Patent · US Active

Multiphase threat analysis and correlation engine

US10270789B2 · kind B2 · utility

7Cited by
5References
22Claims
0Family size

Assignee

Inventor

Key dates

Filing dateJan 12, 2017
Grant dateApr 23, 2019
Priority date
Expiry dateJan 12, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Provided are systems, methods, and computer-program products for a targeted threat intelligence engine, implemented in a network device. The network device may receive incident data, which may include information derived starting at detection of an attack on the network until detection of an event. The network device may include analytic engines that run in a predetermined order. An analytic engine can analyze incident data of a certain data type, and can produce a result indicating whether a piece of data is associated with the attack. The network device may produce a report of the attack, which may include correlating the results from the analytic engines. The report may provide information about a sequence of events that occurred in the course of the attack. The network device may use the record of the attack to generate indicators, which may describe the attack, and may facilitate configuring security for a network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.