against the map of relationships, and issuing security alerts based the extracted risk data.

Claims (17)

1. A computer security monitoring method, including:

acquiring and storing data relating to interactions with malware controllers over a public network,

acquiring and storing a map of relationships between networks connected to the public network,

extracting risk data from the stored data relating to interactions with the malware controllers and the stored map of relationships by cross-referencing the acquired interaction data against the map of relationships,

issuing security alerts based on the extracted risk data, and

issuing reports that each include a plurality of visual elements that visually summarize the relationships and the interactions with malware controllers that lead to the issuing of security alerts, wherein the visual elements are responsive to user actuation and wherein user action of actuating of the visual elements causes the user to explore the relationships and the interactions with malware controllers that lead to the issuing of security alerts, wherein the presenting visual elements further presents the visual elements as including series of textual links that visually summarize additional information about the relationships and the interactions with malware controllers that lead to the issuing of security alerts, and wherein actuating of the textual links causes the user to explore the additional information about the relationships and the interactions with malware controllers that lead to the issuing of security alerts.

2. The method of claim 1 wherein the acquiring and storing a relationship map acquires a map of relationships that includes partnership relationships between networks.

3. The method of claim 1 wherein the issuing security alerts is based on combined information about interaction with malware controllers and information about other network risks.

4. The method of claim 1 further including continuously gathering machine-readable facts relating to a number of topics, including evidence of the presence of infected systems, wherein the issuing alerts is based on combined information about interaction with malware controllers and the gathered machine-readable facts.

5. The method of claim 1 further including responding to user requests to explore the relationships that led to the issuing of security alerts.

6. The method of claim 1 wherein the issuing reports includes issuing reports that each further include a plurality of controls that allow the user to explore the relationships that lead to the issuing of security alerts.

7. The method of claim 1 further including continuously updating the relationships using an ongoing maintenance process.

8. The method of claim 1 wherein the relationships include relationships between different organizational entities.

9. The method of claim 8 wherein the relationships include relationships between organizational entities and their subsidiaries and contractors.

10. The method of claim 1 wherein the relationships include relationships between organizational entities and network identifiers.

11. The method of claim 1 wherein the relationships include relationships between organizational entities and types of technology.

12. The method of claim 1 wherein the relationships can be expressed as a directed acyclic graph.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2024
From: ALTER DOMUS (US) LLC
To: RECORDED FUTURE, INC; SECURITYTRAILS, LLC
Reel/Frame 069665/0398 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 28, 2024
From: RECORDED FUTURE, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 067964/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2023
From: AHLBERG, CHRISTOPHER; LADD, BILL; CHOHAN, SANIL; MATA, ADRIAN TIRADOS; TRAN, MICHAEL; TRUVE, STAFFAN
To: RECORDED FUTURE, INC.
Reel/Frame 062560/0526 →
Continuity (3)
Division 16823282 · Mar 18, 2020
Provisional Application 62819906 · Mar 18, 2019
Related Publication 20230281307A1 · Sep 7, 2023