Network security threat intelligence sharing

US11575703B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11575703-B2
Application numberUS-201916555975-A
CountryUS
Kind codeB2
Filing dateAug 29, 2019
Priority dateMay 5, 2017
Publication dateFeb 7, 2023
Grant dateFeb 7, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are disclosed for obtaining network security threat information and mitigating threats to improve computing network operations. For example, methods may include receiving a message from a central instance; from outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by an agent device within the private network; receiving a search result of the search from the agent device; transmitting the search result to the central instance, wherein the central instance is configured to generate network security threat information based in part on the search result and share the network security threat information with a plurality of customer instances that are associated with a group of customers; and receiving an alert message from the central instance, wherein the alert message includes information that identifies a network security threat.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a memory; and one or more processors, wherein the memory includes instructions that, when executed, are configured to cause the one or more processors to: implement a plurality of customer instances within a datacenter, wherein each customer instance of the plurality of customer instances is associated with a respective customer network of a plurality of customer networks outside of the datacenter; implement a central instance within the datacenter, wherein the central instance is communicatively coupled to the plurality of customer instances; receive, at a first customer instance of the plurality of customer instances, an alert from a first customer network of the plurality of customer networks, wherein the alert is associated with a network security threat; generate, at the central instance, a search query based on one or more observable s associated with the alert; invoke, at a second customer instance of the plurality of customer instances, a search of data of a second customer network associated with the second customer instance based on the search query; receive, at the second customer instance, a search result based on the search of data of the second customer network, wherein the search result reflects occurrences of the one or more observables in the second customer network; conduct, at the central instance, incident analysis comprising: identifying a kill chain based on the search result, wherein the kill chain comprises a combination of related security vulnerabilities that leads to possible network security compromise; and determining a risk score associated with the network security threat based on the occurrences of the one or more observables associated with the search result; conduct, at the plurality of customer instances, incident enrichment comprising determining running processes and network statistics associated with the plurality of customer networks; conduct, at the central instance, threat association comprising identifying a network security threat actor associated with the alert based at least in part on the kill chain and the search result that reflects the occurrences of the one or more observables in the second customer network; determine, at the plurality of customer instances, security threat remediation by selecting a remediation measure to break the kill chain; implement the remediation measure to block communication with the network security threat actor based at least in part on the incident analysis, the incident enrichment, and the threat association; and transmit a recommendation to the second customer instance based on the security threat remediation. 2. The system of claim 1 , wherein invoking the search of data comprises communicating with an agent device to conduct a search within the second customer network. 3. The system of claim 1 , wherein invoking the search of data comprises querying a security information and event management database of the second customer network. 4. The system of claim 1 , wherein the instructions, when executed, are configured to cause the one or more processors to: input, via the second customer instance, data pertaining to the occurrences of the one or more observables to a neural network or a support vector machine; and determine the risk score based on a resulting output of the neural network or the support vector machine. 5. The system of claim 1 , wherein conducting incident enrichment comprises updating a white list, a black list, a firewall rule, or any combination thereof. 6. The system of claim 1 , wherein the instructions, when executed, are configured to cause the one or more processors to cause the central instance to relay a message comprising the search query to the second customer instance based on the alert. 7. A method, comprising: receiving, at a first customer instance of a plurality of customer instances, an alert from a first customer network of a plurality of customer networks, wherein the alert is associated with a network security threat; generating, at a central instance communicatively coupled to the first customer instance, a search query based on one or more observables associated with the alert; invoking, at a second customer instance of the plurality of customer instances, a search of data of a second customer network associated with the second customer instance based on the search query; receiving, at the second customer instance, a search result based on the search of data of the second customer network, wherein the search result reflects occurrences of the one or more observables in the second customer network; performing, at the central instance, incident analysis comprising: identifying a kill chain based on the search result, wherein the kill chain comprises a combination of related security vulnerabilities that leads to possible network security compromise; and determining network security threat information comprising a risk score associated with the network security threat based on the occurrences of the one or more observables associated with the search result; performing, at the plurality of customer instances, incident enrichment comprising determining running processes and network statistics associated with the plurality of customer networks; conducting, at the central instance, threat association comprising identifying a network security threat actor associated with the alert based at least in part on the kill chain and the search result that reflects the occurrences of the one or more observables in the second customer network; determining, at the plurality of customer instances, security threat remediation by selecting a remediation measure to break the kill chain; implementing the remediation measure to block communication with the network security threat actor based at least in part on the incident analysis, the incident enrichment, and the threat association; and transmitting a recommendation to the second customer instance based on the security threat remediation. 8. The method of claim 7 , comprising: invoking, at a third customer instance of the plurality of customer instances, an additional search of data of a third customer network associated with the second customer instance based on the search query; and receiving, at the third customer instance, an additional search result based on the additional search of data of the third customer network, wherein the additional search result reflects the occurrences of the one or more observables in the third customer network. 9. The method of claim 8 , wherein performing the incident analysis comprises determining the risk score associated with the network security threat based on the occurrences of the one or more observables associated with the search result and the additional search result. 10. The method of claim 7 , comprising invoking a threat mitigation measure using a framework configured to interface to a plurality of network security products provided by a plurality of software publishers, wherein determining the security threat remediation is based on the threat mitigation measure. 11. The method of claim 7 , comprising transmitting, via the central instance, an alert message to a third customer instance of the plurality of customer instances, wherein the alert message comprises the network security threat information. 12. The method of claim 7 , wherein invoking the search of data comprises communicating with an agent device of the second customer network to query a security information and event management database of the second customer network. 13. A system, comprising: a memory; and one or more pr

Assignees

Inventors

Classifications

  • G06N20/00Primary

    Machine learning · CPC title

  • Vulnerability analysis · CPC title

  • Indexing; Web crawling techniques · CPC title

  • for detecting or protecting against malicious traffic · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11575703B2 cover?
Systems and methods are disclosed for obtaining network security threat information and mitigating threats to improve computing network operations. For example, methods may include receiving a message from a central instance; from outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by…
Who is the assignee on this patent?
Servicenow Inc
What technology area does this patent fall under?
Primary CPC classification G06N20/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 07 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).