Invention Grant
- Patent Title: Automatic extraction of indicators of compromise from multiple data sources accessible over a network
-
Application No.: US15354680Application Date: 2016-11-17
-
Publication No.: US10250621B1Publication Date: 2019-04-02
- Inventor: Zhou Li
- Applicant: EMC IP Holding Company LLC
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP Holding Company LLC
- Current Assignee: EMC IP Holding Company LLC
- Current Assignee Address: US MA Hopkinton
- Agency: Ryan, Mason & Lewis, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/951 ; G06F16/955

Abstract:
A processing device in one embodiment comprises a processor coupled to a memory and is configured to direct one or more web crawlers to obtain textual information from a plurality of data sources accessible over at least one network, to extract terms likely to be associated with indicators of compromise from the obtained textual information, to filter the extracted terms to identify terms corresponding to respective valid indicators of compromise, to generate links between the terms corresponding to the respective valid indicators of compromise, and to convert the links and the corresponding terms into an output document in a specified indicator of compromise format. Feedback from an analyst device receiving the output document may be used to adjust a filter parameter of the extracted term filtering. Additionally or alternatively, one or more parameters of a network security system may be adjusted based at least in part on the output document.
Information query