Systems and methods for predicting the likelihood of cyber-threats leveraging intelligence associated with hacker communities

US2020036743A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2020036743-A1
Application numberUS-201916522001-A
CountryUS
Kind codeA1
Filing dateJul 25, 2019
Priority dateJul 25, 2018
Publication dateJan 30, 2020
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Various embodiments of a system and methods for reasoning about enterprise-related external cyber threats using a rule-leaning approach are disclosed.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method of predicting cyber threats, comprising: providing a processor in communication with a tangible storage medium storing instructions that are executed by the processor to perform operations comprising: accessing a first dataset defining communications from forums and marketplaces associated with a hacker community; learning a plurality of rules using a plurality of indicators generated from the first dataset and ground truth information associated with known cyberattacks, the plurality of indicators including mappings between a vulnerability and a platform known to be susceptible to the vulnerability; and predicting a cyber threat, including: identifying an indicator of the plurality of indicators from a second dataset, the second dataset defining additional communications from the hacker community and the indicator being a precondition to a corresponding rule of the plurality of rules, and applying information associated with the indicator to the corresponding rule of the plurality of rules to output at least one prediction of an attack associated with the cyber threat. 2 . The method of claim 1 , further comprising generating the plurality of rules by deriving a set of probability boundaries of future actions using an annotated probabilistic temporal logic rules framework and narrowing the set of probability boundaries. 3 . The method of claim 2 , wherein one of the plurality of rules defines a probability value for the attack associated with the cyber threat occurring within a predetermined time interval of a condition being true. 4 . The method of claim 3 , wherein a point frequency function of the annotated probabilistic temporal logic rules framework is applied to output a frequency value for the attack following identification of the indicator from the second dataset in an exact time interval and defines a predetermined precise temporal relationship between the attack and the indicator. 5 . The method of claim 2 , wherein an existential frequency function of the annotated probabilistic temporal logic rules framework is applied to output a frequency value for the attack following identification of the indicator within a predetermined number of time points and defines a specified temporal relationship between the attack and the indicator. 6 . The method of claim 4 , wherein the frequency value for the attack following the indicator in an exact time interval is calculated using a probability interval. 7 . The method of claim 5 , wherein the frequency value for the attack following the indicator within a predetermined number of time points is calculated using a probability interval. 8 . The method of claim 1 , wherein a plurality of rule-learning approaches are applied to learn a set of temporal correlations between the first dataset and the known cyberattacks. 9 . The method of claim 1 , wherein a plurality of indicator extractors are applied to extract indicators from the first dataset and assigns a confidence score to extraction of the indicator.

Assignees

Inventors

Classifications

  • G06N5/025Primary

    Extracting rules from data · CPC title

  • Fuzzy inferencing · CPC title

  • Recurrent networks, e.g. Hopfield networks · CPC title

  • Vulnerability analysis · CPC title

  • gathering intelligence information for situation awareness or reconnaissance · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2020036743A1 cover?
Various embodiments of a system and methods for reasoning about enterprise-related external cyber threats using a rule-leaning approach are disclosed.
Who is the assignee on this patent?
Almukaynizi Mohammed, Marin Ericsson, Shakarian Paulo, and 3 more
What technology area does this patent fall under?
Primary CPC classification G06N5/025. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 30 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).