Data breach prevention and remediation
Abstract
Computer-implemented threat detection method and systems are provided. The method comprises discovering threat data associated with a first entity, translating the threat data to one or more threat models, translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model and translating the parameter threat model to one or more identification queries. The one or more identification queries may be executed and the generated results may be translated to result data in a first format. The one or more result data models may be published from the result data in one or more formats or to one or more locations.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented system comprising one or more processors for communicating with one or more databases to transmit threat-related data, the one or more processors executing logic code that causes the computer-implemented system to:
discover threat data associated with a first entity, the threat data including indicators of a data security breach, wherein a threat model parameter generator translates the threat data to at least a parameter threat model with one or more parameters; translate the threat model parameter to one or more identification queries based on one or more configurations stored on one or more databases; execute the one or more identification queries to generate first results; and format the first results to one or more data formats that are used to identify at least one threat target for the first entity based on the one or more parameters in the parameter threat model.
2 . The system of claim 1 , wherein the first results comprise at least one of the first entity's unique customer identifier, a compromise timestamp, a threat tag, an attribution tag, a provider tag or a feed tag.
3 . The system of claim 1 , wherein the threat data indicators are associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy session, compromised card information or phishing domains.
4 . The system of claim 1 , wherein the first results are aggregated and configured into a data format usable by the first entity.
5 . The system of claim 1 , wherein the first results are translated to a format based on a format suitable for a computing technology used by the first entity.
6 . The system of claim 1 , wherein the treat data includes indicators of financial compromise (IOFC) such that a single IOFC is utilized to create several threat models of the same or different threat model types.
7 . The system of claim 6 , wherein the IOFC comprises at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains.
8 . The system of claim 1 , wherein the parameter threat model includes parameters associated with at least one of equality, inequality, full text, and partial text matches, wherein the parameters are used to identify a threat target associated with the first entity.
9 . The system of claim 8 , wherein the parameter threat model is collected from a parameter model interface to translate the parameter threat model into one or more identification queries based on computing technology or configuration used by the first entity's database implementation.
10 . The system of claim 9 , wherein the computing technology is associated with at least one of a database query language or a distributed search engine utilized by the first entity for managing data.
11 . The system of claim 1 , wherein the result data model includes at least one of the first entity's unique customer identifier, compromise timestamp, threat tag, attribution tag, provider tag, or feed tag from the result data.
12 . A computer-implemented threat identification method, wherein at least one programmable processor is in communication with a non-transitory machine-readable medium for storing instructions that, when executed by the at least one programmable processor, cause the at least one programmable processor to perform one or more operations, the method comprising:
discovering threat data associated with a first entity; translating the threat data to one or more threat models; translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model; translating the parameter threat model to one or more identification queries; executing the one or more identification queries and translating generated results to result data in a first format; and publishing one or more result data models from the result data in one or more formats or to one or more locations, the result data being aggregated and translated to a second format based on a format suitable for use by the first entity.
13 . The system of claim 12 , wherein the result data is translated to a second format based on a format suitable for a computing technology used by the first entity.
14 . The system of claim 12 , wherein the treat data includes indicators of financial compromise (IOFC).
15 . The system of claim 14 , wherein the IOFC is associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains.
16 . A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising:
discovering threat data associated with a first entity; translating the threat data to one or more threat models; translating the one or more threat models, using a threat model parameter generator, to at least a parameter threat model; translating the parameter threat model to one or more identification queries; executing the one or more identification queries and translating generated results to result data in a first format; and publishing one or more result data models from the result data in one or more formats or to one or more locations.
17 . The computer program product of claim 16 , wherein the result data is aggregated and translated to a second format based on a format suitable for use by the first entity.
18 . The computer program product of claim 16 , wherein the result data is translated to a second format based on a format suitable for a computing technology used by the first entity.
19 . The computer program product of claim 16 , wherein the treat data includes indicators of financial compromise (IOFC).
20 . The computer program product of claim 19 , wherein the IOFC is associated with at least one of partial account information, compromised login information, malware netflow, malicious proxy sessions, compromised card information and phishing domains.Join the waitlist — get patent alerts
Track US2022300659A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.