IP Library › Granted Patent US 12,132,745
Granted Patent B2
US 12,132,745 · App. 17/825,098 · Granted Oct 29, 2024

Composite threat score

Inventors: Andrew J. Thomas (Oxfordshire, GB); Mangal Rakesh Vankadaru (Didcot, GB); Prakash Kumar Talreja (Twickenham, GB); Timothy Rayment (Abingdon, GB); Biju Balakrishnan Nair (Bangalore, IN)
Assignee: Sophos Limited
H04L63/1408G06F21/53G06F21/567H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,132,745
App. No.
17/825,098
Granted
Oct 29, 2024
Kind
B2
Abstract

A platform for threat investigation in an enterprise network receives threat data from managed endpoints, and is augmented with data from cloud computing platforms and other third-party resources. The resulting merged data set can be incrementally updated and used to automatically launch investigations at appropriate times.

Claims (36)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

receiving, at a threat management facility, a local threat indication from a local security agent on a compute instance, the local threat indication identifying a category of malicious activity associated with one or more events detected on the compute instance;

calculating, with the threat management facility, a contextual threat score for the compute instance based at least in part on geolocation data retrieved from a third-party service for a suspected threat detected on the compute instance;

receiving cloud resource data based on an action associated with the compute instance at a cloud service;

determining a composite threat score indicative of a threat risk for the compute instance based on at least the local threat indication, the contextual threat score, and the cloud resource data; and

displaying the composite threat score in a user interface.

2. The computer program product of claim 1 , wherein the cloud service includes a zero trust network access resource.

3. The computer program product of claim 1 , wherein the cloud service includes a web application.

4. The computer program product of claim 1 , wherein the cloud service includes one or more of an electronic mail application, a cloud storage service, a cloud computing service, a virtualization platform, and an authentication service.

5. The computer program product of claim 1 , wherein the contextual threat score is based on one or more of classification information for the suspected threat, a network location associated with the suspected threat, a path for the suspected threat, a filename for the suspected threat, a process name for the suspected threat, and a machine identifier for the suspected threat.

6. A method comprising:

receiving, at a threat management facility, a local threat indication from a local security agent on a compute instance, the local threat indication identifying a category of malicious activity associated with one or more events detected on the compute instance;

calculating, with the threat management facility, a contextual threat score for the compute instance based at least in part on contextual information for a suspected threat detected on the compute instance that is received at the threat management facility;

receiving cloud resource data based on an action associated with the compute instance at a cloud service;

determining a composite threat score indicative of a threat risk for the compute instance based on at least the local threat indication, the contextual threat score, and the cloud resource data; and

displaying the composite threat score in a user interface.

7. The method of claim 6 , wherein the local threat indication identifies an event indicative of malicious activity.

8. The method of claim 6 , wherein the local threat indication includes a threat detection obtained by the local security agent by applying a detection rule to events detected on the compute instance.

9. The method of claim 6 , wherein the local threat indication includes a classification indicating a category of malicious activity associated with events detected on the compute instance.

10. The method of claim 6 , wherein the cloud service includes an electronic mail application.

11. The method of claim 6 , wherein the cloud service includes a web application.

12. The method of claim 6 , wherein the cloud service includes a cloud storage service.

13. The method of claim 6 , wherein the cloud service includes a zero trust network access resource.

14. The method of claim 6 , wherein the cloud service includes an authentication service.

15. The method of claim 6 , wherein the cloud service includes a network monitor executing on a third-party firewall.

16. The method of claim 6 , wherein the action at the cloud service includes an activity by a user of the compute instance.

17. The method of claim 6 , wherein the cloud resource data includes one or more of authentication to the cloud service, administrative events at the cloud service, and application activity at the cloud service initiated from the compute instance.

18. The method of claim 6 , wherein the contextual information includes one or more of classification information for a suspected threat, a network location associated with a suspected threat, and geolocation data for a suspected threat.

19. A system comprising:

a plurality of compute instances associated with an enterprise network;

a threat management facility for the enterprise network, the threat management facility implemented by a hardware processor configured to determine a composite threat score based on:

a local threat indication received from a local security agent on one of the compute instances, the local threat indication identifying a category of malicious activity associated with one or more events detected on the one of the compute instances;

cloud resource data based on an action taken at a cloud service and associated with the one of the compute instances; and

a contextual score based on geolocation data received from a remote geolocation service for a suspected threat detected on the one of the compute instances; and

an administrative console configured to display the composite threat score in a user interface.

20. The system of claim 19 , wherein the cloud resource data includes application activity initiated at the cloud service from the one of the compute instances.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2022
From: THOMAS, ANDREW J.; VANKADARU, MANGAL RAKESH; TALREJA, PRAKASH KUMAR; RAYMENT, TIMOTHY; NAIR, BIJU BALAKRISHNAN
To: SOPHOS LIMITED
Reel/Frame 061396/0909 →
Continuity (3)
Continuation PCTUS2022030859 · May 25, 2022
Provisional Application 63254368 · Oct 11, 2021
Related Publication 20230111304A1 · Apr 13, 2023
Cited By (1)
US 12,375,500