US2022300659A1PendingUtilityA1

Data breach prevention and remediation

Assignee: Cyber Team SixPriority: Jul 3, 2019Filed: Jun 9, 2022Published: Sep 22, 2022
Est. expiryJul 3, 2039(~12.9 yrs left)· nominal 20-yr term from priority
G06F 21/6245H04L 63/1416H04L 9/3239G06F 16/245H04L 63/10G06F 21/64G06F 21/31G06F 21/602G06F 16/258G06F 21/6227
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computer-implemented threat detection method and systems are provided. The method comprises discovering threat data associated with a first entity, translating the threat data to one or more threat models, translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model and translating the parameter threat model to one or more identification queries. The one or more identification queries may be executed and the generated results may be translated to result data in a first format. The one or more result data models may be published from the result data in one or more formats or to one or more locations.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented system comprising one or more processors for communicating with one or more databases to transmit threat-related data, the one or more processors executing logic code that causes the computer-implemented system to:
 discover threat data associated with a first entity, the threat data including indicators of a data security breach, wherein a threat model parameter generator translates the threat data to at least a parameter threat model with one or more parameters;   translate the threat model parameter to one or more identification queries based on one or more configurations stored on one or more databases;   execute the one or more identification queries to generate first results; and   format the first results to one or more data formats that are used to identify at least one threat target for the first entity based on the one or more parameters in the parameter threat model.   
     
     
         2 . The system of  claim 1 , wherein the first results comprise at least one of the first entity's unique customer identifier, a compromise timestamp, a threat tag, an attribution tag, a provider tag or a feed tag. 
     
     
         3 . The system of  claim 1 , wherein the threat data indicators are associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy session, compromised card information or phishing domains. 
     
     
         4 . The system of  claim 1 , wherein the first results are aggregated and configured into a data format usable by the first entity. 
     
     
         5 . The system of  claim 1 , wherein the first results are translated to a format based on a format suitable for a computing technology used by the first entity. 
     
     
         6 . The system of  claim 1 , wherein the treat data includes indicators of financial compromise (IOFC) such that a single IOFC is utilized to create several threat models of the same or different threat model types. 
     
     
         7 . The system of  claim 6 , wherein the IOFC comprises at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains. 
     
     
         8 . The system of  claim 1 , wherein the parameter threat model includes parameters associated with at least one of equality, inequality, full text, and partial text matches, wherein the parameters are used to identify a threat target associated with the first entity. 
     
     
         9 . The system of  claim 8 , wherein the parameter threat model is collected from a parameter model interface to translate the parameter threat model into one or more identification queries based on computing technology or configuration used by the first entity's database implementation. 
     
     
         10 . The system of  claim 9 , wherein the computing technology is associated with at least one of a database query language or a distributed search engine utilized by the first entity for managing data. 
     
     
         11 . The system of  claim 1 , wherein the result data model includes at least one of the first entity's unique customer identifier, compromise timestamp, threat tag, attribution tag, provider tag, or feed tag from the result data. 
     
     
         12 . A computer-implemented threat identification method, wherein at least one programmable processor is in communication with a non-transitory machine-readable medium for storing instructions that, when executed by the at least one programmable processor, cause the at least one programmable processor to perform one or more operations, the method comprising:
 discovering threat data associated with a first entity;   translating the threat data to one or more threat models;   translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model;   translating the parameter threat model to one or more identification queries;   executing the one or more identification queries and translating generated results to result data in a first format; and   publishing one or more result data models from the result data in one or more formats or to one or more locations, the result data being aggregated and translated to a second format based on a format suitable for use by the first entity.   
     
     
         13 . The system of  claim 12 , wherein the result data is translated to a second format based on a format suitable for a computing technology used by the first entity. 
     
     
         14 . The system of  claim 12 , wherein the treat data includes indicators of financial compromise (IOFC). 
     
     
         15 . The system of  claim 14 , wherein the IOFC is associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains. 
     
     
         16 . A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising:
 discovering threat data associated with a first entity;   translating the threat data to one or more threat models;   translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model;   translating the parameter threat model to one or more identification queries;   executing the one or more identification queries and translating generated results to result data in a first format; and   publishing one or more result data models from the result data in one or more formats or to one or more locations.   
     
     
         17 . The computer program product of  claim 16 , wherein the result data is aggregated and translated to a second format based on a format suitable for use by the first entity. 
     
     
         18 . The computer program product of  claim 16 , wherein the result data is translated to a second format based on a format suitable for a computing technology used by the first entity. 
     
     
         19 . The computer program product of  claim 16 , wherein the treat data includes indicators of financial compromise (IOFC). 
     
     
         20 . The computer program product of  claim 19 , wherein the IOFC is associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains.

Join the waitlist — get patent alerts

Track US2022300659A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.