IP Library Granted Patent US 12,019,740
Granted Patent B2
US 12,019,740 · App. 17/157,134 · Granted Jun 25, 2024

Automated cybersecurity threat detection with aggregation and analysis

Inventors: Ryan W. Trost (Vienna, VA); Leon Ward (Reading, GB)
Assignee: THREATQUOTIENT, INC.
G06F21/552G06F16/22G06F16/26G06F16/288G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,019,740
App. No.
17/157,134
Filed
Jan 25, 2021
Granted
Jun 25, 2024
Kind
B2
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/23
Abstract

The systems and methods described herein generally relate to techniques for automated detection, aggregation, and integration of cybersecurity threats. The system ingests multiple data feeds which can be in one or numerous different formats. The system evaluates information based on defined scores to display to users threats and risks associated with them. The system also calculates decay rates for expiration of threats and indicators through various methods.

Claims (107)

1. An article of manufacture, comprising a non-transitory machine-readable medium, the medium including instructions, the instructions, when loaded and executed by a processor, cause the processor to:

collect threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parse the collected threat intelligence information into a common format;

store the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

store the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receive the parsed threat intelligence information comprising the threat indicators from the database;

store the parsed threat intelligence information in a first threat data container object;

receive investigation information relating to an active threat investigation, wherein the investigation information is one or more of:

an event type, attack vector, indicator of compromise, adversary attribution, or file, and wherein the investigation information is associated with a threat indicator;

storing the investigation information in a second threat data container object;

identify a common relation between the first threat data container object and the second threat data container object based on the respective threat indicators of the first threat data container object and the second threat data container object;

display the first threat data container object, the second threat data container object and a graphical indication of the common relation between the first threat data container object and the second threat data container object;

export a formatted threat intelligence information, wherein the formatted threat intelligence information includes indicators, sources, and dates for input to a set visualization process; and

calculate a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of: a trend analysis, analysis based on date constraints, side-by-side comparison, or time series analysis.

2. The article of claim 1 , wherein the instructions are further for causing the processor to:

identify multiple common relations between multiple threat data container objects;

assign multiple subsets of the common relations to multiple respective layers; and

select one of the multiple layers for display to a user such that the non-selected layers are not displayed.

3. The article of claim 2 , wherein at least one layer is associated with a level of access or an individual user.

4. The article of claim 1 , wherein the instructions are further for causing the processor to:

record in association with a threat data container object an indication that a user has taken an action with respect to the threat data container object;

record in association with the threat data container object a time associated with the action taken with respect to the threat data container object; and

display the threat data container object, a representation of the action taken, and the time associated with the action taken on the threat data container object.

5. The article of claim 1 , wherein the adversary attribution indicates one or more of a foreign intelligence actor, crimeware, hacktivist, or professional hacker.

6. The article of claim 1 , wherein threat intelligence information in the first threat data container object is a file hash, and the second threat data container object contains at least one file hash, and the instructions are further for causing the processor to:

compare the file hashes in the first threat data container object and the second threat data container object to detect equality; and

if the file hashes are equal, then identifying a common relation between the first threat data container object and the second threat data container object, then identifying a file corresponding to the file hashes detected to be equal and transmitting that file to an external integration for threat analysis.

7. An article of manufacture, comprising a non-transitory machine-readable medium, the medium including instructions, the instructions, when loaded and executed by a processor, cause the processor to:

collect threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parse the collected threat intelligence information into a common format;

store the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

store the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receive the parsed threat intelligence information comprising threat indicators from the database;

store the parsed threat intelligence information in a first threat data container object;

receive investigation information relating to an active threat investigation, wherein the investigation information is one or more of an event type, attack vector, indicator of compromise, adversary attribution, or file, and wherein the investigation information is associated with a threat indicator;

store the investigation information in a second threat data container object;

identify a common relation between the first threat data container object and the second threat data container object based on the respective threat indicators of the first threat data container object and the second threat data container object; and

display a graphical indication of the common relation between the first threat data container object and the second threat data container object.

8. The article of claim 7 , wherein the instructions are further for causing the processor to:

identify multiple common relations between multiple threat data container objects;

assign multiple subsets of the common relations to multiple respective layers; and

select one of the multiple layers for display to a user such that the non-selected layers are not displayed.

9. The article of claim 8 , wherein at least one layer is associated with a level of access or an individual user.

10. The article of claim 7 , wherein the instructions are further for causing the processor to:

record in association with a threat data container object an indication that a user has taken an action with respect to the threat data container object;

record in association with the threat data container object a time associated with the action taken with respect to the threat data container object; and

display the threat data container object, a representation of the action taken, and the time associated with the action taken on the threat data container object.

11. The article of claim 7 , wherein the adversary attribution indicates one or more of a foreign intelligence actor, crimeware, hacktivist, or professional hacker.

12. The article of claim 7 , wherein:

threat intelligence information in the first threat data container object is a file hash;

the second threat data container object contains at least one file hash; and

the instructions are further for causing the processor to compare the file hashes in the first threat data container object and the second threat data container object to detect equality, and if the file hashes are equal, then identify a common relation between the first threat data container object and the second threat data container object.

13. The article of claim 12 , wherein the instructions are further for causing the processor to identify a file corresponding to the file hashes detected to be equal, and transmitting that file to an external integration for threat analysis.

14. A method for collecting and distributing cybersecurity threat intelligence information, comprising:

collecting threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parsing the collected threat intelligence information into a common format;

storing the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

storing the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receiving the parsed threat intelligence information comprising the threat indicators from the database;

exporting a formatted threat intelligence information, wherein the formatted threat intelligence information includes indicators, sources, and dates for input to a set visualization process;

calculating a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of a trend analysis, an analysis based on date constraints, a side-by-side comparison, or a time series analysis;

calculating a graphical side-by-side comparison by comparing the formatted threat intelligence information to an enterprise internal malware sandbox, ticketing system for intrusion or infections, and known successful attack blocks;

identifying overlap of indicators in the side-by-side comparison; and

executing a query for additional indicators of compromise based on the overlap.

15. The method of claim 14 , further comprising:

exporting a first subset of the formatted threat intelligence information, wherein the first subset of the formatted threat intelligence information includes indicators, sources, and dates for input to the set visualization process;

exporting a second subset of the formatted threat intelligence information, wherein the second subset of the formatted threat intelligence information includes indicators, sources, and dates for input to the set visualization process; and

determining a degree of overlap between the first and second subsets.

16. The method of claim 14 , further comprising:

comparing the first and second subsets to identify common indicators of compromise; and

conforming a common name to common indicators of compromise.

17. A method for collecting and distributing cybersecurity threat intelligence information, comprising:

collecting threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parsing the collected threat intelligence information into a common format;

storing the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

storing the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receiving the parsed threat intelligence information comprising threat indicators from the database;

exporting a formatted threat intelligence information, wherein the formatted threat intelligence information includes indicators, sources, and dates for input to a set visualization process;

calculating a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of a trend analysis, an analysis based on date constraints, a side-by-side comparison, or a time series analysis;

identifying the threat intelligence information and extracting indicators of compromise from the threat intelligence information;

storing sensor grid logs from a sensor; and

comparing the extracted indicators of compromise to the stored sensor grid logs; and

performing a timeseries analysis to determine if the sensor detected the indicators of compromise before or after the receiving the parsed threat intelligence information.

18. The method of claim 14 , further wherein the set visualization further comprises a visualization of set intersections in a matrix layout that introduces aggregates based on groupings and queries, enabling a representation of associated data, including as a number of elements in the aggregates and intersections.

19. An article of manufacture, comprising a non-transitory machine-readable medium, the medium including instructions, the instructions, when loaded and executed by a processor, cause the processor to:

collect threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parse the collected threat intelligence information into a common format;

store the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

store the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receive the parsed threat intelligence information comprising the threat indicators from the database;

export a formatted threat intelligence information, wherein the threat intelligence information includes indicators, sources, and dates for input to a set visualization process;

calculate a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of a trend analysis, an analysis based on date constraints, a side-by-side comparison, or a time series analysis;

calculate a graphical side-by-side comparison by comparing the formatted threat intelligence information to an enterprise internal malware sandbox, ticketing system for intrusion or infections, and known successful attack blocks;

identify overlap of indicators in the side-by-side comparison; and

execute a query for additional indicators of compromise based on the overlap.

20. An article of manufacture, comprising a non-transitory machine-readable medium, the medium including instructions, the instructions, when loaded and executed by a processor, cause the processor to:

collect threat intelligence information from a plurality of threat intelligence information sources, the collected threat intelligence information being of different formats;

parse the collected threat intelligence information into a common format;

store the parsed threat intelligence information in a database, wherein the parsed threat intelligence information further comprises multiple threat indicators;

store the threat indicators in the database in association with one or more parameter attributes, wherein a first parameter attribute is a source of the threat indicators;

receive the parsed threat intelligence information comprising threat indicators from the database;

export a formatted threat intelligence information, wherein the formatted threat intelligence information includes indicators, sources, and dates for input to a set visualization process;

calculate a set visualization of the threat intelligence information, wherein the set visualization is configured to calculate and display one or more of a trend analysis, an analysis based on date constraints, a side-by-side comparison, or a time series analysis;

identify the threat intelligence information and extracting indicators of compromise from the threat intelligence information;

store sensor grid logs from a sensor;

compare the extracted indicators of compromise to the stored sensor grid logs; and

perform a timeseries analysis to determine if the sensor detected the indicators of compromise before or after the receiving the parsed threat intelligence information.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: THREATQUOTIENT, INC.
To: SECURONIX, INC.
Reel/Frame 071908/0453 →
SECURITY INTEREST Recorded Jul 31, 2025
From: THREATQUOTIENT, INC.
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 071891/0963 →
RELEASE OF SECURITY INTEREST Recorded Jun 10, 2025
From: AVENUE CAPITAL MANAGEMENT II, L.P.
To: THREATQUOTIENT, INC.
Reel/Frame 071379/0059 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: TROST, RYAN; WARD, LEON
To: THREATQUOTIENT, INC.
Reel/Frame 065144/0960 →
SECURITY INTEREST Recorded Jul 28, 2023
From: THREATQUOTIENT, INC.
To: AVENUE CAPITAL MANAGEMENT II, L.P.
Reel/Frame 064420/0634 →
Continuity (6)
Continuation 16208531 · Dec 3, 2018
Continuation In Part 15261867 · Sep 9, 2016
Provisional Application 62631695 · Feb 17, 2018
Provisional Application 62594014 · Dec 3, 2017
Provisional Application 62215777 · Sep 9, 2015
Related Publication 20210173924A1 · Jun 10, 2021
Cited By (4)
US 12,464,018 US 12,536,300 US 12,563,089 US 12,587,534