IP Library › Granted Patent US 12,395,499
Granted Patent B2
US 12,395,499 · App. 17/825,056 · Granted Aug 19, 2025

Platform for managing threat data

Inventors: Andrew J. Thomas (Oxfordshire, GB); Mangal Rakesh Vankadaru (Didcot, GB); Prakash Kumar Talreja (Twickenham, GB); Timothy Rayment (Abingdon, GB); Biju Balakrishnan Nair (Bangalore, IN)
Assignee: Sophos Limited
H04L63/1408G06F21/53G06F21/567H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,499
App. No.
17/825,056
Granted
Aug 19, 2025
Kind
B2
Abstract

A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.

Claims (39)

1. A system comprising:

a plurality of compute instances coupled to an enterprise network;

a data lake storing an event stream from a number of sources of security data, the event stream including:

security events from one or more sensors on the plurality of compute instances coupled to the enterprise network;

cloud resource data from a cloud service supporting the plurality of compute instances coupled to the enterprise network; and

contextual data for activity by the plurality of compute instances from a third-party service; and

a threat management facility configured to perform the steps of:

updating a composite threat score based on the number of sources of security data as the event stream is asynchronously received from the number of sources of security data, wherein updating the composite threat score includes mapping the security events to an attack matrix enumerating malware strategies in a first dimension and malware techniques for each of the malware strategies in a second dimension, and calculating the composite threat score based on a pattern of traversal of the attack matrix by a chronology of the security events,

automatically creating an investigation container for interactive investigation of security risks when the composite threat score meets one or more predetermined criteria for initiating an investigation,

displaying the investigation container to a user, and

incrementally updating the investigation container with information from the number of sources of security data.

2. The system of claim 1 , wherein the security events include asynchronous data from the plurality of compute instances.

3. The system of claim 1 , wherein the security events include batch data from one or more of the plurality of compute instances.

4. The system of claim 1 , wherein the plurality of compute instances include at least one network device for the enterprise network.

5. The system of claim 1 , wherein the plurality of compute instances include at least one virtual computing device hosted on a virtualization platform.

6. The system of claim 1 , wherein the security events include threat detection data from a local security agent executing on one of the plurality of compute instances.

7. The system of claim 1 , wherein the contextual data includes geolocation data from the third-party service.

8. The system of claim 1 , wherein the data lake applies deduplication logic to remove one or more recurring detections from at least one of the one or more sensors.

9. The system of claim 1 , wherein the cloud service includes one or more of a web application, a cloud storage service, an electronic mail application, an authentication service, a zero trust network access resource, a cloud computing service, and a virtualization platform.

10. The system of claim 1 , wherein the cloud service includes a network monitor executing on a third-party firewall and securely coupled to the threat management facility.

11. The system of claim 1 , wherein the number of sources of security data include a monitor for a query interface to the data lake.

12. The system of claim 1 , wherein the threat management facility is configured to present a user interface associated with the investigation container in a display to the user.

13. The system of claim 1 , wherein the threat management facility is configured to transmit a link to a user interface associated with the investigation container in a message to the user.

14. The system of claim 1 , wherein the threat management facility is configured to display a user interface associated with the investigation container, the user interface including a control for requesting additional event data captured by a data recorder of one of the plurality of compute instances prior for a time window prior to creation of the investigation container.

15. The system of claim 1 , wherein the threat management facility is configured to display a user interface associated with the investigation container, the user interface including a control for adjusting a filter applied by one of the plurality of compute instances to a local event stream when selecting local security events to communicate on the event stream to the data lake.

16. The system of claim 1 , wherein the threat management facility is configured to display a user interface associated with the investigation container, the user interface including a tool for querying the data lake.

17. The system of claim 1 , wherein the threat management facility is configured to calculate the composite threat score by applying a machine learning algorithm to the pattern of traversal of the attack matrix to determine a likelihood of threat.

18. The system of claim 1 , wherein the composite threat score includes two or more scores based on two or more of the number of sources of security data, and wherein the one or more predetermined criteria for initiating the investigation includes a separate threshold for each of the two or more scores.

19. The system of claim 1 , wherein the threat management facility is configured to revise the composite threat score downward when a false positive is identified, and automatically close the investigation container when the composite threat score meets a second one or more predetermined criteria for terminating the investigation.

20. A method comprising:

with a data lake for an enterprise network, storing an event stream from a number of sources of security data, the event stream including:

security events from one or more sensors on a plurality of compute instances coupled to the enterprise network;

cloud resource data from a cloud service supporting the plurality of compute instances coupled to the enterprise network; and

contextual data for activity by the plurality of compute instances from a third-party service; and

with a threat management facility executing on one or more processors, performing the steps of:

updating a composite threat score based on the number of sources of security data as the event stream is asynchronously received from the number of sources of security data, wherein updating the composite threat score includes mapping the security events to an attack matrix enumerating malware strategies in a first dimension and malware techniques for each of the malware strategies in a second dimension, and calculating the composite threat score based on a pattern of traversal of the attack matrix by a chronology of the security events,

automatically creating an investigation container for interactive investigation of security risks when the composite threat score meets one or more predetermined criteria for initiating an investigation,

displaying the investigation container to a user, and

incrementally updating the investigation container with information from the number of sources of security data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2022
From: THOMAS, ANDREW J.; VANKADARU, MANGAL RAKESH; TALREJA, PRAKASH KUMAR; RAYMENT, TIMOTHY; NAIR, BIJU BALAKRISHNAN
To: SOPHOS LIMITED
Reel/Frame 061395/0314 →
Continuity (3)
Continuation PCTUS2022030859 · May 25, 2022
Provisional Application 63254368 · Oct 11, 2021
Related Publication 20230114719A1 · Apr 13, 2023
References Cited (57)
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8595789B2 · Warn et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8769676B1 · Kashyap · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9503472B2 · Laidlaw et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9589245B2 · Coden et al. · 2017 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10587647B1 · Khalid et al. · 2020 [cited by applicant]
US 10902114B1 · Trost · 2021 [cited by examiner]
US 10984122B2 · Thomas · 2021 [cited by applicant]
US 11089047B1 · Kaushal et al. · 2021 [cited by applicant]
US 11552974B1 · Bagga · 2023 [cited by examiner]
US 11651313B1 · Fridakis · 2023 [cited by applicant]
US 20130191919A1 · Basavapatna et al. · 2013 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav · 2016 [cited by examiner]
US 20190318109A1 · Thomas · 2019 [cited by applicant]
US 20190319945A1 · Levy et al. · 2019 [cited by applicant]
US 20190319987A1 · Levy et al. · 2019 [cited by applicant]
US 20190373008A1 · Brandwine et al. · 2019 [cited by applicant]
US 20200007586A1 · Seeber et al. · 2020 [cited by applicant]
US 20200074360A1 · Humphries · 2020 [cited by examiner]
US 20200076835A1 · Ladnai et al. · 2020 [cited by applicant]
US 20200220885A1 · Will · 2020 [cited by examiner]
US 20200329066A1 · Kirti et al. · 2020 [cited by applicant]
US 20210250366A1 · Ladnai et al. · 2021 [cited by applicant]
US 20210294901A1 · Agarwwal et al. · 2021 [cited by applicant]
US 20210377313A1 · Murphy · 2021 [cited by examiner]
US 20220053011A1 · Rao · 2022 [cited by examiner]
US 20220094705A1 · Tineo · 2022 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230111304A1 · Thomas et al. · 2023 [cited by applicant]
US 20230111864A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113375A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113621A1 · Griffin et al. · 2023 [cited by applicant]
US 20230114821A1 · Thomas et al. · 2023 [cited by applicant]
US 20230275917A1 · Karmali et al. · 2023 [cited by applicant]
WO WO2016195985A1 · 2016 [cited by examiner]
WO WO2019200317 · 2019 [cited by applicant]
WO WO2022208045A1 · 2022 [cited by examiner]
WO WO2023064007 · 2023 [cited by applicant]
ISA/EP, “PCT Application No. PCT/US22/30859 International Search Report and Written Opinion mailed Nov. 7, 2022”, 21 pages. [cited by applicant]
ISA/EP, “PCT Application No. PCT/US22/30859 Invitation to Pay Additional Fees mailed Sep. 14, 2022”, 17 pages. [cited by applicant]
“U.S. Appl. No. 17/825,070 Notice of Allowance mailed Apr. 9, 2024”, 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825,083 Notice of Allowance mailed Apr. 9, 2024”, 13 pages. [cited by applicant]
“U.S. Appl. No. 17/825,098 Notice of Allowance mailed Apr. 8, 2024”, 19 pages. [cited by applicant]
“U.S. Appl. No. 17/825,120 Notice of Allowance mailed Mar. 6, 2024”, 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825,146 Notice of Allowance mailed Mar. 11, 2024”, 20 pages. [cited by applicant]
WIPO, “PCT Application No. PCT/US22/30859 International Preliminary Report on Patentability mailed Apr. 25, 2024”, 15 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/825,135 Notice of Allowance mailed Jun. 25, 2025”, , 33 pages. [cited by applicant]