Network security threat intelligence sharing
Abstract
Systems and methods are disclosed for obtaining network security threat information and mitigating threats to improve computing network operations. For example, methods may include receiving a message from a central instance; from outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by an agent device within the private network; receiving a search result of the search from the agent device; transmitting the search result to the central instance, wherein the central instance is configured to generate network security threat information based in part on the search result and share the network security threat information with a plurality of customer instances that are associated with a group of customers; and receiving an alert message from the central instance, wherein the alert message includes information that identifies a network security threat.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system operable to obtain network security threat information, the system comprising:
a memory; and a processor, wherein the memory includes instructions executable by the processor to cause the system to: receive a message from a central instance; based on the message, invoke a search of data associated with a private network, wherein the search is performed by an agent device within the private network and wherein the processor is within a network that is outside of the private network; receive a search result of the search from the agent device; transmit data that is based on the search result to the central instance, wherein the central instance is configured to generate network security threat information based in part on the data that is based on the search result and share the network security threat information with a plurality of customer instances that are associated with a group of customers; and receive an alert message from the central instance, wherein the alert message includes the network security threat information that identifies a network security threat.
2 . The system of claim 1 , wherein the message includes a search query and the search is invoked with the search query.
3 . The system of claim 1 , the search performed by the agent device comprises querying a security information and event management database of the private network.
4 . The system of claim 1 , wherein the memory includes instructions executable by the processor to cause the system to:
responsive to the alert message, invoke a threat mitigation measure using a framework configured to interface to a plurality of network security products provided by different software publishers.
5 . The system of claim 1 , wherein the search result includes an observable and the memory includes instructions executable by the processor to cause the system to:
determine a risk score for the observable based on occurrences of the observable reflected in the search result.
6 . The system of claim 5 , wherein the instructions for determining the risk score include instructions executable by the processor to cause the system to:
input data pertaining to occurrences of the observable to a machine learning module and determining the risk score based on a resulting output of the machine learning module.
7 . The system of claim 1 , wherein the message includes a search query from a member of the group of customers that is relayed by the central instance.
8 . A method for obtaining network security threat information, the method comprising:
receiving a message from a central instance; from a computing device that is connected to a network that is outside of a private network, invoking a search of data associated with the private network, wherein the search is based on the message and the search is performed by an agent device within the private network; receiving a search result of the search from the agent device; transmitting data that is based on the search result to the central instance, wherein the central instance is configured to generate network security threat information based in part on the data that is based on the search result and share the network security threat information with a plurality of customer instances that are associated with a group of customers; and receiving an alert message from the central instance, wherein the alert message includes the network security threat information that identifies a network security threat.
9 . The method of claim 8 , wherein the message includes a search query and the search is invoked with the search query.
10 . The method of claim 8 , the search performed by the agent device comprises querying a security information and event management database of the private network.
11 . The method of claim 8 , comprising:
responsive to the alert message, invoking a threat mitigation measure using a framework configured to interface to a plurality of network security products provided by different software publishers.
12 . The method of claim 8 , wherein the search result includes an observable and further comprising:
determining a risk score for the observable based on occurrences of the observable reflected in the search result.
13 . The method of claim 12 , wherein determining the risk score comprises:
inputting data pertaining to occurrences of the observable to a machine learning module and determining the risk score based on a resulting output of the machine learning module.
14 . The method of claim 8 , wherein the message includes a search query from a member of the group of customers that is relayed by the central instance.
15 . A system operable to gather information relevant to network security threats, the system comprising:
a plurality of customer instances that are configured to invoke searches of data associated with respective customer networks, wherein the searches are performed by a respective agent device in the respective customer network and wherein the customer instance is outside of the respective customer network; and a central instance that is configured to: store data reflecting a group of customers that share network security threat information, wherein the plurality of customer instances are respectively associated with a customer from the group of customers; transmit a search query to the customer instances to cause the customer instances to invoke searches of the respective customer networks; receive results of the searches from the customer instances; analyze the results of the searches to generate network security threat information describing a network security threat; and transmit alert messages that include at least some of the network security threat information describing the network security threat to the customer instances.
16 . The system of claim 15 , wherein the central instance is configured to analyse the results of the searches using a machine learning module to determine a score for the network security threat.
17 . The system of claim 15 , wherein the central instance is configured to analyse the results of the searches using a machine learning module to identify a kill chain of related network security vulnerabilities in one of the respective customer networks of one of the plurality of customer instances.
18 . The system of claim 17 , wherein the central instance is configured to select a remediation measure based on the identified kill chain and transmit a recommendation to perform the selected remediation measure to the one of the plurality of customer instances.
19 . The system of claim 15 , wherein the results of the searches include one or more observables and sightings information for the one or more observables.
20 . The system of claim 19 , wherein the sightings information includes counts of occurrences of the one or more observables bucketed by time intervals.Join the waitlist — get patent alerts
Track US2018324207A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.