Joined and coordinated detection, handling, and prevention of cyberattacks

US11587177B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11587177-B2
Application numberUS-201514919506-A
CountryUS
Kind codeB2
Filing dateOct 21, 2015
Priority dateOct 21, 2014
Publication dateFeb 21, 2023
Grant dateFeb 21, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, devices, systems and computer program products enable monitoring and responding to cyber security attacks. One such system relates to a consortium of monitoring companies and an infrastructure including one or more central monitoring stations or local handling stations for a monitoring company are provided. A central monitoring station of a monitoring company detects a cyberattack that has been launched against a client computer system, and requests a local station to respond to the cyberattack via onsite visits or requests additional resources from other monitoring companies through the consortium system. The central monitoring station also sends to the consortium system updates on a cyberattack that is detected or mitigated by a central monitoring station or local handling station of the monitoring company. The monitoring consortium enables stronger capabilities than any individual monitoring company can offer by the combination and coordination of the efforts and resources of the members.

First claim

Opening claim text (preview).

What is claimed is: 1. A central monitoring station of a monitoring system for detecting and handling cyberattacks to client systems with a management system that manages a consortium of monitoring systems, comprising: a network interface configured to receive and transmit information using a computer network; and a processor and a memory comprising processor executable instructions, the processor executable instructions upon execution by the processor, configuring a plurality of components of the central monitoring station to detect and respond to cyberattacks to client systems, the plurality of components configured to: register the central monitoring station with the management system as a member of the consortium of the monitoring systems; detect a cyberattack to a client computer system; respond to the cyberattack; send an update to the management system on detecting or responding to the cyberattack for sharing by other members of the consortium of monitoring systems; receive data from the management system on detecting and handling a cyberattack created by the management system and other members, wherein each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations associated with one or more specialists with access the client computer systems; and compute a real-time damage assessment based on the detected cyberattack, wherein at least one of the monitoring systems comprises one or more local handling stations, wherein the central monitoring stations and local handling stations in each of the monitoring systems are interconnected with a distinct local network connection; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage; and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems. 2. The central monitoring station of claim 1 , wherein at least one of the plurality of components is further configured to send a notification to the client computer system under attack. 3. The central monitoring station of claim 1 , wherein at least one of the plurality of components sends to the management system information regarding a change in availability of resources associated with the monitoring system or a change of status of detecting or handling the cyberattack by the monitoring system. 4. The central monitoring station of claim 1 , wherein one or more of the plurality of components are further configured to implement predetermined rules to be followed by all central monitoring stations of the members. 5. A computer implemented method of managing a consortium of monitoring systems which detect and handle cyberattacks, comprising: registering each of a plurality of monitoring systems as a member in response to corresponding registration requests for becoming a member of the consortium of monitoring systems, wherein each of the monitoring systems is associated with a distinct, independent business entity and each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations comprising a processor and a memory and monitoring one or more client computer systems for cyberattacks to the client computer systems and associated with one or more specialists who can physically work with the client computer systems, and wherein at least one of the monitoring systems comprises one or more local handling stations; receiving a report in electronic format from a first member coupled to a computer network; processing the electronic report to detect a cyberattack to a client computer system of the first member; responding to the cyberattack with the first member and a second member, wherein the second member assigns computing resources or human resources for mitigating the cyberattack; updating a repository of data related to cyberattacks accessible to members of the consortium; and computing a real-time damage assessment based on the detected cyberattack; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage; and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems. 6. The method of claim 5 , wherein processing the electronic report to detect a cyberattack comprises: receiving the report of the cyberattack from the first member; identifying information relevant to the cyberattack from the repository; sending the identified information to the first member; and logging information included in the report in the repository. 7. A computer program product embodied on one or more non-transitory computer readable media, comprising: program code for registering each of a plurality of monitoring systems as a member in response to corresponding registration requests for becoming a member of a consortium of monitoring systems, wherein each of the monitoring systems is associated with a distinct, independent business entity and each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations comprising a processor and a memory and monitoring one or more client computer systems for cyberattacks to the client computer systems and associated with one or more specialists who can physically work with the client computer systems, and wherein at least one of the monitoring systems comprises one or more local handling stations; program code for receiving a report in electronic format from a first member coupled to a computer network; program code for processing the electronic report to detect a cyberattack to a client computer system of the first member; program code for responding to the cyberattack with the first member and a second member, wherein the second member assigns computing resources or human resources for mitigating the cyberattack; program code for updating a repository of data related to cyberattacks accessible to members of the consortium; and program code for computing a real-time damage assessment based on the detected cyberattack; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • G06Q40/08Primary

    Insurance · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11587177B2 cover?
Methods, devices, systems and computer program products enable monitoring and responding to cyber security attacks. One such system relates to a consortium of monitoring companies and an infrastructure including one or more central monitoring stations or local handling stations for a monitoring company are provided. A central monitoring station of a monitoring company detects a cyberattack that…
Who is the assignee on this patent?
Palantir Technologies Inc
What technology area does this patent fall under?
Primary CPC classification G06Q40/08. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 21 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).