US2022353282A1PendingUtilityA1

System and Method for Cyber Security Threat Detection

Assignee: ResponSight Pty LtdPriority: Mar 2, 2017Filed: Jul 7, 2022Published: Nov 3, 2022
Est. expiryMar 2, 2037(~10.6 yrs left)· nominal 20-yr term from priority
Inventors:Jeffrey Paine
H04L 63/1425H04L 63/18G06F 21/554G06F 2221/034H04L 67/10G06F 21/552H04L 63/1416G06F 21/57H04L 63/20H04L 63/145H04L 2463/141G06F 21/55H04L 63/1466H04L 63/1433
70
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A cyber security threat detection system for one or more endpoints within a computing environment is disclosed. The system comprises a plurality of collector engines. Each of the collector engines is previously installed on an endpoint of a plurality of endpoints and configured to acquire statistical information at the endpoint. The statistical information includes behavioral information, resource information, and metric information associated with the endpoint. The system further comprises an aggregator engine configured to aggregate the statistical information from each of the endpoints into aggregated information. The system further comprises an analytics engine configured to receive the aggregated information, and to invoke learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints. The system further comprises an alerting engine configured to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A cyber security threat detection system for one or more endpoints within a computing environment, the system comprising:
 a plurality of collector engines, each of the collector engines previously installed on an endpoint of a plurality of endpoints and configured to acquire statistical information at the endpoint, wherein the statistical information includes behavioral information and resource information associated with the endpoint;   an aggregator engine configured to aggregate the statistical information from each of the endpoints into aggregated information;   an analytics engine configured to receive the aggregated information, and to invoke learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints; and   an alerting engine configured to issue one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint.   
     
     
         2 . The system of  claim 1 , wherein:
 the analytics engine is further configured to generate a cumulative risk level based on the deviation information, and   the alerting engine is configured to issue the alerts in response to the cumulative risk level.   
     
     
         3 . The system of  claim 1 , wherein:
 the behavioral information includes activity events associated with the endpoint, and   the resource information includes central processing unit (CPU) utilization, memory footprint, disk free space, and network throughput of the endpoint.   
     
     
         4 . The system of  claim 1 , wherein the analytics engine comprises:
 a behavioral analytics engine configured to invoke the analytics rules to output some information of the deviation information, and   a metric analytics engine configured to invoke the machine learning models to output other information of the deviation information.   
     
     
         5 . The system of  claim 1 , wherein the analytics engine is further configured to perform individual metrics checking, historical and cross endpoint comparatives, and activity sequences using the aggregated information and the expected fingerprints associated with the endpoints. 
     
     
         6 . The system of  claim 1 , wherein the analytics engine performs analysis of activity sequences from the behavioral information associated with the endpoint including a determination whether specific metrics are absent from any of the activity sequences. 
     
     
         7 . The system of  claim 1 , wherein the analytics engine performs analysis of activity sequences from the behavior information associated with the endpoint including a determination whether one or more specific activities have occurred. 
     
     
         8 . The system of  claim 1 , wherein to invoke the analytics rules and machine learning models to output the deviation information for each of the endpoints, the analytics engine further invokes a profile management handler that compares the aggregated information to the expected fingerprints and provides results of the comparison. 
     
     
         9 . The system of  claim 1 , wherein:
 the deviation information are associated with a plurality of categories of threat, each of the categories of threat associated with a specific risk value, and   some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat.   
     
     
         10 . The system of  claim 1 , wherein:
 to issue the alerts indicating the security threats for each of the endpoints, the alerting system determines whether an alert is to be issued based on a cumulative risk level, the cumulative risk level being a summation of specific risk values associated with one or more categories of threat that are associated with the deviation information, wherein each category of threat is associated with one of the specific risk values that is registered each time an associated trigger event occurs, and   the alert is to be issued in response to a determination that the cumulative risk level exceeds a risk threshold.   
     
     
         11 . The system of  claim 10 , wherein some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat. 
     
     
         12 . The system of  claim 11 , wherein:
 a baseline level is computed over time for the cumulative risk level,   value excursions for the cumulative risk level with respect to the baseline level are tracked over time, and   the risk threshold is computed based on the tracked excursions.   
     
     
         13 . The system of  claim 1 , wherein the behavioral information for the endpoint include at least one of the following: firewall metric, internet protocol (IP) address metric, activity counter metric, process information metric, keyboard metric, and mouse metric. 
     
     
         14 . The system of  claim 1 , wherein the behavioral information for the endpoint include at least one of the following: mouse telemetry, keyboard connections and activations, process usage, and hot desk information. 
     
     
         15 . The system of  claim 1 , wherein each of the security threats is classified as at least one of the following: manual or automated, malware or custom, hardware or software, and internal or external. 
     
     
         16 . The system of  claim 5 , wherein the activity sequences include an activity sequence associated with an endpoint user logging into the endpoint using stolen credentials or using an unlocked endpoint. 
     
     
         17 . The system of  claim 5 , wherein the activity sequences include an activity sequence associated with a cyber attack performed by attaching to a privileged process with reverse shell access. 
     
     
         18 . The system of  claim 1 , wherein the alerting engine is further configured to issue no alert in response to a determination that an authorized user successfully answers a challenge sent out of band (OoB). 
     
     
         19 . The system of  claim 1 , wherein:
 the alerting engine is further configured to send a text message to a security administrator from a specific phone number, and   a mobile device of the security administrator is programmed to respond with a specific tone when a time critical alert is generated.   
     
     
         20 . The system of  claim 1 , further comprising:
 a prediction engine configured to predict patterns of a software application based on a determined probability and context of an endpoint user, and to traverse an alert threshold according to the determined probability when operating patterns of the software application diverge from the predicted patterns.   
     
     
         21 . A method for detecting cyber security threat of one or more endpoints within a computing environment, the method comprising:
 receiving aggregated information including statistical information from each of the endpoints, wherein the statistical information includes behavioral information and resource information associated with the endpoint;   invoking learning models to output deviation information for each of the endpoints based on the aggregated information and expected fingerprints associated with the endpoints; and   issuing one or more alerts indicating one or more security threats have occurred for each of the endpoints in response to the deviation information for the endpoint;   wherein issuing the alerts comprising:
 determining whether an alert is to be issued based on a cumulative risk level, the cumulative risk level being a summation of specific risk values associated with one or more categories of threat that are associated with the deviation information, wherein each category of threat is associated with one of the specific risk values that is registered each time an associated trigger event occurs, and 
 issuing the alert in response to a determination that the cumulative risk level exceeds a risk threshold. 
   
     
     
         22 . The method of  claim 21 , wherein some categories of threat comprise risk values that are weighted differently from risk values of other categories of threat. 
     
     
         23 . The method of  claim 22 , further comprising:
 computing a baseline level over time for the cumulative risk level, tracking, over time, value excursions for the cumulative risk level with respect to the baseline level, and   computing the risk threshold based on the tracked excursions.

Join the waitlist — get patent alerts

Track US2022353282A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.