Invention Grant
- Patent Title: Enrichment and analysis of cybersecurity threat intelligence and orchestrating application of threat intelligence to selected network security events
-
Application No.: US16857303Application Date: 2020-04-24
-
Publication No.: US11245713B2Publication Date: 2022-02-08
- Inventor: Andrew Pendergast , Andrew Gidwani , Daniel Cole , Jason Spies , Bhaskar Karambelkar , Christopher Johnson , Danny Tineo
- Applicant: ThreatConnect, Inc.
- Applicant Address: US VA Arlington
- Assignee: ThreatConnect, Inc.
- Current Assignee: ThreatConnect, Inc.
- Current Assignee Address: US VA Arlington
- Agency: Faegre Drinker Biddle & Reath LLP
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L29/06

Abstract:
Techniques are disclosed which can provide an orchestrated response to a cybersecurity threat. This orchestrated response may be based upon, at least in part, a reputation score. Threat model(s) may be received that identify cybersecurity threat(s). An indication of observations, false positives, and/or page views for the threat may be obtained. Data feeds may be received including known good data feeds, known bad data feeds, and enrichment data feeds. The data feeds may provide information about one or more indicators of compromise (IOC). For each IOC, a weighted criticality score may be determined. The weighted criticality score may be mapped to a corresponding point value. An aggregated score may be determined based upon at least the corresponding point value. A reputation score may be computed, and in some configurations, provided to a user.
Public/Granted literature
Information query