Source entities of security indicators

US11962609B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11962609-B2
Application numberUS-201616076274-A
CountryUS
Kind codeB2
Filing dateFeb 12, 2016
Priority dateFeb 12, 2016
Publication dateApr 16, 2024
Grant dateApr 16, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Examples disclosed herein relate to source entities of security indicators. Some examples disclosed herein enable identifying, in a security information sharing platform, a security indicator that is originated from a source entity where the security indicator comprises an observable. Some examples further enable determining a reliability level of the source entity based on at least one of: security events, sightings of the observable, a first set of user feedback information that is submitted for the security indicator by users of the security information sharing platform, or a second set of user feedback information that is collected from external resources that are external to the security information sharing platform.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method comprising: identifying, by a processor, a security indicator that is originated from a first source entity of a plurality of source entities in a security information sharing platform, wherein the security indicator provides a warning of a potential security threat and specifies a particular address or domain name of the potential security threat; determining, by the processor, a total count of sightings of the particular address or domain name of the potential security threat as observed by the plurality of source entities in the security information sharing platform; determining a reliability level of the first source entity based on a set of user feedback information including votes about accuracy of the security indicator and the total count of sightings of the particular address or domain name of the potential security threat, wherein a higher number of votes about the accuracy of the security indicator and a higher count of sightings of the particular address or domain name of the potential security threat result in a higher reliability level of the first source entity; determining a score of the security indicator based on the reliability level of the first source entity; and comparing the score of the security indicator to at least one threshold value to determine whether the security indicator is an actual security threat. 2. The method of claim 1 , further comprising: determining an authenticity level of the first source entity based on a type of the first source entity, wherein the type of the first source entity comprises: a non-trusted source type or a trusted source type. 3. The method of claim 1 , wherein the set of user feedback information about the security indicator further includes information provided by an external resource that is external to the security information sharing platform. 4. The method of claim 1 , further comprising: providing a survey to collect the set of user feedback information about the security indicator from users of the security information sharing platform. 5. The method of claim 1 , further comprising: obtaining an article via a second source entity; determining whether the article includes information related to the security indicator; and determining a reliability level of the second source entity based on the determination of whether the article includes the information related to of the security indicator. 6. The method of claim 1 , wherein comparing the score of the security indicator to the at least one threshold value includes: comparing the score of the security indicator to a first threshold value and a second threshold value; in response to a determination that the score of the security indicator is below the first threshold value, continuing monitoring the security indicator; in response to a determination that the score of the security indicator is above the first threshold value hut below the second threshold value, generating a recommendation to perform a further investigation on the security indicator; and in response to a determination that the score of the security indicator is above the second threshold value, determining that the security indicator is the actual security threat. 7. The method of claim 2 , wherein determining the score of the security indicator is further based on the authenticity level of the first source entity. 8. The method of claim 5 , wherein the information related to the security indicator comprises at least one of: a threat actor, a campaign, a technique/tactic/procedure (TTP), an organization, an industry sector, or a community. 9. The method of claim 6 , further comprising: in response to the determination that the security indicator is the actual security threat, blocking any event that matches the security indicator. 10. A non-transitory machine-readable storage medium storing instructions executable by a processor of a computing device to cause the processor to: identify a first security indicator that is originated from a first source entity of a plurality of source entities in a security information sharing platform, wherein the first security indicator provides a warning of a first potential security threat and specifies a first address or domain name of the first potential security threat; determine a total count of sightings of the first address or domain mane of the first potential security threat as observed by the plurality of source entities in the security information sharing platform; determine a reliability level of the first source entity based on a first set of user feedback information including votes about accuracy of the first security indicator and the total count of sightings of the first address or domain name of the first potential security threat, wherein a higher number of votes about the accuracy of the first security indicator and a higher count of sightings of the first address or domain name of the first potential security threat result in a higher reliability level of the first source entity; determine a score of the first security indicator based on the reliability level of the first source entity; and compare the score of the first security indicator to at least one threshold value to determine whether the first security indicator is an actual security threat. 11. The non-transitory machine-readable storage medium of claim 10 , wherein the instructions are executable to cause the processor to: identify a second security indicator that is originated from a second source entity of the plurality of source entities in the security information sharing platform, the second security indicator comprising a second address or domain name of a second potential security threat; determine a reliability level of the second source entity based on a total count of sightings of the second address or domain name of the second potential security threat as observed by the plurality of source entities in the security information sharing platform; determine an authenticity level of the second source entity based on a type of the second source entity; and determine an indicator score of the second security indicator based on the reliability level of the second source entity and the authenticity level of the second source entity. 12. The non-transitory machine-readable storage medium of claim 10 , wherein the instructions are executable to cause the processor to: determine a number of security events that are created in the security information sharing platform, wherein the security events include the first security indicator; and determine the reliability level of the first source entity based on the number of security events, the first set of user feedback information about the first security indicator, and the total count of sightings of the first address or domain name of the first potential security threat. 13. The non-transitory machine-readable storage medium of claim 10 , wherein the instructions that cause the processor to determine the total count of sightings of the first address or domain name include instructions that cause the processor to: obtain, from a second source entity, a first sighting of the first address or domain name, the first sighting of the first address or domain name indicating that the first address or domain name has been observed by the second source entity; obtain, from a third source entity, a second sighting of the first address or domain name, the second sighting of the first address or domain name indicating that the first address or domain name has been observed by the third source entity; and determine the total count of sightings of the first

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • H04L12/22Primary

    Arrangements for preventing the taking of data from a data transmission channel without authorisation (means for verifying the identity or the authority of a user of a secure or secret communication system H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11962609B2 cover?
Examples disclosed herein relate to source entities of security indicators. Some examples disclosed herein enable identifying, in a security information sharing platform, a security indicator that is originated from a source entity where the security indicator comprises an observable. Some examples further enable determining a reliability level of the source entity based on at least one of: sec…
Who is the assignee on this patent?
Entit Software Llc, Micro Focus Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 16 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).