Threat-aware microvisor
US-2015199513-A1 · Jul 16, 2015 · US
US10148679B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10148679-B2 |
| Application number | US-201615051528-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 23, 2016 |
| Priority date | Dec 9, 2015 |
| Publication date | Dec 4, 2018 |
| Grant date | Dec 4, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems, methods, and apparatus, including computer programs encoded on computer storage media, for obtaining, processing, and presenting data related to security events, and for implementing courses of action to protect assets in response to the security events. An event management module identifies malicious activity present on a first network domain and/or a second network domain based on received network domain activity. A threat intelligence module receives data identifying the malicious activity in first data constructs of a predefined data structure. The threat intelligence module obtains additional data related to the identified malicious activity and generates second data constructs that include enriched data regarding the malicious activity. The enriched data includes data describing a campaign in which at least a portion of the malicious activity is involved and one or more courses of action. A course of action module receives the second data constructs and implements a given course of action.
Opening claim text (preview).
What is claimed is: 1. A system comprising: an event management device adapted to: receive, for a network of an organization, network domain activity that includes first domain activity data from a first network domain and second domain activity from a second network domain; identify malicious activity present on at least one of the first network domain or the second network domain based on the received network domain activity; determine whether the malicious activity indicates a new attack pattern that is not identified by data in a pattern database by comparing the malicious activity with attack patterns identified by data in the pattern database; and in response to determining that the malicious activity indicates a new attack pattern that is not identified by data in the pattern database: generate one or more first data constructs of a predefined data structure that each include data that identifies the malicious activity; and store the one or more first data constructs in the pattern database; a threat intelligence device connected to the event management device and adapted to: receive, from the event management device, the one or more first data constructs of the predefined data structure that identify the malicious activity; in response to receiving the one or more first data constructs of the predefined data structure that identify the malicious activity: determine, using the one or more first data constructs that identify the malicious activity, whether additional data related to the identified malicious activity is available from one or more third party sources; and in response to determining that additional data related to the identified malicious activity is available from the one or more third party sources, generate, using the data identifying the malicious activity and the additional data, one or more second data constructs of the predefined data structure that include data describing (i) a campaign of related malicious activity in which at least a portion of the malicious activity is involved and (ii) one or more courses of action for mitigating the campaign of related malicious activity, wherein each of the one or more second data constructs are different data constructs from and comprise different data than each of the one or more first data constructs, and the campaign of related malicious activity is a) by a common malicious actor as an actor for the malicious activity, b) with common tactics, techniques, and procedures as those of the malicious activity, c) with common observables as those of the malicious activity, or d) with common security incidents to those of the malicious activity; and a course of action device connected to the threat intelligence device and adapted to: receive the one or more second data constructs from the threat intelligence device; and implement, for the network for the organization and using the one or more second data constructs, a given course of action of the one or more courses of action. 2. The system of claim 1 further comprising a connection processor configured to coordinate processing functions between the event management device, the threat intelligence device, and the course of action device, and configured to communicate messages between the event management device, the threat intelligence device, and the course of action device using the first and second data constructs of the predefined data structure. 3. The system of claim 1 , wherein the one or more first data constructs includes at least one of: (i) an incident data construct that includes data describing a particular security event identified from the received network domain activity; (ii) an indicator data construct that includes data describing attack patterns identified from the received network domain activity; or (iii) an actor data construct that includes data describing a malicious actor that caused at least a portion of the malicious activity. 4. The system of claim 1 , wherein one or more second data constructs include at least one of (i) a campaign data construct that includes data describing a malicious campaign; (ii) a weakness data construct that includes data describing a weakness of the network; or (iii) a course of action data construct that includes data describing at least one of the one or more courses of action. 5. A computer-implemented method comprising: receiving, by an event management device and for a network of an organization, network domain activity that includes first domain activity data from a first network domain and second domain activity from a second network domain; identifying, by the event management device, malicious activity present on at least one of the first network domain or the second network domain based on the received network domain activity; determining whether the malicious activity indicates a new attack pattern that is not identified by data in a pattern database by comparing the malicious activity with attack patterns identified by data in the pattern database; in response to determining that the malicious activity indicates a new attack pattern that is not identified by data in the pattern database: generating, by the event management device, one or more first data constructs of a predefined data structure that each include data that identifies the malicious activity; and storing, by the event management device, the one or more first data constructs in the pattern database; receiving, by a threat intelligence device and from the event management device, the one or more first data constructs of the predefined data structure that identify the malicious activity; in response to receiving the one or more first data constructs of the predefined data structure that identify the malicious activity: determining, by the threat intelligence device and using the one or more first data constructs that identify the malicious activity, whether additional data related to the identified malicious activity is available from one or more third party sources; and in response to determining that additional data related to the identified malicious activity is available from the one or more third party sources, generating, by the threat intelligence device and using the data identifying the malicious activity and the additional data, one or more second data constructs of the predefined data structure that include data describing (i) a campaign of related malicious activity in which at least a portion of the malicious activity is involved and (ii) one or more courses of action for mitigating the campaign of related malicious activity, wherein each of the one or more second data constructs are different data constructs from and comprise different data than each of the one or more first data constructs, and the campaign of related malicious activity is a) by a common malicious actor as an actor for the malicious activity, b) with common tactics, techniques, and procedures as those of the malicious activity, c) with common observables as those of the malicious activity, or d) with common security incidents to those of the malicious activity; receiving, by a course of action device, the one or more second data constructs from the threat intelligence device; and implementing, by the course of action device for the network for the organization and using the one or more second data constructs, a given course of action of the one or more courses of action. 6. The method of claim 5 , wherein the predefined data structure comprises a Structured Threat Information Expression STIX data structure. 7. The method of claim 5 , wherein the one or more first data constructs includes at least one of: (i) an incident data construct that includes data describing a particular security event identified from the received networ
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Vulnerability analysis · CPC title
Filtering policies (mail message filtering H04L51/212) · CPC title
involving event detection and direct action · CPC title
Traffic logging, e.g. anomaly detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.