Unstructured security threat information analysis

US9716721B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9716721-B2
Application numberUS-201414473743-A
CountryUS
Kind codeB2
Filing dateAug 29, 2014
Priority dateAug 29, 2014
Publication dateJul 25, 2017
Grant dateJul 25, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for creating structured data using data received from unstructured textual data sources. One of the methods includes receiving unstructured textual data, identifying one or more keywords in the unstructured textual data, determining one or more patterns included in the unstructured textual data using the identified keywords, identifying one or more intelligence types that correspond with the unstructured textual data using the determined patterns, and associating, for each of the identified intelligence types, a data subset from the unstructured textual data with the respective intelligence type.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method comprising: receiving, by an analysis system that includes one or more computers, a plurality of unstructured textual datasets that each include information about a respective potential security threat; determining that a first subset of the plurality of unstructured textual datasets and a second, different subset of the plurality of unstructured textual datasets both comprise information about a particular threat, the second, different subset being a different subset than the first subset; discarding the first subset in response to determining that the first subset of the plurality of unstructured textual datasets and the second, different subset of the plurality of unstructured textual datasets both comprise information about the particular threat; for each respective subset in the plurality of unstructured textual datasets that has not been discarded: identifying, by the analysis system, one or more keywords in the respective subset; determining, by the analysis system, one or more patterns included in the respective subset using the identified one or more keywords; identifying, by the analysis system, one or more intelligence types that correspond with the respective subset using the one or more patterns; and associating, by the analysis system for each respective intelligence type of the identified one or more intelligence types, the respective subset from the plurality of unstructured textual datasets with the respective intelligence type; determining a rule for a third party that indicates that the third party should receive data associated with a particular intelligence type of the one or more intelligence types; determining that the second subset of the plurality of unstructured textual datasets is associated with the particular intelligence type; and providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party. 2. The method of claim 1 , wherein associating, for each respective intelligence type of the identified one or more intelligence types, the respective subset from the plurality of unstructured textual datasets with the respective intelligence type comprises storing, for each respective intelligence type of the identified one or more intelligence types, at least one new record, in a database, specific to the respective intelligence type that each comprises information from the respective subset. 3. The method of claim 1 , wherein: receiving the plurality of unstructured textual datasets comprises receiving a security advisory that identifies at least one of a particular hardware device or a particular software application; determining that the first subset of the plurality of unstructured textual datasets and the second, different subset of the plurality of unstructured textual datasets both comprise information about the particular threat comprises determining that the first subset and the second, different subset both comprise information about the particular hardware device or the particular software application; and providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party comprises providing, to the third party, the second subset that comprises information about the particular hardware device or the particular software application. 4. The method of claim 1 , wherein receiving the plurality of unstructured textual datasets comprises receiving at least some of the plurality of unstructured textual datasets from a government source or a security source. 5. The method of claim 1 , wherein identifying the one or more intelligence types that correspond with the respective subset using the one or more patterns comprises: determining one or more rules using the one or more patterns; and identifying the one or more intelligence types that correspond with the respective subset using the one or more rules. 6. The method of claim 1 , wherein providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party is responsive to determining the rule for the third party that indicates that the third party should receive data associated with the particular intelligence type of the one or more intelligence types and determining that the second subset of the plurality of unstructured textual datasets is associated with the particular intelligence type. 7. The method of claim 6 , wherein providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party comprises providing instructions to the third party for presentation of information included in the second subset. 8. A system comprising: one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising: receiving a plurality of unstructured textual datasets that each include information about a respective potential security threat; determining that a first subset of the plurality of unstructured textual datasets and a second, different subset of the plurality of unstructured textual datasets both comprise information about a particular threat, the second, different subset being a different subset than the first subset; discarding the first subset in response to determining that the first subset of the plurality of unstructured textual datasets and the second, different subset of the plurality of unstructured textual datasets both comprise information about the particular threat; for each respective subset in the plurality of unstructured textual datasets that has not been discarded: identifying one or more keywords in the respective subset; determining one or more patterns included in the respective subset using the identified one or more keywords; and identifying one or more intelligence types that correspond with the respective subset using the one or more patterns; and associating, for each respective intelligence type of the identified one or more intelligence types, the respective subset from the plurality of unstructured textual datasets with the respective intelligence type; determining a rule for a third party that indicates that the third party should receive data associated with a particular intelligence type of the one or more intelligence types; determining that the second subset of the plurality of unstructured textual datasets is associated with the particular intelligence type; and providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party. 9. The system of claim 8 , wherein associating, for each respective intelligence type of the identified one or more intelligence types, the respective subset from the plurality of unstructured textual datasets with the respective intelligence type comprises storing, for respective intelligence type of the identified one or more intelligence types, at least one new record, in a database, specific to the respective intelligence type that each comprises information from the respective subset. 10. The system of claim 8 , wherein providing the second subset of the plurality of unstructured textual datasets that is associated with the particular intelligence type to the third party is responsive to determining the rule for the third party that indicates that the third party should receive data associated with the particular intelligence type of the one

Assignees

Inventors

Classifications

  • for detecting or protecting against malicious traffic · CPC title

  • Presentation of query results · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • using natural language analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9716721B2 cover?
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for creating structured data using data received from unstructured textual data sources. One of the methods includes receiving unstructured textual data, identifying one or more keywords in the unstructured textual data, determining one or more patterns included in the unstructured textual data using…
Who is the assignee on this patent?
Accenture Global Services Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 25 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).