Invention Grant
- Patent Title: Systems and methods of information security monitoring with third-party indicators of compromise
-
Application No.: US17584520Application Date: 2022-01-26
-
Publication No.: US11949719B2Publication Date: 2024-04-02
- Inventor: Michael James Bailey
- Applicant: Open Text Holdings, Inc.
- Applicant Address: US CA San Mateo
- Assignee: OPEN TEXT HOLDINGS, INC.
- Current Assignee: OPEN TEXT HOLDINGS, INC.
- Current Assignee Address: US CA Menlo Park
- Agency: SPRINKLE IP LAW GROUP
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
An information security monitoring system can import indicators of compromise (IOC) definitions in disparate formats from third-party source systems, convert them into editable security definitions in an internal system format, and provide a user interface for composing or editing these security definitions with enhancements, including complex security definitions such as those having a nested Boolean structure and/or those that reference one or more security definitions, a behavioral rule, and/or a vulnerability description. One or more whitelists can be added to handle exceptions. Each composed or modified security definition is then compiled into an executable rule. The executable rule, when evaluated, produces a result indicative of an endpoint security action needed in view of an endpoint event that meets the composed or modified security definition.
Public/Granted literature
- US20220150282A1 SYSTEMS AND METHODS OF INFORMATION SECURITY MONITORING WITH THIRD-PARTY INDICATORS OF COMPROMISE Public/Granted day:2022-05-12
Information query