IP Library › Granted Patent US 12,609,940
Granted Patent B2
US 12,609,940 · App. 18/811,488 · Granted Apr 21, 2026

Incremental enrichment of threat data

Inventors: Andrew J. Thomas (Oxfordshire, GB); Mangal Rakesh Vankadaru (Buckinghamshire, GB); Prakash Kumar Talreja (Twickenham, GB); Timothy Rayment (Abingdon, GB); Biju Balakrishnan Nair (Bangalore, IN)
Assignee: Sophos Limited
H04L63/1408G06F21/53G06F21/567H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,940
App. No.
18/811,488
Granted
Apr 21, 2026
Kind
B2
Abstract

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.

Claims (46)

1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

receiving threat data asynchronously from a plurality of sources, the threat data including at least:

a local threat indication from a local security agent executing on a compute instance in an enterprise network, the local threat indication identifying a category of malicious activity associated with one or more events detected on the compute instance;

geolocation data retrieved from a third-party service for a suspected threat detected on the compute instance; and

cloud resource data based on an action associated with the compute instance at a cloud service supporting one or more cloud-based applications for users of the enterprise network;

in response to asynchronous data from one of the plurality of sources, incrementally evaluating a threat risk for the compute instance based on the threat data;

automatically creating an investigation container when the threat risk based on the local threat indication, the geolocation data, and the cloud resource data meets a predetermined threshold, the investigation container associated with a user interface for interactively investigating sources of the threat risk;

displaying the threat data to a user in the user interface associated with the investigation container; and

updating the threat data in the user interface in response to additional asynchronous data from one of the plurality of sources.

2 . The computer program product of claim 1 , further comprising computer executable code that, when executing on the one or more computing devices, performs the step of creating an alert to the user when the threat risk meets the predetermined threshold.

3 . The computer program product of claim 2 , wherein the alert includes a message containing a link to the investigation container.

4 . The computer program product of claim 1 , wherein incrementally evaluating the threat risk includes calculating a composite threat score including a number of scores each individually based on one of the local threat indication, the geolocation data, and the cloud resource data.

5 . The computer program product of claim 4 , further comprising automatically launching the investigation container in response to at least one of the number of scores meeting at least one or more predetermined thresholds.

6 . A method comprising:

receiving threat data asynchronously from a plurality of sources, the threat data including at least:

a local threat indication from a local security agent executing on a compute instance in an enterprise network, the local threat indication identifying a category of malicious activity associated with one or more events detected on the compute instance;

contextual data from a third-party service for a suspected threat detected on the compute instance; and

cloud resource data based on an action associated with the compute instance at a cloud service supporting users of the enterprise network;

in response to asynchronous data from one of the plurality of sources, incrementally evaluating a threat risk for the compute instance based on the threat data;

automatically creating an investigation container based on the local threat indication, the contextual data, and the cloud resource data, the investigation container associated with a user interface for interactively investigating sources of malware data meets a predetermined threshold;

displaying the threat data to a user in the user interface associated with the investigation container; and

updating the threat data in the user interface in response to additional asynchronous data from one of the plurality of sources wherein the contextual data includes geolocation data.

7 . The method of claim 6 , wherein evaluating the threat risk includes calculating a composite threat score including a number of scores each individually based on one of the local threat indication, the contextual data, and the cloud resource data.

8 . The method of claim 7 , further comprising automatically launching the investigation container in response to at least one of the number of scores meeting at least one or more predetermined thresholds.

9 . The method of claim 7 , wherein the user interface associated with the investigation container provides interactive access to supporting data for the composite threat score.

10 . The method of claim 7 , wherein the composite threat score includes a single score for each of the local threat indication, the contextual data, and the cloud resource data.

11 . The method of claim 6 , further comprising transmitting a notification with a link to the user interface associated with the investigation container to a device associated with a security technician for the enterprise network.

12 . The method of claim 6 , wherein the cloud service includes one or more of a web application, a cloud storage service, an electronic mail application, an authentication service, a zero trust network access resource, a network monitor executing on a third-party firewall, a cloud computing service, and a virtualization platform.

13 . The method of claim 6 , wherein the plurality of sources include a third party security service.

14 . The method of claim 6 , wherein the plurality of sources include a source of malware signature updates.

15 . The method of claim 6 , wherein the plurality of sources include two or more cloud service providers.

16 . The method of claim 6 , wherein the plurality of sources include a threat management facility for the enterprise network, the threat management facility configured to augment information in the investigation container based on a history of responses by other users to a potential threat associated with the investigation container.

17 . The method of claim 6 , wherein the local threat indication includes a malware detection from the local security agent executing on the compute instance.

18 . A system comprising:

a plurality of compute instances associated with an enterprise network; and

a threat management facility for the enterprise network, the threat management facility implemented using at least one hardware processor and configured to receive threat data asynchronously from a plurality of sources, the threat data including at least:

a local threat indication from a local security agent on a compute instance, the local threat indication identifying a category of malicious activity associated with one or more events detected on the compute instance;

geolocation data retrieved from a third-party service for a suspected threat detected on the compute instance; and

cloud resource data based on an action associated with the compute instance at a cloud service supporting one or more cloud-based applications for users of the enterprise network;

wherein the threat management facility is configured to respond to asynchronous data from one of the plurality of sources by:

incrementally evaluating a threat risk for the compute instance based on the local threat indication, the geolocation data, and the cloud resource data;

creating an investigation container when the threat risk meets a predetermined threshold based on the local threat indication, the geolocation data, and the cloud resource data;

displaying the threat risk in a user interface associated with the investigation container; and

updating the threat risk in the user interface in response to additional asynchronous data from one of the plurality of sources.

19 . The system of claim 18 , wherein evaluating the threat risk includes calculating a composite threat score including a number of scores each individually based on one of the local threat indication, the geolocation data, and the cloud resource data.

20 . The system of claim 19 , wherein the threat management facility is further configured to respond to the asynchronous data from one of the plurality of sources by automatically launching the investigation container in response to at least one of the number of scores meeting at least one or more predetermined thresholds.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2024
From: THOMAS, ANDREW J.; VANKADARU, MANGAL RAKESH; TALREJA, PRAKASH KUMAR; RAYMENT, TIMOTHY; NAIR, BIJU BALAKRISHNAN
To: SOPHOS LIMITED
Reel/Frame 068367/0669 →
Continuity (4)
Continuation 17825146 · May 26, 2022
Continuation PCTUS2022030859 · May 25, 2022
Provisional Application 63254368 · Oct 11, 2021
Related Publication 20250047686A1 · Feb 6, 2025
References Cited (86)
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8595789B2 · Warn et al. · 2013 [cited by applicant]
US 8713633B2 · Andrew · 2014 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8769676B1 · Kashyap · 2014 [cited by examiner]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9503472B2 · Laidlaw et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9589245B2 · Coden et al. · 2017 [cited by applicant]
US 9697352B1 · Armstrong · 2017 [cited by examiner]
US 9721296B1 · Chrapko · 2017 [cited by applicant]
US 10063654B2 · Kirti · 2018 [cited by examiner]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10587647B1 · Khalid et al. · 2020 [cited by applicant]
US 10902114B1 · Trost et al. · 2021 [cited by applicant]
US 10984122B2 · Thomas · 2021 [cited by examiner]
US 11089047B1 · Kaushal · 2021 [cited by examiner]
US 11552974B1 · Bagga et al. · 2023 [cited by applicant]
US 11558401B1 · Vashisht et al. · 2023 [cited by applicant]
US 11651313B1 · Fridakis · 2023 [cited by applicant]
US 11777992B1 · Cross et al. · 2023 [cited by applicant]
US 12019754B2 · Tineo · 2024 [cited by applicant]
US 20130191919A1 · Basavapatna · 2013 [cited by examiner]
US 20130347052A1 · Choudrie · 2013 [cited by applicant]
US 20150319185A1 · Kirti · 2015 [cited by examiner]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160173509A1 · Ray · 2016 [cited by examiner]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20170171231A1 · Reybok, Jr. et al. · 2017 [cited by applicant]
US 20180004948A1 · Martin et al. · 2018 [cited by applicant]
US 20180124098A1 · Carver et al. · 2018 [cited by applicant]
US 20190034641A1 · Gil · 2019 [cited by examiner]
US 20190081968A1 · Wang · 2019 [cited by examiner]
US 20190318109A1 · Thomas · 2019 [cited by applicant]
US 20190319945A1 · Levy et al. · 2019 [cited by applicant]
US 20190319987A1 · Levy et al. · 2019 [cited by applicant]
US 20190373008A1 · Brandwine · 2019 [cited by examiner]
US 20200007586A1 · Seeber et al. · 2020 [cited by applicant]
US 20200074360A1 · Humphries et al. · 2020 [cited by applicant]
US 20200076835A1 · Ladnai et al. · 2020 [cited by applicant]
US 20200220885A1 · Will et al. · 2020 [cited by applicant]
US 20200302058A1 · Kenyon et al. · 2020 [cited by applicant]
US 20200327223A1 · Sanchez et al. · 2020 [cited by applicant]
US 20200329066A1 · Kirti · 2020 [cited by examiner]
US 20200356666A1 · Reybok et al. · 2020 [cited by applicant]
US 20200358807A1 · Connell et al. · 2020 [cited by applicant]
US 20210250366A1 · Ladnai · 2021 [cited by examiner]
US 20210294901A1 · Agarwwal et al. · 2021 [cited by applicant]
US 20210377313A1 · Murphy et al. · 2021 [cited by applicant]
US 20220053011A1 · Rao et al. · 2022 [cited by applicant]
US 20220094705A1 · Tineo · 2022 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230111304A1 · Thomas et al. · 2023 [cited by applicant]
US 20230111864A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113375A1 · Thomas et al. · 2023 [cited by applicant]
US 20230113621A1 · Griffin et al. · 2023 [cited by applicant]
US 20230114719A1 · Thomas et al. · 2023 [cited by applicant]
US 20230114821A1 · Thomas et al. · 2023 [cited by applicant]
US 20230275917A1 · Karmali · 2023 [cited by examiner]
US 20240414174A1 · Thomas et al. · 2024 [cited by applicant]
US 20250039190A1 · Nair et al. · 2025 [cited by applicant]
WO WO2016195985 · 2016 [cited by applicant]
WO WO2019200317 · 2019 [cited by applicant]
WO WO2022129085 · 2022 [cited by applicant]
WO WO2022208045 · 2022 [cited by applicant]
WO WO2023064007 · 2023 [cited by applicant]
“U.S. Appl. No. 18/769,267 Notice of Allowance mailed Nov. 19, 2025”, 24 pages. [cited by applicant]
“Application No. 17/825, 135 Notice of Allowance mailed Jun. 25, 2025”, 33 pages. [cited by applicant]
“U.S. Appl. No. 17/825,056 Final Office Action mailed Dec. 30, 2024”, 14 pages. [cited by applicant]
“U.S. Appl. No. 17/825,056 Non-Final Office Action mailed Jul. 18, 2024”, 13 pages. [cited by applicant]
“U.S. Appl. No. 17/825,056 Notice of Allowance mailed Apr. 9, 2025”, , 7 pages. [cited by applicant]
“U.S. Appl. No. 17/825,070 Notice of Allowance mailed Apr. 9, 2024”, 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825,083 Notice of Allowance mailed Apr. 9, 2024”, 13 pages. [cited by applicant]
“U.S. Appl. No. 17/825,098 Notice of Allowance mailed Apr. 8, 2024”, 19 pages. [cited by applicant]
“U.S. Appl. No. 17/825,120 Notice of Allowance mailed Mar. 6, 2024”, 20 pages. [cited by applicant]
“U.S. Appl. No. 17/825, 135 Final Office Action mailed Feb. 27, 2025”, , 31 pages. [cited by applicant]
“U.S. Appl. No. 17/825,135 Non-Final Office Action mailed Sep. 9, 2024”, 25 pages. [cited by applicant]
“U.S. Appl. No. 17/825,146 Notice of Allowance mailed Mar. 11, 2024”, 20 pages. [cited by applicant]
WIPO, , “PCT Application No. PCT/US22/30859 International Preliminary Report on Patentability mailed Apr. 25, 2024”, 15 pages. [cited by applicant]
ISA/EP, , “PCT Application No. PCT/US22/30859 International Search Report and Written Opinion mailed Nov. 7, 2022”, 21 pages. [cited by applicant]
ISA/EP, , “PCT Application No. PCT/US22/30859 Invitation to Pay Additional Fees mailed Sep. 14, 2022”, 17 pages. [cited by applicant]