Network security threat intelligence sharing

US2019394227A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2019394227-A1
Application numberUS-201916555975-A
CountryUS
Kind codeA1
Filing dateAug 29, 2019
Priority dateMay 5, 2017
Publication dateDec 26, 2019
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are disclosed for obtaining network security threat information and mitigating threats to improve computing network operations. For example, methods may include receiving a message from a central instance; from outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by an agent device within the private network; receiving a search result of the search from the agent device; transmitting the search result to the central instance, wherein the central instance is configured to generate network security threat information based in part on the search result and share the network security threat information with a plurality of customer instances that are associated with a group of customers; and receiving an alert message from the central instance, wherein the alert message includes information that identifies a network security threat.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system, comprising: a memory; and one or more processors, wherein the memory includes instructions that, when executed, are configured to cause the one or more processors to: implement a plurality of customer instances within a datacenter, wherein each customer instance of the plurality of customer instances is associated with a respective customer network of a plurality of customer networks outside of the datacenter; implement a central instance within the datacenter, wherein the central instance is communicatively coupled to the plurality of customer instances; receive, at a first customer instance of the plurality of customer instances, an alert from a first customer network of the plurality of customer networks, wherein the alert is associated with a network security threat; generate, at the central instance, a search query based on one or more observables associated with the alert; invoke, at a second customer instance of the plurality of customer instances, a search of data of a second customer network associated with the second customer instance based on the search query; receive, at the second customer instance, a search result based on the search of data of the second customer network; conduct, at the central instance, incident analysis comprising determining a risk score associated with the network security threat based on occurrences of the one or more observables associated with the search result; conduct, at the plurality of customer instances, incident enrichment comprising determining running processes and network statistics associated with the plurality of customer networks; conduct, at the central instance, threat association comprising identifying a network security threat actor associated with the alert; and determine, at the plurality of customer instances, security threat remediation based at least in part on the incident analysis, the incident enrichment, and the threat association. 2 . The system of claim 1 , wherein invoking the search of data comprises communicating with an agent device to conduct a search within the second customer network. 3 . The system of claim 1 , wherein invoking the search of data comprises querying a security information and event management database of the second customer network. 4 . The system of claim 1 , wherein the instructions, when executed, are configured to cause the one or more processors to: input, via the second customer instance, data pertaining to occurrences of the one or more observables to a neural network or a support vector machine; and determine the risk score based on a resulting output of the neural network or a support vector machine. 5 . The system of claim 1 , wherein conducting incident enrichment comprises updating a white list, a black list, a firewall rule, or any combination thereof. 6 . The system of claim 1 , wherein conducting incident analysis comprises identifying a kill chain based on the search result, wherein the kill chain comprises a combination of related security vulnerabilities that leads to possible network security compromise, and wherein the security threat remediation is based at least in part on the risk score and the kill chain associated with the incident analysis. 7 . The system of claim 1 , wherein the instructions, when executed, are configured to cause the one or more processors to cause the central instance to relay a message comprising the search query to the second customer instance based on the alert. 8 . The system of claim 1 , wherein the instructions, when executed, are configured to cause the one or more processors to transmit a recommendation to the second customer instance based on the security threat remediation. 9 . A method, comprising: receiving, at a first customer instance of a plurality of customer instances, an alert from a first customer network of a plurality of customer networks, wherein the alert is associated with a network security threat; generating, at a central instance communicatively coupled to the first customer instance, a search query based on one or more observables associated with the alert; invoking, at a second customer instance of the plurality of customer instances, a search of data of a second customer network associated with the second customer instance based on the search query; receiving, at the second customer instance, a search result based on the search of data of the second customer network; performing, at the central instance, incident analysis to determine network security threat information comprising a risk score associated with the network security threat based on occurrences of the one or more observables associated with the search result; performing, at the plurality of customer instances, incident enrichment comprising determining running processes and network statistics associated with the plurality of customer networks; conducting, at the central instance, threat association comprising identifying a network security threat actor associated with the alert; and determining, at the plurality of customer instances, security threat remediation based at least in part on the incident analysis, the incident enrichment, and the threat association. 10 . The method of claim 9 , comprising: invoking, at a third customer instance of the plurality of customer instances, an additional search of data of a third customer network associated with the second customer instance based on the search query; and receiving, at the third customer instance, an additional search result based on the search of data of the third customer network. 11 . The method of claim 10 , wherein performing the incident analysis comprises determining the risk score associated with the network security threat based on occurrences of the one or more observables associated with the search result and the additional search result. 12 . The method of claim 9 , comprising invoking a threat mitigation measure using a framework configured to interface to a plurality of network security products provided by a plurality of software publishers, wherein determining the security threat remediation is based on the threat mitigation measure. 13 . The method of claim 9 , comprising transmitting, via the central instance, an alert message to a third customer instance of the plurality of customer instances, wherein the alert message comprises the network security threat information. 14 . The method of claim 9 , wherein invoking the search of data comprises communicating with an agent device of the second customer network to query a security information and event management database of the second customer network. 15 . A system, comprising: a memory; and one or more processors, wherein the memory includes instructions that, when executed, are configured to cause the one or more processors to: implement a plurality of customer instances within a network, wherein the plurality of customer instances is associated with respective private networks of a plurality of private networks that are outside of the network; implement a central instance within the network, wherein the central instance is communicatively coupled to the plurality of customer instances; receive, at a first customer instance of the plurality of customer instances, an alert from a first private network of the plurality of private networks, wherein the alert is associated with a network security threat; generate, at the central instance, a search query based on one or more observables associated with the alert; invoke, at a second customer instance of the plurality of custom

Assignees

Inventors

Classifications

  • Event detection, e.g. attack signature detection · CPC title

  • G06N20/00Primary

    Machine learning · CPC title

  • Vulnerability analysis · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • for detecting or protecting against malicious traffic · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2019394227A1 cover?
Systems and methods are disclosed for obtaining network security threat information and mitigating threats to improve computing network operations. For example, methods may include receiving a message from a central instance; from outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by…
Who is the assignee on this patent?
Servicenow Inc
What technology area does this patent fall under?
Primary CPC classification G06N20/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Dec 26 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).