System and method for enforcing compliance with subscription requirements for cyber-attack detection service

US10848397B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10848397-B1
Application numberUS-201715721621-A
CountryUS
Kind codeB1
Filing dateSep 29, 2017
Priority dateMar 30, 2017
Publication dateNov 24, 2020
Grant dateNov 24, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system featuring a cloud-based malware detection system for analyzing an object to determine whether the object is associated with a cyber-attack. Herein, subscription review service comprises a data store storing subscription information. The subscription information includes identifier for the customer and one or more identifiers each associated with a corresponding customer submitter operable to submit an object to the cloud-based malware detection system for analysis. The first customer submitter receives credentials provided by the subscription review service to establish communications with the cloud-based malware detection system. The first customer submitter includes a first submitter identifier that comprises (i) enforcement logic that enforces compliance with a plurality of requirements of the subscription to the cloud-based malware detection system and (ii) reporting logic that transmits a result of the analysis of the object by the cloud-based malware detection system in determining whether the object is associated with a cyber-attack.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a cloud-based malware detection system including at least a processor and a memory, the memory includes object analysis logic that, during execution by the processor, analyzes an object to determine whether the object is associated with a cyber-attack; a portal that provides access over a network to displayable data for a customer to register with and obtain a subscription to the cloud-based malware detection system; and a subscription review service communicatively coupled with the portal, the subscription review service comprises a data store storing subscription information, wherein the subscription information includes an identifier for the customer and one or more identifiers each associated with a corresponding customer submitter being logic operable to submit an object to the cloud- based malware detection system for analysis, wherein the cloud-based malware detection system further comprises a cloud broker to perform one or more inter-cluster analyses to select a cluster to conduct a malware analysis of the object from a plurality of clusters based, at least in part, on the subscription information and operational metadata associated with operations of the plurality of clusters, and a cluster broker communicatively coupled with and remotely located from the cloud broker and deployed within the selected cluster, the cluster broker to perform one or more intra-cluster analyses for causing an object analyzer of the selected cluster to analyze the object to determine whether the analyzed object is associated with a cyber-attack. 2. The system of claim 1 further comprising: a first customer submitter to receive credentials associated with the subscription provided by the subscription review service to establish communications with the cloud-based malware detection system. 3. The system of claim 2 , wherein the first customer submitter being communicatively coupled to a subscriber management system, the subscriber management system to (i) monitor objects including the object being submitted by the first customer submitter for analysis to the cloud-based malware detection system and (ii) enforce compliance with a plurality of requirements of the subscription to the cloud-based malware detection service based on operations performed by at least the first customer submitter. 4. The system of claim 3 , wherein the subscriber management system includes enforcement logic to enforce compliance with the plurality of requirements of the subscription by at least monitoring the operations of the first customer submitter, comparing the operations of the first customer submitter to one or more attributes of the subscription, and altering operations of the first customer submitter in response to detecting that the operations of the first customer submitter exceed limits imposed by the one or more attributes. 5. The system of claim 3 , wherein the subscriber management system includes enforcement logic that (i) collects and aggregates metadata associated with data submissions to the cloud-based malware detection system from a plurality of customer submitters including the first customer submitter associated with the customer and controlled by the subscriber management system, (ii) receives a portion of the subscription information including one or more service attributes establishing a service performance level for the subscription, (iii) analyzes whether the aggregated metadata associated with the data submissions to the cloud-based malware detection system complies with the service performance level established by the one or more service attributes associated with the subscription, and (iv) responsive to detecting that the customer failing to comply with the service performance level, performs an operation to address a failure by the customer in complying with the service performance level associated with the subscription. 6. The system of claim 5 , wherein the analyzing whether the aggregated metadata complies with the service performance level by the enforcement logic comprises determining whether the aggregated metadata indicates that the customer has exceeded a predetermined number or rate of data submissions set for the customer to the cloud- based malware detection system. 7. The system of claim 6 , wherein the performing, by the subscriber management system, of the operation to address the failure by the customer to comply with the service performance level associated with the subscription comprises notifying an administrator for the customer via an alert message issued by the enforcement logic of the subscriber management system to alter the subscription to increase the predetermined number or rate of data submissions for the customer to support a number of data submissions being provided by the customer to the cloud-based malware detection system. 8. The system of claim 6 , wherein the performing, by the subscriber management system, of the operation to address the failure by the customer to comply with the service performance level associated with the subscription comprises altering operations of at least the first customer submitter to reduce a number or rate of data submissions transmitted to the cloud-based malware detection system, the first customer submitter includes a sensor to (i) capture network traffic and (ii) perform a preliminary analysis on the network traffic to determine whether at least the object is suspicious by (a) comparing content of the object to content associated with known malware to produce a result, and (b) comparing the result to an attack threshold being a minimum percentage of content shared with known malware. 9. The system of claim 8 , wherein the altering of the operations by at least the first customer submitter to reduce the number or rate of data submissions transmitted to the cloud-based malware detection system comprises increasing an attack threshold identifying that the objects extracted from the network traffic are potentially associated with a cyber-attack thereby reducing the number of suspicious objects provided by the first customer submitter to the cloud-based malware detection system. 10. The system of claim 3 , wherein the subscriber management system being configured to receive statistical information based on the metadata from the cloud-based malware detection system, and after receipt of the statistical information, the subscriber management system changing the subscription via the portal. 11. The system of claim 3 , wherein the subscriber management system includes enforcement logic to enforce compliance with the plurality of requirements of the subscription by at least monitoring the operations of the first customer submitter, comparing the operations of the first customer submitter to one or more attributes of the subscription that are associated with operations of a submitter, and altering operations of the first customer submitter in response to detecting that the operations of the first customer submitter exceed limits imposed by the one or more attributes. 12. The system of claim 2 , wherein the first customer submitter includes a sensor to capture network traffic, perform a preliminary analysis on the network traffic to identify suspicious traffic, and provide objects extracted from the suspicious traffic to the cloud-based malware detection system for further analysis to determine whether the objects are associated with a cyber-attack, the sensor includes analysis logic operable in a network device communicatively coupled to the cloud-based malware detection system and the subscription review service. 13. The system of claim 12 , wherein the network traffic is identified

Assignees

Inventors

Classifications

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • Vulnerability analysis · CPC title

  • Customer-centric QoS measurements · CPC title

  • Market modelling; Market analysis; Collecting market data · CPC title

  • G06F21/562Primary

    Static detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10848397B1 cover?
A system featuring a cloud-based malware detection system for analyzing an object to determine whether the object is associated with a cyber-attack. Herein, subscription review service comprises a data store storing subscription information. The subscription information includes identifier for the customer and one or more identifiers each associated with a corresponding customer submitter opera…
Who is the assignee on this patent?
Fireeye Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/5067. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 24 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).