IP Library › Granted Patent US 12,495,056
Granted Patent B1
US 12,495,056 · App. 18/487,493 · Granted Dec 9, 2025

Scanning of security logs to detect data indicative of cyber threats

Inventors: Peng-Yuan Yueh (Taipei, TW); Josefino IV Fajilago (Pasig, PH); Chi-Yang Tsai (Taipei, TW); Ming-Chin Zhuang (Taipei, TW)
Assignee: Trend Micro Incorporated
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,056
App. No.
18/487,493
Filed
Oct 16, 2023
Granted
Dec 9, 2025
Kind
B1
Examiner
SONG, HOSUK
Art Unit
2435
USPC
726/1
Abstract

Filters that include matching criteria for detecting data indicative of attack techniques of cyber threats are provided in a repository. Filters that meet filter conditions of a rule of a heuristic model are automatically included in the rule. Filters that have been automatically included in the rule by having met the filter conditions of the rule are automatically removed from the rule when the filters no longer meet the filter conditions of the rule. A security log is scanned for data that meet matching criteria of filters included in the rule. The heuristic model issues an alert at least in response to detecting that the security log includes data that meet matching criteria of filters included in the rule.

Claims (28)

1 . A method of scanning security logs for data indicative of cyber threats, the method comprising:

providing a plurality of filters in a filter repository, each of the plurality of filters comprising matching criteria that describe data indicative of an attack technique of a cyber threat;

automatically including a first filter of the plurality of filters in a rule of a heuristic model for detecting a particular cyber threat, the rule including a first filter condition for automatically adding filters from the filter repository into a subset of the plurality of filters that are included in the rule, wherein the first filter is automatically added to the subset of the plurality of filters in response to the first filter having an attribute that is indicated by the first filter condition of the rule;

scanning a security log for data that are described by matching criteria of the subset of the plurality of filters; and

the heuristic model issuing an alert at least in response to detecting that the security log includes data that are described by matching criteria of the first filter.

2 . The method of claim 1 , further comprising:

automatically removing the first filter from the rule in response to the first filter no longer having the attribute.

3 . The method of claim 2 , further comprising:

automatically including a second filter of the plurality of filters in the subset of the plurality of filters in response to the second filter having an attribute that is indicated by a second filter condition for automatically adding filters from the filter repository into the subset of the plurality of filters; and

scanning the security log for data that are described by matching criteria of the second filter.

4 . The method of claim 3 , wherein the heuristic model issues the alert in response to detecting that the security log includes data that are described by the matching criteria of the first filter and the matching criteria of the second filter.

5 . The method of claim 3 , wherein the heuristic model issues the alert in response to detecting that the security log includes data that are described by the matching criteria of the first filter or the matching criteria of the second filter.

6 . The method of claim 1 , wherein the first filter condition of the rule indicates a static attribute.

7 . The method of claim 6 , wherein the static attribute is a tag that is included in the first filter.

8 . The method of claim 1 , wherein the first filter condition of the rule indicates a dynamic attribute.

9 . The method of claim 8 , wherein the dynamic attribute is prevalence of the first filter.

10 . A backend system for scanning security logs to detect data indicative of cyber threats, the backend system comprising at least one processor and a memory, the memory storing instructions that when executed by the at least one processor cause the backend system to:

store a plurality of filters in a filter repository, each of the plurality of filters describing an attack technique of a cyber threat;

automatically include a first filter of the plurality of filters in a rule of a heuristic model for detecting a particular cyber threat in response to the first filter having an attribute that is indicated by a first filter condition of the rule, wherein the first filter condition is for automatically including filters from the filter repository into a subset of the plurality of filters that are included in the rule;

automatically include a second filter of the plurality of filters in the rule in response to the second filter having an attribute that is indicated by a second filter condition of the rule, wherein the second filter condition is for automatically including filters from the filter repository into the subset of the plurality of filters;

receive the security logs from a plurality of security event sources;

scan the security logs for data that are described by the first filter and the second filter; and

issue an alert based at least on a security log including data that are described by the first filter as indicative of an attack technique of a cyber threat.

11 . The backend system of claim 10 , wherein the instructions stored in the memory when executed by the at least one processor cause the backend system to issue the alert based at least on the security log including data that are described by the first filter and the second filter as indicative of attack techniques of cyber threats.

12 . The backend system of claim 10 , wherein the first filter condition indicates a static attribute and the attribute of the first filter is the static attribute.

13 . The backend system of claim 10 , wherein the first filter condition indicates a dynamic attribute, and the attribute of the first filter is the dynamic attribute.

14 . The backend system of claim 10 , wherein the instructions stored in the memory when executed by the at least one processor cause the backend system to:

automatically remove the first filter from the rule in response to the first filter no longer having the attribute.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2023
From: YUEH, PENG-YUAN; FAJILAGO, JOSEFINO IV; TSAI, CHI-YANG; ZHUANG, MING-CHIN
To: TREND MICRO INCORPORATED
Reel/Frame 065338/0443 →
References Cited (12)
US 7523493B2 · Liang · 2009 [cited by examiner]
US 10061918B2 · Sultana · 2018 [cited by examiner]
US 10367834B2 · Sweet · 2019 [cited by examiner]
US 10917417B2 · Wang · 2021 [cited by examiner]
US 11528294B2 · Bargnesi · 2022 [cited by examiner]
US 11611591B2 · Parekh · 2023 [cited by examiner]
US 11824875B2 · Moore · 2023 [cited by examiner]
US 11962620B2 · Parekh · 2024 [cited by examiner]
US 12113771B2 · Fenton · 2024 [cited by examiner]
US 20230095306A1 · Fenton · 2023 [cited by examiner]
“Detection Model Management”, Trend Micro: Online Help Center, Downloaded Sep. 13, 2023, https://docs.trendmicro.com/en-us/enterprise/trend-vision-one/xdr-part/detection-model-mana.aspx. [cited by applicant]
“What Are XDR Security Analytics?”, Trend Micro, Downloaded Sep. 13, 2023, in https://www.trendmicro.com/en_us/what-is/xdr/security-analytics.html. [cited by applicant]