Apparatus, system, and method for autonomous threat response and security enhancement

The autonomous threat scoring system addresses the inefficiencies of current SIEM tools by calculating credible IoC threat scores and automating security responses, improving threat management and reducing costs for MSSPs and clients.

JP2025527181AActive Publication Date: 2025-08-20BLUEVOYANT LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025504309
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-27
Filing Date
2023-07-26
Publication Date
2025-08-20
Estimated Expiration
2043-07-26

AI Technical Summary

Technical Problem

Current SIEM tools face challenges in efficiently managing multiple client networks due to inconsistent and unreliable data sources, difficulty in classifying IoCs, and lack of automation for real-time threat response, leading to inefficiencies and increased costs for MSSPs and their clients.

Method used

An autonomous threat scoring system that calculates an IoC threat score based on credibility scores from multiple data sources, enabling automated security hardening and response, including threat classification and scalable deployment across networks.

Benefits of technology

Enhances the reliability and efficiency of threat management by providing trusted data and automated responses, reducing manual intervention and operational costs, while ensuring real-time threat detection and response across multiple client networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025527181000001
    Figure 2025527181000001
  • Figure 2025527181000002
    Figure 2025527181000002
  • Figure 2025527181000003
    Figure 2025527181000003
Patent Text Reader

Abstract

Disclosed is a system and method for autonomous hardening of a tenant network via a managed security service provider (MSSP) server having a processor and a memory, using information from a plurality of data sources, the method including: querying, by a security system upon encountering an indicator of compromise (IoC), a database or server to identify a data source from the plurality of data sources, the data source including information about the IoC; generating, via the processor, an IoC threat score for the IoC; generating at least one actionable security hardening notification based on the IoC threat score; and deploying an automated security response, which may include displaying the IoC threat score and the actionable security hardening notification to a user to enable triggering or disabling of at least one action based on the single IoC threat score.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of and priority to U.S. Provisional Patent Application No. 63 / 369,582, filed July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT," the disclosure of which is incorporated herein by reference in its entirety.

[0002] The present technology relates to systems and methods for autonomous threat detection and automated management in a managed security service provider environment. In particular, but not by way of limitation, the present technology provides systems and methods for autonomous threat response and security enforcement. Summary of the Invention

[0003] The following summary is provided to facilitate an understanding of some of the innovative features unique to the embodiments disclosed herein and is not intended to be a complete description, A complete understanding of the various embodiments can be obtained by taking the specification, claims, and abstract as a whole.

[0004] In various aspects, a method is provided for autonomous hardening of a tenant network via a managed security service provider (MSSP) server having a processor and a memory, the method including: upon encountering an indicator of compromise (IoC) by a security system, performing a query via the processor, database, or server to identify an associated source or feed referencing the encountered IoC; generating or calculating via the processor an IoC threat score for the encountered IoC based on output of the query; generating via the processor at least one actionable security hardening notification based on the single threat score of the encountered IoC; and displaying via a user interface the IOC threat score of the encountered IoC and the actionable security hardening notification to a user of the security system, wherein the user may trigger or disable one or more actions in the at least one actionable security hardening notification.

[0005] In various aspects, generating an IoC threat score includes: for each associated source or feed, identifying a threat value of the encountered IOCs categorized by the associated source or feed; for each associated source or feed, adding a multiplier to the threat value of the source or feed to generate an adjusted threat value, where the multiplier is determined based on the credibility score associated with the source or feed; normalizing all adjusted threat values of the associated sources or feeds; and generating a single threat score for the encountered IoCs.

[0006] The method for autonomously hardening the security of a tenant network may further include deploying an automated security response that may include one or more of automatically adjusting a security threat threshold level, automatically reconfiguring a database to identify other potential malware variants, sending notifications to a number of other users of the security system, determining exposure and future risk of exposure of other tenant networks to the IoC, and quarantining one or more tenant networks or portions of a network.

[0007] In some embodiments, the contemplated method also includes classifying the encountered IoC as malicious, unknown, or benign based on at least one or more of the generated IoC threat score, the generated confidence score, and the security threat threshold level, and a user interface may display the classification to a user of the security system.

[0008] These and other objects, features, and characteristics of the present invention, as well as the method of operation, function of the associated structural elements, combination of parts, and economies of manufacture, will become more apparent from a consideration of the following description and appended claims, which refer to the accompanying drawings, all of which form a part of this specification, and in which like reference characters indicate corresponding parts in the various views. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the invention. [Brief explanation of the drawings]

[0009] Various features of the aspects described herein are set forth with particularity in the appended claims. However, various aspects, both as to organization and method of operation, and their advantages may be understood by reading the following description in conjunction with the accompanying drawings, as set forth below.

[0010] [Figure 1]FIG. 1 illustrates a system configured to remotely manage another organization's security orchestration, automation, and response (“SOAR”) in accordance with at least one non-limiting aspect of the present disclosure. [Figure 2] FIG. 2 illustrates a functional architecture of the system of FIG. 1 in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 3] FIG. 3 illustrates a diagram of a method for autonomously securing a tenant network via a managed security service provider (MSSP). [Figure 4] FIG. 4 shows a diagram of an autonomous method for calculating a threat score for an encountered indicator of compromise (IoC). [Figure 5] FIG. 5 illustrates a graphical user interface of an autonomous threat scoring and management application dashboard showing an overview of detected and managed threats, according to some non-limiting aspects of the present disclosure. [Figure 6] FIG. 6 illustrates another graphical user interface displaying details of detected threats or indicators of compromise, according to some non-limiting aspects of the present disclosure. [Figure 7] FIG. 7 illustrates a graphical user interface displaying details of indicators of infringement encountered, according to some non-limiting aspects of the present disclosure. [Figure 8] FIG. 8 illustrates a graphical user interface that provides investigation notes for each investigated indicator of compromise, according to some non-limiting aspects of the present disclosure. [Figure 9] FIG. 9 illustrates a diagrammatic representation of an exemplary machine in the form of a computer system in which a set of instructions may be executed to cause the machine to perform any one or more of the methods discussed herein, in accordance with certain non-limiting aspects of the present disclosure.

[0011] Corresponding reference characters indicate corresponding parts throughout the several views. The examples described herein illustrate various aspects of the present invention in one form and are not to be construed as limiting the scope of the invention in any way. DETAILED DESCRIPTION OF THE INVENTION

[0012] The applicant of the present application owns the following US provisional patent applications, the disclosures of each of which are incorporated herein by reference in their entirety: - International Patent Application No. PCT / US2022 / 072739, filed June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS; - International Patent Application No. PCT / US2022 / 072743, filed June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS; - International Patent Application No. PCT / US2022 / 082167, filed December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS; - International Patent Application No. PCT / US2022 / 082173, filed December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS; - International Patent Application No. PCT / US2023 / 061069, filed January 23, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION'S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE; - International Patent Application No. PCT / US2023 / 062894, filed February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS. - International Patent Application No. PCT / US2023 / 021736, entitled DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS, filed May 10, 2023; - International Patent Application No. PCT / US2023 / 022858, filed May 19, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS; - International Patent Application No. PCT / US2023 / 022535, filed May 17, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM; - International Patent Application No. PCT / US2023 / 024386, entitled DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX, filed June 4, 2023; - International Patent Application No. PCT / US2023 / 068590, filed June 16, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS; - U.S. Provisional Patent Application No. 63 / 368,567, filed July 17, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY; - U.S. Provisional Patent Application No. 63 / 369,582, filed July 27, 2022, entitled AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT; - U.S. Provisional Patent Application No. 63 / 377,304, entitled DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES, filed September 27, 2022; - U.S. Provisional Patent Application No. 63 / 507,250, filed June 9, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR ATTRIBUTING NETWORK-IMPLEMENTED CYBER ASSETS TO OPERATING ENTITIES AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON THE ATTRIBUTION.

[0013] Numerous specific details are set forth in this disclosure to provide a thorough understanding of the overall structure, function, manufacture, and use of the embodiments described in the accompanying drawings. Well-known operations, components, and elements have not been described in detail so as not to obscure the embodiments described herein. The reader will understand that the embodiments described and illustrated herein are non-limiting embodiments. Accordingly, it will be understood that specific structural and functional details disclosed herein may be representative and exemplary. Changes and modifications can be made without departing from the scope of the claims. Furthermore, it should be understood that such terms as "front," "rear," "left," "right," "upper," "lower," and similar terms are terms of convenience and should not be construed as limiting terms.

[0014] In the following description, like reference numerals indicate like or corresponding parts throughout the several views of the drawings. Also, in the following description, it should be understood that such terms as "front," "rear," "left," "right," "upper," "lower," etc. are terms of convenience and should not be construed as terms of limitation.

[0015] Before describing in detail the various aspects of the systems and methods disclosed herein, it should be noted that the exemplary aspects are not limited in application or use to the details disclosed in the accompanying drawings and description. It should be understood that the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications, and may be practiced or carried out in various ways. Furthermore, unless otherwise indicated, the terms and phrases used herein have been chosen for the convenience of the reader to describe the exemplary aspects and are not intended to be limiting thereof. For example, it will be understood that any reference to a particular manufacturer, software suite, application, or development platform disclosed herein is intended merely to illustrate some of the many aspects of the present disclosure. This includes any trademark references. It should therefore be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any intended use and / or user preference.

[0016] As used herein, the term "server" may refer to or include one or more computing devices that operate through or facilitate communication and processing for multiple parties in a network environment, such as the Internet or any public or private network. As used herein, references to a "server" or "processor" may refer to a previously enumerated server and / or processor that is enumerated as performing the previous step or function, a different server and / or processor and / or combination of servers and / or processors.

[0017] As used herein, the term "platform" is intended to include an ecosystem of software and / or physical resources necessary to enable the technical benefits provided by the software. For example, a platform may include either a standalone software product or a software product configured to integrate with other software or physical resources in the ecosystem necessary for the software to provide its technical benefits. According to some non-limiting aspects, the technical benefits provided by the software are provided to the physical resources of the ecosystem or to other software employed by the physical resources in the ecosystem (e.g., APIs, services, etc.). According to other non-limiting aspects, a platform may include a framework for several software applications intended and designed to function together.

[0018] SIEM and MSSP As used herein, the term "network" includes an entire enterprise information technology ("IT") system, and a tenant "network" applies to a client of an MSSP for whom the MSSP provides SIEM services. For example, a network may include a group of two or more nodes (e.g., devices) connected by any physical and / or wireless connection and configured to communicate and share information with one or more other nodes. However, the term network is not limited to any particular nodes or any particular means of connecting those nodes. A network may include any combination of devices (e.g., servers, databases, local or cloud storage, desktop computers, laptop computers, personal digital assistants, mobile phones, wearables, smart appliances, etc.) connected via Ethernet, intranet, and / or extranet and configured to communicate with each other via ad hoc connections (e.g., Bluetooth, near field communication (NFC), etc.), local area connections ("LANs"), wireless local area networks ("WLANs"), and / or virtual private networks ("VPNs"), regardless of the physical location of each device. The network may further include any tools, applications, and / or services deployed by the devices or otherwise utilized by the enterprise IT systems, such as firewalls, email clients, document management systems, office systems, etc. In some non-limiting aspects, the "network" may include third-party devices, applications, and / or services that are owned and controlled by a third party, but that the tenant is authorized to access the enterprise IT systems.

[0019] Security information and event management (SIEM) includes software configured to aggregate and analyze activity from many different resources across an information technology (IT) infrastructure. For example, a SIEM may be utilized by a SIEM service provider, also known as a managed security service provider (MSSP), to aggregate data (e.g., log data, event data, threat intelligence data, etc.) from multiple systems and analyze that data to capture anomalous behavior or potential cyberattacks. For example, a SIEM may collect security data from network devices, servers, domain controllers, etc. A SIEM may then store, normalize, aggregate, and apply analytics to that data to detect trends, detect threats, and enable an organization to investigate any alerts.

[0020] Commonly implemented SIEMs include Azure Sentinel and Splunk Cloud, Devo, LogRhythm, IBM's QRadar, Securonix, McAfee Enterprise Security Manager, LogPoint, Elastic Stack, ArcSight Enterprise Security Manager, and InsightIDR. Deploying Azure Sentinel as a cloud-based tool has gained widespread acceptance among managed security service providers (MSSPs), and as such, Azure Sentinel is described as a non-limiting example. However, other SIEMs are naturally contemplated by this disclosure. Like most SIEMs, deploying Azure Sentinel requires advanced skills, is time-consuming, and can be error-prone. Each organization needing a security solution has specific needs regarding ingest log sources, detection / alert rules, response automation, monitoring (e.g., reporting), and alerting. Microsoft (MSFT) is often used by MSSPs to manage multiple clients, but the complexity of initial configuration, deployment, and ongoing maintenance of artifacts (e.g., resource groups, log analysis workspaces, alert rules, workbooks, playbooks, etc.) increases significantly. This can result in high costs for both MSSPs, who must hire more expensive specialists, and their clients, who often bear at least part of the increased expenses. However, there is often overlap between some of the deployment needs of various clients. For example, many organizations may need similar firewall monitoring solutions. In these cases, asset reuse and redeployment (and updates) can lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are not technically capable of taking advantage of these synergies.As a result, MSSPs have limited opportunities for reuse to capture efficiencies across multiple clients, from initial provisioning, data collection, analysis, and classification, to threat detection, to automating incident response. This necessitates the issuance of improved devices, systems, and implementation methods, as well as SIEM client updates. These enhancements can improve the technical performance and cost efficiency of SIEMs, including the deployment of detection rules, visualizations, investigation workbooks, and ongoing maintenance.

[0021] Therefore, there is a need for devices, systems, and methods that employ an automated "as a service" approach to generate and deploy a reusable, pre-packaged solution that can be executed in a single step while providing a complete end-to-end SIEM solution. Such devices, systems, and methods allow a Sentinel implementation to be deployed with a single click of a button, requiring minimal understanding of SIEM (e.g., Sentinel, Azure, etc.). Thus, such devices, systems, and methods can be used to consistently and repeatedly extend cloud-based SIEM implementations. Users only need to provide the location where the entire deployment occurs and / or login credentials for the respective client.

[0022] Indicator of Compromise (IoC) While known SIEM tools provide impressive functionality, including monitoring events, collecting data, and issuing security alerts across a network, the quality of the data collected and relied upon to perform these functions is inconsistent and often unreliable. Every MSSP or user of SIEM services or software has access to and utilizes a variety of sources of information and data (referred to herein as "sources" or "data sources") that may be used as indicators of potentially malicious files or activity against their clients, secure databases, and networks for which they provide security services. These forms of data may contain some discrepancies between different sources, including inconsistencies regarding the nature of threats, as well as misreported, underreported, or unreported information.

[0023] Additionally, the large number of data sources utilized by MSSPs that purport to indicate threats and threat indicators (threat indicators are collectively referred to herein as "indicators of compromise" or "IoCs") makes it difficult for security providers, analysts, or MSSPs to address and manage threats to client networks or databases in real time. Current SIEM software and systems can acquire and receive raw data from numerous data sources, but are unable to classify the trustworthiness of the data and / or data sources, prioritize which sources or IoCs should be addressed and in what order, or detect or identify new and non-competing threats within the data, meaning that the large amount of data in SIEM systems adds layers of complexity without significantly improving their effectiveness in managing threats on tenant networks.

[0024] The indicators of compromise discussed may include various indicators known in the art, as well as undiscovered or newly discovered indicators. Some examples of IoCs include evidence of data breach, multiple logins, anomalous DNS requests, unusual inbound / outbound traffic, geographic irregularities in incoming requests or traffic, unknown applications running, multiple requests for the same file, etc. The methods and systems described herein may also be applied to indicators of attack and are not limited to only IoCs.

[0025] Concerns about the reliability of the large amount of data and sources available to SIEM software or MSSPs stem in part from the sheer volume of IoC data. Because this data is automatically generated, user-reported, or insufficiently vetted, it can lead to both false positives (benign indicators flagged as malicious) that disrupt useful processes, and false negatives (malicious indicators not marked as such) that allow malware to operate unimpeded. Furthermore, detecting new variants or forms of malware in IoCs can be difficult. The lack of an ability to properly rank IoCs and programmatically consider the reliability of various threat information sources has led most well-established SIEM methods to simplify the security management process by reducing the number of data sources and IoC data processed by the software, provider, and / or security analyst. This can mean that effective or valid data sources may be discarded in favor of routine or more familiar sources, reducing the SIEM service's or MSSP's potential effectiveness and flexibility to respond to new threats and receive new forms of information.

[0026] Thus, there is a need for devices, systems, and methods that employ an automated "as a service" approach to generate and deploy a reusable, pre-packaged solution that can be executed in a single step, while providing a complete end-to-end SIEM solution; provide trusted data from trusted data sources; and can automate responses, all of which can be deployed at scale across thousands of devices. Such devices, systems, and methods could be deployed with a single click of a button, for example, through a Sentinel implementation, with minimal understanding of SIEM (e.g., Sentinel, Azure, etc.). Thus, such devices, systems, and methods could be used to consistently and repeatedly scale cloud-based SIEM implementations.

[0027] The present disclosure contemplates such devices, systems, and methods, all of which offer numerous technical advantages over traditional MSSP and SIEM platforms, for handling IoC data and associated sources and feeds (also referred to herein as data sources and data feeds, respectively). A data feed may include a mechanism by which a user receives updated data from a data source. This is commonly used in point-to-point settings as well as by real-time applications on the World Wide Web, and examples may include web feeds or RSS feeds. A data source may refer to a location, such as a database or server, from which data originates, including the data in the data feed.

[0028] This disclosure presents such devices, systems, and methods, all of which offer numerous technical benefits, enabling MSSPs to deploy cloud-based SIEM implementations, such as, in one non-limiting embodiment, Azure Sentinel implementations, at scale, repeatedly, and consistently. For example, the devices, systems, and methods disclosed herein can provide an effective way to resolve discrepancies between data and data sources, generate information that can utilize a multitude of IoC data, while ensuring the reliability of the data used in effectively managing threats in real time. The presented techniques provide automated methods and systems for aggregating, categorizing, and scoring data sources, detecting and identifying new threats, and responding to IoCs in a SIEM environment.

[0029] In some embodiments of the presented technology, a SIEM autonomous security system or MSSP server (hereinafter collectively referred to as the "security system") searches for and encounters IoCs within a tenant network and determines whether the IoCs present a tangible threat or are benign. The disclosed security system and method can collect information about IoCs from data sources or feeds and assign or provide a credibility score for each source. These sources or feeds may be periodically collected, updated, aggregated, and indexed in security system documents, databases, servers, nodes, or networks (collectively referred to as the "SIEM autonomous security system database" or "security system database," which may refer to one or more databases, even if not described in multiple forms). These steps may occur once or may be repeated over time to refine and update the data and credibility scores associated with the sources and feeds based on performance over time. Thus, the security system database includes information from various sources and feeds, as well as the assigned, pre-set, or calculated credibility scores and historical performance scores of these sources or feeds, and each of the sources or feeds may contain information or data regarding various indicators of compromise. Each time the security system encounters an IoC within the tenant network, the security system database may be queried by the security system, allowing the security system to calculate an IoC threat score, classify the IoC as a malicious or benign threat, and then take additional, autonomous action as necessary, which may include sending alerts, notifications, recommendations, or implementing an autonomous security response.

[0030] figure Referring now to FIG. 1 , a block diagram of a system 1000 configured to remotely manage another organization's security orchestration, automation, and response (SOAR) is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to the non-limiting aspect of FIG. 1 , the system 1000 may include a SOAR management server 1002 comprising a memory 1006 configured to store a SOAR application (see FIG. 2 ) and a processor 1004 configured to execute the stored SOAR application (see FIG. 2 ), as further discussed with reference to FIG. 2 . For example, the SOAR management server 1002 may be a computing resource owned or leased by a managed security service provider (“MSSP”). The SOAR management server 1002 may communicate with multiple tenants 1010 via a network 1008. a , 1010 b , …1010 n Each of the plurality of tenants 10101, 10102, ... 1010 n may represent customers (e.g., organizations) that have contracted with the MSSP. According to a non-limiting aspect of Figure 1, network 1008 may include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, network 1008 may include, among others, an internal network, a local area network (LAN), Wi-Fi, a cellular network, a near-field communication (NFC), etc.

[0031] Further referring to FIG. 1, each of the multiple tenants 10101, 10102, ... 1010 n can host one or more instances of one or more clients 1012, 1014, 1016. For example, a first tenant 10101 may host one or more client applications 10121, 10122, ... 1012 n , and a second tenant 10102 may include one or more machines running one or more client applications 10141, 10142, ... 1014 nand / or a third tenant 1010n may include one or more machines running one or more client applications 10161, 10162, ... 1016 n Each tenant 10101, 10102, and 1010 n can include an intranet with each machine running a client application. For example, each tenant 10101, 10102, and 1010 n Each of the can represent a customer, such as an organization that has contracted with the MSSP for security services.

[0032] Therefore, the SOAR management server 1002 manages each of the multiple tenants 10101, 10102, and 1010 n 10101, 10102, and 10103, and is therefore responsible for monitoring and managing each client application 1012, 1014, and 1016 against threats. n Differences and complexities in architecture can make this complicated and inefficient for MSSPs. Therefore, known SOAR tools may only manage tenants 10101, 10102, and 10103. n This can leave the SOAR management server 1002 technically exposed and therefore vulnerable to attacks. According to a non-limiting aspect of the present disclosure, the SOAR management server 1002 can run a SOAR management application (see FIG. 2 ) that addresses these deficiencies technically and practically by enhancing the SOAR management server's 1002's management capabilities for multiple tenants, sending alerts, and updating client applications based on correlated and synergistic development needs. Additionally, the architecture 2000 of FIG. 2 further illustrates different means of communication between the various modules, tenants, and the SOAR management server 1002.

[0033] 2, a block diagram of a functional architecture 2000 of the system 1000 of FIG. 1 is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to the non-limiting aspect of FIG. 2, the architecture 2000 may include a content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, collectively provided via applications stored in the memory 1006 (FIG. 1) of the SOAR management server 1002. According to some non-limiting aspects, the SOAR management server 1002 manages the content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, which are collectively provided via applications stored in the memory 1006 (FIG. 1) of the SOAR management server 1002. According to some non-limiting aspects, the SOAR management server 1002 manages the content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, which collectively provide services to the MSSPs and / or tenants 1010. n For example, the SOAR management server 1002 may be cloud-based. When executed by the processor 1004 (FIG. 1), the application's content library 2002, variable store 2004, automation scheme 2008, and service operation engine 2012 can collectively facilitate the simultaneous configuration, management, and / or control of multiple SOAR platforms 2018 for multiple tenants 1010n, or client organizations, at scale. Furthermore, when executed by the processor 1004 (FIG. 1), the application can support the client organization's SOAR platform 2018, either abstractly or dynamically, as described in further detail herein.

[0034] According to some non-limiting embodiments, the application deployed by the SOAR management server 1002 may be configured as the Azure Sentinel Automation Portal (ASAP), as disclosed in U.S. Provisional Patent Application No. 63 / 196,458 and PCT Application No. PCT / US22 / 72739, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," filed June 3, 2021 and June 3, 2022, respectively, the disclosures of which are incorporated herein by reference in their entireties. For example, according to one non-limiting embodiment, the ASAP portal runtime software code may include server middleware responsible for processing content from the content library 2002, connections to the SOAR platform 2018, and / or other services, and service requests for the SOAR management server 1002 to deploy, update, and / or read. In other words, the applications deployed by the SOAR management server 1002, including the content library 2002, variable store 2004, and automation scheme 2008, together with the ability to work with one or more tenants 10101-n simultaneously, may be deployed across all tenants 10101-n. 1-n (Figure 1) can provide a unified, simplified view of deployment.

[0035] The content library 2002 is a database in which the SOAR management server 1002 manages one or more tenants 1010. n2 may be configured to store various artifacts (e.g., detections, automations, workbooks, alert rules, playbooks, etc.) that can configure and manage the SOAR platform. According to some non-limiting aspects, the content library 2002 of FIG. 2 may be stored local to the application, meaning provided via memory 1006 (FIG. 1) of the SOAR management server 1002. However, according to other non-limiting aspects, the content library 2002 may be stored on a remote server communicatively coupled to the SOAR management server 1002. In yet another non-limiting aspect, the content library 2002 may be provided by a third party provider (e.g., GitHub, GitLab, etc.), similar to those disclosed in U.S. Provisional Patent Application No. 63 / 196,458, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," and PCT International Application No. PCT / US22 / 72739, the disclosures of both of which are incorporated herein by reference in their entireties. In summary, the content library 2002, and more specifically, the artifacts stored within the content library 2002, may be managed by the SOAR management server 1002 for managing the tenants 1010. n For example, the content library 2002 may interface with and / or manage the SOAR platform 2018 remotely, or for a client organization. n One or more rules and / or templates may be stored that are configured to automate the deactivation of a user account if the determined risk score, based on the overall detected variables, exceeds a predetermined threshold.

[0036] According to a non-limiting embodiment of FIG. 2, a particular client organization and / or tenant 1010 n Tenant 1010, including points of variation specific to the architecture n The requirements may be provided in artifacts stored in content library 2002. Content library 2002 can accomplish this according to deployable artifact templates, such as those disclosed in U.S. Provisional Patent Application No. 63 / 196,458 and PCT International Application No. PCT / US22 / 72739, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," filed June 3, 2021 and June 3, 2022, respectively, the disclosures of which are incorporated herein by reference in their entireties. For example, content library 2002 may include "JSON" files for defining alert rules, workbooks, playbooks, etc. When new content is added to the content library 2002 or existing content is updated, the changes are reported to the tenant 1010 via the SOAR management server 1002. n In other words, once deployed, the SOAR management server 1002 can automatically push the data to the SOAR platform 2018 of each tenant, which varies based on the architecture of each tenant. 1-n (Figure 1) Can be configured for specific SOAR needs.

[0037] The variable store 2004 includes a SOAR management server 1002 and a tenant 1010. n, or a client organization's architecture. For example, the variable store 2004 allows a user of the SOAR management server 1002, such as an MSSP, to define and / or link variables associated with the tenant 1010n architecture to various artifacts stored in the content library 2002 for detection by the SOAR management server 1002, thereby enhancing the ability of the SOAR management server 1002 to automate client-specific execution. According to some non-limiting aspects, variables may be stored using a primary key that uniquely indicates the destination environment. For example, when registering an environment to be managed, an MSSP or another user may indicate an administrator account associated with the environment so that content can be configured when it is deployed to the specific environment. Thus, deployed automations may need to be provided with which accounts are administrators to execute automations specific to those account roles.

[0038] Automation Scheme 2008 is a variety of tenants 1010 1-n (See FIG. 1 ) Recognizing commonalities between architectures, the SOAR management server 1002 may be configured to run for a single client organization or to serve multiple tenants 1010. 1-n This represents a significant technological improvement over traditional SOAR management platforms, which require significant amounts of manual labor to implement across a single organization or client organization. For example, traditional SOAR platforms require an assessment of a client's unique environment and needs, which necessitates the design and implementation of a custom solution. The automation scheme 2008 of FIG. 2 enables the SOAR management server 1002 of FIGS. 1 and 2, in conjunction with the content library 2002 and variable store 2004, to automatically generate customized SOAR solutions and deploy such solutions to an unprecedented number of tenants 1010. 1-n or across client organizations simultaneously.

[0039] Applications initiated by the SOAR management server 1002 may further include an API broker 2006 as well as a graphical user interface 2010. According to one non-limiting aspect, an example of such a graphical user interface 4000 is shown in FIG. 4. For example, the graphical user interface 4000 of FIG. 4 may include one or more platforms 4002, 4004, 4006 for manipulating authentication settings. The platforms may be third-party applications that serve as authentication mechanisms, such as, for example, Okta 4002, Duo 4004, and / or Azure AD 4006, among others. Once the platform 4002 is selected, the graphical interface may display a configuration wizard 4008. The configuration wizard 4008 may include one or more windows 4010 that allow a user to configure various settings for various parameters, such as users, user groups, and / or remediation playbooks. Each window 4010, when selected, can display instructions 4012 that allow a user to visually present information and configure specific settings for its parameters configured to receive user input via a display and / or peripheral devices (e.g., keyboard, mouse, touch screen, etc.) communicatively coupled to the SOAR management server 1002. For example, the graphical user interface 2010 can be used to allow a user to configure one or more tenants 1010. n , or may be configured to run a wizard that may control the setup and / or automation of the SOAR platform for a client organization.

[0040] With further reference to FIG. 2, one such tenant 1010 n An example architecture is illustrated in accordance with at least one non-limiting aspect of the present disclosure. A SOAR management server 1002 manages tenants 1010. nTenant 1010, which detects variables associated with the architecture and includes one or more modules shown in FIG. n For example, according to the non-limiting embodiment of FIG. n The architecture comprises a remote SOAR platform 2018, a dashboard / reporting module 2022, and one or more security tool application program interfaces (“APIs”) 2020. a~d Each security tool API 2020 a~d is Tenant 1010 n APIs can be configured to prevent malicious attacks or misuse of client APIs deployed in the cloud. APIs are key to programming web-based interactions, making them a target for hackers. Therefore, security tools like API 2020 a~d can monitor the client's API and send an alert 2030 back to the SOAR platform 2018 if a suspicious event is detected.

[0041] According to some non-limiting aspects, the dashboard / reports module 2022 may include a tenant 1010 n The dashboard / reports module 2022 may include a customizable visual representation of the cybersecurity of a specific tenant 1010n. For example, the dashboard / reports module 2022 may enable employees of the MSSP and / or client organization to view what is happening across the tenant 1010n network and, in response to detected threats, take corrective action to protect the network. This may enable the MSSP and / or client organization to identify, prevent, mitigate, and / or predict cybersecurity incidents in a significantly more efficient manner. Of course, the specific tenant 1010n of FIG. 2 may also be used to visualize the network. n The architecture is presented for illustrative purposes only. According to another non-limiting aspect, a tenant 1010 designed and deployed by a SOAR management server 1002 nThe architecture can alternatively be configured to include alternative types and / or quantities of modules. The capabilities of the SOAR management server 1002, more specifically, the content library 2002, the variable store 2004, and the automation scheme 2008, can be remotely managed on behalf of tenant 1010 n to enable a customized SOAR-based solution that can be remotely managed instead of tenant 1010. Each solution is different depending on the variables detected by the variable store 2004 and the artifacts selected from the content library 2002 based on the detected variables, as introduced by the SOAR management server 1002

[0042] Furthermore, architecture 2000 of FIG. 2 further shows different communication means between various modules of the SOAR management server 1002 and one or more tenants 1010n. For example, certain modules such as the API broker 2006 can communicate with other modules such as the service operations engine 2012, the graphical user interface 2010, the remote SOAR platform 2018, and the dashboard / reporting module 2022 via the service layer 2024. Other modules such as the content library 2002, the variable store 2004, and the API broker 2006 can communicate with the remote SOAR platform 2018 of tenant 1010 n via the management and content delivery layer 2026. The remote SOAR platform 2018 can communicate with one or more security tool APIs 2020 of tenant 1010 n via the SOAR communication protocol 2028 a~cThe one or more security tool APIs may communicate with the remote SOAR platform 2018 via alert protocol 2030. The one or more security tool APIs send alerts back to the remote SOAR platform 2018 according to rules defined by artifacts 2032 applied from content library 2002, as defined by variables from variable store 2004. The impact of artifacts selected from content library 2002 and variables detected from variable store 2004 on artifacts 2032 is indicated in FIG. 2 via corresponding cross-hatching. In other words, while similar or the same protocols and / or methods may apply, each communication vehicle may include different content. Thus, an end user can utilize architecture 2000 of FIG. 2 with or without a specific "Managed Detection and Response" (MDR) service. However, once delivered with a specific MDR service, the same APIs can be used by a specific MDR service user to interface with the API to manage architecture 2000 and take action on behalf of one or more tenants.

[0043] As illustrated in the non-limiting embodiment of FIG. 2, the various modules of the SOAR management server 1002 architecture manage the tenants 1010 as determined by the variable store 2004 and / or as previously stored. n The tenant 1010 is configured to: n The content library 2002 and variable store 2004, in conjunction with the automation scheme 2008, may be configured to communicate with, manage, and control the remote SOAR platform 2018 of each tenant. nFor example, the artifact 2032 may enable the SOAR management server 1002, the API broker 2006, and the service operation engine 2012 to autonomously generate custom configurations for integration with and remote management of the tenant 1010. n The artifacts 2032 may define a means for interfacing with the remote SOAR platform 2018. Additionally, the artifacts 2032 may define content alerts 2030 and how they interface with one or more security tool APIs 2020. a~d The conditions that are sent from to the remote SOAR platform 2018 can further be defined.

[0044] The SOAR management server 1002, including the content library 2002, variable store 2004, and automation scheme 2008, can provide a powerful cloud-based tool that allows MSSPs to remotely manage their client organization's SOAR platform 2018. While the primary interface is the graphical user interface 2010, the API interface 2006 can further enable programmatic control of the SOAR platform 2018 management functions, allowing users to manage tenants 1010 through a central interface. n The SOAR management server 1002 also includes a content library 2002, a variable store 2004, and an automation scheme 2008 that allow customization of that content and deployment to tenants 1010. n Provides features that allow for custom deployments based on unique needs. In other words, the SOAR management server 1002 can provide a modular and scalable way to reference a stored library of code and content (e.g., content library 2002) so that options can be determined autonomously at deployment time.

[0045] For example, a user may deploy a set of artifacts stored in the content library 2002, such as playbooks, code, integrations, and / or dashboards, that enable integration of next-generation antivirus ("NGAV") products, email security products, and / or identity protection products, and that can then automate the detection, investigation, and response stages based on controls received from the user via the graphical user interface 2010. Additionally and / or alternatively, the SOAR management server 1002 may allow a user to manage the content of a tenant 1010. n 2008. Additionally, the graphical user interface 2010 may enable a user to "opt-in" and / or "opt-out" of automation features as presented by the automation scheme 2008 via wizard-like tracing, walk-throughs, and application simplifications. A user may further customize report and / or dashboard functionality and preferences to be applied via the dashboard / reports module 2022, which may be packaged for deployment along with automation content.

[0046] According to some non-limiting aspects, the applications launched by the SOAR management server 1002 may be scalable, i.e., tenants 1010 with a SOAR platform 2018 that can be remotely managed (e.g., scalability). nThe SOAR management server 1002 may be configured with the ability to scale or extend with respect to the number of components and / or the number of SOAR management functions it provides. In other words, the application, including the content library 2002, the variable store 2004, and the automation scheme 2008, may be designed to minimize the level of effort required to allow the SOAR management server 1002 to be extended for future use. For example, an extension mechanism provided by the application launched by the SOAR management server 1002, a pluggable add-on configured to enable additional service components and features of the SOAR management server 1002, may be introduced in the future.

[0047] According to some non-limiting aspects, the extension mechanism may be implemented in various ways to enable plugging in of additional SOAR service components. For example, authentication mechanisms such as DUO, Okta, among others, may be simultaneously supported (as illustrated via graphical user interface 4000 in FIG. 4 ). These authentication mechanisms may not be hard-coded, but configuration files may be discoverable (e.g., a main “config” file for each of the authentication mechanisms may be placed in a well-known repository location that is scanned for new or deleted files). If new configurations such as Azure AD are also supported, configuration files corresponding to Azure AD may be placed in the same repository location as the Duo and Okta configurations, discovered by the application management server, and presented to the user for selection and configuration from the client as needed. The configuration files may conform to a scheme defined and understood by this application management tool, and user interface 4000 ( FIG. 4 ) elements 4002, 4004, 4006 ( FIG. 4 ) may be generated and auto-populated accordingly. In particular, the SOAR applications discussed herein are constructed in a way that is easily extended with additional configuration features that are not hard-coded into the source code, but are dynamically plugged in through new configurations according to this method.

[0048] When a user deploys these add-ons via automation, they trigger an application launched by the SOAR management server 1002 to enable additional subscription-based services on behalf of the MSSP and provide them to the tenant 1010. n Additionally and / or alternatively, applications deployed by the SOAR management server 1002 may be deployed as entirely new, customized tenants 1010, as illustrated in FIG. n Instead of generating the architecture, tenant 1010 n It may be configured to work with existing "ungoverned" content, which may allow for discovery and light management of at least some of the previous SOAR assets already deployed by.

[0049] As previously described, when executed by the processor 1004 (FIG. 1), the application may be configured to abstractly and / or dynamically manage a client organization's SOAR platform 2018. For example, in an abstract implementation, the SOAR management server 1002 may employ generically defined artifacts stored in a content library 2002, as disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed June 3, 2021, and entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," the disclosure of which is incorporated herein by reference in its entirety. The generically defined artifacts may include, for example, blocks of executable code. However, platform-specific implementations may subsequently be provided (e.g., Azure Defender, Crowdstrike, etc.). Summary automations / playbooks can be written in a general format and then translated into specific formats at deployment time. For example, an automation / playbook can be created that is specifically configured to disable a user's email account if their business email is compromised. However, upon actual implementation of that automation / playbook in a specific customer environment, the system 1000 (FIG. 1) and functional architecture 2000 (FIG. 2) disclosed herein can translate the generally written content into a version that is specifically implemented for the particular mail application used by the tenant. In this way, unlike conventional systems and architectures, content can be generated that can be programmatically adapted to multiple environments without rewriting it.Thus, the system 1000 (FIG. 1) and functional architecture 2000 (FIG. 2) disclosed herein provide a significant technical solution to the technical problems of traditional automation / playbooks: flexible formats and interfaces that allow users to extend services to multiple tenants and their authentication mechanisms.

[0050] Alternatively, in a dynamic implementation, the SOAR management server 1002, via the content library 2002, can dynamically generate new automation types, which can be automatically detected and displayed for selection by the graphical user interface 2010 for subsequent deployment. Similarly, a new automation, such as an endpoint monitoring solution (e.g., CarbonBlack), can be added to the content library 2002 for a given automation type, such as one that blocks the execution of harmful programs detected by the automation (e.g., block executable file automations), which can then be automatically made available in the GUI and deployed to appropriate client SOARs (which use these security tools).

[0051] When deployed via SOAR management server 1002, tenant 1010 n, or client, specific change points can be detected by the variable store 2004 and correlated with artifacts stored in the content library 2002. For example, the SOAR management server 1002 has the ability to configure automated responses / corrective actions (e.g., playbooks) for a given configuration. These corrective actions may require optional steps, e.g., the tenant must first approve the action. Thus, configuring a remediation automation may involve similar configuration to the actual task (e.g., blocking an account), but the approval step may be done manually via phone, email, or workflow form (e.g., integration via a service ticket). In this way, the approval step may be variable (e.g., it may or may not be present, and if present, it may be accomplished in several ways) and require pulling the appropriate code and configuration from the automation repository to configure for this client and SOAR automation.

[0052] Therefore, at the time of deployment, the change point is tenant 1010 n Based on the network architecture of tenant 1010 n According to one non-limiting aspect, the SOAR management server 1002 can automate the SOAR platform 2018 to block user accounts upon detection of a security event based on input received by the security tool APIs 2020a-d. For example, the automation can be configured for specific SOAR needs. n During deployment, for example, through a wizard presented via the graphical user interface 2010, the automation is performed by the tenant 1010. nThe user may be required to provide information associated with one or more administrative accounts (e.g., phone number, short message service (“SMS”) address, email address, etc.). Accordingly, specific steps and / or conditions, such as contacts and / or prompts for action from the administrative accounts, may be programmed into the automation via the graphical user interface 2010.

[0053] According to one non-limiting aspect, when executing a custom automation, the SOAR management server 1002, and more specifically, the custom automation generated by the SOAR management server 1002, can manage the SOAR platform 2018 to detect a security event and determine that a user account needs to be blocked based on input / alerts received from one or more security tool APIs 2020a-d. The SOAR management server 1002 can manage the SOAR platform 2018 to notify the managed account, and the automation can wait for approval. Upon receiving approval, the automation can continue with subsequent steps in the automation, ultimately blocking the tenant 1010. n Suspicious accounts can be removed from the network. As previously mentioned, this can be abstracted into an automated type of action using specific implementations for each security tool API 2020a-d and / or notification method. Removing suspicious accounts can be performed by the SOAR platform 2018 in the tenant 1010. n This is just one example of the actions that can be taken to strengthen the security of a network. For example, besides blocking accounts, the SOAR Platform 2018 can also delete suspicious files, send emails to security administrators, among other actions.

[0054] When deployed by the SOAR management server 1002, the artifacts 2032 (e.g., automations) are deployed to the tenant 1010 nDepending on the non-limiting aspects, the MSSP and / or the client may modify the deployed configuration. For example, according to some non-limiting aspects, the client may modify the deployed configuration. n A client may desire to control the configuration deployed across the network. However, according to other non-limiting aspects, the client may desire the MSSP to have exclusive control of the configuration. In either case, the applications deployed by the SOAR management server 1002 may be configured to automatically detect changes made by the MSSP and / or the client and use them to manage future deployments and / or updates to already deployed artifacts 2032. According to some non-limiting aspects, such changes may be utilized by artificial intelligence stored in memory 1006 (FIG. 1) of the SOAR management server 1002 to adapt one or more artifacts 2032 (e.g., templates, workflows, etc.) in the content library 2002 for expanded deployment for similar clients and / or architectures.

[0055] Thus, the content library 2020, along with the graphical user interface 2010 and the API broker 2006, when deployed by applications on the SOAR management server 1002, can function as a contribution mechanism that can abstractly and / or dynamically discover updates to both the content library 2002 and the client's SOAR platform 2018. These updates can be collectively managed via the SOAR management server 1002, which serves as the central console for the system 1000 (FIG. 1), enabling unprecedented scalability to manage a large number of clients. In this way, the SOAR management server 1002 can remotely manage different clients' SOAR platforms 2018 reliably and consistently. Its modular design allows users and third-party applications to contribute new artifacts 2032 and / or update existing artifacts 2032 as third-party vendor solutions evolve, making it "future-proof."

[0056] 3 shows a diagram of a method 100 for autonomously hardening a tenant network via a managed security service provider. Various aspects of the method 100 may be initiated by a SIEM, autonomous security system, or MSSP server (collectively referred to herein as a “security system”), where a query 105, database, or server may be initiated upon an IoC being encountered by the security system, generally in the tenant network. Because the security system database contains or receives historical and contextual data or information from data sources or feeds that are stored, indexed, and available to the security system upon request, querying the security system database or network 105 allows the system to search the data and information accessible to each source or feed to identify information regarding the encounter or other relevant IoC.

[0057] Each data source or feed from which IoCs are received may include a preset reliability score or value, or a reliability score calculated and / or updated by the security system. This reliability score defines the trustworthiness of each data source or feed and may be automatically determined by the security system based on known or available data, including the level and / or quality of human involvement, the number of IoCs identified by the source or feed, the source or feed's reliability history (e.g., the number of false positives or false negatives generated from data obtained from the source or feed), the age of the source or feed, the age or date of the IoCs in the source or feed, the reputation of the source or feed in the community or based on community / user reviews, the relevance of the source or feed to a particular tenant or tenant network, the type of tenant network the security system manages, and the range of information available to the security system on the source or feed. Query 105 may match or identify the encountered IoCs with identical or similar IoCs in the SIEM autonomous security system database and identify related or relevant sources or feeds that contain references or information to the encountered IoCs.

[0058] After collating or identifying sources associated with the encountered IoCs, the security system calculates and / or generates 110 a single IoC threat score / IoC threat score intended to indicate the level or severity of the threat. After the IoC threat score is calculated by the system, an actionable security hardening notification is generated 115 based on the IoC threat score. The actionable security hardening notification may be sent to a security analyst or other user of the security system and may include recommendations regarding security control measures that can be taken to protect networks, databases, servers, or other nodes belonging to the tenant or under the control of the MSSP.

[0059] In various aspects, an actionable security hardening notification may require the calculated IoC threat score to meet or exceed a specified or preset security threat threshold; in some aspects, different thresholds may be set, meeting or exceeding which will result in different security hardening notifications, responses, or actionable recommendations, some of which may be sent to a user of the security system or a security analyst, while another portion may create other automated actions, such as recording an event or updating a database, or other parts of the tenant network or security system. In various embodiments of the present disclosure, the IoC threat score, security thresholds, and / or security hardening notifications or alerts may be displayed to a user of the security system via a user interface. The user interface may utilize color coding or other visual effects or techniques for different IoC threat scores, actionable recommendations, etc.

[0060] Optionally, indicators of compromise may also be classified 125 by the SIEM autonomous security system into one or more categories or classified as one or more types of threats, where the classification may be based on its IoC threat score, threat level, thresholds it meets, exceeds, or otherwise does not meet, and a generated confidence score for the IoC score. An IoC may be given a different classification as malicious, benign, unknown, or another category or type. The classification may also be transmitted or displayed to a user or security analyst of the security system. The classification level may also, in various embodiments, affect the type of recommendations or actionable security enhancements displayed, generated, or transmitted by the system.

[0061] In some optional aspects, new malware variants or threat types may be identified based on one or more of the following factors: the classification of the IoC, the calculated IoC threat score, the calculated IoC confidence interval or value, the security threshold level that the IoC meets or exceeds, the age of the IoC, the prevalence and / or distribution of the IoC; in preferred embodiments, an IoC shares some, but not all, characteristics of a previously encountered IoC or threat; for example, a new malware variant may be identified if the IoC shared an origin server with a previous malware lineage or variant, but does not itself contain the same or identical code; further, the malware may share some, but not all, behaviors or characteristics (or code) as the previous lineage, which, individually or in combination with the factors enumerated herein, may enable the autonomous security system to identify new malware variants or other threats.

[0062] In response to identifying IoCs, calculating IoC threat scores, and / or classifying IoCs, and to improve the security system's functionality, the security system may automatically modify or update the false / true positive / negative scores of sources and feeds used to receive IoC data. The security system may optionally autonomously adjust 135 and update one or more security threat thresholds and levels and / or source or feed reliability scores by determining one or more ratios of at least two of the number of false positives, the number of true positives, the number of false negatives, and the number of true negatives. This response improves the accuracy and usefulness of scores to the system, allowing better deployment of response and processing resources, improving response times by more quickly identifying threats with more accurate scores and information, as well as more effectively managing system resources based on the immediacy of each encountered threat, and employing processing and memory resources for more urgent tasks, e.g., in response to more immediate threats.

[0063] In various aspects, the security system may autonomously implement an automated security response to the identified IoCs, identified malware variants, IoC threat scores, and / or one or more security threat thresholds based on the calculated scores, IoCs, or identified values / threshold levels. The automated security response may include one or more of the following responses: automatically adjusting the security threat threshold level, automatically reconfiguring a database to include the identified malware variants, automatically identifying, adding additional identified malware variants, automatically sending notifications to multiple users or security analysts of the security system, determining the risk of exposure or future exposure of one or more tenant networks to the identified IoCs or new malware variants, and quarantining one or more tenant networks or portions of networks to prevent the spread of malware, viruses, or other threats.

[0064] Reconfiguring the database can include automatically, continuously, and dynamically updating the database, which updating or reconfiguring the database can be based on multiple factors, including, but not limited to, automatic periodic ingestion of information about new malware variants or emerging threats based on commercial and community threat intelligence, data feeds via industry standard mechanisms (e.g., STIX, API, YARA), malicious or potentially unwanted activity observed in the monitored environment via deployed sensors, or manually curated indicators of compromise (IOC) feeds maintained by threat intelligence analysts working with various data sources or feeds. This database reconfiguration can enable faster identification, matching, and / or response to potential threats and malware.

[0065] Automatically sending notifications to other parts of the network or SIEM, or to multiple users or analysts of the security system, can be accomplished in a variety of ways, including, but not limited to, creating a time-sensitive output list (e.g., a lookup table) of currently valid IoCs and their respective risk scores, allowing the security system to automatically correlate raw information obtained from the monitored environment with the risk scoring results calculated by the system. The scoring output is periodically exported to a structured set of data, which is then fed to a data log analysis and management system, which continuously evaluates incoming data against new findings from the scoring output. Thus, if something is observed within the network matching a risk score above a certain threshold, an automatic alert can be generated or one of a variety of automated security responses can be triggered, including automatic database or network quarantine (automatic quarantine may be limited in time or scope, e.g., the number of databases / networks quarantined or portions of the network database depending on the IoC threat score), allowing time for a human analyst to review and take further action, for example.

[0066] The output list and real-time data lookup capabilities enable both automated and manual lookup of various indicators and factors, including indicator or IoC history, risk scoring, and the origin of a particular indicator as part of an ongoing security incident. In various aspects, this is achieved via API integration between the security orchestration platform used for incident management and the database hosting the indicator risk scoring results. For example, if an artifact is observed as part of an investigation into a particular type of activity in the environment, the orchestration system (and in some aspects, the security analyst) is permitted to autonomously query data stored within a risk calculation system for further information about this artifact, such as when the artifact was first detected, what assessment the system gave it, and what the risk or risk range is associated with the artifact based on the assigned / calculated risk score.

[0067] Determining the risk to which other tenants or tenant networks are exposed or will be exposed in the future can be accomplished through an API connection between the security system's orchestration layer and a database hosting the scoring algorithm. When an IoC is observed in a client environment and determined to be a reliable indicator of unwanted or potentially malicious activity, the finding is forwarded to the scoring algorithm via an API call, which notes the finding in the database. This, in turn, determines the risk score assigned to this particular indicator in the database until the next time a risk score is calculated for the IoC in question. Additionally, capturing one or more tenant networks or portions of a network can benefit multiple network segments, or multiple discrete networks, without requiring connectivity or knowledge of each other.

[0068] In most embodiments, if the risk score exceeds a set threshold, the overall incident severity rating increases accordingly. As a result, the incident is assigned a higher priority for review by a security analyst or for any of the potential responses described above, with dedicated resources assigned as a more urgent matter. Furthermore, if the client and service provider have agreed to an arrangement that includes automated response and threat mitigation capabilities, a higher risk score assigned to an indicator associated with a particular incident may trigger an automated response (e.g., endpoint isolation, network traffic disruption, and the aforementioned automated response), a decision that might otherwise have been less accurate. In a different scenario, the ability to confirm that a particular indicator is known to be associated with legitimate activity may result in the postponement of automated or semi-automated response and threat mitigation activities to avoid potential disruption of legitimate activity related to authorized business use of the environment.

[0069] FIG. 4 shows a diagram of an autonomous method for calculating an encountered indicator of compromise (IoC) threat score. When an IoC is encountered and the security system database is queried as shown in FIG. 1, for each source or feed identified as associated with the encountered IoC, a threat value / level provided or classified by the associated source or feed is identified 205 for that IoC. For example, some security feeds may classify IoCs via a threat level of 55 / 100, 8 / 10, moderately malicious, or benign, or any other classification system. The security system can autonomously identify or provide each IoC associated with the current query with a threat level assigned by each security source, which in many embodiments generates a source or feed IoC threat value that is normalized across different sources or feeds, even if the sources or feeds each use different types or classification methods. Based on the source credibility score of each feed identified as associated with the IoC, a multiplier is added / assigned 210 to the threat value provided by the source or feed to generate an adjusted threat value for the IoC. The multiplier may be based directly on the established or assigned trustworthiness score of the source or feed, or may be based in part along with other factors such as the distribution and / or variance among threat values provided by the source compared to other threat values provided by other sources or feeds, or alternatively / additionally based on security system internal metrics related to the source or feed, or IoC, or type of IoC.

[0070] In various aspects of the present technology, anomalous or outlier threat values (which may include adjusted threat values or anomalous adjusted threat values that may be identified as anomalous before and / or after adjustment) may be identified and / or removed 215 from the calculation. In this disclosure, reference to a “threat value” in its broadest sense encompasses adjusted or unadjusted threat values, and / or anomalous or non-anomalous threat values, and / or normalized or unnormalized threat values. In some embodiments, different types of sources may generate or provide different threat values for a particular IoC, although these differences may stem from differences in the feeds or sources themselves; for example, publicly generated and freely provided threat values on a large number of IoCs may classify the threat value of the IoC as low, while a small number of exclusively available, paid, professional security services may provide a high threat value for the same IoC. In such an example, the security system may weight 220 the differences between the two groups to provide a threat value that takes into account the publicly and privately generated data, with the weighting depending on the particular IoCs, their types, the number of IoCs in each source or feed, the threat value provided, the reliability of the source or feed, the size of each group of closely related sources or feeds, and the goals of the security system itself, to generate or produce a weighted, adjusted threat value. In this optional step, the security system may take into account both public, crowd-sourced information and information privately generated by professional security firms, and in some cases, the system may weight the threat value or adjusted threat value more heavily for one group of data sources than another, depending on the particular IoCs and the factors enumerated herein.Crowdsourced public information allows security systems the flexibility to take into account information that has not yet been curated, professionally organized, or coordinated, while privately generated, dedicated sources allow security systems to take into account industry and expert perspectives in the field regarding the threats they face.

[0071] Depending on aspects of the invention, the various threat values and / or various adjusted threat values may be normalized 225 across all relevant sources or feeds. A single threat score is then generated 230 for the encountered IoCs. In some embodiments, an optional reliability score may also be generated 235, which may be provided along with or incorporated into the single threat score. In some aspects, the reliability score may also be within a certain threshold for the security system to provide the generated threat score to a security analyst or other user of the system, or to take some other additional action as illustrated in FIG. 1 . Aspects of the systems and methods presented herein, including methods for collecting and verifying the reliability of data sources and feeds, determining and calculating the importance or significance of identified data, and scoring that data, may be used in a variety of industries and applications that utilize large amounts of data and information and require the data and its reliability to meet certain threshold levels.

[0072] 5 illustrates a graphical user interface for an autonomous SIEM threat scoring and management application dashboard showing an overview of detected and managed threats according to some non-limiting aspects of the present disclosure. This user dashboard 300 may include a side panel 301 that allows a user, such as a security analyst, to select another interface dedicated to cases 302 that the system is addressing or has addressed. The dashboard side panel 301 may also include links to other screens, including security alerts 303, a list of assets 304, a list of vulnerabilities 305, reports 306, compliance 307, and a clickable logout button 308. The exemplary dashboard may include several selectable headers, including a general overview header 309 to provide an overview or system activity, an environment header 310, a vulnerability header 311, a trend header 312, an event header 313, and an external threats header 314. When the Overview header 309 is selected, a screen may be displayed that may include information groups relating to the number of pending items awaiting user action 315, items in progress 316, recent escalations 317, recent service requests 318, recent alerts and incidents 319, recent actions taken 320, recent investigation results 321, recent security cases 322, number of protected assets 323, bypassed assets 324, and a list of security incidents 325. Many of these tabs, lists, and information groups may include graphical views, charts, tables, and graphs.

[0073] FIG. 6 presents another graphical user interface and incident screen 400 displaying details of detected threats or indicators of compromise, according to some non-limiting aspects of the present disclosure. In one aspect, an incident number 401 is provided along with a description or name of the incident or indicator of compromise 402. An incident status 403 may also be set within the incident screen, which may indicate, for example, whether user action is required, the incident is closed, the incident is resolved, and the like. An IoC category 404 may also be provided, including, for example, “Outage,” or “DNS Anomaly,” “Login Red Flag,” etc. An alert source 405 may also be listed, i.e., the source of the detected threat or alert trigger. Any taken actions 406 may also be presented. The incident screen 400 may also include a summary header 407, an evidence header 408, and a message header 409. The summary header 407 may include information about the date / time the incident was created 410, updates 411, the total time the incident was active 412, the hostname 413, the criticality or importance of the device 414, the location of the asset involved 415, the device IP 416, the device type 417, which may relate to the software or hardware of the device, and the associated username 418, the device category 419 (e.g., the device is an endpoint), and the device type version 420, which may also relate to both the hardware or software running on the device.

[0074] FIG. 7 presents a graphical user interface displaying details of encountered indicators of compromise (IoC) screen 500, according to some non-limiting aspects of the present disclosure. IoC screen 500 includes a list of encountered IoCs 501, including a list of their names 502 and their types 503, such as “file,” “domain,” “IP,” “URL,” “secure hash algorithm,” etc. IoC screen 500 may also include a list of each IoC’s 504 reputation, which may be directly linked to a single IoC score generated by a security system and / or may be a classification, for example, unknown, suspicious, malicious, or clean. IoC rating 504 may also be directly associated with or derived from any score or value calculated, determined, or contributed to in a manner that derives a single generated threat score, or may be a rating provided by a source or feed containing information about the IoC. IoC screen 500 may also include a designation 505 of each IoC, which may include its identity, for example, as a specific variant of malware or bot.

[0075] FIG. 8 presents a graphical user interface providing investigation notes for each investigated indicator of compromise, according to some non-limiting aspects of the present disclosure. The investigation screen 600 may include investigation results 601 originating from a human user or security analyst, or from the automated system itself, generated by any of the methods and systems described herein. The investigation screen 600 may also include investigation notes 602, which may summarize the nature of the IoC, its current status, the history of the IoC, and how it triggered the alert, as well as any actions taken by the system or a user of the system. Action notes 603 related to actions taken to counter the IoC may also be provided, as well as a guidance section 604 regarding any actions or steps that need to be taken by the end user or client, or any other information that may be relevant to the client or tenant.

[0076] FIG. 9 is a schematic diagram of an exemplary machine in the form of a computer system 1, within which a set of instructions for causing the machine to perform any one or more of the methodologies discussed herein may be executed. In various exemplary embodiments, the machine may operate as a standalone device or may be connected (e.g., networked) to other machines. In a network deployment, the machine may operate in the capacity of a server or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine may be a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), mobile phone, portable music player (e.g., a portable hard drive audio device such as a Move Picture Experts Group Audio Layer 3 (MP3) player), web appliance, network router, switch, or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Moreover, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines, individually or collectively, executing a set (or sets) of instructions to perform any one or more of the methodologies discussed herein.

[0077] Exemplary computer system 1 includes a processor or processors 5 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both), a main memory 10, and a static memory 15 that communicate with each other via a bus 20. Computer system 1 may further include a video display 35 (e.g., a liquid crystal display (LCD)). Computer system 1 may also include an alphanumeric input device 30 (e.g., a keyboard), a cursor control device (e.g., a mouse), a voice recognition or biometric verification unit (not shown), a drive unit 37 (also called a disk drive unit), a signal generator 40 (e.g., a speaker), and a network interface device 45. Computer system 1 may further include a data encryption module (not shown) for encrypting data.

[0078] The components provided in computer system 1 are components typically found in computer systems that may be suitable for use with embodiments of the present disclosure and are intended to represent broad categories of such computer components known in the art. Accordingly, computer system 1 may be a server, a minicomputer, a mainframe computer, or any other computer system. Computers may also include different bus configurations, network platforms, multiprocessor platforms, etc. A variety of operating systems may be used, including UNIX®, LINUX®, WINDOWS®, QNX ANDROID®, IOS®, CHROME®, TIZEN®, and other suitable operating systems.

[0079] Disk drive unit 37 includes computer or machine-readable medium 50 on which is stored one or more sets of instructions and data structures (e.g., instructions 55) that embody or utilize any one or more of the methodologies or functions described herein. Instructions 55 may also reside, completely or at least partially, within main memory 10 and / or within processor 5 during execution thereof by computer system 1. Main memory 10 and processor 5 may also constitute machine-readable media.

[0080] The instructions 55 may further be transmitted or received over the network 70 via the network interface device 45 utilizing any one of several well-known transfer protocols (e.g., a hypertext transfer protocol (HTTP)). Although the machine-readable medium 50 is shown in the exemplary embodiment as a single medium, the term "computer-readable medium" should be taken to include a single medium or multiple media (e.g., centralized or distributed databases and / or associated caches and servers) that store one or more sets of instructions. The term "computer-readable medium" also refers to a medium capable of storing, encoding, or carrying a set of instructions for execution by a machine and for instructing a machine to implement any of the methodologies of the present application. The term "computer-readable medium" should be taken to encompass any medium capable of storing, encoding, or carrying one or more instructions or data structures utilized by or associated with such a set of instructions. Accordingly, the term "computer-readable medium" includes, but is not limited to, solid-state memory, optical and magnetic media, and carrier wave signals. Such media may also include, but are not limited to, hard disks, floppy disks, flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc. The exemplary embodiments described herein may be implemented in an operating environment including software, hardware, or a combination of software and hardware installed on a computer.

[0081] Those skilled in the art will recognize that an Internet service may be configured to provide Internet access to one or more computing devices coupled to the Internet service, and that the computing devices may include one or more processors, buses, memory devices, display devices, input / output devices, etc. Additionally, those skilled in the art will recognize that an Internet service may be coupled to one or more databases, repositories, servers, etc., which may be utilized to implement any of the embodiments of the present disclosure described herein.

[0082] The computer program instructions may also be loaded onto a computer, server, other programmable data processing device, or other device to cause the computer, other programmable device, or other device to perform a series of operational steps to generate a computer-implemented process, such that the software instructions executing on the computer or other programmable device provide a process for implementing the functions / acts specified in the flowchart and / or block diagram blocks.

[0083] Suitable networks may include or interface with, for example, one or more of a local intranet, a PAN (Personal Area Network), a LAN (Local Area Network), a WAN (Wide Area Network), a MAN (Metropolitan Area Network), a Virtual Private Network (VPN), a Storage Area Network (SAN), a Frame Relay connection, an Advanced Intelligent Network (AIN) connection, a Synchronous Optical Network (SONET) connection, a digital T1, T3, E1 or E3 line, a Digital Data Service (DDS) connection, a DSL (Digital Subscriber Line) connection, an Ethernet connection, an ISDN (Integrated Services Digital Network) line, a dial-up port such as V.90, a V.34 or V.34bis analog modem connection, a cable modem, an ATM (Asynchronous Transfer Mode) connection, or an FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connection. Additionally, communications may also include links to any of a variety of wireless networks, such as WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access) or TDMA (Time Division Multiple Access), cellular networks, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), RIM (Research in Motion, Limited) two-way paging networks, Bluetooth radio, or IEEE 802.11-based radio frequency networks. Network 215 may further include or interface with any one or more of an RS-232 serial connection, an IEEE-1394 (Firewire) connection, a Fibre Channel connection, an IrDA (Infrared) port, a SCSI (Small Computer System Interface) connection, a USB (Universal Serial Bus) connection, or other wired or wireless, digital or analog interface or connection, mesh or Digi® networking.

[0084] In general, cloud-based computing environments are resources that typically combine the computing power of a large group of processors (such as in web servers) and / or the storage capacity of a large grouping of computer memory or storage devices. Systems that provide cloud-based resources may be used exclusively by their owners, or such systems may be accessible to external users to deploy applications within the computing infrastructure and take advantage of the large computing or storage resources.

[0085] A cloud is formed by a web server network including multiple computing devices, such as computer equipment 1, where each server (or at least multiple servers) provides processor and / or storage resources. These servers manage the load provided by multiple users (e.g., customers or other users of the cloud resources). Typically, each user imposes workload demands on the cloud that change in real time, sometimes dramatically. The nature and extent of these fluctuations typically depend on the type of business associated with the user.

[0086] It is worth noting that any hardware platform suitable for carrying out the processes described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage media" refer to any medium or media that participate in providing instructions to a CPU for execution. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks, such as fixed disks. Volatile media include dynamic memory, such as system RAM. Transmission media include coaxial cables, copper wire, and fiber optics, including the wires that comprise an embodiment of a bus, among others. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, flexible disks, hard disks, magnetic tape, any other magnetic media, CD-ROM disks, digital video disks (DVDs), any other optical media, any other physical media with a pattern of marks or holes, RAM, PROM, EPROM, EEPROM, FLASHEPROM, any other memory chip or data exchange adapter, carrier wave, or any other medium from which a computer can read.

[0087] Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to the CPU for execution. A bus carries data to system RAM, from which the CPU retrieves and executes the instructions. The instructions received by the system RAM may optionally be stored on a fixed disk either before or after execution by the CPU.

[0088] Computer program code for carrying out operations of aspects of the present technology may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as the "C" programming language, Go, Python, or other programming languages including assembly language. The program code may run partially on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer, partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). [Example]

[0089] Example clause Various aspects of the subject matter described herein are set forth in the following numbered sections.

[0090] Clause 1: A method for autonomously hardening a tenant network via a Managed Security Service Provider (MSSP) server having a processor and a memory, using information from a plurality of data sources, the method comprising: querying, by a security system, via the processor, a database or server upon encountering an indicator of compromise (IoC), to identify a data source among the plurality of data sources, the data source including a reference to the IoC; and generating, via the processor, an IoC threat score for the IoC based on output of the query, the generating including, for each data source among the data sources, identifying an IoC threat value provided by the data source; and generating, for each data source among the data sources, an IoC threat value provided by the data source. and displaying the IoC threat score and the actionable security notification to a user via a user interface to enable triggering or disabling of at least one action in the at least one actionable security notification, the at least one action being based on the IoC threat score.

[0091] Clause 2: The method of clause 1, further comprising deploying an automated security response, the deployment including at least one of automatically adjusting a security threat threshold level, automatically reconfiguring a database or server to identify potential malware variants, sending notifications to a plurality of other users, determining exposure to IoCs of other tenant networks, determining risk of future exposure, or quarantining one or more tenant networks or portions of networks, or a combination thereof.

[0092] Clause 3: The method of any one of clauses 1 to 2, further comprising classifying the IoC as malicious, unknown, or benign based on at least one of the IoC threat score, the generated reliability score, or the security threat threshold level, or a combination thereof, wherein the user interface is capable of displaying the classification.

[0093] Clause 4: The method of any one of clauses 1 to 3, wherein the security threat threshold is automatically adjusted based on a ratio representing the accuracy or precision of the classification of the IoC as malicious or benign by using a ratio including at least two of the number of false positives, the number of true positives, the number of false negatives, and the number of true negatives.

[0094] Clause 5: The method of any one of clauses 1 to 4, further comprising: determining that an IoC is classified as a malicious threat and that the encountered IoC indicators share a portion of a set of features with other IoCs stored in the database or server; and identifying new malware variants when determining the IoC as a malicious threat based on at least one of the IoC threat score, the portion of the set of features, the generated confidence score, and the security threat threshold level, or a combination thereof.

[0095] Clause 6: The method of any one of clauses 1 to 5, further comprising reconfiguring the database to identify new malware variants based on at least one of IoC features, IoC threat scores, generated confidence scores, security threat threshold levels, or IoC classifications, or combinations thereof.

[0096] Clause 7: The method of any one of clauses 1 to 6, wherein the executable security hardening notification includes an indication of a new malware variant on the tenant network, and the new malware variant may be determined based on data of other malware.

[0097] Clause 8: The method of any one of clauses 1 to 7, further comprising receiving data from data sources, each data source of the data sources being associated with at least one IoC, and each data source defining a reliability score; and indexing the data sources and their associated at least one IoC into a database or memory component.

[0098] Clause 9: The method of any one of clauses 1 to 8, wherein the trustworthiness score of each data source of the data sources is determined by at least one of human involvement and includes the number of IoCs identified by the data source, the trustworthiness history of the data source, the number of data inputs into the data source, the age of the data source, the age of the IoCs in the data source, a reputation associated with the data source, the relevance of the data source to a client or user of the security system, and the amount of information available on the data source.

[0099] Clause 10: The method of any one of clauses 1 to 9, wherein at least one actionable security enhancement notification is based on at least one of an IoC threat score, a generated confidence score, or a security threat threshold level, or a combination thereof.

[0100] Clause 11: The method of any one of clauses 1 to 10, wherein the query includes cross-referencing the identified DNS query and IP address with a plurality of IoCs stored in a database, the plurality of IoCs including the IoC; and identifying associated data sources of the data sources, the relevance of the associated data sources being determined by an association of the associated data sources with the identified DNS query and IP address.

[0101] Clause 12: The method of any one of clauses 1-11, wherein querying further includes identifying DNS queries and IP addresses contacted by machines in the defined computing environment.

[0102] Clause 13: The method of any one of clauses 1 to 12, wherein generating an IoC threat score further includes identifying anomalous IoC threat values and discarding the anomalous IoC threat values.

[0103] Clause 14: A method according to any one of clauses 1 to 13, wherein generating an IoC threat score includes weighting various IoC threat values from data sources having a particular reliability score relative to IoC threat values from data sources having a lower reliability score.

[0104] Clause 15: A method according to any one of clauses 1 to 14, wherein generating the IoC threat score is performed by at least one of a machine learning neural network, and input to the machine learning network includes a credibility score of the data source and an IoC threat value provided by the data source.

[0105] Clause 16: The method of any one of clauses 1 to 15, further comprising generating a converged score associated with the IoC threat score based on a distribution of threat values provided by the data source.

[0106] Clause 17: An autonomous security system directed to continuously hardening one or more tenant networks, the system comprising: a plurality of tenant networks; and at least one Managed Security Service Provider (MSSP) server comprising a processor and a memory, the memory, when executed by the processor, causing the processor to, upon encountering an indicator of compromise (IoC) by the security system, query at least one database or server to identify a data feed with a reference to the IoC; and based on output of the query, generate an IoC threat score for the IoC, wherein the generating includes: identifying, for each data feed of the data feeds, an IoC threat value classified by the data feed; and, for each data feed of the data feeds, adding a multiplier to the IoC threat value. generating an adjusted IoC threat value for the data feed, wherein a multiplier is determined based on a confidence score associated with the data feed; normalizing the adjusted IoC threat value of the data feed; and outputting an IoC threat score; generating at least one actionable security enhancement notification based on the IoC threat score; and displaying the IoC threat score and the actionable security enhancement notification to a user of the security system via a user interface on at least one display device connected to an MSSP server to enable triggering or disabling of at least one action in the at least one actionable security enhancement notification, wherein the at least one action is based on the IoC threat score.

[0107] Clause 18: The autonomous security system of claim 17, wherein the executable security hardening notification includes an indication of a new malware variant on at least one tenant network of the plurality of tenant networks, the new malware variant being determined based on other malware data.

[0108] Clause 19: The autonomous security system of claim 17, wherein the stored instructions, when executed by a processor, configure the processor to implement an automated security response including at least one of automatically adjusting a security threat threshold level, automatically reconfiguring a database or server to identify other potential malware variants, sending notifications to multiple other users of the security system, determining exposure or risk of exposure of other tenant networks to the new malware variant, and quarantining at least one tenant network of the multiple tenant networks.

[0109] Clause 20: A method for autonomously hardening security of a tenant network, the method comprising: upon encountering an indicator of compromise (IoC) by a security system within a tenant network of a plurality of tenant networks, querying a security server to identify a data feed including at least one reference to the IoC; generating, via a processor, an IoC threat score for the IoC based on results of the query; deploying an automated security response by the security system based on the IoC threat score; and displaying, via a user interface, at least one of the IoC threat score, a status of the automated security response, or an actionable security hardening notification to a user of the security system, wherein the actionable security hardening notification facilitates triggering of an additional security response.

[0110] All patents, patent applications, publications, or other disclosure materials mentioned herein are incorporated herein by reference in their entirety, as if each individual reference were expressly incorporated by reference. All references and any material, or portions thereof, said to be incorporated herein by reference are incorporated herein only to the extent that the incorporated material does not contradict existing definitions, descriptions, or other disclosed material set forth in this disclosure. Therefore, and to the extent necessary, the present disclosure as set forth herein supersedes any conflicting material incorporated herein by reference, and this disclosure is expressly set forth within the control of this application.

[0111] Various exemplary and illustrative embodiments have been described. The embodiments described herein are understood to provide illustrative features of various details of various embodiments of the present disclosure, and therefore, unless otherwise specified, it is to be understood that, to the extent possible, one or more features, elements, components, ingredients, materials, structures, modules, and / or aspects of the embodiments of the present disclosure may be combined, separated, interchanged, and / or rearranged with or relative to one or more other features, elements, components, ingredients, materials, structures, modules, and / or aspects of the embodiments of the present disclosure without departing from the scope of the present disclosure. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the exemplary embodiments may be made without departing from the claimed subject matter. Moreover, those skilled in the art will recognize or be able to ascertain, upon review of this specification and using no more than routine experimentation, numerous equivalents to the various embodiments of the present disclosure. Accordingly, the present disclosure is not limited by the description of the various embodiments, but only by the scope of the claims.

[0112] Those skilled in the art will recognize that the terms used herein generally, and in the appended claims in particular (e.g., the body of the appended claims), are generally intended as "open-ended" terms (e.g., the term "including" should be interpreted as "including, but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "including, but not limited to," etc.). It will be further understood by those skilled in the art that where recitation of a specific number of introduced claims is intended, such intention will be expressly recited in the claim, and that in the absence of such recitation, no such intention exists. For example, as an aid to understanding, the following appended claims may include the use of the introductory phrases "at least one" and "one or more" to introduce the recitation of claims. However, the use of such phrases should not be construed as implying that the introduction of a claim recitation by the indefinite article "a" or "an" limits any particular claim that includes such an introduced claim recitation to claims containing only one such recitation, even when the same claim also includes the introductory phrase "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should ordinarily be construed to mean "at least one" or "one or more").

[0113] Furthermore, even if a particular number of enumerations in an introduced claim are explicitly recited, those skilled in the art will recognize that such enumerations should typically be interpreted to mean at least the recited number (e.g., the mere enumeration of "two enumerations," without other modifiers, typically means at least two enumerations or more than two enumerations). Furthermore, in those instances where a convention similar to "at least one of A, B, and C, etc." is used, such construction is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). In instances where a convention similar to "at least one of A, B, or C, etc." is used, such construction is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). It will be further understood by those of ordinary skill in the art that disjunctions and / or phrases, whether in the description, claims, or drawings, typically present two or more alternative terms, should be understood to contemplate the possibility of including one of the terms, either of the terms, or both terms, unless the context dictates otherwise. For example, the phrase "A or B" will typically be understood to include the possibilities of "A" or "B" or "A and B."

[0114] With respect to the appended claims, those skilled in the art will understand that the actions recited therein may generally occur in any order. Also, while the claim recitations are presented sequentially, it should be understood that various actions may occur in other orders than those described, or may occur simultaneously. Examples of such alternative orders include overlapping, interleaved, interrupted, reordered, incremental, preparatory, supplemental, simultaneous, reverse, or other variant orders, unless the context dictates otherwise. Furthermore, unless the context dictates otherwise, terms such as "responsive," "related," or other past tense adjectives are generally not intended to exclude such variants.

[0115] It should be noted that any reference to "one aspect," "an embodiment," "one embodiment," "aspect," "example," "one example," and the like means that a particular feature, structure, or characteristic described in connection with an aspect is included in at least one aspect. Thus, the appearances of the phrases "in one aspect," "in an aspect," "in one example," and "in one example" in various places throughout this specification do not necessarily all refer to the same aspect. Furthermore, particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0116] As used herein, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise.

[0117] Directional terms used herein, such as, but not limited to, up, down, left, right, below, over, front, back, and variations thereof, relate to the orientation of the elements as shown in the accompanying drawings and are not intended to be limiting with respect to the claims, unless expressly stated otherwise.

[0118] As used in this disclosure, the term "about" or "approximately," unless otherwise specified, refers to an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the term "about" or "approximately" means within 1, 2, 3, or 4 standard deviations. In certain embodiments, the term "about" or "approximately" means within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0119] As used herein, unless otherwise indicated, all numerical parameters are understood to be predicated and, in all instances, modified by the term "about" given the inherent variability characteristic of the underlying measurement technique used to determine the numerical value of that parameter. At the very least, and not as an attempt to limit the application of the doctrine of equivalents to the scope of the claims, each numerical parameter set forth herein should at least be construed in light of the number of reported significant digits and by applying ordinary rounding techniques.

[0120] Any numerical range recited herein includes all subranges subsumed within the recited range. For example, a range of "1 to 100" includes all subranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., having a minimum value of 1 or greater and a maximum value of 100 or less. Also, all ranges recited herein include the recited endpoints. For example, a range of 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, applicants reserve the right to amend this specification, including the claims, to explicitly recite subranges subsumed within the explicitly recited ranges. All such ranges are inherently set forth herein.

[0121] Any patent applications, patents, non-patent publications, or other disclosure materials mentioned herein and / or listed in any application data sheets are incorporated herein by reference to the extent that the incorporated materials do not contradict this specification. Accordingly, and to the extent necessary, the present disclosure as expressly set forth herein supersedes any conflicting material incorporated herein by reference. Any material, or portion thereof, that is said to be incorporated herein by reference but that contradicts existing definitions, statements, or other disclosure materials set forth herein is incorporated only to the extent that no contradiction arises between the incorporated material and the existing disclosure materials.

[0122] The terms "comprise" (and any form of comprise, such as "comprises" or "comprising"), "have" (and any form of have, such as "has" and "having"), "include" (and any form of include, such as "includes" and "including"), and "contain" (and any form of contain, such as "contains" and "containing") are open-ended linking verbs. Consequently, a system that "comprises," "has," "includes," or "contains" one or more elements possesses those one or more elements, but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises," "has," "includes," or "contains" one or more features possesses those one or more features, but is not limited to possessing only those one or more features.

[0123] The foregoing detailed description sets forth various aspects of devices and / or processes through the use of block diagrams, flowcharts, and / or examples. Where such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each function and / or operation in such block diagrams, flowcharts, and / or examples can be individually and / or collectively implemented by a wide range of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the embodiments disclosed herein can be equivalently implemented in whole or in part in integrated circuits as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or substantially any combination thereof, and that designing the circuitry and / or writing the code for the software and / or firmware is within the skill of those skilled in the art in light of this disclosure. Furthermore, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed as one or more program products in a variety of forms, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal-bearing medium used to actually effect the distribution.

[0124] The instructions used to program logic to implement various disclosed aspects may be stored in memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage device. Additionally, the instructions may be distributed over a network or via other computer-readable media. Thus, a machine-readable medium is any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), including, but not limited to, a floppy diskette, an optical disk, a compact disk, a read-only memory (CD-ROM), and a magneto-optical disk, a read-only memory (ROM), a random access memory (RAM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic or optical card, a flash memory, or a tangible machine-readable storage device used in transmitting information over the Internet via an electrical, optical, acoustic, or other form of propagated signal (e.g., carrier wave, infrared signal, digital signal, etc.). Accordingly, non-transitory computer-readable media includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0125] As used in any aspect herein, the term "control circuitry" can refer to, for example, hardwired circuitry, programmable circuitry (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA)), a state machine circuit, firmware that stores instructions executed by the programmable circuit, and any combination thereof. Control circuitry can be embodied collectively or individually as circuitry that forms part of a larger system, e.g., an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on a chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuitry" includes, but is not limited to, electrical circuitry having at least one discrete electrical circuit, electrical circuitry having at least one integrated circuit, electrical circuitry having at least one application-specific integrated circuit, electrical circuitry forming a general-purpose computing device configured by a computer program (e.g., a general-purpose computer configured by a computer program at least in part to execute a process and / or a device described herein, or a microprocessor configured by a computer program at least in part to execute a process and / or a device described herein), electrical circuitry forming a memory device (e.g., a form of random access memory), and / or electrical circuitry forming a communications device (e.g., a modem, a communications switch, or an optoelectronic device). Those skilled in the art will recognize that the subject matter described herein can be implemented in an analog or digital fashion or some combination thereof.

[0126] As used in any aspect of this specification, the term "logic" may refer to an application, software, firmware, and / or circuitry configured to perform any of the aforementioned operations. Software may be embodied as a software package, code, instructions, an instruction set, and / or data recorded on a non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, or an instruction set, and / or hard-coded (e.g., non-volatile) data within a memory device.

[0127] As used in any aspect of this specification, the terms "component," "system," "module," etc. may refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.

[0128] As used in any aspect herein, an "algorithm" refers to a self-consistent sequence of steps leading to a desired result, and the "steps" refer to manipulations of physical quantities and / or logical states which may, but need not, take the form of electrical or magnetic signals capable of being stored, moved, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, or the like. These and similar terms may be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

Claims

1. 1. A method for autonomously securing a tenant network via a Managed Security Service Provider (MSSP) server comprising a processor and a memory, the method comprising: The method includes using information from a plurality of data sources to: querying, via the processor, a database or server upon encountering an indicator of compromise (IoC) by the security system to identify a data source among a plurality of data sources, the data source including a reference to the IoC; generating, via the processor, an IoC threat score for the IoC based on an output of the query; for each data source among the data sources, identifying an IoC threat value provided by the data source; for each data source among the data sources, assigning a multiplier to the IoC threat value provided by the data source to generate an adjusted IoC threat value, the multiplier being based on a confidence score associated with the data source; normalizing the adjusted IoC threat values from the data sources to output the IoC threat score; said generating comprising: generating, via the processor, at least one actionable security hardening notification based on the IoC threat score; displaying the IoC threat score and the actionable security hardening notification to a user via a user interface, the display enabling triggering or disabling of at least one action in the at least one actionable security hardening notification, the at least one action being based on the IoC threat score; A method comprising:

2. The method further comprises deploying an automated security response; The expanding automatically adjusting a security threat threshold level; automatically reconfiguring said database or server to identify potential malware variants; Sending notifications to multiple other users; determining the risk that other tenant networks are or will be exposed to said IoCs; or isolating one or more tenant networks or portions of a network; or a combination thereof, The method of claim 1.

3. The method further comprises classifying the IoC as malicious, unknown, or benign based on at least one of the IoC threat score, a generated confidence score, or a security threat threshold level, or a combination thereof; The user interface may display the classification. The method of claim 1.

4. 4. The method of claim 3, wherein the security threat threshold is automatically adjusted based on a ratio representing the accuracy or precision of the classification of the IoC as malicious or benign by using a ratio including at least two of a number of false positives, a number of true positives, a number of false negatives, and a number of true negatives.

5. The method comprises: determining that the IoC is classified as a malicious threat and that the encountered IoC indicator shares a portion of a set of characteristics with other IoCs stored in the database or server; identifying a new malware variant based on at least one of the IoC threat score, the portion of the set of features, a generated confidence score, and a security threat threshold level, or a combination thereof, in determining the IoC as the malicious threat; The method of claim 1 further comprising:

6. 6. The method of claim 5, further comprising reconfiguring the database to identify the new malware variant based on at least one of the features of the IoC, the IoC threat score, the generated confidence score, the security threat threshold level, or the classification of the IoC, or a combination thereof.

7. The method of claim 1 , wherein the actionable hardening notification includes an indication of a new malware variant on the tenant network, the new malware variant being determined based on data of other malware.

8. The method comprises: receiving data from the data sources, each data source associated with at least one IoC, each data source defining a reliability score; indexing the data sources and their associated at least one IoC into a database or memory component; The method of claim 1 further comprising:

9. 2. The method of claim 1, wherein the trustworthiness score of each data source of the data sources is determined by at least one of human involvement, the number of IoCs identified by the data source, the history of trustworthiness of the data source, the number of data inputs to the data source, the age of the data source, the age of IoCs in the data source, a reputation associated with the data source, the relevance of the data source to a client or the user of the security system, and the amount of information available on the data source.

10. 2. The method of claim 1, wherein the at least one actionable security hardening notification is based on at least one of the IoC threat score, a generated confidence score, or a security threat threshold level, or a combination thereof.

11. The querying comprises: cross-referencing the identified DNS queries and IP addresses with a plurality of IoCs stored in the database, the plurality of IoCs including the IoC; identifying a related data source of the data source, the related data source's relevance being determined by an association of the related data source with the identified DNS query and IP address; The method of claim 1 , comprising:

12. The method of claim 11 , wherein the querying further comprises identifying DNS queries and IP addresses contacted by machines in the defined computing environment.

13. The generation of the IoC threat score comprises: Identifying anomalous IoC threat values; discarding the anomalous IoC threat value; and The method of claim 1 further comprising:

14. 2. The method of claim 1, wherein the generating the IoC threat score comprises weighting various IoC threat values from data sources having a particular reliability score relative to IoC threat values from data sources having a lower reliability score.

15. 2. The method of claim 1 , wherein the generation of the IoC threat score is performed by at least one of a machine learning neural network, and inputs to the machine learning network comprise a credibility score of the data source and the IoC threat value provided by the data source.

16. The method of claim 1 , further comprising generating a convergence score associated with the IoC threat score based on a distribution of the threat values provided by the data source.

17. 1. An autonomous security system directed to continuously hardening one or more tenant networks, the system comprising: Multiple tenant networks and at least one Managed Security Service Provider (MSSP) server having a processor and a memory; Equipped with The memory, when executed by the processor, causes the processor to: Upon encountering an indicator of compromise (IoC) by the security system, querying at least one database or server to identify a data feed with a reference to said IoC; generating an IoC threat score for the IoC based on an output of the query; for each data feed of the data feeds, identifying an IoC threat value classified by the data feed; For each data feed of the data feeds, adding a multiplier to the IoC threat value to generate an adjusted IoC threat value, the multiplier being determined based on a confidence score associated with the data feed; and normalizing the adjusted IoC threat value of the data feed; and outputting the IoC threat score; said generating comprising: generating at least one actionable security hardening notification based on the IoC threat score; displaying the IoC threat score and the actionable security enhancement notification to a user of the security system via a user interface on at least one display device connected to the MSSP server, the at least one actionable security enhancement notification enabling triggering or disabling of at least one action, the at least one action being based on the IoC threat score; Storing instructions to be executed, method.

18. the executable hardening notification includes an indication of a new malware variant on at least one tenant network of the plurality of tenant networks; the new malware variant is determined based on other malware data; 18. The autonomous security system of claim 17.

19. the stored instructions, when executed by the processor, are further configured to cause the processor to deploy an automated security response; The expanding automatically adjusting a security threat threshold level; Automatically reconfiguring the database or server to identify other potential malware variants; and sending notifications to a plurality of other users of the security system; Determining the exposure or risk of exposure of other tenant networks to new malware variants; and isolating at least one tenant network among the plurality of tenant networks; including at least one of 18. The autonomous security system of claim 17.

20. 1. A method for autonomously enhancing security of a tenant network, comprising: Upon encountering an indicator of compromise (IoC) by a security system within a tenant network of the plurality of tenant networks, querying a security server to identify a data feed comprising at least one reference to the IoC; generating, via a processor, an IoC threat score for the IoC based on results of the query; deploying an automated security response by the security system based on the IoC threat score; displaying at least one of the IoC threat score, the status of the automated security response, or an actionable security hardening notification to a user of the security system via a user interface; Equipped with the actionable security enhancement notification facilitates triggering of additional security responses; method.

Citation Information

Patent Citations

  • Tenant self-service troubleshooting for multi-tenant identity and data security management cloud services

    JP2019531534A

  • Network surveillance and security system

    US20030051026A1

  • Automatically preventing and remediating network abuse

    US20170006053A1

  • Device vulnerability management

    US20180351987A1

  • Autonomous monitoring of applications in a cloud environment

    US20220174097A1