IP Library › Granted Patent US 12,739,274
Granted Patent B2
US 12,739,274 · App. 18/400,654 · Granted Sep 15, 2026

Large scale security data aggregation, with machine learning analysis and use of that security data aggregation

Inventors: Philip Sellars (Cambridge, GB); Stephen Pickman (Huntington, GB); Andres Curto Martin (Cambridge, GB); Tim Bazalgette (Knebworth, GB); Soufian El Yadmani (The Hague, NL)
Assignee: Darktrace Holdings Limited
H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,274
App. No.
18/400,654
Granted
Sep 15, 2026
Kind
B2
Abstract

An apparatus to protect a network from a potential cyber threat associated with a new endpoint to that network is described. The apparatus comprises a memory to store a representation of an artificial intelligence (AI) model. The AI model is at least partly trained based on information aggregated from a first information source and a second information source. The first information source comprises information about a first factor that at least partly characterizes endpoints. The second information source comprises information about a second, different, factor that at least partly characterizes endpoints. The apparatus further comprises a processor. The processor is to receive information about the new endpoint to that network. The processor is further to determine, using the AI model, whether the information about the new endpoint indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat. The processor is further to, in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

Claims (46)

1 . An apparatus to protect a network from a potential cyber threat associated with a new endpoint to that network, the apparatus comprising: a memory to store a representation of an artificial intelligence (AI) model, where the AI model is at least partly trained based on information aggregated from a first information source and a second information source, where the first information source comprises information about a first factor that at least partly characterizes endpoints, and where the second information source comprises information about a second, different, factor that at least partly characterizes endpoints; and a processor to: receive information about the new endpoint to that network; determine, using the AI model, whether the information about the new endpoint indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat by identifying that a metric defining a distance between a factor value representative of the characteristic of the new endpoint and a corresponding factor value of endpoints known to be associated with the cyber threat is within a specified range indicative of characteristic overlap; and in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

2 . The apparatus of claim 1 , wherein factors that at least partly characterize endpoints comprise one or more of:

an identifier of the new endpoint;

geographic region of the new endpoint;

age of the new endpoint;

where the new endpoint is registered;

content accessible at the new endpoint;

an activity time associated with the new endpoint;

a number of connections associated with the new endpoint;

an identity of one or more nodes that have communicated with the new endpoint; and

metadata associated with the new endpoint.

3 . The apparatus of claim 2 , wherein the information about the new endpoint includes a factor value corresponding to a factor that at least partly characterizes endpoints including the new endpoint.

4 . The apparatus of claim 1 , wherein the information aggregated from the first information source and the second information source is derived from one or more of: publicly available information; privately held information; a database comprising information about malicious endpoints; a database comprising information about safe endpoints; a database comprising information about emails sent by malicious entities; a database comprising information about emails sent by safe entities; or data provided by a fleet of cyber security appliances.

5 . An apparatus to protect a network from a potential cyber threat associated with a new endpoint to that network, the apparatus comprising: a memory to store a representation of an artificial intelligence (AI) model, wherein the AI model is trained to detect a property associated with the new endpoint, where the property is masked in the information about the new endpoint; and a processor to: receive information about the new endpoint to that network; determine using the AI model, whether the information about the new endpoint indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat; and in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

6 . The apparatus of claim 5 , wherein the property is one of:

an identifier of the new endpoint that is masked by being represented by a different identifier;

an embedding in a message that is masked from being detected by a recipient of the message; and

a service associated with the new endpoint.

7 . The apparatus of claim 5 , wherein the AI model is at least partly trained based on Masked-Language Modeling (MLM).

8 . An apparatus, to protect a network from a potential cyber threat associated with a new endpoint to that network, the apparatus comprising: a memory to store a representation of an artificial intelligence (AI) model, wherein the AI model is trained to detect an indication that a command and control server is associated with the new endpoint, where the AI model is at least partly trained based on information indicative of a behavior profile of command and control servers; and a processor to: receive information about the new endpoint to that network; determine using the AI model, whether the information about the new endpoint indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat; and in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

9 . The apparatus of claim 8 , wherein the information indicative of the behavior profile of command and control servers comprises one or more of:

information derived from a certificate associated with a known command and control server;

a metric indicative of a pattern of responses from different services;

a fingerprint indicative of a known command and control server;

a handshake indicative of a known command and control server;

information about registered domains; and

information associated with communications with a known command and control server.

10 . The apparatus of claim 1 , wherein the aggregated information comprises a metric that at least partly characterizes a known endpoint.

11 . The apparatus of claim 10 , wherein the metric is derived from data associated with an activity of the known endpoint, where the data is obtained by a plurality of detectors, and where the metric is a combined metric based on a combination of a plurality of metrics determined by the plurality of detectors that has been weighted according to a relevance of the metric determined by each detector.

12 . The apparatus of claim 11 , wherein the combined metric is based on a distribution indicative of how many detectors of the plurality of detectors have determined that the metric associated with the detector falls within one of a set of intervals that represent a range of metric values, and where a weighting function is applied to the metric value associated with each interval based on how many detectors fall within the interval.

13 . The apparatus of claim 11 , wherein the data associated with the activity of the known endpoint is indicative of:

a popularity of communications with the known endpoint or a node associated with the known endpoint; or

a rarity of communications with the known endpoint or a node associated with the known endpoint.

14 . The apparatus of claim 1 , wherein the processor is to receive the information about the new endpoint, and in response, determine whether information about the new endpoint indicates that the characteristic of the new endpoint overlaps with the profile of characteristics.

15 . The apparatus of claim 1 , wherein the apparatus is a cyber security appliance.

16 . The apparatus of claim 1 , wherein one or more of the first information source and the second information source belongs to a fleet of cyber security appliances.

17 . A non-transitory computer readable medium storing instructions readable and executable by a processor to:

determine, using an artificial intelligence (AI) model, whether information about a new endpoint to a network indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat by identifying that a metric defining a distance between a factor value representative of the characteristic of the new endpoint and a corresponding factor value of endpoints known to be associated with the cyber threat is within a specified range indicative of characteristic overlap, where the AI model is at least partly trained based on information aggregated from a first information source and a second information source, where the first information source comprises information about a first factor that at least partly characterizes endpoints, and where the second information source comprises information about a second, different, factor that at least partly characterizes endpoints; and

in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

18 . A computer-implemented method of protecting a network from a potential cyber threat associated with a new endpoint to the network, the method comprising:

determining, using an artificial intelligence (AI) model, whether information about the new endpoint indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat by identifying that a metric defining a distance between a factor value representative of the characteristic of the new endpoint and a corresponding factor value of endpoints known to be associated with the cyber threat is within a specified range indicative of characteristic overlap, where the AI model is at least partly trained based on information aggregated from a first information source and a second information source, where the first information source comprises information about a first factor that at least partly characterizes endpoints, and where the second information source comprises information about a second, different, factor that at least partly characterizes endpoints; and

in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instructing an action to be taken to protect the network from the cyber threat.

19 . The computer-implemented method of claim 18 , wherein the AI model is trained to detect an indication that a command and control server is associated with the new endpoint, where the AI model is at least partly trained based on information indicative of a behavior profile of command and control servers.

20 . A non-transitory computer readable medium storing instructions readable and executable by a processor to:

determine, using an artificial intelligence (AI) model, whether information about a new endpoint to a network indicates that a characteristic of the new endpoint overlaps with a profile of characteristics associated with endpoints known to be associated with a cyber threat, where the AI model is trained to detect an indication that a command and control server is associated with the new endpoint, where the AI model is at least partly trained based on information indicative of a behavior profile of command and control servers; and

in response to determining that the characteristic of the new endpoint overlaps with the profile of characteristics, instruct an action to be taken to protect the network from the cyber threat.

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2024
From: SELLARS, PHILIP; PICKMAN, STEPHEN; MARTIN, ANDRE´S CURTO; BAZALGETTE, TIM; YADMANI, SOUFIAN EL
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 068230/0001 →
Continuity (3)
Provisional Application 63470571 · Jun 2, 2023
Provisional Application 63436425 · Dec 30, 2022
Related Publication 20240223596A1 · Jul 4, 2024
References Cited (21)
US 10268821B2 · Stockdale · 2019 [cited by applicant]
US 10419466B2 · Ferguson · 2019 [cited by applicant]
US 10701093B2 · Dean · 2020 [cited by applicant]
US 11463457B2 · Bazalgette · 2022 [cited by examiner]
US 11539716B2 · Meng · 2022 [cited by applicant]
US 20200244673A1 · Stockdale · 2020 [cited by applicant]
US 20200285737A1 · Kraus · 2020 [cited by applicant]
US 20210141897A1 · Seifert · 2021 [cited by examiner]
US 20210273958A1 · McLean · 2021 [cited by examiner]
US 20210398109A1 · Huber, Jr. · 2021 [cited by applicant]
US 20220038489A1 · Thakur · 2022 [cited by applicant]
US 20220108238A1 · Liposky · 2022 [cited by examiner]
US 20220147607A1 · Streit · 2022 [cited by applicant]
US 20220150275A1 · McNee · 2022 [cited by applicant]
US 20220164697A1 · Subramaniam · 2022 [cited by examiner]
US 20220337488A1 · Najman · 2022 [cited by examiner]
US 20220414344A1 · Makki Niri · 2022 [cited by applicant]
US 20230063913A1 · Balaji · 2023 [cited by applicant]
US 20230206261A1 · Cella · 2023 [cited by applicant]
US 20230328086A1 · Kapoor · 2023 [cited by examiner]
US 20240106846A1 · Kapoor · 2024 [cited by examiner]