Multiphase threat analysis and correlation engine
US10270789B2 · kind B2 · utility
Assignee
Inventor
Key dates
| Filing date | Jan 12, 2017 |
| Grant date | Apr 23, 2019 |
| Priority date | — |
| Expiry date | Jan 12, 2037 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/1408
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Provided are systems, methods, and computer-program products for a targeted threat intelligence engine, implemented in a network device. The network device may receive incident data, which may include information derived starting at detection of an attack on the network until detection of an event. The network device may include analytic engines that run in a predetermined order. An analytic engine can analyze incident data of a certain data type, and can produce a result indicating whether a piece of data is associated with the attack. The network device may produce a report of the attack, which may include correlating the results from the analytic engines. The report may provide information about a sequence of events that occurred in the course of the attack. The network device may use the record of the attack to generate indicators, which may describe the attack, and may facilitate configuring security for a network.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.