SYSTEM AND METHOD FOR DETECTING MALICIOUS EVENTS - Patent application

The system allows security professionals to submit curated detection rules in a domain-specific language, automating threat monitoring and alert generation, thus separating developer and security expert responsibilities, enhancing efficiency and reducing update times.

JP2025532138APending Publication Date: 2025-09-29SECUREWORKS CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025517393
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-23
Filing Date
2023-08-28
Publication Date
2025-09-29

AI Technical Summary

Technical Problem

Existing security systems require frequent updates and long feedback loops due to continuously changing malicious threat activities, necessitating collaboration between engineering and security experts, which is inefficient and time-consuming.

Method used

A rules platform engine and malicious sequence detection engine that allows security professionals to submit curated detection rules in a domain-specific language, enabling automated monitoring and alert generation based on predefined thresholds, separating developer and security expert responsibilities.

Benefits of technology

Facilitates independent work by developers and security experts, reducing the need for continuous feedback loops and enabling rapid updates to security software without frequent engineering intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025532138000001_ABST
    Figure 2025532138000001_ABST
Patent Text Reader

Abstract

A method and system for detecting malicious threat activity or event sequences are disclosed. In an embodiment, the method may include generating one or more malicious sequence detection rules defined in a domain-specific language. The method may include generating a rule repository configured to receive and store one or more predefined rules and one or more curated sets of malicious sequence detection rules. The method may include monitoring a network and / or computing devices and detecting malicious threat activity or event sequences based on the one or more curated sets of malicious sequence detection rules.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to detecting malicious sequences, events, and / or activities, and more particularly to systems and methods utilizing a rules platform engine or system and / or providing a rules platform engine or system to entities and / or users to enable entities and / or users to submit one or more curated sets of malicious sequence or event detection rules and / or for automated monitoring of malicious events based on a curated set of malicious sequence detection rules. [Background technology]

[0002] New types of security threat activity or events in the threat landscape arise daily or periodically. Updating and / or developing new software and / or applications to address such new threat activity is often not cost-effective and requires highly skilled teams that understand both the cybersecurity field and advanced data science development techniques.

[0003] Threat activity can be detected and an alert generated by aggregating multiple weak-signal events occurring close to each other. However, such events may not always be cause for an alert; often, alerts regarding such events may be general to a broad set of events, and updates to such alerts may require additional resources and time. For example, an engineering team may build software to monitor for such events based on rules determined by security experts. Heuristic algorithms may then be added to such software, which may then be run in production and then re-evaluated by security experts, which may often require changes and updates to such software. Due to continuously changing and / or occurring malicious events, these requests from security experts to update such software may be frequent, thus resulting in very long feedback loop times. As a result, the level of effort and time expended by both engineering and security experts collaborating during the software development lifecycle from security experts and engineers in connection with developing security software and creating updates thereto is increased.

[0004]

[0006] Thus, it can be seen that a need exists for a system and method for utilizing and / or providing a rules platform engine or system to users to enable them to submit curated sets of malicious sequence detection rules and / or for automated monitoring of malicious events based on curated sets of malicious sequence detection rules.

[0007] The present disclosure is directed to the foregoing and other related and unrelated problems / challenges in the art. Summary of the Invention [Means for solving the problem]

[0005] Briefly, according to various aspects, the present disclosure is directed to systems and methods for detecting security threat activity, such as sequences of malicious events. Such systems and methods may include or utilize memory and / or at least one processor. Such systems (e.g., at least one processor) may include a rules platform engine and / or a malicious sequence detection engine. The rules platform engine may be configured to provide one or more sets of user-readable instructions, defined in a domain-specific language or other similar language, to one or more users. The one or more sets of user-readable instructions may be utilized to generate detection rules for malicious sequences of activity or events or sets of malicious sequence detection rules. In other words, the one or more sets of user-readable instructions may enable or enable a user to generate rules for detecting sequences or potentially malicious or threatening activities or events. Such malicious sequence rules may be defined by rules based on one or more malicious or threatening activities or events, and / or interactions provided by each of one or more users, or a combination thereof.

[0006] In embodiments, the rules platform engine may be configured to receive from one or more users (e.g., via a user interface or via receiving data through a message-based system) one or more curated sets of malicious sequence activity or event detection rules (e.g., in embodiments, one or more sets of conditions indicative of potential threats, which may be of variable severity and may hereinafter be referred to as malicious sequence detection rules) and instructions for generating alerts related to such malicious sequence activity or event-based rules in a defined domain-specific language. The rules platform engine may further be configured to generate a rules repository. The rules repository may generally be stored separately from the memory of the system, for example, as a separate repository residing on a separate server, network, memory, or another location. In embodiments, at least a portion of the malicious sequence detection rules may be loaded into memory, and in some embodiments, a copy of a subset of the rules repository may also be stored in memory. The rules repository may be utilized by other engines or algorithms to continuously or substantially continuously scan computing devices for malicious activity or events. Additionally, one of the one or more malicious sequence detection rules in the rule repository may include one or more draft sets or draft malicious sequence detection rules. In embodiments, one or more conditions of a malicious sequence detection rule may be provided by a service lookup, e.g., an event with an identified potential threat or malicious IP address is received, and using domain-specific language, a security expert is provided with functionality to work with the rule repository for analysis of the event, e.g., pull / access a threat service and / or threat database, etc.

[0007] Such systems and methods may also include a malicious sequence threat activity or event detection engine or system configured to receive, from one or more users or from a repository, a curated set of malicious sequence detection rules adapted to analyze and determine a threat score for a series or set of detected threat activities or events that are aggregated to define a malicious sequence of such threat activities or events detected as occurring within a selected or determined time period (e.g., the malicious sequence detection engine or system may periodically receive updated rules from the repository or rule repository). Using such rules, the malicious sequence detection engine or system may monitor a computer network or system and / or data, such as from incoming security logs, for malicious activity or events or multiple weak signal activities or events. A rule designated as a draft malicious sequence detection rule may not be utilized by the malicious sequence detection engine or system until the draft malicious sequence detection rule is received by or further curated by a user and / or entity. The malicious sequence detection engine or system may aggregate any detected malicious activity (e.g., multiple weak signal events) and generate a threat score. If the threat score exceeds a threshold, the malicious sequence detection engine or system may generate an alert (eg, an alert that includes instructions specified by one or more users).

[0008] Thus, the systems and methods disclosed herein are adapted to enable and / or provide a "separation of concerns" for the development of security software or applications, such that, for example, the responsibilities of a software engineer, enabling engineer, or developer may be performed in parallel with and substantially independent of the scrutiny of threat activity or events associated with the software being developed by security professionals; The present system and method allows for independent work and work by distinct groups (e.g., engineers versus security experts) without requiring a substantially continuous feedback loop between engineers and security experts. Thus, developer responsibilities or concerns can be separated from those of security experts, and the required level of effort and length of the product development lifecycle due to the continuous updates that need to be added to a software product upon reviewing numerous security expert requests and / or examining detected events can be correspondingly reduced. (E.g., for a company or organization, many security expert requests and smaller software changes can be independently resolved by a security expert who communicates with a system's malicious sequence detection engine and provides curated security rules to the system's malicious sequence detection engine, which can then implement the security rules for the associated security software product, which can then be applied and modified substantially automatically, without frequent back-and-forth between the security expert and the developer / engineer.)

[0009] By providing an extensible set of human-readable instructions defined in a domain-specific language, (1) security professionals may be enabled to provide their own curated sets of rules to the sequence detection engine via an interface usable by such security professionals (e.g., users potentially without engineering experience); (2) security professionals may manage non-engineering workflows around the contents of the curated set of rules; (3) security professionals or other users may build access controls around the curated rules outside of the engineering system development lifecycle; and / or (4) security professionals or other users may use the domain-specific sequence rule language to support new curated security rules or instructions, which may be applied by the sequence detection engine to substantially automatically update the malicious sequence detection rules applied by the engine, and interaction with a context-providing service may provide more appropriate or better context information where it is most needed.

[0010] In one aspect, the present disclosure provides a system for detecting security threats. The system may include a memory. The system may include at least one processor. The at least one processor may include a rules platform engine. The rules platform engine may be configured to provide a set of user-readable instructions defined in a domain-specific language to one or more users and / or one or more entities to generate a set of malicious sequence alerts created by specific malicious sequence detection rules. The malicious sequence detection rules may be defined by one or more malicious sequence activity-based rules and / or interactions provided by each of the one or more users and / or one or more entities. The rules platform engine may be configured to receive one or more curated sets of malicious sequence detection rules and instructions in a defined domain-specific language from one or more of the one or more users and / or one or more entities. The rules platform engine may be configured to generate a rules repository, stored in memory and / or stored separately from the memory, including one or more existing malicious sequence detection rules, and configured to receive and store one or more curated sets of malicious sequence detection rules received from one or more users and / or one or more entities. The at least one processor may further comprise a malicious sequence detection engine. The malicious sequence detection engine may be configured to receive one or more curated sets of malicious sequence detection rules from one or more users and / or one or more entities.The malicious sequence detection engine may be configured to monitor incoming security data to detect one or more malicious threat activities or event sequences indicative of at least one security threat based on one or more curated sets of malicious sequence detection rules. The malicious sequence detection engine may be configured to aggregate multiple malicious threat activities or event sequences detected within a predetermined time frame and generate a threat score. The malicious sequence detection engine may be configured to generate an alert if the threat score of the aggregated malicious threat activities or event sequences exceeds a threshold score.

[0011] In one embodiment, the rule repository may comprise persistent and secure storage. In another embodiment, the content of the alert may include contextual information related to the detected malicious sequence activity. The one or more users may include one or more of a developer, a development operator, a security specialist, or a combination thereof. The one or more entities may include a host or multiple hosts, a server, or other computing device, an account (e.g., which may include or encompass one or more users), or an Internet Protocol (IP) address. One or more networks, one or more computing devices, or one or more combinations thereof may be monitored for malicious sequence activity.

[0012] In another embodiment, the rules platform engine may be configured to generate a user interface, in which one or more curated sets of malicious sequence detection rules and instructions in a defined domain-specific language may be received from one or more of one or more users and / or one or more entities via the generated user interface.

[0013] In another aspect, the present disclosure provides a method for detecting malicious sequence activity. The method may include generating one or more malicious sequence detection rules defined in a domain-specific language based on interactions provided by each of one or more users and / or one or more entities. The method may include generating a rule repository configured to receive and store one or more predefined rules and receive one or more curated sets of malicious sequence detection rules. The method may include receiving the one or more curated sets of malicious sequence detection rules based on interactions from the one or more users and / or one or more entities. The method may include monitoring one or more networks, one or more computing devices, or a combination thereof, and detecting malicious threat activity or event sequences indicative of at least one potential security threat based on the one or more curated sets of malicious sequence detection rules. The method may include aggregating multiple malicious threat activities or event sequences detected within a predetermined time frame to generate a threat score. The method may further include generating an alert based on one of the one or more curated sets of malicious sequence detection rules if the threat score of the aggregated malicious threat activities or event sequences exceeds a threshold score. The method may include storing the one or more curated sets of malicious sequence detection rules in a rule repository.

[0014] In another embodiment, the malicious threat activity or event sequence may include an aggregate of multiple weak-signal events occurring within a selected time period. The alert content may include contextual information related to the detected malicious sequence of activity. In an embodiment, the method may include receiving alert content corresponding to one of the one or more curated sets of rules from one or more users and / or one or more entities. The alert content corresponding to one of the one or more curated sets of rules may be editable by the user and / or entity that submitted the corresponding one of the one or more curated sets of rules.

[0015] Various objects, features and advantages of the present disclosure will become apparent to those skilled in the art upon review of the following detailed description when considered in conjunction with the accompanying drawings. [Brief explanation of the drawings]

[0016] It should be understood that for simplicity and clarity of illustration, elements illustrated in the figures have not necessarily been drawn to scale. For example, the dimensions of some elements may be exaggerated relative to other elements. Embodiments incorporating the teachings of the present disclosure are shown and described with reference to the drawings herein.

[0017] [Figure 1] FIG. 1 is a schematic diagram of a data center including a networked system of information handling systems according to one aspect of the present disclosure.

[0018] [Figure 2A] 2A and 2B are schematic diagrams of a system for detecting security threats according to one aspect of the present disclosure. [Figure 2B] 2A and 2B are schematic diagrams of a system for detecting security threats according to one aspect of the present disclosure.

[0019] [Figure 3] FIG. 3 is a schematic diagram of a graphical user interface for editing and saving a malicious sequence rule or set of rules according to one aspect of the present disclosure.

[0020] [Figure 4] FIG. 4 is a flow diagram for detecting security threats according to one aspect of the present disclosure.

[0021] [Figure 5] FIG. 5 is a schematic diagram of an information handling system capable of implementing each of the illustrative embodiments according to one aspect of the present disclosure.

[0022] The use of the same reference symbols in different drawings indicates similar or identical items. DETAILED DESCRIPTION OF THE INVENTION

[0023] Detailed Description The following description in combination with the figures is provided to aid in understanding the teachings disclosed herein. This description focuses on specific implementations and embodiments of the present teachings and is provided to help explain the present teachings. This focus should not be construed as a limitation on the scope or applicability of the present teachings.

[0024] According to various aspects, the present disclosure is directed to systems and methods for detecting malicious sequence events, and more particularly, to systems and methods for automated monitoring of malicious events based on a curated set of malicious sequence detection rules, including utilizing a rules platform engine or system to enable users and / or entities to submit a curated set of malicious sequence detection rules and / or providing a rules platform engine or system to users and / or entities and / or enabling filtering of lower risk activity or event sequences to substantially reduce the occurrence of alerts generated for the lower risk activities.

[0025] In embodiments, such systems and methods may be directed to analyzing incoming security data and detecting malicious threat activities or events that may constitute a low threat risk by themselves, but that, when occurring in sequence or within a selected time period, may create stronger indicators of a higher threat risk and / or failure. For example, in embodiments, a series or detected sequence of threat activities or events with a lower assigned threat risk may be aggregated over a selected time window, and the aggregation may create a risk level or factor that exceeds a threshold risk level; and if a detection rule that would apply to such a sequence of threat activities or events has not yet been enacted, a malicious sequence detection engine may alert one or more security professionals. In response, the security expert may curate or modify one or more rules applicable to the detected sequence of activity or events and provide such curated rules or events to a malicious sequence detection engine, which may utilize such curated malicious sequence detection rules and automatically apply the malicious sequence detection rules stored in the rule repository to subsequent detections of similar sequences of threat activity or events without requiring further expert intervention and / or update the malicious sequence detection rules stored in the rule repository.

[0026] The system and method may comprise or utilize a memory and / or at least one processor. The system (e.g., at least one processor) may comprise a rules platform engine and / or a malicious sequence detection engine. The rules platform engine may be configured to provide one or more sets of user-readable instructions, defined in a domain-specific language, to one or more users. The one or more sets of user-readable instructions may be utilized to generate a set of malicious sequence detection rules. In other words, the one or more sets of user-readable instructions may enable or permit a user to generate rules to detect malicious sequence activity or events.

[0027] In embodiments, such malicious sequence detection rules may be defined by one or more malicious sequence activity-based rules and / or interactions provided by each of one or more users. The rules platform engine may be configured to receive one or more curated sets of malicious sequence activity detection rules and instructions for alerting on malicious sequence activity-based rules in a defined domain-specific language from one or more users and / or one or more entities (e.g., via a user interface or via receiving data through a message-based system). In another embodiment, the rules platform engine may be configured to receive a draft set of malicious sequence activity detection rules (e.g., in embodiments, a set of conditions) and instructions. The rules platform engine may further be configured to generate a rules repository. The rules repository may be stored in memory and / or externally (e.g., in an external database). The rule repository may be utilized by other engines or algorithms to continuously or substantially continuously scan computing devices and / or other entities (e.g., a host or multiple hosts, servers, or other computing devices, an account (e.g., which may include or encompass one or more users), or an Internet Protocol (IP) address associated with one or more users) for malicious events. In embodiments, the rule repository may include an indicator to show whether a particular rule is a draft rule or is ready for production (e.g., to be utilized in a scanning operation).

[0028] In embodiments, the systems and methods may include a malicious sequence detection engine or system. The malicious sequence detection engine or system may be configured to receive a curated set of malicious sequence detection rules from one or more users or from a repository (e.g., the malicious sequence detection engine or system may periodically receive updated rules from the repository). Using such rules, the malicious sequence detection engine or system may monitor for malicious events or sequences of events and / or multiple weak signal events, e.g., sequences of such events that may occur over a selected period of time. The malicious sequence detection engine or system may aggregate any detected sequences of malicious activity and / or potentially malicious threat activity or events (e.g., multiple weak signal events detected as occurring sequentially and / or within a selected period of time) and generate a threat score. If the threat score exceeds a threshold, the malicious sequence detection engine or system may generate an alert (e.g., an alert including instructions specified by one or more users).

[0029] Thus, as described, the problem of "separation of concerns" (e.g., developer versus security expert responsibilities, and long levels of effort and development lifecycles in development and based on numerous security expert requests and / or scrutiny of detected events) can be solved on a large scale (e.g., numerous security expert requests and numerous software updates for a company or organization, etc.) In other words, by separating the development of such software from requests by security experts, updates regarding monitoring of newly discovered events or sequences can occur automatically and more quickly than in a typical software development lifecycle.

[0030] Thus, as described, the problem of "separation of concerns" (e.g., developer versus security expert responsibilities, and long levels of effort and development lifecycles in development and based on numerous security expert requests and / or scrutiny of detected events) can be solved on a large scale (e.g., numerous security expert requests and numerous software updates for a company or organization, etc.) In other words, by separating the development of such software from requests by security experts, updates regarding monitoring of newly discovered events or sequences can occur automatically and more quickly than in a typical software development lifecycle.

[0031] Furthermore, by providing an extensible set of human-readable instructions defined by a domain-specific language, (1) security experts may be enabled to provide their own curated set of rules to the sequence detection engine via an interface usable by such security experts (e.g., potentially users without engineering experience); (2) security experts may manage non-engineering workflows around the content of the rules; (3) security experts or other users may build access controls around the rules outside of the engineering system development lifecycle; and / or (4) use of the possibilities of the sequence rule language to support new instructions and therefore interaction with a context-providing service for rule curation by different security experts may provide more relevant or better context information most needed for alerts created by specific malicious sequence detection rules.

[0032] As shown in Figures 1-5, the present disclosure includes systems and methods for detecting malicious sequences or events. The systems and methods disclosed herein are adapted to enable the creation or generation of a curated set of malicious sequence detection rules and / or automated monitoring of malicious events or threat activity based on the curated set of malicious sequence detection rules.

[0033] 1 is a block diagram of an exemplary data center 10 that may be in communication with or incorporated as part of a system and method for detecting malicious threat activity or event sequences. As shown in FIG. 1, data center 10 may include a network 12 that may provide communication between a plurality of information handling systems 14, which may include workstations, personal computers, smart phones, personal digital assistants, laptop computers, servers, computing devices, other suitable devices, and / or combinations thereof. Information handling systems 14 may be further coupled to network 12 through wired connections 16, wireless connections 18, or any information handling system 14 may be further coupled to network 12 through wired connections 16, wireless connections 18, or any other suitable communication or connection line. As further shown in FIG. 1 , the data center 10 and / or one or more of its information handling systems 14 may be communicatively coupled to a network, including a cloud-based or other network as shown at 12 or 20 in FIG. 1 , for example, through a wired connection 16 or through any other suitable connection, such as a wireless connection 18 (e.g., Wi-Fi, cellular, etc.). The network 12 may further be accessible to / by one or more users or client management information handling systems or devices 22 and may facilitate communication between the client management information handling systems 22 and the data center 10 (for which rules may be generated and / or enforced). The network 12 may include an API interface of the event management center, although the network may include any suitable network, such as the Internet or other wide area network, a local area network, or a combination of networks, that may provide communication, e.g., data communication, between the event management center and the client management information handling systems 22.

[0034] The client management information handling system 22 is connected to a network 20 (FIG. 1) through a wired connection, e.g., an Ethernet cable or other suitable wired or wireless connection 18, e.g., Wi-Fi 33, Bluetooth 33, a cellular connection (e.g., 3G, 4G, LTE, 5G, etc.), other suitable wireless connection, or a combination thereof, to enable clients or operators of the information handling system 22 to communicate with the event management center, thereby, for example, to access one or more of the services offered. For example, the event management center may be or include a web service.

[0035] For purposes of this disclosure, an information handling system 14 / 22 may include any means or collection of means operable to calculate, compute, determine, classify, process, transmit, receive, retrieve, emit, switch, store, display, communicate, reveal, detect, record, reproduce, handle, or utilize any form of information, sensitive information, or data for business, scientific, control, or other purposes. In one embodiment, an information handling system may include storage devices such as random access memory (RAM) or (ROM), one or more processing resources such as a central processing unit (CPU) or hardware or software control logic, ROM, and / or other types of non-volatile memory. Additional components of an information handling system may include one or more disk drives, one or more network ports for communicating with external devices, and various input / output (I / O) devices such as a keyboard, mouse, touchscreen, and / or video display. An information handling system may also include one or more buses operable to transmit communications between various hardware components.

[0036] 2A and 2B are schematic diagrams of embodiments of a system for detecting malicious sequences of events or threat activity in accordance with one or more aspects of the present disclosure. Turning to FIG. 2A, system 200 may include a threat intelligence system 202. Threat intelligence system 202 may include at least one processor 204 and memory 206. Memory 206 may include or store a rules platform engine 210 and / or a malicious sequence detection engine 212. Memory 206, in some embodiments, may include or store a rules repository 214. In another embodiment, rules repository 214 may be distributed across more than one storage device (e.g., one or more internal / external databases, etc.), in addition to or instead of being stored within memory 206. Threat intelligence system 202 may include other components, such as an input / output module 220. In an embodiment, the input / output module 220 may be configured to receive and / or transmit data from an external source (e.g., to security computing devices 218A, 218B, 218N and / or to one or more computing devices 220A, 220B, and 220N).

[0037] In one embodiment, processor 204 may execute various instructions stored in memory 206, such as APIs or other instructions or programs associated with, corresponding to, or comprising one or more of rules platform engine 210 or malicious detection engine 212. In one embodiment, security computing devices 218A, 218B, and 218N and / or computing devices 220A, 220B, and 220N may be separate from, i.e., not directly included within, threat intelligence system 202. In another embodiment, threat intelligence system 202 may include one or more security computing devices 218A, 218B, and 218N and / or one or more computing devices 220A, 220B, and 220N. Additionally or alternatively, the threat intelligence system 202 may include and / or be configured to execute instructions associated with or corresponding to user interfaces, agents, and / or other monitoring algorithms.

[0038] Rules platform engine 210 may be configured to receive one or more drafts and / or one or more curated sets of malicious sequence detection rules from each of security computing devices 218A, 218B, and 218N. Rules platform engine 210 may further generate rules repository 214. Rules platform engine 210 may be further configured to add any received one or more drafts and / or one or more curated sets of malicious sequence detection rules to rules repository 214. Rules platform engine 210 may be further configured to include or generate at least one interface, such as a user interface, configured to receive the one or more curated sets of malicious sequence detection rules along with instructions for implementation or application of each of such one or more curated sets of malicious sequence detection rules. The instructions may include, in addition to or rather than implementation or application details, information regarding methods for addressing security threats, destinations (e.g., selected security experts or sets of experts) to send alerts regarding threats or sequences that qualify as malicious threat activity or events, and / or language to be included within the alerts, among other data and / or information. In an embodiment, rules engine platform 210, with or without users and / or entities and / or user interaction (e.g., through engagement or interaction with rules engine platform 210), may classify or indicate each user's permission or access level.

[0039] In another embodiment, security computing devices 218A, 218B, and up to 218N may each be directly connected to rules repository 214. In such an embodiment, security computing devices 218A, 218B, and up to 218N may each provide one or more draft and / or one or more curated sets of malicious sequence detection rules directly to rules repository 214 (e.g., via a user interface and / or other message-based system). Additionally, threat intelligence system 202 may collect rules from the rules repository (e.g., via rules platform SDK 210, malicious detection engine 212, and / or another algorithm or engine) at preselected time intervals or substantially continuously. Threat intelligence system 202 may provide the collected rules directly to rules platform SDK 210 and / or malicious detection engine 212.

[0040] In an embodiment, malicious sequence detection rules may include events, activities, or occurrences corresponding to potentially malicious outcomes (e.g., if these events occur, a malicious event or threat activity may have occurred). In an embodiment, malicious sequence detection rules may include events, activities, or occurrences associated with one or more specified users and / or entities. Malicious sequence detection rules may include events based on anomalous behavior, frequency of the event, type of event, user and / or entity (e.g., a host or multiple hosts, servers, or other computing devices, an account associated with the event (e.g., which may include or encompass one or more users), or an Internet Protocol (IP) address associated with one or more users), profile of the user and / or entity associated with the event (e.g., a profile including statistics based on previous collected data associated with the user and / or entity), and / or where and / or how the occurrence occurs (e.g., a login on a server that boots a specified operating system, an action performed on the server, typically performed on a laptop, etc.). A malicious sequence detection rule may be applicable to an aggregated set or sequence of multiple detected threat activities or events that are individually recognized as having a low risk score that would not normally necessarily initiate an alert, but when all or some of those multiple events occur in sequence, such as within a selected or predetermined time period, the threat score for the aggregated sequence of such threat activities or events may indicate a higher level of threat, i.e., a malicious event is occurring, so as to generate an alert and / or initiate corrective action.

[0041] In yet another embodiment, a user and / or entity may submit a malicious sequence detection rule (e.g., a draft malicious sequence detection rule) for testing prior to submission for use via the malicious detection engine 212. In such an embodiment, the rules platform engine 210 may generate a test or sandbox area. The rules platform engine 210 may execute events within a controlled environment in an attempt to trigger detection. Additionally, the rules platform engine 210 may utilize actual data (e.g., from a user, a security expert, and / or an external data source) to perform such execution. Thus, a user, an entity, and / or the rules platform engine 210 may determine whether a particular malicious sequence detection rule is written and / or interpreted correctly prior to being used by the malicious detection engine 212.

[0042] Based on one or more curated sets of malicious sequence detection rules stored in the rule repository 214, the malicious detection engine 212 may scan or automatically scan one or more computing devices 220A, 220B, and 220N, and / or other users and / or entities, for a series or sequence of corresponding threat activity and / or events, which may or may not be malicious, according to the curated set of malicious sequence detection rules. The malicious detection engine 212 may further scan the network and / or other devices for such threat activity or events. If a series of events corresponds to one or more of the curated set of malicious sequence detection rules, the malicious detection engine 212 may aggregate the series or sequence of detected events over a determined period of time, which is a selected type or class of threat activity or event, and generate a threat score. The aggregated series or sequence of detected events may, in some embodiments, include all or a portion of the events described in the one or more curated sets of malicious sequence detection rules. The malicious detection engine 212 may then compare the threat score to a threshold score, and if the threat score exceeds the threshold score, in some embodiments, the malicious detection engine 212 may generate an alert and send the sequence of events to one or more security experts for review. Additionally, after review by the one or more security experts, a new curated rule / rules may be created by the malicious detection engine 212, the rules platform engine 210, and / or by a user or by one or more of the security experts.In other embodiments, if curated rules applicable to a sequence of events exist in the rules repository 214, the malicious detection engine can apply the rules and take appropriate action (e.g., classify the events as indicative of a threat and initiate corrective action or an alert, or determine a sequence of events that is less likely to be a threat).

[0043] As described above, after review by one or more security experts, a new curated rule / rules may be created by the malicious detection engine 212, the rules platform engine 210, an entity, and / or by a user or by one or more of the security experts. In such examples, detected events may be indicated by, among other data, text describing the events that occurred, files (e.g., emails, documents, etc.) associated with those events, timestamps, and / or identification or identifying data (e.g., username, IP address, etc.). Once a series or sequence of events (e.g., as specified within a rule) is detected, data associated with the series or sequence of events may be sent to one or more security experts. Furthermore, additional data corresponding to a preselected time preceding or following the occurrence of the series or sequence of events may be sent to one or more security experts. Still further, the rules platform engine 210 may receive such data. The rules platform engine 210 may analyze data (e.g., data associated with a sequence of events and data corresponding to events occurring prior to and after the sequence of events). The rules platform engine 210 may determine new rules and / or updates to existing rules based on such analysis. For example, the rules platform engine 210 may recognize patterns, frequencies, and / or recurring identifying details that indicate a malicious event or another malicious event is occurring, and based on this recognition, the rules platform engine 210 may update the rules or add rules to the rules repository 214. Furthermore, such updates may be transmitted to one or more security experts prior to or after being produced (e.g., the malicious detection engine 212 may actively scan such rules).

[0044] For example, if a user receives an email (e.g., a first weak signal) from an unknown source (e.g., a second weak signal) using a link (e.g., a third weak signal), and then the user subsequently selects the link (e.g., a fourth weak signal), an alert may be generated according to the rules in the rules repository 214. The events, in such an example, would be receiving an email from an unknown user using the link and selecting the link. Separately, the events may be innocuous, but when examined together, a security issue may be deemed to exist. Thus, rather than notifying a security expert for each weak signal, the security expert may be notified when a defined combination (e.g., an event within a curated set of malicious sequence detection rules) is exhibited, or when several similar / identical events occur within a selected time period (e.g., the same email using the same link is received by multiple users on the system, or multiple failed login attempts are detected within a selected time period, etc.). Other events may include, but are not limited to, exploring a website, downloading a file, accessing a file, receiving an email, following a link, using a specified IP address, using outdated software, using software with known vulnerabilities, login attempts, operating system versions, etc.

[0045] In another embodiment, the rules platform engine 210 may allow users and / or entities to submit or delete new rules based on their access level. In response to receiving such instructions, the rules platform engine 210 may automatically deploy such updates. In other words, once deployed, the new curated set of malicious sequence detection rules is active / inactive and scanned / no longer scanned by the malicious detection engine 212.

[0046] Turning to Figure 2B, in one embodiment, system 200 or device may include processing circuitry 228, memory 206, communications circuitry 222, rules platform circuitry 224, and malicious intent detection circuitry 226, each of which will be described in more detail below. While the various components are illustrated in Figure 2B as connected only to processing circuitry 228, it should be understood that system 200 or device may further include a bus (not explicitly shown in Figure 2B) for passing information among any combination of the various components of system 200 or device. System 200 or device may further include programming or instructions configured to perform various operations described herein, such as those described above in connection with Figures 1 and 2A and below in connection with Figures 3 and 4.

[0047] Processing circuitry 228 (and / or coprocessors, or any other processors supporting or otherwise associated with processing circuitry 228) may communicate with memory 206 via a bus to pass information between components of system 200 or an apparatus. Processing circuitry 228 may be embodied in several different ways and, for example, may include one or more processing devices configured to perform independently. Furthermore, processing circuitry 228 may include one or more processors configured in conjunction via a bus to enable independent execution of software instructions, pipelining, and / or multithreading. Use of the term “processor” may be understood to include a single-core processor, a multi-core processor, multiple processors of system 200 or an apparatus, a remote or “cloud” processor, or any combination thereof.

[0048] Processing circuitry 228 may be configured to execute software instructions stored in memory 206 or otherwise accessible to processing circuitry 228. In some cases, processing circuitry 228 may be configured to execute hard-coded functionality. Thus, whether configured by hardware or software methods, or a combination of hardware and software, processing circuitry 228 represents an entity or device (e.g., an element that may be physically embodied in circuitry) that can be configured accordingly while performing operations in accordance with various embodiments of the present invention. Alternatively, as another example, when processing circuitry 228 is embodied as an executor of software instructions, the software instructions, when executed, may configure processing circuitry 228 to specifically perform the algorithms and / or operations described herein.

[0049] The memory 206 may be a non-transitory machine-readable storage medium, e.g., may include one or more volatile and / or non-volatile memories. In other words, for example, the memory 206 may be an electronic storage device (e.g., a computer-readable storage medium). The memory 206 may be configured to store information, data, content, applications, software instructions, or the like to enable the device to perform various functions in accordance with the exemplary embodiments contemplated herein.

[0050] The memory 206 may be a non-transitory machine-readable storage medium, e.g., may include one or more volatile and / or non-volatile memories. In other words, for example, the memory 206 may be an electronic storage device (e.g., a computer-readable storage medium). The memory 206 may be configured to store information, data, content, applications, software instructions, or the like to enable the device to perform various functions in accordance with the exemplary embodiments contemplated herein.

[0051] Communications circuitry 222 may include at least one device or circuitry, embodied either in hardware or a combination of hardware and software, configured to receive data from and / or transmit data to a network and / or any other device, circuitry, or module in communication with system 200 or an apparatus. In this regard, communications circuitry 222 may include a network interface, for example, to enable communication with a wired or wireless communications network. For example, communications circuitry 222 may include one or more network interface cards, antennas, buses, switches, routers, modems, and supporting hardware and / or software, or any other devices suitable for enabling communication over a network. Additionally, communications circuitry 222 may include processing circuitry for causing the transmission of such signals to the network or for processing the reception of signals received from the network.

[0052] The system 200 or device will generally include rules platform circuitry 224 configured to provide a set of user-readable instructions defined by or expressed in a domain-specific language. Accordingly, a user may submit new malicious threat activity or event sequence rules, or curated malicious sequence activity rules and instructions for monitoring against the system 200 or device (e.g., such submission occurs via utilization of the set of user-readable instructions). Additionally, the rules platform circuitry 224 may be configured to generate and / or update a rules repository. The rules repository may be populated with new identified security threats or malicious threat activity or event sequences, and / or curated sequence activity rules.

[0053] The rules platform circuitry 224 may also generate a user interface, a graphical user interface, or a web-based user interface. The user interface may be configured to allow a user (e.g., a security professional) to submit rules for a curated sequence of activities based on the user's access and / or permission level. In another embodiment, the rules for a curated sequence of activities may be submitted to the rules repository via other communication or interface methods (e.g., via a RESTless API, via direct entry into the rules repository, and / or via another communication interface or method facilitated by the rules platform circuitry 224).

[0054] The system 200 or device may include malicious detection circuitry 226 configured to monitor for malicious events and / or multiple weak signal events (e.g., a series of weak signal events that collectively indicate a malicious event). The malicious detection circuitry 226 may be configured to receive or obtain a curated sequence of activities (e.g., from either the rules platform circuitry 224 and / or the rules repository). Using the received or obtained curated sequence of events, the malicious detection circuitry 226 may monitor for corresponding events. Such monitoring may occur continuously, substantially continuously, or for a selected period or at selected intervals. In response to detecting a series of potentially malicious events, the malicious detection circuitry 226 may aggregate the events and then generate a threat score. The malicious detection circuitry 226 may then compare the threat score to a selected threshold score. If the threat score exceeds the selected threshold score, the malicious detection circuitry 226 may generate an alert. An alert may include data or instructions as specified by one or more users (eg, security experts).

[0055] FIG. 3 is a schematic diagram of a graphical user interface (GUI) 302 or web-based user interface for editing or updating and saving malicious sequence detection rules or rule sets according to one aspect of the present disclosure. The GUI 302, which may be associated with a security professional, may receive one or more malicious sequence detection rules or rule sets (e.g., from the system 200 or an apparatus described above). In addition to receiving one or more malicious sequence detection rules or rule sets, the GUI 302 may include an update view button 310. In response to selection of the update view button 310, the GUI 302 may display the current set of one or more malicious sequence detection rules or rule sets in the rule repository (e.g., see 308). The GUI 302 may include an export button 312. In response to selection of the export button 312, the GUI 302 may cause the currently displayed list of one or more malicious sequence detection rules or rule sets to be downloaded to a specified location (e.g., the security professional's computing device).

[0056] Further, in embodiments, GUI 302 may include an edit button 304 and a save button 306. In response to selecting edit button 304 and one of the displayed one or more of the malicious sequence detection rules or rule sets, GUI 302 may enable a security professional to update or edit the selected one of the one or more of the malicious sequence detection rules or rule sets. Alternatively, an edit function or drop-down menu may be accessed in response to selecting a displayed malicious sequence detection rule. In response to selecting save button 306, the edited one of the one or more of the malicious sequence detection rules or rule sets may be saved in a rule repository for use in detecting malicious sequence detection rules or rule sets.

[0057] In one embodiment, GUI 302 may include a syntax check button 314. Once a user edits, updates, and / or writes a rule, the user may select the syntax check button 314. In response to selecting the syntax check button 314, a system (e.g., system 200) may scan the edited, updated, or newly written rule and correct the rule based on the domain-specific language. In one embodiment, rather than the syntax check button 314, GUI 302 may include functionality to automatically check the syntax of the rule, update the rule, and / or provide the user with suggestions for correcting the rule. In another embodiment, GUI 302 may include dynamic simulation language completion based on the domain-specific language. In other words, as the user begins typing a word or phrase, GUI 302 may provide and / or suggest completed words and / or phrases.

[0058] In another embodiment, GUI 302 may be or include an XML editor, a JSON editor, or another editor configured to enable a user to edit, update, or write rules. In one example, a user may select a rule and edit button 304. In response to such a selection, GUI 302 may open the rule in a text, XML, JSON, or other format editor. GUI 302 may also include a visualization that illustrates correlated events. In such an embodiment, a user may select such events and create a new rule, or select several events and add them to an existing rule.

[0059] 4 is a method / process for detecting malicious events according to one aspect of the present disclosure. It should also be understood that any of the diagrams described herein may implement method 400 in FIGS. 1-3, among others. Method 400 may be included in one or more programs, protocols, or instructions loaded into the memory of a computing device. The order in which the operations are described is not intended to be limiting, and any number of the described blocks may be combined in any order and / or in parallel to implement the disclosed method.

[0060] In block 402, a system (e.g., system 200 of FIGS. 2A-2B) may generate malicious sequence detection rules. Such rules may initially include previously known event sequences that indicate malicious events or intent. The malicious sequence detection rules may be received from one or more sources, such as a user, an entity, a database, a separate repository, a public database, or a security threat repository (e.g., a threat repository may indicate certain events or conditions that indicate potential malicious sequences and / or include additional instructions), and / or via an internal database or repository specific to an organization or enterprise, among other sources. In another embodiment, as described, system 200 may generate malicious sequence detection rules and instructions based on a description of certain events or conditions (e.g., whitelists / blacklists and / or other threat-identifying data received from one or more sources). System 200 may utilize such descriptions to enrich and / or add further information to such rules and instructions.

[0061] In block 404, system 200 may generate a rule repository. The rule repository may be a database and / or a location in the system's memory for storing one or more malicious sequence detection rules and / or a curated set of malicious sequence detection rules. The rule repository may be structured as a database. The rule repository, in some embodiments, may be publicly accessible for reading from it. In another embodiment, the rule repository may not be directly accessible by any user. Rather, in such an embodiment, reading from and writing to the rule repository may be enabled and / or facilitated via a device or component of system 200.

[0062] In block 406, the system 200 may, in some embodiments, generate a user interface. The user interface may be generated for one or more users. The user interface may allow a user to enter or add a new curated set of malicious sequence detection rules. The user interface may also allow a user to enter instructions related to any of the malicious sequence detection rules. The instructions may include a message for the alert, a destination for the message for the alert, and / or other information that ensures that the appropriate data is received by the appropriate user. In another embodiment, access to the database may occur via an interface (e.g., an API, etc.) or a user interface (e.g., a graphical user interface, etc.).

[0063] As described, in block 408, the system 200 may determine whether a new curated set of malicious sequence detection rules has been received. In response to receiving a new curated malicious sequence detection rule or set of rules, the system 200 may add the new curated malicious sequence detection rule to the rule repository. In another embodiment, the new curated malicious sequence detection rule or set of rules may be added directly to the rule repository by a security expert. In block 410, the system 20 or an apparatus may monitor a network and / or computing devices. The network may include a public network, a private network, or some combination thereof. Monitoring the network may include monitoring network devices, including switches, access points, routers, network-attached storage devices, storage area networks, antenna systems, Bluetooth and / or WiFi transceivers / receivers, or other network devices.

[0064] In block 412, system 200 may determine whether malicious threat activity or event sequences indicative of a potential security threat have been discovered or detected. System 200 or an apparatus may scan multiple networks and / or computing devices. System 200 or an apparatus may scan such networks and / or computing devices via agents, software, algorithms, intrusion algorithms, monitoring algorithms, and / or some other set of instructions or algorithms configured to monitor one or more networks or computing devices.

[0065] In block 414, if a malicious sequence of activity (e.g., a series of events, activities, or occurrences indicated in a set or curated set of malicious sequence detection rules) has been detected, the system 200 or device may aggregate the detected malicious sequence of activity. In an embodiment, the detected malicious threat activity or event sequence may include several weak signal events. The detected malicious threat activity or event sequence may include events that may be harmless when considered separately. The detected malicious threat activity or event sequence or event may include events that correspond to or are defined in one or more of the rules originally added to the curated set of rules or rule repository.

[0066] In another embodiment, a rule may be selected for application or review by one or more security experts when a detected malicious threat activity or event sequence is discovered. In one embodiment, the system 200 or device may collect each detected event that corresponds to a rule in the malicious sequence of activity. The system 200 or device may then associate a number or other indicator with each event that corresponds to a rule in the malicious sequence of activity.

[0067] In an embodiment, malicious sequence activity or other events may be detected by one or more of an agent running on the user's computing device, a plug-in corresponding to the user's web browser, email application, and / or other application on the user's computing device, and / or another monitoring application associated with the network and / or computing device.

[0068] At block 416, the system 200 may generate a threat score. The system 200 or device may utilize the aggregated number of detected events or other indicators to generate such a score. In another embodiment, the detected events or information corresponding to the detected events may be passed through or applied to machine learning and / or probabilistic models to generate a threat score.

[0069] In block 418, the system 200 may determine whether the threat score exceeds a threshold score. If the threat score exceeds the threshold score, the system 200 or device may generate an alert in block 420. Instructions included with a rule for a particular malicious sequence of activity may specify where (location or person) to send the alert and / or information to include in such an alert.

[0070] As described, system 200 may transmit one or more of the malicious sequence detection rules or rule sets, for example, at block 422. System 200 may receive any updated malicious sequence detection rules or rule sets from a security expert at block 424 and may replace previous malicious sequence detection rules or rule sets in the rule repository based on those updates. In another embodiment, system 200 may update the malicious sequence detection rules or rule sets based on one or more factors, such as, but not limited to, other events occurring within a selected period of time of other events specified in the malicious sequence detection rule or rule set.

[0071] FIG. 5 is a schematic diagram of an information handling system capable of implementing each of the illustrative embodiments according to one aspect of the present disclosure. Information handling system 500 can represent the systems and methods of FIGS. 1-4. Information handling system 500 may include a computer system or processor 502, such as a central processing unit (CPU), a graphics processing unit (GPU), or both. Information handling system 500 may also include a main memory 504 and a static memory 507, which may communicate with each other via a bus 508. Information handling system 500 includes an antenna and a near-field communication (NFC) device and interface 518, such as an NFC subsystem. Information handling system 500 may also include a disk drive unit 516 and a network interface device 520. As shown, information handling system 500 may further include a video display unit 510, such as a liquid crystal display (LCD), organic light-emitting diode (OLED), flat panel display, solid-state display, or cathode ray tube (CRT), or other suitable display. Video display unit 510 may also serve as an input for receiving touchscreen input. Additionally, information handling system 500 may include input devices 512 such as a keyboard or cursor control device such as a mouse or touchpad, or a selectable interface on a display unit.

[0072] As described, system 200 may transmit one or more of the malicious sequence detection rules or rule sets, for example, at block 422. System 200 may receive any updated malicious sequence detection rules or rule sets from a security expert at block 424 and may replace previous malicious sequence detection rules or rule sets in the rule repository based on those updates. In another embodiment, system 200 may update the malicious sequence detection rules or rule sets based on one or more factors, such as, but not limited to, other events occurring within a selected period of time of other events specified in the malicious sequence detection rule or rule set.

[0073] FIG. 5 is a schematic diagram of an information handling system capable of implementing each of the illustrative embodiments according to one aspect of the present disclosure. Information handling system 500 can represent the systems and methods of FIGS. 1-4. Information handling system 500 may include a computer system or processor 502, such as a central processing unit (CPU), a graphics processing unit (GPU), or both. Information handling system 500 may also include a main memory 504 and a static memory 507, which may communicate with each other via a bus 508. Information handling system 500 includes an antenna and a near-field communication (NFC) device and interface 518, such as an NFC subsystem. Information handling system 500 may also include a disk drive unit 516 and a network interface device 520. As shown, information handling system 500 may further include a video display unit 510, such as a liquid crystal display (LCD), organic light-emitting diode (OLED), flat panel display, solid-state display, or cathode ray tube (CRT), or other suitable display. Video display unit 510 may also serve as an input for receiving touchscreen input. Additionally, information handling system 500 may include input devices 512, such as a keyboard, or cursor control device such as a mouse or touchpad, or a selectable interface on a display unit. Information handling system may also include a battery system 514. Information handling system 500 may represent a device capable of electrical communications and may share resources, voice communications, and data communications among multiple devices. Information handling system 500 may also represent a server device whose resources may be shared by multiple client devices, or it may represent an individual client device, such as a laptop or tablet personal computer.

[0074] The information handling system 500 may include a set of instructions that may be executed to cause a processor to perform any one or more of the methods or computer-based functions disclosed herein. The processor 502 may operate as a stand-alone device or may be connected to other computer systems or peripheral devices using a network, etc.

[0075] In a networked deployment, information handling system 500 may operate in a server capacity or as a client user computer in a server-client user network environment, or as a peer computer system in a peer-to-peer (or distributed) network environment. Information handling system 500 can also be implemented as or incorporated into a variety of devices, such as a personal computer (PC), tablet PC, set-top box (STB), smartphone, PDA, mobile device, palmtop computer, laptop computer, desktop computer, communication device, wireless telephone, landline telephone, control system, camera, scanning device, facsimile machine, printer, pager, personal trusted device, web appliance, network router, switch or bridge, or any other machine capable of executing (sequentially or otherwise) a set of instructions that define actions to be taken by the machine. In particular embodiments, computer system 500 can be implemented using electronic devices that provide voice, video, or data communications. Furthermore, although a single information handling system 500 is illustrated, the term "system" is also intended to include any collection of systems or subsystems that individually or collectively execute a set or sets of instructions to perform one or more computer functions.

[0076] The disk drive unit 516 or static memory 514 may include a computer-readable medium 522 on which one or more sets of instructions 524, such as software, may be embedded. The disk drive unit 516 or static memory 514 also includes space for data storage. Furthermore, the instructions 524 may embody one or more of the methods or logic as described herein. In particular embodiments, the instructions 524 may reside, completely or at least partially, within the main memory 504, the static memory 506, and / or the processor 502 during execution by the information handling system 500. The main memory 504 and the processor 502 may also include computer-readable media. The network interface device 520 may provide connectivity to a network 526, such as a wide area network (WAN), a local area network (LAN), a wireless network (IEEE 802), or other network. The network interface device 520 may also interface with a macrocellular network, including wireless telecommunications networks such as those characterized as 2G, 3G, 4G, 5G, LTE, or similar wireless telecommunications networks similar to those described above. The network interface 520 may be a wireless adapter having an antenna system 532 for various wireless connectivity and a radio frequency subsystem 530 for signal reception, transmission, or related processing.

[0077] In alternative embodiments, dedicated hardware implementations such as application-specific integrated circuits, programmable logic arrays, and other hardware devices can be constructed to implement one or more of the methods described herein. Applications that may include the apparatus and systems of various embodiments can broadly include various electronic and computer systems. One or more embodiments described herein may implement functionality using two or more specific interconnected hardware modules or devices with associated control and data signals that may be communicated between and through the modules, or as part of an application-specific integrated circuit. Thus, the system encompasses software, firmware, and hardware implementations. According to various embodiments of the present disclosure, the methods described herein may be implemented by a software program executable by a computer system. Furthermore, in exemplary, non-limiting embodiments, implementations can include distributed processing, component / object distributed processing, and parallel processing. Alternatively, a virtual computer system process can be constructed to implement one or more of the methods or functionality as described herein.

[0078] This disclosure contemplates computer-readable media containing instructions 524 or receiving and executing instructions 524 in response to propagated signals such that devices connected to network 528 may communicate audio, video, or data over network 528. Additionally, instructions 524 may be transmitted or received over network 528 via network interface device 520. In particular embodiments, BIOS / FW code 524 resides in memory 504 and includes machine-executable code that is executed by processor 502 to implement various functions of information handling system 500.

[0079] Information handling system 500 includes one or more application programs 524 and basic input / output system and firmware (BIOS / FW) code 524. BIOS / FW code 524 functions to initialize information handling system 500 upon power-on, to launch the operating system, and to manage input / output interaction between the operating system and other elements of information handling system 500.

[0080] In another embodiment (not shown), the application program and BIOS / FW code reside in another storage medium of information handling system 500. For example, the application program and BIOS / FW code may reside in drive 516, in a ROM (not shown) associated with information handling system 500, in option ROM (not shown) associated with various devices of information handling system 500, in storage system 507, in a storage system (not shown) associated with network channel 520, in another storage medium of information handling system 500, or a combination thereof. Application program 524 and BIOS / FW code 524 may each be implemented as a single program or as separate programs that perform various features as described herein.

[0081] Although the computer-readable medium is shown to be a single medium, the term "computer-readable medium" includes a single medium or multiple media, such as a centralized or distributed database and / or associated caches and servers that store one or more sets of instructions. The term "computer-readable medium" is also intended to include any medium capable of storing, encoding, or carrying a set of instructions for execution by a processor, or causing a computer system to perform any one or more of the methods or operations disclosed herein.

[0082] In certain non-limiting exemplary embodiments, the computer-readable medium may include solid-state memory, such as a memory card or other package that stores one or more non-volatile read-only memories. Furthermore, the computer-readable medium may be random access memory or other volatile rewritable memory. Additionally, the computer-readable medium may include magneto-optical or optical media, such as disks or tapes or other storage devices for storing information received via carrier signals, such as signals communicated via transmission media. Furthermore, the computer-readable medium may store information received from distributed network resources, such as from a cloud-based environment. A digital file attachment to an email or other self-contained information archive or set of archives may be considered a distribution medium equivalent to a tangible storage medium. Thus, the present disclosure is considered to include any one or more of computer-readable or distribution media and other equivalent and successor media on which data or instructions may be stored.

[0083] In embodiments described herein, an information handling system includes any means or collection of means operable to calculate, classify, process, transmit, receive, retrieve, emit, switch, store, display, reveal, detect, record, reproduce, handle, or use any form of information, sensitive information, or data for business, scientific, control, entertainment, or other purposes. For example, an information handling system may be a personal computer, a consumer electronic device, a network server or storage device, a switch router, a wireless router, or other network communication device, a network-connected device (such as a mobile phone, tablet device, etc.), or any other suitable device, and may vary in size, shape, performance, price, and functionality.

[0084] An information handling system may include one or more processing resources, such as memory (volatile (such as random access memory), non-volatile (such as read-only memory, flash memory), or any combination thereof), a central processing unit (CPU), a graphics processing unit (GPU), hardware or software control logic, or any combination thereof. Additional components of an information handling system may include one or more storage devices, one or more communication ports for communicating with external devices, and various input / output (I / O) devices, such as a keyboard, a mouse, a video / graphics display, or any combination thereof. An information handling system may also include one or more buses operable to carry communications between the various hardware components. A portion of an information handling system may itself be considered an information handling system.

[0085] When referred to as a "device," "module," or the like, embodiments described herein may be configured as hardware. For example, part of an information handling system device may be hardware such as an integrated circuit (such as an application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), structured ASIC, or device embedded on a larger chip), a card (such as a Peripheral Component Interface (PCI) card, PCI Express card, Personal Computer Memory Card International Association (PCMCIA) card, or other such expansion card), or a system (such as a motherboard, system-on-chip (SoC), or standalone device).

[0086] This device or module is a Pentium class or PowerPC TMThe information handling system may include software, including firmware, embedded in a device such as a brand processor or other such device, or software capable of operating the relevant environment of the information handling system. The device or module may also include a combination of the foregoing embodiments of hardware or software. It is noted that the information handling system may include a board-level product having an integrated circuit or portion thereof, which may also be any combination of hardware and software.

[0087] Devices, modules, resources, or programs that communicate with each other need not be in continuous communication with each other unless explicitly specified otherwise. In addition, devices, modules, resources, or programs that communicate with each other may communicate directly or indirectly through one or more intermediaries.

[0088] The terms "computing device" or "system device" are used herein to refer to any one or all of programmable logic controllers (PLCs), programmable automation controllers (PACs), industrial computers, desktop computers, personal digital assistants (PDAs), laptop computers, tablet computers, smartbooks, palmtop computers, personal computers, smartphones, wearable devices (such as headsets, smartwatches, or the like), and similar electronic devices that necessarily include at least a processor and any other physical components to perform the various operations described herein. Devices such as smartphones, laptop computers, tablet computers, and wearable devices are generally collectively referred to as mobile devices.

[0089] The terms “server” or “server device” are used herein to refer to any computing device capable of functioning as a server, such as a master exchange server, web server, mail server, document server, or any other type of server. A server may be a dedicated computing device or a server module (e.g., an application) hosted by a computing device that causes the computing device to operate as a server. A server module (e.g., a server application) may be a full-featured server module or a lite or secondary server module (e.g., a lite or secondary server application) configured to provide synchronization services between dynamic databases on the computing device. A lite or secondary server may be a slimmed-down version of server-type functionality implemented on a computing device such as a smartphone, thereby enabling it to function as an Internet server (e.g., a corporate email server) only insofar as necessary to provide the functionality described herein.

[0090] The term "non-transitory machine-readable storage medium" is used herein to refer to any electronic, magnetic, optical, or other physical storage device for containing or storing information such as executable instructions, data, and the like. For example, any machine-readable storage medium described herein may be any of random access memory (RAM), volatile memory, non-volatile memory, flash memory, a storage drive (e.g., a hard drive), a solid-state drive, any type of storage disk, and the like, or a combination thereof. The memory may store or include instructions executable by a processor.

[0091] The terms "processor" or "processing circuitry" are used herein to refer to any processor or processors contained within a single device or distributed across multiple computing devices. A processor may be at least one of a central processing unit (CPU), a semiconductor-based microprocessor, a graphics processing unit (GPU), a field programmable gate array (FPGA) for reading and executing instructions, a real-time processor (RTP), other electronic circuitry suitable for reading and executing instructions stored on a machine-readable storage medium, or a combination thereof.

[0092] The foregoing description generally illustrates and describes various embodiments of the present disclosure. However, it will be understood by those skilled in the art that various changes and modifications may be made to the above-discussed structures of the present disclosure without departing from the spirit and scope of the disclosure as disclosed herein, and that all matter contained in the above description or shown in the accompanying drawings is intended to be interpreted as illustrative and not limiting. Furthermore, the scope of the present disclosure shall be interpreted to cover various modifications, combinations, additions, alterations, etc. to the above and above-described embodiments, which shall be considered to be within the scope of the present disclosure. Thus, the various features and characteristics of the present disclosure as discussed herein may be selectively substituted and applied to other illustrated and non-illustrated embodiments of the present disclosure, and numerous variations, modifications, and additions may further be made to the various features and characteristics of the present disclosure as discussed herein without departing from the spirit and scope of the invention as set forth in the appended claims.

Claims

1. 1. A system for detecting security threats, comprising: Memory and at least one processor; Equipped with The at least one processor 1. A rules platform engine, comprising: providing one or more users with a set of user-readable instructions defined in a domain-specific language to generate a set of malicious sequence detection rules, wherein the malicious sequence detection rules are defined by one or more malicious sequence activity-based rules and interactions provided by each of the one or more users; receiving one or more curated sets of malicious sequence detection rules and instructions in the defined domain-specific language from one or more of the one or more users; generating a rule repository stored in the memory, the rule repository including one or more existing malicious sequence detection rules and configured to receive and store the one or more curated sets of malicious sequence detection rules received from the one or more users; a rules platform engine configured to: A malicious sequence detection engine, comprising: receiving one or more curated sets of malicious sequence detection rules from the one or more users; monitoring incoming security data and detecting one or more malicious threat activities or events indicative of at least one security threat based on the one or more curated sets of malicious sequence detection rules; aggregating multiple malicious threat activities or events detected as occurring within a predetermined time period to generate at least one malicious threat activity or event sequence; generating a threat score for the at least one malicious threat activity or event sequence based on an aggregation of the plurality of malicious activities; generating an alert if the threat score of the aggregated at least one malicious threat activity or event sequence exceeds a threshold score; a malicious sequence detection engine configured to A system comprising:

2. The system of claim 1 , wherein the rule repository comprises persistent and secure storage.

3. The system of claim 1 , wherein the content of the alert includes contextual information related to at least one detected malicious threat activity or event sequence.

4. The system of claim 1 , wherein the one or more users include one or more of a developer, a development operator, a security expert, or a combination thereof.

5. The system of claim 1 , wherein one or more of one or more networks, one or more computing devices, or a combination thereof are monitored for occurrences of malicious threat activity or events.

6. 1. A method for detecting malicious sequence activity, the method comprising: generating one or more malicious sequence detection rules defined in a domain-specific language based on interactions provided by each of the one or more users; generating a rule repository, the rule repository configured to receive and store one or more predefined rules and to receive one or more curated sets of malicious sequence detection rules; receiving one or more curated sets of malicious sequence detection rules based on interactions from one or more users and storing the curated sets of rules in the rule repository; monitoring one or more networks, one or more computing devices, or a combination thereof to detect malicious threat activity or events indicative of at least one potential security threat based on one or more curated sets of malicious sequence detection rules; aggregating multiple detected malicious threat activities or events within a predetermined time frame to form one or more malicious threat activity or event sequences; generating a threat score for the one or more malicious threat activities or event sequences based on the aggregated detected malicious threat activities or events; generating an alert based on one of the one or more curated sets of rules if the threat score of the one or more malicious threat activities or event sequences exceeds a threshold score; A method comprising:

7. The method of claim 6 , further comprising storing the one or more curated sets of rules in the rule repository.

8. The method of claim 6 , wherein the malicious threat activity or event sequence comprises an aggregated number of weak signal events occurring within a selected time period.

9. The method of claim 6 , wherein the content of the alert includes contextual information related to the detected malicious sequence activity.

10. 7. The method of claim 6, further comprising receiving, from one of the one or more users, content for the alert corresponding to one of the one or more curated sets of rules.

11. 10. The method of claim 6, further comprising determining whether the detected malicious threat activity or event is subject to one or more curated sets of malicious sequence detection rules prior to aggregating the detected malicious threat activity or event, and, if so, applying at least one applicable malicious sequence rule and initiating remedial action.

12. 13. The method of claim 12, wherein the content of the alert corresponding to one of the one or more curated sets of rules is editable by a user who submitted the corresponding one of the one or more curated sets of rules.

Citation Information

Patent Citations

  • Method and apparatus for Security Event Correlation Analysis based on Context Language

    KR1020080047826A

  • Method for predicting and characterizing cyber attacks

    US20180004948A1

  • Stateful rule generation for behavior based threat detection

    US20200389472A1

  • Information processing device, information processing system, information processing method, and storage medium

    WO2016208159A1