ConceptioArchiveGoogle Patents
Google Patentsopen access

Artificial intelligence controller orchestrating network components for a cyber … — Darktrace Holdings Limited (US11522887B2)

Darktrace Holdings Limited · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
darktraceholdingslimitedmatthewdunn
patent, google patents, intellectual property, US11522887B2, Darktrace Holdings Limited, Matthew Dunn, en, 2022

ABSTRACT

Abstract

A cyber-threat coordinator-component identifies devices and/or users that are in a breach state of a benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network. The cyber-threat coordinator-component sends an external communication to selected network devices in order to initiate actions with that network device in order to change a behavior of a detected threat of at least one a user and/or a device acting abnormal to the normal pattern of life on the network. The initiated actions are also targeted to minimize an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

Description

RELATED APPLICATION

This application claims priority to and the benefit of under 35 USC 119 of U.S. provisional patent application titled “A cyber threat defense system with various improvements,” filed Feb. 20, 2018, Ser. No. 62/632,623, which is incorporated herein by reference in its entirety.

NOTICE OF COPYRIGHT

A portion of this disclosure contains material that is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the material subject to copyright protection as it appears in the United States Patent & Trademark Office's patent file or records, but otherwise reserves all copyright rights whatsoever.

FIELD

Embodiments of the design provided herein generally relate to a cyber threat defense system.

BACKGROUND

In the cyber security environment, firewalls, endpoint security methods and other tools such as SIEMs and sandboxes are deployed to enforce specific policies, and provide protection against certain threats. These tools currently form an important part of an organization's cyber defense strategy, but they are insufficient in the new age of cyber threat. Legacy tools are failing to deal with new cyber threats because the traditional approach relies on being able to pre-define the cyber threat in advance, by writing rules or producing signatures. In today's environment, this approach to defend against cyber threats is fundamentally flawed:

Threats are constantly evolving—novel attacks do not match historical-attack “signatures”, and even subtle changes to previously understood attacks can result in them going undetected by legacy defenses; Rules and policies defined by organizations are continually insufficient—security teams simply can't imagine every possible thing that may go wrong in future; and Employee ‘insider’ threat is a growing trend—it is difficult to spot malicious employees behaving inappropriately as they are a legitimate presence on the business network.

The reality is that modern threats bypass the traditional legacy defense tools on a daily basis. These tools need a new tool based on a new approach that can complement them and mitigate their deficiencies at scale across the entirety of digital organizations. In the complex modern world it is advantageous that the approach is fully automated as it is virtually impossible for humans to sift through the vast amount of security information gathered each minute within a digital business.

SUMMARY

In an embodiment, a cyber-threat coordinator-component identifies devices and/or users that are in a breach state of a benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network. The cyber-threat coordinator-component sends an external communication to selected network devices in order to initiate actions with that network device in order to change/counter a behavior of a detected threat of at least one of a user and/or a device acting abnormal to the normal pattern of life on the network. The initiated actions are also targeted to minimize an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

These and other features of the design provided herein can be better understood with reference to the drawings, description, and claims, all of which form the disclosure of this patent application.

DRAWINGS

The drawings refer to some embodiments of the design provided herein in which:

FIG. 1 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component.

FIG. 2 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component monitoring and cooperating with an example set of network devices.

FIG. 3 illustrates a diagram of an embodiment of the cyber-threat coordinator-component cooperating and coordinating with an example set of network capabilities of various network devices.

FIG. 4 illustrates a diagram of an embodiment of the cyber-threat coordinator-component using the AI models to understand the normal pattern of life of the network, identifying abnormal activity, and orchestrating an autonomous response from the network's defense system.

FIG. 5 illustrates a diagram of an embodiment of the cyber-threat coordinator-component discovering capabilities of network devices and establishing what automated effect is possible on each network component to stop or interfere with a detected threat.

FIG. 6 illustrates a diagram of an embodiment of the cyber-threat coordinator-component that will establish which entities are outside their normal pattern of life and initiate actions to take.

FIG. 7 illustrates a flow diagram of an embodiment of the cyber-threat coordinator-component with an example decision process to initiate a chosen set of actions to cause a best targeted change/counter of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

FIG. 8 illustrates an example cyber threat defense system protecting an example network.

While the design is subject to various modifications, equivalents, and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and will now be described in detail. It should be understood that the design is not limited to the particular embodiments disclosed, but—on the contrary—the intention is to cover all modifications, equivalents, and alternative forms using the specific embodiments.

DESCRIPTION

In the following description, numerous specific details are set forth, such as examples of specific data signals, named components, number of servers in a system, etc., in order to provide a thorough understanding of the present design. It will be apparent, however, to one of ordinary skill in the art that the present design can be practiced without these specific details. In other instances, well known components or methods have not been described in detail but rather in a block diagram in order to avoid unnecessarily obscuring the present design. Further, specific numeric references such as a first server, can be made. However, the specific numeric reference should not be interpreted as a literal sequential order but rather interpreted that the first server is different than a second server. Thus, the specific details set forth are merely exemplary. Also, the features implemented in one embodiment may be implemented in another embodiment where logically possible. The specific details can be varied from and still be contemplated to be within the spirit and scope of the present design. The term coupled is defined as meaning connected either directly to the component or indirectly to the component through another component.

In general, a cyber-threat coordinator-component identifies devices and/or users that are in a breach state of a benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network. The cyber-threat coordinator-component sends an external communication to selected network devices in order to initiate actions with that network device in order to change a behavior of a detected threat of at least one a user and/or a device acting abnormal to the normal pattern of life on the network. The initiated actions are also targeted to minimize an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

FIG. 1 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component.

In an embodiment, the cyber-threat coordinator- component 100 , such as an Antigena Network Firewall Share Component, is a real time threat intelligence system that uses one or more Artificial Intelligence models that are configured to intelligently work with other third party defense systems in that customer's network against threats. The cyber-threat coordinator- component 100 and other third party defense systems are orchestrated to create a unified defense response against a detected threat within or external to that customer's network. The cyber-threat coordinator- component 100 can be an autonomous self-learning digital response coordinator that is trained specifically to control and reconfigure the actions of traditional legacy computer defenses (e.g. firewalls, switches, proxy servers, etc.) to contain threats propagated by, or enabled by, networks and the internet.

The cyber-threat coordinator- component 100 may include the following components. One or more input ports receive input data from probes in the network, such as in-line taps or external monitoring connections, collecting data on entities associated with the network. An analysis module analyzes the input data, such metrics themselves or data derived from one or more clusters of metrics on network traffic, from the input ports using one or more self-learning Artificial Intelligence models trained on a normal behavior of users and devices associated with the network. A normal behavior benchmark can be used by a given AI model as a benchmark of parameters that correspond to a normal pattern of life for the network. The normal behavior benchmark allows that self-learning model to spot behavior on the network that falls outside the parameters set by the normal behavior benchmark. The benchmark may be continuously updated; and thus, be a moving benchmark of parameters forming that benchmark/threshold.

A comparison module compares the analyzed input data received from the probes to the benchmark of parameters that correspond to the normal pattern of life for the devices and users of the network utilized by the self-learning Artificial Intelligence models trained on the normal pattern of life for the network. The comparison module may further identify one or more devices and/or users that are in a breach state of the benchmark of parameters, utilized by the Artificial Intelligence models, which correspond to the normal pattern of life for the network.

The coordinator module sends one or more external communications to selected network devices in order to initiate actions with that network device in order to change a behavior of a detected threat of a user and/or a device acting abnormal to the normal pattern of life on the network while minimizing an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark. Thus, the cyber-threat coordinator- component 100 may detect and initiate responses to change a behavior of a detected threat of at least one of i) a user, ii) a device, iii) both a user and a device, iv) a set of users, v) a set of devices acting abnormal to the normal pattern of life on the network, and vi) various combinations of these entities.

The cyber-threat coordinator- component 100 further uses a discovery module to i) discover capabilities of each network device in the network being monitored and ii) discover actions they can take to counter and/or contain the detected threat to the network, as well as iii) discover the communications needed to initiate those actions.

The coordinator module may then coordinate the capabilities of two or more network devices that are selected to counter the detected threat acting abnormal to the normal pattern of life by sending an external communication to each selected network device in order to initiate actions with that network device in order to change the behavior of the detected threat while minimizing the impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

The cyber-threat coordinator- component 100 may i) internally contain one or more of the AI models, ii) cooperate with external AI models, and have a combination of internal and external AI models. The AI models are configured to understand the normal pattern of life of the network; and thus, normal behaviors of entities, (e.g. users, network devices, connections, etc.) in the network. The AI models use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then the coordinator module is configured to use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions. The AI models may use the one or more mathematical functions to generate a score for each of the possible actions and/or sequence of multiple possible actions that can be taken in order to determine which set of actions to choose among many possible actions to take/initiate. The one or more possible actions to take and their calculated scores can be stacked against each other to factor 1) a likelihood of containing/countering the detected threat acting abnormal with each possible set of actions, 2) a severity level of the detected threat to the network, and 3) the impact of taking each possible set of actions i) on users and ii) on devices currently active in the network not acting abnormal to the normal behavior of the network. The AI models may then communicate with the coordinator module to initiate the chosen set of actions to cause a best targeted change of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark. The AI models can choose an initial set of one or more actions indicated as a best targeted initial response to the detected threat by autonomously initiating those actions to defend against the detected threat without any human interaction. The self-learning Artificial Intelligence models choose the best initial response and then communicate with the coordinator module to autonomously initiate that initial set of one or more actions. The self-learning AI models of normal behavior can be configured to use an architecture that is continuously updated. Thus, the self-learning Artificial Intelligence models trained on the normal behavior of users and devices associated with the network. As the models continue to operate on this network, they record and continuously update their training on the normal behavior of the network system. Accordingly, the normal behavior benchmark used by the AI models can th

RELATED APPLICATION

This application claims priority to and the benefit of under 35 USC 119 of U.S. provisional patent application titled “A cyber threat defense system with various improvements,” filed Feb. 20, 2018, Ser. No. 62/632,623, which is incorporated herein by reference in its entirety.

NOTICE OF COPYRIGHT

A portion of this disclosure contains material that is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the material subject to copyright protection as it appears in the United States Patent & Trademark Office's patent file or records, but otherwise reserves all copyright rights whatsoever.

FIELD

Embodiments of the design provided herein generally relate to a cyber threat defense system.

BACKGROUND

In the cyber security environment, firewalls, endpoint security methods and other tools such as SIEMs and sandboxes are deployed to enforce specific policies, and provide protection against certain threats. These tools currently form an important part of an organization's cyber defense strategy, but they are insufficient in the new age of cyber threat. Legacy tools are failing to deal with new cyber threats because the traditional approach relies on being able to pre-define the cyber threat in advance, by writing rules or producing signatures. In today's environment, this approach to defend against cyber threats is fundamentally flawed:

Threats are constantly evolving—novel attacks do not match historical-attack “signatures”, and even subtle changes to previously understood attacks can result in them going undetected by legacy defenses; Rules and policies defined by organizations are continually insufficient—security teams simply can't imagine every possible thing that may go wrong in future; and Employee ‘insider’ threat is a growing trend—it is difficult to spot malicious employees behaving inappropriately as they are a legitimate presence on the business network.

The reality is that modern threats bypass the traditional legacy defense tools on a daily basis. These tools need a new tool based on a new approach that can complement them and mitigate their deficiencies at scale across the entirety of digital organizations. In the complex modern world it is advantageous that the approach is fully automated as it is virtually impossible for humans to sift through the vast amount of security information gathered each minute within a digital business.

SUMMARY

In an embodiment, a cyber-threat coordinator-component identifies devices and/or users that are in a breach state of a benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network. The cyber-threat coordinator-component sends an external communication to selected network devices in order to initiate actions with that network device in order to change/counter a behavior of a detected threat of at least one of a user and/or a device acting abnormal to the normal pattern of life on the network. The initiated actions are also targeted to minimize an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

These and other features of the design provided herein can be better understood with reference to the drawings, description, and claims, all of which form the disclosure of this patent application.

DRAWINGS

The drawings refer to some embodiments of the design provided herein in which:

FIG. 1 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component.

FIG. 2 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component monitoring and cooperating with an example set of network devices.

FIG. 3 illustrates a diagram of an embodiment of the cyber-threat coordinator-component cooperating and coordinating with an example set of network capabilities of various network devices.

FIG. 4 illustrates a diagram of an embodiment of the cyber-threat coordinator-component using the AI models to understand the normal pattern of life of the network, identifying abnormal activity, and orchestrating an autonomous response from the network's defense system.

FIG. 5 illustrates a diagram of an embodiment of the cyber-threat coordinator-component discovering capabilities of network devices and establishing what automated effect is possible on each network component to stop or interfere with a detected threat.

FIG. 6 illustrates a diagram of an embodiment of the cyber-threat coordinator-component that will establish which entities are outside their normal pattern of life and initiate actions to take.

FIG. 7 illustrates a flow diagram of an embodiment of the cyber-threat coordinator-component with an example decision process to initiate a chosen set of actions to cause a best targeted change/counter of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

FIG. 8 illustrates an example cyber threat defense system protecting an example network.

While the design is subject to various modifications, equivalents, and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and will now be described in detail. It should be understood that the design is not limited to the particular embodiments disclosed, but—on the contrary—the intention is to cover all modifications, equivalents, and alternative forms using the specific embodiments.

DESCRIPTION

In the following description, numerous specific details are set forth, such as examples of specific data signals, named components, number of servers in a system, etc., in order to provide a thorough understanding of the present design. It will be apparent, however, to one of ordinary skill in the art that the present design can be practiced without these specific details. In other instances, well known components or methods have not been described in detail but rather in a block diagram in order to avoid unnecessarily obscuring the present design. Further, specific numeric references such as a first server, can be made. However, the specific numeric reference should not be interpreted as a literal sequential order but rather interpreted that the first server is different than a second server. Thus, the specific details set forth are merely exemplary. Also, the features implemented in one embodiment may be implemented in another embodiment where logically possible. The specific details can be varied from and still be contemplated to be within the spirit and scope of the present design. The term coupled is defined as meaning connected either directly to the component or indirectly to the component through another component.

In general, a cyber-threat coordinator-component identifies devices and/or users that are in a breach state of a benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network. The cyber-threat coordinator-component sends an external communication to selected network devices in order to initiate actions with that network device in order to change a behavior of a detected threat of at least one a user and/or a device acting abnormal to the normal pattern of life on the network. The initiated actions are also targeted to minimize an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

FIG. 1 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component.

In an embodiment, the cyber-threat coordinator- component 100 , such as an Antigena Network Firewall Share Component, is a real time threat intelligence system that uses one or more Artificial Intelligence models that are configured to intelligently work with other third party defense systems in that customer's network against threats. The cyber-threat coordinator- component 100 and other third party defense systems are orchestrated to create a unified defense response against a detected threat within or external to that customer's network. The cyber-threat coordinator- component 100 can be an autonomous self-learning digital response coordinator that is trained specifically to control and reconfigure the actions of traditional legacy computer defenses (e.g. firewalls, switches, proxy servers, etc.) to contain threats propagated by, or enabled by, networks and the internet.

The cyber-threat coordinator- component 100 may include the following components. One or more input ports receive input data from probes in the network, such as in-line taps or external monitoring connections, collecting data on entities associated with the network. An analysis module analyzes the input data, such metrics themselves or data derived from one or more clusters of metrics on network traffic, from the input ports using one or more self-learning Artificial Intelligence models trained on a normal behavior of users and devices associated with the network. A normal behavior benchmark can be used by a given AI model as a benchmark of parameters that correspond to a normal pattern of life for the network. The normal behavior benchmark allows that self-learning model to spot behavior on the network that falls outside the parameters set by the normal behavior benchmark. The benchmark may be continuously updated; and thus, be a moving benchmark of parameters forming that benchmark/threshold.

A comparison module compares the analyzed input data received from the probes to the benchmark of parameters that correspond to the normal pattern of life for the devices and users of the network utilized by the self-learning Artificial Intelligence models trained on the normal pattern of life for the network. The comparison module may further identify one or more devices and/or users that are in a breach state of the benchmark of parameters, utilized by the Artificial Intelligence models, which correspond to the normal pattern of life for the network.

The coordinator module sends one or more external communications to selected network devices in order to initiate actions with that network device in order to change a behavior of a detected threat of a user and/or a device acting abnormal to the normal pattern of life on the network while minimizing an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark. Thus, the cyber-threat coordinator- component 100 may detect and initiate responses to change a behavior of a detected threat of at least one of i) a user, ii) a device, iii) both a user and a device, iv) a set of users, v) a set of devices acting abnormal to the normal pattern of life on the network, and vi) various combinations of these entities.

The cyber-threat coordinator- component 100 further uses a discovery module to i) discover capabilities of each network device in the network being monitored and ii) discover actions they can take to counter and/or contain the detected threat to the network, as well as iii) discover the communications needed to initiate those actions.

The coordinator module may then coordinate the capabilities of two or more network devices that are selected to counter the detected threat acting abnormal to the normal pattern of life by sending an external communication to each selected network device in order to initiate actions with that network device in order to change the behavior of the detected threat while minimizing the impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

The cyber-threat coordinator- component 100 may i) internally contain one or more of the AI models, ii) cooperate with external AI models, and have a combination of internal and external AI models. The AI models are configured to understand the normal pattern of life of the network; and thus, normal behaviors of entities, (e.g. users, network devices, connections, etc.) in the network. The AI models use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then the coordinator module is configured to use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions. The AI models may use the one or more mathematical functions to generate a score for each of the possible actions and/or sequence of multiple possible actions that can be taken in order to determine which set of actions to choose among many possible actions to take/initiate. The one or more possible actions to take and their calculated scores can be stacked against each other to factor 1) a likelihood of containing/countering the detected threat acting abnormal with each possible set of actions, 2) a severity level of the detected threat to the network, and 3) the impact of taking each possible set of actions i) on users and ii) on devices currently active in the network not acting abnormal to the normal behavior of the network. The AI models may then communicate with the coordinator module to initiate the chosen set of actions to cause a best targeted change of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark. The AI models can choose an initial set of one or more actions indicated as a best targeted initial response to the detected threat by autonomously initiating those actions to defend against the detected threat without any human interaction. The self-learning Artificial Intelligence models choose the best initial response and then communicate with the coordinator module to autonomously initiate that initial set of one or more actions. The self-learning AI models of normal behavior can be configured to use an architecture that is continuously updated. Thus, the self-learning Artificial Intelligence models trained on the normal behavior of users and devices associated with the network. As the models continue to operate on this network, they record and continuously update their training on the normal behavior of the network system. Accordingly, the normal behavior benchmark used by the AI models can then be varied according to the updated changes in the network.

The cyber-threat coordinator- component 100 may also include one or more observation and evaluation feedback loops. An observation and evaluation feedback loop is used to choose a best targeted initial response and the initial set of actions to take while minimizing the impact on other network devices that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark. The coordinator module of the cyber-threat coordinator- component 100 directs the initial set of actions to be taken and expects i) an impact on the detected threat and ii) an effect on the rest of the active devices and active users in the network. The feedback loop monitors an actual effect on the detected threat in breach from the initial set of actions taken as well as an actual effect on the rest of the devices and users in the network not in breach from the initial set of actions taken. The observation and evaluation feedback loop is used to take a sequence of actions and evaluate the actual impact after each action in the sequence, in order to yield a best possible result to contain the detected threat while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach, from different possible actions to take. Generally, at least a first action is initiated and the resulting actual effects are monitored; and then, a second action (and possibly a third and fourth action in the set of actions) in the sequence of actions is initiated and monitored with the observation and evaluation feedback loop to yield the best possible result.

The cyber defense system may have at least 3 machine learning models. Each machine learning model may be trained on specific aspects of the normal pattern of life for the system such as devices, users, network traffic flow, outputs from one or more cyber security analysis tools analyzing the system, etc. One or more machine learning models may also be trained on characteristics and aspects of all manner of types of cyber threats.

The self-learning Artificial Intelligence models are able to detect a previously unknown threat earlier as well as enact one or more autonomous responses to implement a faster response time to contain the detected threat.

FIG. 2 illustrates a block diagram of an embodiment of a cyber-threat coordinator-component monitoring and cooperating with an example set of network devices.

The example network can include one or more firewalls, one or more network switches, one or more computing devices operable by users of the network, bridges, databases, and one or more cyber-threat coordinator-components. The cyber-threat coordinator- component 100 can be an autonomous self-learning digital response coordinator that is trained specifically to control and reconfigure the actions of traditional legacy computer defenses (e.g. firewalls, switches, proxy servers, etc.) to contain threats propagated by, or enabled by, networks and the internet.

In general, the cyber-threat coordinating- component 100 can direct a firewall to grant or block access to a port. The cyber-threat coordinating- component 100 can direct a network switch to block a port or redirect to another port or to reduce the rate of traffic through the switch such as a download, etc. The cyber-threat coordinating- component 100 can direct a proxy server to dynamically decrypt traffic, divert connection to another URL, etc. The cyber-threat coordinating- component 100 can direct a device such as a computer to shut down.

The cyber-threat coordinator- component 100 can improve one or more of the computing devices themselves by containing the detected threat and minimizing consumption of CPU cycles, minimizing memory space used, and minimizing power consumption by that detected threat in one or more of the computing devices when the detected threat, such as malware/viruses, or unauthorized user actions, is contained by the initiated actions.

FIG. 3 illustrates a diagram of an embodiment of the cyber-threat coordinator-component cooperating and coordinating with an example set of network capabilities of various network devices. The network devices may have various capabilities such as identity management including setting user permissions, network security controls, firewalls denying or granting access to various ports, encryption capabilities, centralize logging, antivirus anti-malware software quarantine and immunization, patch management, etc.

Some example types of capabilities of network devices; and thus, actions that can be directed from the cyber-threat coordinator-component 100 :

open or block access to a port and IP address combination; open or block access for a limited amount of time; redirect communication to another URL or redirect the user to a specific URL; preventing the device from reading a file share on server; block access to specific IP addresses and/or to specific types of devices; open or block outbound web access for a specific user and/or device; open or block outbound DNS access for a specific user and/or device; open or block all outbound access for a specific user and/or device; altering the user's permissions, restricting login in for that person; blocking a connection based on a source or destination address; look at type of traffic and then reroute the network traffic of a specific type via security device; slow down a transfer rate by allocating a lowest bandwidth to that port, user, or device; quarantine files and/or send shutdown signal to a device; close authentication to different parts of the network; and do all of the above actions until a specified window of time is elapsed, such as an hour, or until reset by a human network administrator.

FIG. 4 illustrates a diagram of an embodiment of the cyber-threat coordinator-component using the AI models to understand the normal pattern of life of the network, identifying abnormal activity, and orchestrating an autonomous response from the network's defense system.

The cyber-threat coordinator- component 100 can use AI models trained with unsupervised machine learning to build a deep understanding of the normal pattern of life of devices and users and connections with the network.

The cyber-threat coordinator- component 100 can maintain a list of behavioral indicators that represent either desired behavior or undesired behavior. These indicators are dynamically produced as a reaction to events witnessed in a network.

The cyber-threat coordinator- component 100 identifies highly anomalous activity to the normal pattern. For example, a rare file download from an unusual source address or to an unusual destination address would be a major deviation from the normal activity associated with that source or destination.

The behavioral indicators produced by the cyber-threat coordinator- component 100 are produced reactively to witnessed behavior, by the comparison of this behavior to previous behavioral trends of a person or device on a computer network. These indicators are produced by artificial intelligence modules, and other statistical or mathematical mechanisms that deduce whether any given behavior should be permitted, denied or elsewise manipulated in accordance with the abilities of the third-party device. It is important to note that the specific behavior that is required to be prevented, or permitted, is not required to have been previously witnessed occurring on a network in order for a decision to be made about whether it should be interfered with.

Referring back to FIG. 2 , an example that illustrates this technology might be a network firewall that is configured to consult the cyber-threat coordinator- component 100 as to each connection that is passing through it. The network firewall permits the consultation of external data sources to determine an appropriate reaction which, in this example, is limited to deny or permit.

The implementation of this feature, in this example, has been made, by the third-party, to consult the external data source periodically and cache the results locally for speed efficiency purposes.

In this example, the network behavior of a laptop is witnessed by the cyber-threat coordinator- component 100 that, when compared to a normal baseline of that laptop is indicative of undesirable behavior. In this example, this is the download, by the laptop, of a rare executable. In the context of this example, and the hypothetical network in which it occurs, this represents a departure from normal to the extent that the cyber-threat coordinator- component 100 decides the most appropriate response is to restrict the laptop's connections to only those which match its behaviorally deduced normal behavior.

In this instance the cyber-threat coordinator- component 100 makes available to the network firewall a list of behavioral indicators that the specific laptop is permitted to exhibit. All other connections not covered by these indicators should be denied. The network firewall polls the cyber-threat coordinator- component 100 and stores a copy of these indicators locally for speed of access.

When the laptop next attempts to make a connection that traverses the network firewall, the firewall consults the locally stored set of behavioral indicators supplied from the cyber-threat coordinator- component 100 to determine whether it contains a match to attempted connection. In this example, the laptop is attempting to connect to an IP address on the Internet that is not contained within the list of behavioral indicators. In this case, the firewall will deny the connection. The laptop then attempts a connection to another IP address on the Internet that the laptop frequently visits, and the cyber-threat coordinator- component 100 has judged to reflect normal activity for the laptop, in this case, the connection is present in the behavioral indicators and the connection is permitted.

In the preceding example, an anomalous event, as determined by the cyber-threat coordinator- component 100 , led to the decision to only permit future connections that comply with known normal behavior. It is equally possible that the cyber-threat coordinator- component 100 decides to restrict types of behavior, rather than as given in the example, permit types of behavior.

In an example, a behavioral pattern analysis of what are the unusual behaviors of the network/system/device/user under analysis by the machine learning models may be as follows. The a cyber defense system uses unusual behavior deviating from the normal behavior and then builds a chain of unusual behavior and the causal links between the chain of unusual behavior to detect cyber threats. The unusual pattern is determined by filtering out what activities/events/alerts that fall within the window of what is the normal pattern of life for that network/system/device/user under analysis, and then the pattern of the behavior of the activities/events/alerts that are left, after the filtering, can be analyzed to determine whether that pattern is indicative of a behavior of a malicious actor—human, program, or other threat. The cyber defense system can go back and pull in some of the filtered out normal activities to help support or refute a possible hypothesis of whether that pattern is indicative of a behavior of a malicious actor. If the pattern of behaviors under analysis is believed to be indicative of a malicious actor, then a score of how confident is the system in this assessment of identifying whether the unusual pattern was caused by a malicious actor is created. Next, also assigned is a threat level score or probability indicative of what level of threat does this malicious actor pose. Lastly, the cyber defense system is configurable in a user interface by each different user, enabling what type of automatic response actions, if any, the cyber defense system may take when for different types of cyber threats that are equal to or above a configurable level of threat posed by this malicious actor indicated by the pattern of behaviors under analysis.

In an embodiment, a cyber-threat coordinator- component 100 is configured to supply an artificial intelligence model that is configured to intelligently work with other third party defense systems in that customer's network against threats to create a unified defense response against a detected threat within that customer's network.

The cyber-threat coordinator- component 100 monitors and can act to regulate network behavior for all connections, users, and devices outside of their normal pattern of life by initiating actions to terminate or otherwise restrict their behavior. The normal activity for the rest of the remaining active devices and users, not in breach of their normal behavior, should remain, as much as possible, not affected by the autonomous response initiated by the cyber-threat coordinator- component 100 .

The instruction to consult the cyber-threat coordinator- component 100 can be configured with the database of third-party products including border protection products, firewalls, web proxy servers, sandboxes and other third-party applications (software or hardware based). These third-party products have the ability, as part of their function within a network, to permit, deny, or in some other way interfere or manipulate network communications.

For each event that the third-party device or application witnesses, it may consult the cyber-threat coordinator- component 100 to determine an appropriate reaction. Should the information sent by the third-party device or application match any of the behavioral indicators stored within the cyber threat coordinator component, then a recommended action is provided to the third-party device.

Note, the exact implementation of this capability is dependent on the specific third-party device. For some third-party devices, the cyber-threat coordinator- component 100 may be consulted in real time at the moment a decision is required to be made, in other implementations the third-party device may poll and cache any set of behavioral indicators produced by the cyber threat coordinator component.

FIG. 5 illustrates a diagram of an embodiment of the cyber-threat coordinator-component discovering capabilities of network devices and establishing what automated effect is possible on each network component to stop or interfere with a detected threat.

The cyber threat coordinator component discovers i) capabilities of each network device (e.g. firewall, switch, proxy server, and other network devices) in the network being monitored by the cyber threat coordinator component and ii) actions they can take to counter and/or contain a detected threat to the network as well as iii) the communications needed to initiate those actions. Typically, the cyber threat coordinator component discovers the capabilities of each network device (e.g. firewall, switch, proxy server, and other network devices) in the network ahead of detecting a threat. However, the cyber threat coordinator component can confirm or discover what currently are the capabilities available of each network device at the time when a threat is detected.

The cyber-threat coordinator-component discovers the capabilities of each network device, for example firewall, switch, proxy, etc. The cyber threat coordinator component may reference a database on all of the different possible types of security and network components the firewall share component will need to interact with. Alternatively, the cyber-threat coordinating component can send a communication to each of the network components in order to explore and obtain what actions it can request from that network component. Both ways explore and interpret what capabilities/actions that each network component can do from a communication from an external device.

The cyber-threat coordinator-component establishes what automated effect is possible on each network component to stop or interfere with the network traffic of any given device in that network. The cyber-threat coordinator-component will initially establish a list of all of the capabilities in all connected network devices that can be used to achieve a desired effect of reacting to this potential cyber threat. The cyber-threat coordinator-component detects with its AI models or is otherwise given notice of the initial detection of threat in the first place. The cyber-threat coordinator-component then reviews this list of options with network components it can direct them to take.

FIG. 6 illustrates a diagram of an embodiment of the cyber-threat coordinator-component will establish which entities are outside their normal pattern of life and initiate actions to take.

The AI models are trained to the normal pattern of life of the network; and thus, understand normal behaviors of entities in the network. The cyber-threat coordinator- component 100 has the intelligence and trained models to dynamically create rules of normal behavior for pre-existing network components and its equipment and users within that network. A detected anomaly may fall outside of the benchmark of parameters set by the model for being normal. When a network device, user, or connection is in a breach state of a given model of a normal pattern of life for that entity, then the cyber threat coordinator component will establish which entities are outside their normal pattern of life.

The cyber-threat coordinator- component 100 also has the intelligence and trained models to take actions based upon anomalies perceived by the cyber-threat coordinator- component 100 . The cyber-threat coordinator- component 100 evaluates in real-time the network connections and the network traffic in order to analyze pattern of life information regarding this network. When events occur that create anomalies for this network, then the cyber-threat coordinator- component 100 , in response to an evaluation, will take one or more actions within the capabilities of the network components to contain the anomaly while minimizing an impact to other network components and other users not generating the anomaly.

The AI models are configured to use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then the coordinator module is configured to use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions. The cyber-threat coordinating- component 100 uses the set of APIs to translate commands for each different component with its own language syntax. The cyber-threat coordinating-component uses the one or more mathematical functions to generate a score for each action and/or sequence of multiple actions that can be taken in order to determine which action to choose among many possible actions to take/initiate. The score, which can also be a probability, for each one of these activities may indicate how much these actions will affect the overall system and other users of the network. The result of one or more actions to take and their calculated scores can be stacked against each other to consider factors such as likelihood of countering the threat, the severity of the threat, and impact of taking that action on users and devices not acting abnormal to the normal behavior of the network.

The cyber-threat coordinator- component 100 uses an AI model to evaluate options that each device may take and then specifies how it wants to change the behavior of a device or a user of the network acting abnormal to the normal pattern of life on the network. The cyber-threat coordinator- component 100 can initially evaluate all of the capabilities in all connected network devices that will achieve the desired effect of reacting to this potential cyber threat. However, the cyber-threat coordinator- component 100 will also evaluate the level of impact to other devices in the network should that action take place. For example, the cyber-threat coordinator- component 100 will evaluate how acceptable blocking this connection compared to blocking other connections is for the continued operations of the network. The cyber-threat coordinator- component 100 will evaluate initially which one or more of the possible actions to perform on the network components, based on the score, and then initiate the chosen actions to perform to best cause the desired targeted effect of pattern of life restriction with a least effect on other non-badly behaving devices and/or users.

In an example, after the cyber-threat coordinator- component 100 sees unusual uploads to a fileshare coming from a device with IP 10.1.1.2, the cyber-threat coordinator- component 100 decides to prevent communication from this IP address or a device from reaching the Internet over port 443 for one hour.

Thus, the cyber threat coordinator component externally directs and orchestrates at least the legacy network defense components for an overall system response to a detected threat by restricting, blocking or otherwise changing the behavior of abnormally acting device or user.

The cyber threat coordinator component can also use a feedback loop monitor to ensure the directed actions to the network components actually have the anticipated effect against the detected threat to counter and/or contain that threat. Thus, the feedback loop monitors the actual impact of the direct actions to the network components ability to constrain the threat as well as the actual impact on other network components or users that were acting normally. If either is not working or performing as anticipated, then taking a second set of actions to get to the desired containment of the detected threat while minimizing the impact on the other network components or users that were acting normally. Repeating this feedback loop of monitoring and taking actions until the desired effect against the detected threat while minimizing the impact on the other network components or users that were acting normally is achieved.

The cyber threat coordinator component does not initiate just a binary reaction of identifying a virus/malware signature ‘yes’ or ‘no,’ but ensures first set of actions work and if not, then proceeds with the remaining series of actions and monitors how these actions are working.

The mathematical functions can factor in how many other components will be affected, how many other components will both be affected and that are also currently active (i.e. not shutdown, in a sleep mode, etc.), overall impact on the network, and the level of severity of the threat, etc., which all are fed as inputs into an algorithm/mathematical function that then calculates this into a score, and compare scores of taking each action from a plurality of options to take for this event and then selects the best target action(s), which also minimize effects on other active network components and users that were acting within their normal bounds of behavior.

In an embodiment, the mathematical functions will factor the following factors:

The number of devices not in breach that would be affected by the action. The relative interference to the pattern of life of all those devices not in breach (e.g. significance of stopping a communication, how often affected devices communicate via that affected port,) (e.g. whether a particular connection has a lot of traffic or rarely has traffic during this time window (during working hours vs. past normal working hours, and number of active users/devices, etc.) The level of severity of the threat indicated by model for the breaching device. Filter out devices and users who are not currently active. The level of effectiveness in that capability's ability to block or interfere with the specific connection. The impact to other devices/processes in the network should that capability be enacted. Popularity of a connection occurring from this device to another devices as well as Popularity of other devices and/users in the network using this connection to connect to other devices. Some other factors used as inputs are created dynamically by the machine learning being trained on the normal bounds of behavior of this network.

FIG. 7 illustrates a flow diagram of an embodiment of the cyber-threat coordinator-component with an example decision process to initiate a chosen set of actions to cause a best targeted change of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

The cyber-threat coordinator- component 100 uses the AI models to understand the normal pattern of life of the network; and thus, normal behaviors of entities in the network. The AI models use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions. The cyber-threat coordinator- component 100 determines is this user, connection, or device within the normal pattern of life? If yes, the cyber-threat coordinator- component 100 does not need to do anything.

If no, the cyber-threat coordinator- component 100 needs to evaluate i) for each capability ii) for each network device, the following analysis. The cyber-threat coordinator- component 100 uses the one or more mathematical functions to generate a score for each of the possible actions and/or sequence of multiple possible actions that can be taken in order to determine which set of actions to choose among many possible actions to take/initiate. The one or more possible actions to take and their calculated scores will be stacked against each other to factor 1) a likelihood of containing/countering the detected threat acting abnormal with each possible set of actions, 2) a severity level of the detected threat to the network, and 3) the impact of taking each possible set of actions i) on users and ii) on devices currently active in the network not acting abnormal to the normal behavior of the network, and then initiate the chosen set of actions to cause a best change of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

The cyber-threat coordinator- component 100 determines will this block or interfere with this network connection? If no, the cyber-threat coordinator- component 100 can initiate that capability and then evaluate if any additional actions are needed. In this situation it is a simple determination for the cyber-threat coordinator- component 100 to choose an initial set of one or more actions indicated as a best initial response to the detected threat by autonomously initiating those actions to defend against the detected threat without any human interaction. The self-learning Artificial Intelligence models chose the best initial response and autonomously initiate that initial set of one or more actions.

If yes, the cyber-threat coordinator- component 100 another factor is as follows. Will this block or interfere with other users, connections, or devices? If no, the cyber-threat coordinator- component 100 directs the initial set of actions to be taken and expects i) an impact on the detected threat and ii) an effect on the rest of the active devices and active users in the network. The feedback loop monitors an actual effect on the detected threat in breach from the initial set of actions taken as well as an actual effect on the rest of the devices and users in the network not in breach from the initial set of actions taken.

If yes, then the cyber-threat coordinator- compone

CLAIMS

Claims ( 16 )

What is claimed is:

1. A method for a cyber threat protection system, comprising:

analyzing input data on entities associated with a network using one or more models that are self-learning Artificial Intelligence models trained on a normal behavior of users and devices associated with the network;

where a normal behavior benchmark is used by a given model as a benchmark of parameters that correspond to a normal pattern of life for the network, and the normal behavior benchmark allows that self-learning model to spot behavior on the network that falls outside the parameters set by the normal behavior benchmark;

comparing the analyzed input data on one or more of the entities associated with the network to the benchmark of parameters that correspond to the normal pattern of life for the devices and users of the network;

identifying at least one of a device, a user, or a combination of both, that are in a breach state of the benchmark of parameters, utilized by the Artificial Intelligence models, that correspond to the normal pattern of life for the network;

sending an external communication to selected network devices in order to initiate actions with that network device in order to counter a behavior of a detected threat of at least one of i) a user, ii) a device, iii) both a user and a device, iv) a set of users, v) a set of devices acting abnormal to the normal pattern of life on the network, and vi) various combinations of these entities; while minimizing an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark;

using an observation and evaluation feedback loop to choose a best initial response and the initial set of actions to take while minimizing the impact on other network devices that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark, where a cyber-threat coordinator-component directs the initial set of actions to be taken and expects i) an impact on the detected threat and ii) an effect on the rest of the active devices and active users in the network, and where the feedback loop monitors an actual effect on the detected threat in breach from the initial set of actions taken as well as an actual effect on the rest of the devices and users in the network not in breach from the initial set of actions taken; and

using the observation and evaluation feedback loop to take a sequence of actions and evaluate the actual impact after each action in the sequence, in order to yield a best possible result to contain the detected threat while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach, from different possible actions to take, where at least a first action is initiated and resulting actual effects are monitored and then a second action in the sequence of actions is initiated and monitored with the observation and evaluation feedback loop to yield the best possible result.

2. The method for the cyber threat protection system of claim 1 , further comprising:

i) discovering capabilities of each network device in the network being monitored and ii) discovering actions they can take to counter and/or contain the detected threat to the network, as well as iii) discovering the communications needed to initiate those actions.

3. The method for the cyber threat protection system of claim 2 , further comprising:

coordinating the capabilities of two or more network devices that are selected to counter the detected threat acting abnormal to the normal pattern of life by sending an external communication to each selected network device in order to initiate actions with that network device in order to counter the behavior of the detected threat while minimizing the impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

4. The method for the cyber threat protection system of claim 1 , further comprising:

using the AI models to understand the normal pattern of life of the network; and thus, normal behaviors of entities in the network, where the AI models use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions.

5. The method for the cyber threat protection system of claim 4 , further comprising:

using the one or more mathematical functions to generate a score for each of the possible actions and/or sequence of multiple possible actions that can be taken in order to determine which set of actions to choose among many possible actions to initiate, where the one or more possible actions to take and their calculated scores will be stacked against each other to factor 1) a likelihood of containing the detected threat acting abnormal with each possible set of actions, 2) a severity level of the detected threat to the network, and 3) the impact of taking each possible set of actions i) on users and ii) on devices currently active in the network not acting abnormal to the normal behavior of the network, and then initiate the chosen set of actions to cause a best counter of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

6. The method for the cyber threat protection system of claim 1 , further comprising:

choosing an initial set of one or more actions indicated as a best initial response to the detected threat by autonomously initiating those actions to defend against the detected threat without any human interaction, where the self-learning Artificial Intelligence models choose the best initial response and autonomously initiate that initial set of one or more actions.

7. The method for the cyber threat protection system of claim 1 , wherein the self-learning models of normal behavior use an architecture that is continuously updated, where the self-learning Artificial Intelligence models trained on the normal behavior of users and devices associated with the network, record and continuously update their training on the normal behavior of the network system that a cyber-threat coordinator-component using the self-learning Artificial Intelligence models is monitoring and protecting, and where the normal behavior benchmark is varied according to the updated changes in the network.

8. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the computer system to instruct a computing device to perform the method of claim 1 .

9. A cyber-threat coordinator-component, comprising:

an analysis module configured to analyze input data on entities associated with a network using one or more self-learning Artificial Intelligence models trained on a normal behavior of users and devices associated with the network;

where a normal behavior benchmark is used by a given AI model as a benchmark of parameters that correspond to a normal pattern of life for the network, and the normal behavior benchmark allows that self-learning model to spot behavior on the network that falls outside the parameters set by the normal behavior benchmark;

a comparison module configured to compare the analyzed input data on one or more of the entities associated with the network utilized by the self-learning Artificial Intelligence models trained on the normal pattern of life for the network;

where the comparison module is further configured to identify at least one of a device, a user, or a combination of both, that are in a breach state of the benchmark of parameters, utilized by the Artificial Intelligence models, that correspond to the normal pattern of life for the network;

a coordinator module configured to cooperate with the comparison module and send an external communication to selected network devices in order to initiate actions with that network device in order to counter a behavior of a detected threat of a user and/or a device acting abnormal to the normal pattern of life on the network while minimizing an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark;

an observation and evaluation feedback loop is used to choose a best targeted initial response and the initial set of actions to take while minimizing the impact on other network devices that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark, where the coordinator module of the cyber-threat coordinator-component directs the initial set of actions to be taken and expects i) an impact on the detected threat and ii) an effect on the rest of the active devices and active users in the network, and where the feedback loop monitors an actual effect on the detected threat in breach from the initial set of actions taken as well as an actual effect on the rest of the devices and users in the network not in breach from the initial set of actions taken; and

where the observation and evaluation feedback loop is used to take a sequence of actions and evaluate the actual impact after each action in the sequence, in order to yield a best possible result to contain the detected threat while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach, from different possible actions to take, where at least a first action is initiated and resulting actual effects are monitored and then a second action in the sequence of actions is initiated and monitored with the observation and evaluation feedback loop to yield the best possible result.

10. The apparatus for the cyber threat protection system of claim 9 , further comprising:

a discovery module configured to i) discover capabilities of each network device in the network being monitored and ii) discover actions they can take to counter and/or contain the detected threat to the network, as well as iii) discover the communications needed to initiate those actions.

11. The apparatus for the cyber threat protection system of claim 10 , further comprising:

where the coordinator module is further configured to coordinate the capabilities of two or more network devices that are selected to counter the detected threat acting abnormal to the normal pattern of life by sending an external communication to each selected network device in order to initiate actions with that network device in order to counter the behavior of the detected threat while minimizing the impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark.

12. The apparatus for the cyber threat protection system of claim 9 , further comprising:

where the AI models are trained on the normal pattern of life of the network; and thus, normal behaviors of entities in the network, where the AI models are configured to use one or more mathematical functions to evaluate different factors, and then choose a best set of one or more actions from all of the possible actions, and then the coordinator module is configured to use one or more Application Programming Interfaces to translate desired actions from selected network devices into a specific language and syntax utilized by that network device in order to send the communications to the selected network devices from potentially multiple different vendors to take those desired actions.

13. The apparatus for the cyber threat protection system of claim 12 , further comprising:

where the AI models are configured to use the one or more mathematical functions to generate a score for each of the possible actions and/or sequence of multiple possible actions that can be taken in order to determine which set of actions to choose among many possible actions to initiate, where the one or more possible actions to take and their calculated scores will be stacked against each other to factor 1) a likelihood of containing the detected threat acting abnormal with each possible set of actions, 2) a severity level of the detected threat to the network, and 3) the impact of taking each possible set of actions i) on users and ii) on devices currently active in the network not acting abnormal to the normal behavior of the network, and then communicate with the coordinator module to initiate the chosen set of actions to cause a best targeted counter of the behavior of the detected threat acting abnormal to the normal pattern of life on the network while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach of being outside the normal behavior benchmark.

14. The apparatus for the cyber threat protection system of claim 9 , further comprising:

where the AI models are configured to choose an initial set of one or more actions indicated as a best targeted initial response to the detected threat by autonomously initiating those actions to defend against the detected threat without any human interaction, where the self-learning Artificial Intelligence models choose the best initial response and then communicate with the coordinator module to autonomously initiate that initial set of one or more actions.

15. The apparatus for the cyber threat protection system of claim 9 , wherein the self-learning models of normal behavior are configured to use an architecture that is continuously updated, where the self-learning Artificial Intelligence models trained on the normal behavior of users and devices associated with the network, and record and continuously update their training on the normal behavior of the network system, and where the normal behavior benchmark is varied according to the updated changes in the network.

16. A network, comprising:

one or more firewalls;

one or more network switches;

one or more computing devices operable by users of the network; and

a cyber-threat coordinator-component that includes:

a comparison module configured to identify at least one of a device, a user, or a combination of both, that are in a breach state of the benchmark of parameters, utilized by AI models, that correspond to the normal pattern of life for the network, and

a coordinator module configured to send an external communication to selected network devices in order to initiate actions with that the selected network devices in order to change a behavior of a detected threat of at least one of a user and/or a device acting abnormal to the normal pattern of life on the network while minimizing an impact on other network devices and users that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark,

where an observation and evaluation feedback loop is used to choose a best targeted initial response and the initial set of actions to take while minimizing the impact on other network devices that are i) currently active in the network and ii) that are not in breach of being outside the normal behavior benchmark, where the coordinator module of the cyber-threat coordinator-component directs the initial set of actions to be taken and expects i) an impact on the detected threat and ii) an effect on the rest of the active devices and active users in the network, and where the feedback loop monitors an actual effect on the detected threat in breach from the initial set of actions taken as well as an actual effect on the rest of the devices and users in the network not in breach from the initial set of actions taken,

where the observation and evaluation feedback loop is used to take a sequence of actions and evaluate the actual impact after each action in the sequence, in order to yield a best possible result to contain the detected threat while minimizing the impact on other network devices and users that are i) currently active and ii) not in breach, from different possible actions to take, where at least a first action is initiated and resulting actual effects are monitored and then a second action in the sequence of actions is initiated and monitored with the observation and evaluation feedback loop to yield the best possible result, and

where the cyber-threat coordinator-component improves one or more of the computing devices themselves by containing the detected threat and minimizing an amount of CPU cycles, memory space, and power consumed by that detected threat in a first computing device when the detected threat is contained by the initiated actions.

US16/279,067

2018-02-20

2019-02-19

Artificial intelligence controller orchestrating network components for a cyber threat defense

Active

2041-04-24

US11522887B2

( en )

Priority Applications (1)

Application Number

Priority Date

Filing Date

Title

US16/279,067

US11522887B2

( en )

2018-02-20

2019-02-19

Artificial intelligence controller orchestrating network components for a cyber threat defense

Applications Claiming Priority (2)

Application Number

Priority Date

Filing Date

Title

US201862632623P

2018-02-20

2018-02-20

US16/279,067

US11522887B2

( en )

2018-02-20

2019-02-19

Artificial intelligence controller orchestrating network components for a cyber threat defense

Publications (2)

Publication Number

Publication Date

US20190260786A1

US20190260786A1 ( en )

2019-08-22

US11522887B2

true

US11522887B2 ( en )

2022-12-06

Family

ID=65516440

Family Applications (27)

Application Number

Title

Priority Date

Filing Date

US16/279,067

Active

2041-04-24

US11522887B2

( en )

2018-02-20

2019-02-19

Artificial intelligence controller orchestrating network components for a cyber threat defense

US16/279,031

Active

2040-04-12

US11336670B2

( en )

2018-02-20

2019-02-19

Secure communication platform for a cybersecurity system

US16/278,920

Active

2041-07-10

US11546359B2

( en )

2018-02-20

2019-02-19

Multidimensional clustering analysis and visualizing that clustered analysis on a user interface

US16/278,991

Active

2041-07-22

US11689556B2

( en )

2018-02-20

2019-02-19

Incorporating software-as-a-service data into a cyber threat defense system

US16/278,918

Active

2040-03-07

US11336669B2

( en )

2018-02-20

2019-02-19

Artificial intelligence cyber security analyst

US16/278,982

Active

2041-06-08

US11546360B2

( en )

2018-02-20

2019-02-19

Cyber security appliance for a cloud infrastructure

US16/279,039

Active

2040-09-04

US11477219B2

( en )

2018-02-20

2019-02-19

Endpoint agent and system

US16/278,957

Active

2041-03-23

US11457030B2

( en )

2018-02-20

2019-02-19

Artificial intelligence researcher assistant for cybersecurity analysis

US16/278,953

Active

2042-03-17

US11843628B2

( en )

2018-02-20

2019-02-19

Cyber security appliance for an operational technology network

US16/278,932

Active

2041-07-13

US11606373B2

( en )

2018-02-20

2019-02-19

Cyber threat defense system protecting email networks with machine learning models

US16/279,013

Active

2041-04-10

US11418523B2

( en )

2018-02-20

2019-02-19

Artificial intelligence privacy protection for cybersecurity analysis

US16/279,022

Active

2040-06-12

US11689557B2

( en )

2018-02-20

2019-02-19

Autonomous report composer

US16/278,998

Active

2040-02-07

US11075932B2

( en )

2018-02-20

2019-02-19

Appliance extension for remote communication with a cyber security appliance

US16/278,969

Active

2040-05-30

US11799898B2

( en )

2018-02-20

2019-02-19

Method for sharing cybersecurity threat analysis and defensive measures amongst a community

US16/941,874

Active

2039-06-12

US11716347B2

( en )

2018-02-20

2020-07-29

Malicious site detection for a cyber threat response system

US17/745,255

Active

US11902321B2

( en )

2018-02-20

2022-05-16

Secure communication platform for a cybersecurity system

US17/745,250

Active

US12407712B2

( en )

2018-02-20

2022-05-16

Artificial intelligence cyber security analyst

US17/966,720

Active

US12563087B2

( en )

2018-02-20

2022-10-14

Endpoint agent and system

US18/213,123

Active

2039-04-09

US12225045B2

( en )

2018-02-20

2023-06-22

Incorporating software-as-a-service data into a cyber threat defense system

US18/213,128

Active

US12407713B2

( en )

2018-02-20

2023-06-22

Autonomous report composer

US18/373,157

Pending

US20240022595A1

( en )

2018-02-20

2023-09-26

Method for sharing cybersecurity threat analysis and defensive measures amongst a community

US18/387,322

Active

2039-04-25

US12363157B2

( en )

2018-02-20

2023-11-06

Cyber security appliance for an operational technology network

US18/414,786

Pending

US20240372889A1

( en )

2018-02-20

2024-01-17

A Secure Communication Platform for A Cybersecurity System

US19/025,773

Pending

US20250175493A1

( en )

2018-02-20

2025-01-16

Incorporating software-as-a-service data into a cyber threat defense system

US19/242,732

Pending

US20250317472A1

( en )

2018-02-20

2025-06-18

Cyber security appliance for an operational technology network

US19/292,707

Pending

US20250365309A1

( en )

2018-02-20

2025-08-06

Artificial intelligence cyber security analyst

US19/298,027

Pending

US20250373652A1

( en )

2018-02-20

2025-08-12

Autonomous Report Composer

Family Applications After (26)

Application Number

Title

Priority Date

Filing Date

US16/279,031

Active

2040-04-12

US11336670B2

( en )

2018-02-20

2019-02-19

Secure communication platform for a cybersecurity system

US16/278,920

Active

2041-07-10

US11546359B2

( en )

2018-02-20

2019-02-19

Multidimensional clustering analysis and visualizing that clustered analysis on a user interface

US16/278,991

Active

2041-07-22

US11689556B2

( en )

2018-02-20

2019-02-19

Incorporating software-as-a-service data into a cyber threat defense system

US16/278,918

Active

2040-03-07

US11336669B2

( en )

2018-02-20

2019-02-19

Artificial intelligence cyber security analyst

US16/278,982

Active

2041-06-08

US11546360B2

( en )

2018-02-20

2019-02-19

Cyber security appliance for a cloud infrastructure

US16/279,039

Active

2040-09-04

US11477219B2

( en )

2018-02-20

2019-02-19

Endpoint agent and system

US16/278,957

Active

2041-03-23

US11457030B2

( en )

2018-02-20

2019-02-19

Artificial intelligence researcher assistant for cybersecurity analysis

US16/278,953

Active

2042-03-17

US11843628B2

( en )

2018-02-20

2019-02-19

Cyber security appliance for an operational technology network

US16/278,932

Active

2041-07-13

US11606373B2

( en )

2018-02-20

2019-02-19

Cyber threat defense system protecting email networks with machine learning models

US16/279,013

Active

2041-04-10

US11418523B2

( en )

2018-02-20

2019-02-19

Artificial intelligence privacy protection for cybersecurity analysis

US16/279,022

Active

2040-06-12

US11689557B2

( en )

2018-02-20

2019-02-19

Autonomous report composer

US16/278,998

Active

2040-02-07

US11075932B2

( en )

2018-02-20

2019-02-19

Appliance extension for remote communication with a cyber security appliance

US16/278,969

Active

2040-05-30

US11799898B2

( en )

2018-02-20

2019-02-19

Method for sharing cybersecurity threat analysis and defensive measures amongst a community

US16/941,874

Active

2039-06-12

US11716347B2

( en )

2018-02-20

2020-07-29

Malicious site detection for a cyber threat response system

US17/745,255

Active

US11902321B2

( en )

2018-02-20

2022-05-16

Secure communication platform for a cybersecurity system

US17/745,250

Active

US12407712B2

( en )

2018-02-20

2022-05-16

Artificial intelligence cyber security analyst

US17/966,720

Active

US12563087B2

( en )

2018-02-20

2022-10-14

Endpoint agent and system

US18/213,123

Active

2039-04-09

US12225045B2

( en )

2018-02-20

2023-06-22

Incorporating software-as-a-service data into a cyber threat defense system

US18/213,128

Active

US12407713B2

( en )

2018-02-20

2023-06-22

Autonomous report composer

US18/373,157

Pending

US20240022595A1

( en )

2018-02-20

2023-09-26

Method for sharing cybersecurity threat analysis and defensive measures amongst a community

US18/387,322

Active

2039-04-25

US12363157B2

( en )

2018-02-20

2023-11-06

Cyber security appliance for an operational technology network

US18/414,786

Pending

US20240372889A1

( en )

2018-02-20

2024-01-17

A Secure Communication Platform for A Cybersecurity System

US19/025,773

Pending

US20250175493A1

( en )

2018-02-20

2025-01-16

Incorporating software-as-a-service data into a cyber threat defense system

US19/242,732

Pending

US20250317472A1

( en )

2018-02-20

2025-06-18

Cyber security appliance for an operational technology network

US19/292,707

Pending

US20250365309A1

( en )

2018-02-20

2025-08-06

Artificial intelligence cyber security analyst

US19/298,027

Pending

US20250373652A1

( en )

2018-02-20

2025-08-12

Autonomous Report Composer

Country Status (7)

Country

Link

US

( 27 )

US11522887B2

( en )

EP

( 8 )

EP4312420A3

( en )

JP

( 2 )

JP7614715B2

( en )

AU

( 1 )

AU2019201137B2

( en )

CA

( 2 )

CA3034176C

( en )

DK

( 4 )

DK3528462T3

( en )

SG

( 1 )

SG10201901386UA

( en )

Cited By (3)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20210234848A1

( en )

*

2018-01-11

2021-07-29

Visa International Service Association

Offline authorization of interactions and controlled tasks

US20230418637A1

( en )

*

2018-07-19

2023-12-28

Twistlock Ltd.

Cloud native virtual machine runtime protection

US12238009B1

( en )

*

2023-10-05

2025-02-25

Oracle International Corporation

Distributed rate limiting

Families Citing this family (550)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

WO2015094372A1

( en )

*

2013-12-20

2015-06-25

Mcafee, Inc.

Intelligent firewall access rules

US10671470B2

( en )

*

2015-06-11

2020-06-02

Instana, Inc.

Application performance management system with dynamic discovery and extension

US12500929B2

( en )

*

2023-07-28

2025-12-16

Qomplx Llc

Host-level ticket forgery detection and extension to network endpoints

US10607004B2

( en )

*

2016-09-29

2020-03-31

Intel Corporation

Methods and apparatus to improve feature engineering efficiency with metadata unit operations

US10999296B2

( en )

2017-05-15

2021-05-04

Forcepoint, LLC

Generating adaptive trust profiles using information derived from similarly situated organizations

US10992652B2

( en )

2017-08-25

2021-04-27

Keysight Technologies Singapore (Sales) Pte. Ltd.

Methods, systems, and computer readable media for monitoring encrypted network traffic flows

US10903985B2

( en )

2017-08-25

2021-01-26

Keysight Technologies Singapore (Sales) Pte. Ltd.

Monitoring encrypted network traffic flows in a virtual environment using dynamic session key acquisition techniques

US10769306B2

( en )

*

2017-09-21

2020-09-08

International Business Machines Corporation

Applying a differential privacy operation on a cluster of data

US12489771B1

( en )

*

2017-11-27

2025-12-02

Fortinet, Inc.

Detecting anomalous behavior of nodes in a hierarchical cloud deployment

US10616260B2

( en )

2017-11-30

2020-04-07

Bank Of America Corporation

System for information security threat assessment

US10635822B2

( en )

*

2017-11-30

2020-04-28

Bank Of America Corporation

Data integration system for triggering analysis of connection oscillations

US10826929B2

( en )

2017-12-01

2020-11-03

Bank Of America Corporation

Exterior data deployment system using hash generation and confirmation triggering

US10666666B1

( en )

2017-12-08

2020-05-26

Logichub, Inc.

Security intelligence automation platform using flows

US10735272B1

( en )

*

2017-12-08

2020-08-04

Logichub, Inc.

Graphical user interface for security intelligence automation platform using flows

US11403958B2

( en )

*

2017-12-13

2022-08-02

T-Mobile Usa, Inc.

Lesson determination for dynamic gamification application

US10834111B2

( en )

*

2018-01-29

2020-11-10

International Business Machines Corporation

Method and system for email phishing attempts identification and notification through organizational cognitive solutions

DK3528462T3

( en )

2018-02-20

2024-02-26

Darktrace Holdings Ltd

Approach to share a cybersecurity threat analysis and defensive measures in a community

US10862912B2

( en )

*

2018-03-23

2020-12-08

Juniper Networks, Inc.

Tracking host threats in a network and enforcing threat policy actions for the host threats

US10887327B2

( en )

2018-03-23

2021-01-05

Juniper Networks, Inc.

Enforcing threat policy actions based on network addresses of host threats

US12261870B2

( en )

2018-03-23

2025-03-25

Juniper Networks, Inc.

Tracking host threats in a network and enforcing threat policy actions for the host threats

US11003773B1

( en )

*

2018-03-30

2021-05-11

Fireeye, Inc.

System and method for automatically generating malware detection rule recommendations

US10749882B2

( en )

*

2018-04-19

2020-08-18

Raytheon Bbn Technologies Corp.

Network security system and methods for encoding network connectivity for activity classification

RU2715025C2

( en )

*

2018-04-19

2020-02-21

Акционерное общество "Лаборатория Касперского"

Method for automated testing of software and hardware systems and complexes

US11575688B2

( en )

*

2018-05-02

2023-02-07

Sri International

Method of malware characterization and prediction

US12081567B2

( en )

*

2018-05-03

2024-09-03

Siemens Aktiengesellschaft

Analysis device, method and system for operational technology system and storage medium

US11544374B2

( en )

*

2018-05-07

2023-01-03

Micro Focus Llc

Machine learning-based security threat investigation guidance

US10397272B1

( en )

2018-05-10

2019-08-27

Capital One Services, Llc

Systems and methods of detecting email-based attacks through machine learning

US11586711B2

( en )

*

2018-05-14

2023-02-21

Cisco Technology, Inc.

Systems and methods for securing and controlling access to electronic data, electronic systems, and digital accounts

US11438357B2

( en )

2018-06-22

2022-09-06

Senseon Tech Ltd

Endpoint network sensor and related cybersecurity infrastructure

GB201810294D0

( en )

2018-06-22

2018-08-08

Senseon Tech Ltd

Cybe defence system

GB2602254B

( en )

2020-12-15

2023-04-05

Senseon Tech Ltd

Network traffic monitoring

US12057011B2

( en )

*

2018-06-28

2024-08-06

Cavh Llc

Cloud-based technology for connected and automated vehicle highway systems

US11483313B2

( en )

*

2018-06-28

2022-10-25

Intel Corporation

Technologies for updating an access control list table without causing disruption

US11157834B2

( en )

*

2018-07-10

2021-10-26

Cisco Technology, Inc.

Automated identification of higher-order behaviors in a machine-learning network security system

GB201812171D0

( en )

2018-07-26

2018-09-12

Senseon Tech Ltd

Cyber defence system

US10742484B1

( en )

*

2018-07-31

2020-08-11

Splunk Inc.

Generating action suggestions based on anonymized data from multiple information technology environments

US10893030B2

( en )

2018-08-10

2021-01-12

Keysight Technologies, Inc.

Methods, systems, and computer readable media for implementing bandwidth limitations on specific application traffic at a proxy element

US11386304B2

( en )

*

2018-08-20

2022-07-12

Samsung Electronics Co., Ltd.

Electronic device and method of controlling the same

US11431725B2

( en )

*

2020-09-23

2022-08-30

BabelWorks AI, Inc.

Systems and methods for dynamic network pairings to enable end-to-end communications between electronic devices

US11012421B2

( en )

2018-08-28

2021-05-18

Box, Inc.

Predicting user-file interactions

US10972461B2

( en )

*

2018-08-28

2021-04-06

International Business Machines Corporation

Device aware network communication management

US11552962B2

( en )

2018-08-31

2023-01-10

Sophos Limited

Computer assisted identification of intermediate level threats

US10574512B1

( en )

*

2018-09-04

2020-02-25

Cisco Technology, Inc.

Deep learning architecture for collaborative anomaly detection and explanation

US10778689B2

( en )

*

2018-09-06

2020-09-15

International Business Machines Corporation

Suspicious activity detection in computer networks

WO2020056390A1

( en )

*

2018-09-15

2020-03-19

Quantum Star Technologies LLC

Bit-level data generation and artificial intelligence techniques and architectures for data protection

JP7121276B2

( en )

*

2018-09-19

2022-08-18

富士通株式会社

DATA MANAGEMENT LEVEL DETERMINATION PROGRAM AND DATA MANAGEMENT LEVEL DETERMINATION METHOD

CN110943961B

( en )

2018-09-21

2022-06-21

阿里巴巴集团控股有限公司

Data processing method, device and storage medium

US11070632B2

( en )

*

2018-10-17

2021-07-20

Servicenow, Inc.

Identifying computing devices in a managed network that are involved in blockchain-based mining

<tr itemprop="forwardRefere

Related documents

Record · ID 607061
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.