Apparatus, system, and method for autonomous threat response and security enhancement
The MSSP server system addresses SIEM inefficiencies by autonomously classifying IoCs and deploying automated responses, enhancing security across multiple tenant networks with reliable threat management and cost reduction.
Patent Information
- Application Number
- JP2025504309
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-07-27
- Filing Date
- 2023-07-26
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2043-07-26
AI Technical Summary
Current SIEM tools face challenges in efficiently managing threats across multiple tenant networks due to inconsistent and unreliable data sources, difficulty in classifying IoCs, and lack of automated response mechanisms, leading to inefficiencies and increased costs for MSSPs and clients.
A system and method for autonomously enhancing security using a MSSP server that queries data sources, generates IoC threat scores, and deploys automated responses, including threat classification and customizable security enhancements, to manage threats across multiple tenant networks.
The system provides reliable, scalable, and efficient threat management by classifying IoCs, automating responses, and reducing operational costs through a unified, automated 'as-a-service' approach, enabling consistent and repeated cloud-based SIEM implementations.
Smart Images

Figure 0007714829000001 
Figure 0007714829000002 
Figure 0007714829000003
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims the benefit and priority of U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT", the disclosure of which is hereby incorporated by reference in its entirety.
[0002] The present technology relates to systems and methods for autonomous detection and automatic management of threats in a managed security service provider environment. In particular, but not limited to, the present technology provides systems and methods for autonomous threat response and security enhancement.
Summary of the Invention
[0003] The following summary is provided to facilitate an understanding of some of the innovative features specific to the aspects disclosed herein and is not intended as a complete description. A complete understanding of the various aspects can be obtained by taking the entire specification, claims, and abstract.
[0004] In various aspects, a method for autonomously enhancing the security of a tenant network via a managed security service provider (MSSP) server comprising a processor and memory is provided. The method includes, via the processor, database or server, querying, upon encountering an indicator of compromise (IoC) by a security system, with reference to the encountered IoC, to identify a related source or feed; generating or calculating, via the processor, an IoC threat score for the encountered IoC based on the output of the query; generating, via the processor, at least one actionable security enhancement notification based on a single threat score of the encountered IoC; and displaying, via a user interface, the IoC threat score and the actionable security enhancement notification of the encountered IoC to a user of the security system. The user may trigger or invalidate one or more actions in at least one actionable security enhancement notification.
[0005] In various aspects, generating an IoC threat score includes, for each related source or feed, identifying a threat value of the encountered IoC classified by the related source or feed; for each related source or feed, adding a multiplier to the threat value of the source or feed to generate an adjusted threat value, wherein the multiplier is determined based on a reliability score associated with the source or feed; normalizing all of the adjusted threat values of the related sources or feeds; and generating a single threat score for the encountered IoC.
[0006] A method for autonomously enhancing the security of a tenant network may include deploying an automated security response that includes one or more of automatically adjusting a security threat threshold level, automatically reconfiguring a database to identify other potential malware variants, sending notifications to a plurality of other users of the security system, determining that other tenant networks are exposed to an IoC and the risk of future exposure, and isolating one or more tenant networks or portions of a network.
[0007] In some aspects, the method considered may also include classifying an encountered IoC as malicious, unknown, or benign based on at least one of a generated IoC threat score, a generated reliability score, and a security threat threshold level, and a user interface may display the classification to a user of the security system.
[0008] These and other objects, features, and characteristics of the present invention, as well as the methods of operation, functions of the related structural elements, combinations of parts, and economies of manufacture, will become more apparent upon consideration of the following description, the appended claims, and the accompanying drawings, which form a part of this specification, and wherein like reference numerals refer to corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the present invention.
Brief Description of the Drawings
[0009] The various features of the aspects described herein are set forth in detail in the appended claims. However, various aspects regarding both the organization and method of operation, as well as the advantages thereof, can be understood from the following description in conjunction with the accompanying drawings as follows.
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
[0011] Corresponding reference numerals indicate corresponding parts throughout the several views. The embodiments described herein illustrate various aspects of the present invention in one form, and such embodiments should not be construed as limiting the scope of the present invention in any way.
BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The applicant of the present application owns the following US provisional patent applications, the disclosures of each of which are incorporated herein by reference in their entirety. - International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS - International Patent Application No. PCT / US2022 / 072743, filed on June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS - International Patent Application No. PCT / US2022 / 082167, filed on December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS - International Patent Application No. PCT / US2022 / 082173, filed on December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS - International Patent Application No. PCT / US2023 / 061069, filed on January 23, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION’S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE - International Patent Application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS - International Patent Application No. PCT / US2023 / 021736, filed on May 10, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS - International Patent Application No. PCT / US2023 / 022858, filed on May 19, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS - International Patent Application No. PCT / US2023 / 022535, filed on May 17, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM - International Patent Application No. PCT / US2023 / 024386, filed on June 4, 2023, entitled DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX - International Patent Application No. PCT / US2023 / 068590, filed on June 16, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS - U.S. Provisional Patent Application No. 63 / 368,567, filed on July 17, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY - U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT - U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES - U.S. Provisional Patent Application No. 63 / 507,250, filed on June 9, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR ATTRIBUTING NETWORK-IMPLEMENTED CYBER ASSETS TO OPERATING ENTITIES AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON THE ATTRIBUTION.
[0013] Numerous specific details are described in this disclosure and are set forth in order to provide a complete understanding of the overall structure, function, manufacture, and use of the aspects illustrated in the accompanying drawings. Well-known operations, components, and elements are not described in detail so as not to obscure the aspects described herein. The reader will understand that the aspects described and illustrated herein are non-limiting aspects. Accordingly, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary and that variations and modifications can be made without departing from the scope of the claims. Further, it should be understood that such terms as "front," "rear," "left," "right," "above," "below," and similar terms are terms of convenience and are not to be construed as limiting terms.
[0014] In the following description, like reference numerals denote like or corresponding parts throughout several views of the drawings. Also, in the following description, it should be understood that such terms as "front," "rear," "left," "right," "above," "below," etc. are terms of convenience and are not to be construed as limiting terms.
[0015] Before detailing the various aspects and methods of the systems disclosed herein, it should be noted that the exemplary aspects are not limited to the application or use in the details disclosed in the accompanying drawings and description. Naturally, the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications and may be practiced or carried out in various ways. Further, unless otherwise indicated, the terms and expressions used herein are selected for the purpose of describing the exemplary aspects for the convenience of the reader and are not intended for limitation. For example, any reference herein to a particular manufacturer, software suite, application, or development platform is understood to merely intend to illustrate some of the many aspects of the present disclosure. This includes any reference to trademarks. Accordingly, it should be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any purpose of use and / or user preference.
[0016] As used herein, the term "server" can refer to or include one or more computing devices that are operated or facilitated by communication and processing for multiple parties in a network environment such as the Internet or any public or private network. As used herein, a reference to a "server" or "processor" can refer to a previously enumerated server and / or processor that executes a previous step or function, a different server, and / or processor, and / or a combination of servers, and / or a combination of processors as enumerated.
[0017] As used herein, the term "platform" shall include an ecosystem of physical resources necessary to enable software and / or the technical benefits provided by software. For example, a platform can include either a stand-alone software product or a software product configured to integrate with other software or physical resources within the ecosystem in which the software provides its technical benefits. According to some non-limiting aspects, the technical benefits provided by software are provided to either the physical resources of the ecosystem or other software employed by the physical resources within the ecosystem (e.g., APIs, services, etc.). According to other non-limiting aspects, a platform can include a framework for several software applications that are intended and designed to function together.
[0018] SIEM and MSSP As used herein, the term "network" encompasses the entire enterprise information technology ("IT") system, and the tenant "network" applies this term to the clients of the MSSP that provides SIEM services. For example, a network can include a group of two or more nodes (e.g., devices) that are connected by any physical and / or wireless connection and configured to communicate and share information with one or more other nodes. However, the term "network" is not limited to any specific node or any specific means of connecting those nodes. A network can be connected to Ethernet, intranet, and / or extranet, and can be configured to communicate with each other via ad hoc connections (e.g., Bluetooth®, Near Field Communication (NFC), etc.), local area connections ("LAN"), wireless local area networks ("WLAN"), and / or virtual private networks ("VPN") regardless of the physical location of each device. The network can include any combination of devices (e.g., servers, databases, local or cloud storage, desktop computers, laptop computers, personal digital assistants, mobile phones, wearables, smart home appliances, etc.). The network can further include any tools, applications, and / or services that are deployed by the devices or otherwise utilized by enterprise IT systems such as firewalls, email clients, document management systems, office systems, etc. In some non-limiting aspects, "network" can include third-party devices, applications, and / or services that are owned and controlled by a third party but the tenant is approved to access the enterprise IT system.
[0019] Security Information and Event Management (SIEM) includes software configured to aggregate and analyze activities from many different resources across an information technology (IT) infrastructure. For example, SIEM can be used by a SIEM service provider, also known as a managed security service provider (MSSP), to aggregate data (e.g., log data, event data, threat intelligence data, etc.) from multiple systems and analyze that data to capture abnormal behavior or potential cyberattacks. For example, SIEM can collect security data from network devices, servers, domain controllers, etc. SIEM can be run to apply storage, normalization, aggregation, and analysis to that data to detect trends, detect threats, and enable an organization to investigate any alerts.
[0020] Examples of commonly implemented SIEMs include Azure Sentinel and Splunk Cloud, Devo, LogRhythm, IBM’s QRadar, Securonix, McAfee Enterprise Security Manager, LogPoint, Elastic Stack, ArcSight Enterprise Security Manager, InsightIDR, etc. Introducing Azure Sentinel as a cloud-based tool is widely accepted among Managed Security Service Providers (MSSPs), and thus, Azure Sentinel is described as a non-limiting example. However, of course, other SIEMs are contemplated by this disclosure. Similar to most SIEMs, introducing Azure Sentinel requires advanced skills and is a time-consuming task that is prone to errors. Each organization that requires a security solution has specific needs regarding monitoring such as ingestion log sources, detection / alert rules, automation of responses, reports, and alerts. Microsoft (MSFT) is often used by MSSPs to manage multiple clients, but the complexity of the initial configuration, introduction, and ongoing maintenance of artifacts (e.g., resource groups, log analytics workspaces, alert rules, workbooks, playbooks, etc.) has increased significantly. This can result in high costs for both MSSPs, which must employ more expensive specialists, and clients, which often bear at least a portion of the increasing costs. However, in many cases, there is overlap among the introduction needs of various clients. For example, many organizations may require similar firewall monitoring solutions. In such cases, asset reuse and reintroduction (and updates) can potentially lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are technically unable to utilize such synergistic effects.Therefore, from initial provisioning, data collection, analysis, and classification, to threat detection and incident response automation, MSSPs have limited opportunities for reuse to capture efficiency across multiple clients. Therefore, improved devices, systems, and implementation methods, as well as the issuance of SIEM client updates are needed. Such enhancements can improve the technical performance and cost efficiency of SIEM, including the introduction of detection rules, visualization, investigation workbooks, and ongoing maintenance.
[0021] Therefore, there is a need for devices, systems, and methods that employ an automated "as-a-service" approach to generate and introduce reusable, pre-packaged solutions that can be executed in a single step while providing a complete end-to-end SIEM solution. Such devices, systems, and methods can introduce the implementation of Sentinel with just a single click of a button with minimal understanding of SIEM (e.g., Sentinel, Azure, etc.). Therefore, such devices, systems, and methods can be used to consistently and repeatedly expand cloud-based SIEM implementations. The user only needs to provide the location where the entire introduction will take place and / or the login authentication information for each client.
[0022] Indicators of Compromise (IoC) Known SIEM tools provide excellent features including event monitoring, data collection, and issuance of security alerts across the network. However, the quality of the data collected and relied upon to perform these functions is inconsistent and often unreliable. All MSSPs or users of SIEM services or software can access and utilize various sources of information and data (referred to herein as "sources" or "data sources") that can be used as indicators of files or activities that may be malicious to clients, secure databases, and the network providing security services. These forms of data may contain some inconsistencies between different sources, including contradictions regarding the nature of the threat, as well as false reporting, underreporting, or unreported information.
[0023] Furthermore, since there are numerous data sources utilized by MSSPs that are intended to indicate threats and threat indicators (threat indicators are collectively referred to herein as "indicators of compromise" or "IoCs"), it is difficult for security providers, analysts, or MSSPs to respond to and manage threats to the client network or database in real time. Current SIEM software and systems can acquire and receive raw data from multiple data sources, but they cannot classify the reliability of the data and / or data sources, prioritize which sources or IoCs should be addressed and in what order, or detect or identify new and non-conflicting threats within the data, which means that a large amount of data adds a layer of complexity to the SIEM system without sufficiently improving its effectiveness in managing threats on the tenant network.
[0024] The threat indicators to be examined may include various known indicators in the art, as well as indicators that have not been discovered or newly discovered. Some examples of IoCs include evidence of data breaches, multiple logins, irregular DNS requests, abnormal receive / send traffic, geographical irregularities related to receive requests or traffic, unknown applications in execution, multiple requests for the same file, and the like. The methods and systems described herein may also be applied to indicators of attacks and are not limited to IoCs only.
[0025] Concerns regarding the reliability of the large amounts of data and sources available to SIEM software or MSSPs arise, in part, from the large amount of IoC data, while this data may be automatically generated, reported by users, or not adequately vetted, which can cause both false positives (where benign indicators are flagged as malicious) and can cause useful processes to be hindered, and false negatives (where malicious indicators are not marked as such) can potentially allow malware to operate without being disrupted. Additionally, it is difficult to detect new variants or forms of malware in IoCs. The most well-established SIEM methods aim to simplify the security management process by reducing the number of data sources and IoC data processed by software, providers, and / or security analysts due to the lack of ability to properly rank IoCs and programmatically consider the reliability of various threat information sources. This can mean that effective or valid data sources can be advantageously discarded for routine or more familiar sources, reducing the potential effectiveness and flexibility of SIEM services or MSSPs to respond to new threats and receive new forms of information.
[0026] Therefore, there is a need for devices, systems, and methods that can be deployed at scale across thousands of devices, provide reliable data from reliable data sources that can classify and present data and automate responses, while adopting an automated "as-a-service" approach to generate and introduce reusable pre-packaged solutions that can be run in a single step and provide a complete end-to-end SIEM solution. Such devices, systems, and methods can be introduced, for example, through the implementation of Sentinel, with only a minimal understanding of SIEM (e.g., Sentinel, Azure, etc.) and by clicking a button once. Thus, such devices, systems, and methods can be used to consistently and repeatedly expand cloud-based SIEM implementations.
[0027] The present disclosure contemplates such devices, systems, and methods, all of which provide more technical benefits than conventional MSSP and SIEM platforms and contemplate the handling of IoC data and related sources and feeds (hereinafter also referred to as data sources and data feeds, respectively). A data feed can include a mechanism by which a user receives updated data from a data source. This is commonly used by point-to-point settings as well as real-time applications on the World Wide Web and can include, by way of example, web feeds or RSS feeds. A data source can refer to a place, such as a database or a server, from which data results from the data source containing the data of the data feed.
[0028] The present disclosure presents such devices, systems, and methods, all of which provide numerous technical benefits and enable MSSPs to introduce cloud-based SIEM implementations, such as the implementation of Azure Sentinel, on a large scale, repeatedly, and consistently. For example, the devices, systems, and methods disclosed herein can be used in effectively managing threats in real time while resolving discrepancies between data and data sources and generating information that can utilize a large number of IoC data, thereby providing an effective way to ensure the reliability of the data used. The presented techniques provide automated methods and systems for aggregating, classifying, scoring data sources, detecting and identifying new threats, and responding to IoCs in a SIEM environment.
[0029] In some embodiments of the disclosed technology, a SIEM autonomous security system or an MSSP server (hereinafter collectively referred to as the "security system") searches for IoCs within a tenant network, encounters them, and determines whether the IoCs pose a tangible threat or whether they are benign. The disclosed security systems and methods can collect information regarding IoCs from data sources or feeds and assign each source or provide a reliability score. These sources or feeds can be periodically collected, updated, aggregated, and indexed in a security system's documents, databases, servers, nodes, or networks (which, even if not described in multiple forms, can be collectively referred to as a "SIEM autonomous security system database" or a "security system database" which can represent one or more databases). These steps can occur once or be repeated over time to improve and update the data and reliability scores associated with the sources and feeds based on performance over time. Thus, the security system database includes information from various sources and feeds, as well as the assignment, pre - setting, or calculated reliability scores of these sources or feeds, and past performance scores, and each source or feed can include information or data regarding various indicators of compromise. Each time the security system encounters an IoC within the tenant network, the security system database can be queried by the security system, whereby the security system can calculate an IoC threat score, classify the IoC as a malicious or benign threat, and then, if necessary, take additional and autonomous measures, which can include sending alerts, notifications, recommendations, or initiating an autonomous security response.
[0030] Figure Referring now to FIG. 1, a block diagram of a system 1000 configured to remotely manage security orchestration, automation, and response (SOAR) of another organization is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 1, the system 1000 may include a SOAR management server 1002 comprising a memory 1006 configured to store a SOAR application (see FIG. 2) and a processor 1004 configured to execute the stored SOAR application (see FIG. 2), as further discussed with reference to FIG. 2. For example, the SOAR management server 1002 may be computing resources owned or leased by a managed security service provider (“MSSP”). The SOAR management server 1002 is communicatively coupled via a network 1008 to a plurality of tenants 1010 a , 1010 b , … 1010 n . Each of the plurality of tenants 10101, 10102, … 1010 n may represent a customer (e.g., an organization) contracted with the MSSP. According to a non-limiting aspect of FIG. 1, the network 1008 may include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, the network 1008 may include, among other things, an internal network, a local area network (LAN), Wi-Fi®, a cellular network, near field communication (hereinafter, NFC), and the like.
[0031] Referring still to FIG. 1, each of the plurality of tenants 10101, 10102, … 1010 n may host one or more instances of one or more clients 1012, 1014, 1016. For example, the first tenant 10101 may include one or more machines executing one or more client applications 10121, 10122, … 1012 n , and the second tenant 10102 may include one or more machines executing one or more client applications 10141, 10142, … 1014 nmay include one or more machines that execute it, and / or a third tenant 1010n may include one or more client applications 10161, 10162, … 1016 n may include one or more machines that execute it. Each tenant 10101, 10102, and 1010 n can include an intranet by each machine that executes a client application. For example, each tenant 10101, 10102, and 1010 n can each represent a customer such as an organization that has contracted with an MSSP for security services.
[0032] Accordingly, the SOAR management server 1002 can be configured to have monitoring of a plurality of each tenant 10101, 10102, and 1010 n and thus is responsible for monitoring and managing each client application 1012, 1014, 1016 against threats. As described above, the differences and complexities in the tenant 10101, 10102, and 1010 n architecture can complicate this and make it inefficient for the MSSP. Accordingly, known SOAR tools can leave the tenant 10101, 10102, and 1010 n technologically exposed to attacks and thus vulnerable. According to non-limiting aspects of the present disclosure, the SOAR management server 1002 can execute a SOAR management application (see FIG. 2) that addresses these deficiencies technically and practically by enhancing the management capabilities of the SOAR management server 1002 for a plurality of tenants, and the alert sending capabilities, and the client application update capabilities, based on correlated and synergistic development needs. Further, the architecture 2000 of FIG. 2 further shows different means of communication among various modules, tenants, and the SOAR management server 1002.
[0033] Referring now to FIG. 2, a block diagram of the functional architecture 2000 of the system 1000 of FIG. 1 is shown in accordance with at least one non-limiting aspect of the present disclosure. According to a non-limiting aspect of FIG. 2, the architecture 2000 may include a content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, which are collectively provided via an application stored in the memory 1006 (FIG. 1) of the SOAR management server 1002. According to some non-limiting aspects, the SOAR management server 1002 may be remotely located with respect to the MSSP and / or tenant 1010 n For example, the SOAR management server 1002 may be cloud-based. When executed by the processor 1004 (FIG. 1), the application's content library 2002, variable store 2004, automation scheme 2008, and service operation engine 2012 can collectively and easily enable the simultaneous configuration, management, and / or control of multiple SOAR platforms 2018 for multiple tenants 1010n, or client organizations, on a large scale. Further, when executed by the processor 1004 (FIG. 1), the application can support the SOAR platform 2018 of the client organization, either abstractly or dynamically, as described in more detail herein.
[0034] According to some non-limiting aspects, the application introduced by the SOAR management server 1002 may be configured as an Azure Sentinel Automation Portal (ASAP), as disclosed in U.S. Provisional Patent Application No. 63 / 196,458 and PCT Application PCT / US22 / 72739, both entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021 and June 3, 2022, respectively, the disclosure of which is hereby incorporated by reference in its entirety. For example, according to one non-limiting aspect, the ASAP portal runtime software code may include server middleware that is involved in processing content from the content library 2002, connections to the SOAR platform 2018, and / or other services, as well as service requests for the SOAR management server 1002 to deploy, update, and / or read. In other words, the application introduced by the SOAR management server 1002, including the content library 2002, the variable store 2004, and the automation scheme 2008, can work with one or more tenants 10101-n simultaneously, along with the ability to provide a unified, simplified view of the introduction for all tenants 1010 1-n (FIG. 1) can provide a unified, simplified view of the introduction.
[0035] The content library 2002 is where the SOAR management server 1002 can manage content for one or more tenants 1010 nconfigured to store various artifacts (e.g., detections, automations, workbooks, alert rules, playbooks, etc.) that can configure and manage the SOAR platform. According to some non-limiting aspects, the content library 2002 of FIG. 2 can be stored locally for an application, which means it is provided via the memory 1006 (FIG. 1) of the SOAR management server 1002. However, according to other non-limiting aspects, the content library 2002 can be stored on a remote server communicatively coupled to the SOAR management server 1002. In yet other non-limiting aspects, the content library 2002 is similar to that disclosed in U.S. Provisional Patent Application No. 63 / 196,458 and PCT International Application No. PCT / US22 / 72739, both entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", the disclosures of both of which are incorporated herein by reference in their entirety. In summary, the content library 2002, and more specifically, the artifacts stored within the content library 2002, enable the SOAR management server 1002 to remotely interface and / or manage the SOAR platform 2018 for the tenant 1010 n or client organization. For example, the content library 2002 can store one or more rules and / or templates configured to automate the deactivation of a user account if it is determined that a risk score determined based on all detected variables of the tenant architecture 1010 exceeds a predetermined threshold, where the SOAR management server 1002 and / or the SOAR platform 2018 make such a determination. n
[0036] According to a non-limiting aspect of FIG. 2, a specific client organization, and / or tenant 1010 n Requirements of tenant 1010, such as variable points specific to the architecture n can be provided to the artifacts stored in the content library 2002. The content library 2002 can achieve this according to introducible artifact templates, such as those disclosed in U.S. Provisional Patent Application No. 63 / 196,458 and PCT International Application No. PCT / US22 / 72739, titled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", filed on June 3, 2021 and June 3, 2022, the disclosure of which is incorporated herein by reference in its entirety. For example, the content library 2002 can include "JSON" files for defining alert rules, workbooks, playbooks, etc. When new content is added to the content library 2002 or existing content is updated, the changes can be automatically pushed to the SOAR platform 2018 of tenant 1010 via the SOAR management server 1002. In other words, the SOAR management server 1002 can be configured for the unique SOAR needs of each tenant 1010 that change based on the architecture of each tenant (FIG. 1). n can be configured for the unique SOAR needs of each tenant 1010 that change based on the architecture of each tenant 1-n (FIG. 1).
[0037] The variable store 2004 is between the SOAR management server 1002 and tenant 1010 nor can be configured to further customize the interface with the architecture of the client organization. For example, the Variable Store 2004 enables users of the SOAR Management Server 1002, such as an MSSP, to define and / or link variables associated with the Tenant 1010n architecture to various artifacts stored in the Content Library 2002 so that they can be detected by the SOAR Management Server 1002, thereby enhancing the SOAR Management Server 1002's ability to automate client-specific executions. According to some non-limiting aspects, variables can be stored using a primary key that uniquely identifies the destination environment. For example, when registering a managed environment, an MSSP, or another user, can indicate the administrator account associated with the environment so that it can be configured when the content is deployed to a specific environment. Thus, the introduced automation may require the supply of which accounts are administrators so that it can perform automation specific to those account roles.
[0038] The Automation Scheme 2008 can be configured to recognize commonalities between the various Tenant 1010 1-n (see Figure 1) architectures and standardize the execution of the SOAR Management Server 1002. This represents a significant technical improvement over conventional SOAR management platforms that are configured to be executed for a single client organization or require a large amount of manual labor to execute across multiple Tenants 1010 1-n or client organizations. For example, conventional SOAR platforms require an assessment of client-specific environments and needs, which requires the design and implementation of custom solutions. The Automation Scheme 2008 of Figure 2, in conjunction with the Content Library 2002 and the Variable Store 2004, enables the SOAR Management Server 1002 of Figures 1 and 2 to automatically generate customized SOAR solutions and scale such solutions simultaneously across a number of Tenants 1010 1-n or client organizations.
[0039] The applications initiated by the SOAR management server 1002 can further include an API broker 2006 and a graphical user interface 2010. An example of such a graphical user interface 4000 according to one non-limiting aspect is shown in FIG. 4. For example, the graphical user interface 4000 of FIG. 4 can include one or more platforms 4002, 4004, 4006 for manipulating authentication settings. The platforms can be, among other things, third-party applications that function as authentication mechanisms such as, for example, Okta 4002, Duo 4004, and / or Azure AD 4006. When platform 4002 is selected, the graphical interface can display a setup wizard 4008. The setup wizard 4008 can include one or more windows 4010 that enable the user to configure various settings for various parameters such as users, user groups, and / or remediation playbooks. Each window 4010, when selected, can display instructions 4012 for visually presenting information and receiving user input via a display and / or peripheral devices (such as a keyboard, mouse, touch screen, etc.) communicatively coupled to the SOAR management server 1002 so that the user can configure specific settings for the parameter. For example, the graphical user interface 2010 can be configured to execute a wizard that can control the setup and / or automation of the SOAR platform for one or more tenants 1010 n or client organizations.
[0040] Referring further to FIG. 2, one such tenant 1010 n An example of an architecture is illustrated in accordance with at least one non-limiting aspect of the present disclosure. The SOAR management server 1002 is a tenant 1010 nTenant 1010, which is configured to detect variables associated with the architecture and includes one or more modules shown in FIG. 2 n A unique configuration can be designed and introduced. For example, according to the non-limiting aspects of FIG. 2, Tenant 1010 n The architecture can include a remote SOAR platform 2018, a dashboard / reporting module 2022, and one or more security tool application programming interfaces (APIs) 2020 a~d Each security tool API 2020 a~d can be configured to prevent malicious attacks or misuse against the client's API introduced in Tenant 1010 n Since APIs are key to programming web-based interactions, they are a target for hackers. Therefore, security tool API 2020 a~d can monitor the client's API and, if a suspicious event is detected, send an alert 2030 back to the SOAR platform 2018
[0041] According to some non-limiting aspects, the dashboard / reporting module 2022 can include a customizable visual representation of the cybersecurity of Tenant 1010 n For example, the dashboard / reporting module 2022 can enable MSSPs and / or employees of the client organization to visually see what is happening across the Tenant 1010 network and take corrective actions to protect the network in response to detected threats. This allows MSSPs and / or client organizations to identify, prevent, mitigate, and / or predict cybersecurity incidents in a significantly more efficient manner. Of course, the unique Tenant 1010 architecture of FIG. 2 n is presented for illustrative purposes only. According to other non-limiting aspects, Tenant 1010 designed and introduced by the SOAR management server 1002 nThe architecture can be alternatively configured to include alternative types and / or quantities of modules. The capabilities of the SOAR management server 1002, more specifically, the content library 2002, the variable store 2004, and the automation scheme 2008, enable a customized SOAR-based solution that can be remotely managed on behalf of tenant 1010 n Each solution is different depending on the variables detected by the variable store 2004 and the artifacts selected from the content library 2002 based on the detected variables, as introduced by the SOAR management server 1002, which can be remotely managed instead of tenant 1010
[0042] Furthermore, architecture 2000 of FIG. 2 further shows different communication means between the various modules of the SOAR management server 1002 and one or more tenants 1010n. For example, a particular module such as the API broker 2006 can communicate with other modules such as the service operation engine 2012, the graphical user interface 2010, the remote SOAR platform 2018, and the dashboard / reporting module 2022 via the service layer 2024. Other modules such as the content library 2002, the variable store 2004, and the API broker 2006 can communicate with the remote SOAR platform 2018 of tenant 1010 n via the management and content delivery layer 2026. The remote SOAR platform 2018 can communicate with one or more security tool APIs 2020 of tenant 1010 n via the SOAR communication protocol 2028 a~cIt can communicate with. One or more security tool APIs send and return warnings to the remote SOAR platform 2018 according to the rules defined by the artifacts 2032 applied from the content library 2002, as defined by the variables from the variable store 2004, via the alert protocol 2030. The influence of the artifacts selected from the content library 2002 and the variables detected from the variable store 2004 on the artifacts 2032 is shown in FIG. 2 via the corresponding cross-hatching. In other words, similar or the same protocols and / or methods can be applied, but each communication means may contain different content. Therefore, the end user can utilize the architecture 2000 of FIG. 2 regardless of the presence or absence of a specific "MDR" (Managed Detection and Response) service. However, when delivered by a specific MDR service, it can use the same API as a specific MDR service user who interfaces with the API, manage the architecture 2000, and take measures on behalf of one or more tenants.
[0043] As exemplified in the non-limiting manner of FIG. 2, the various modules of the architecture of the SOAR management server 1002 are determined by the variable store 2004 and / or are autonomously selected variables associated with the tenant 1010, as previously stored n According to specific artifacts 2032 from the content library 2002, communicate with, manage, and control the remote SOAR platform 2018 of the tenant 1010. Therefore, the content library 2002 and the variable store 2004, together with the automation scheme 2008, enable the SOAR management server 1002 to n for each tenant 1010 nIt may be possible to automatically generate a custom configuration for integrating with and remotely managing the SOAR platform 2018. For example, the artifact 2032 may define the means by which the SOAR management server 1002, the API broker 2006, and the service operation engine 2012 interface with the remote SOAR platform 2018 of the tenant 1010 n . Further, the artifact 2032 may further define the conditions under which content alerts 2030 and they are sent from one or more security tool APIs 2020 a~d to the remote SOAR platform 2018.
[0044] The SOAR management server 1002, including the content library 2002, the variable store 2004, and the automation scheme 2008, can provide a powerful cloud-based tool for an MSSP to remotely manage a client organization's SOAR platform 2018. The primary interface is the graphical user interface 2010, but the API interface 2006 can further enable program control of the SOAR platform 2018 management functions, whereby a user can introduce content in the form of playbooks, automations, integrations, dashboards, and other SOARs to control code-based content in a remote environment such as the tenant 1010 n . Further, the content library 2002, the variable store 2004, and the automation scheme 2008 of the SOAR management server 1002 enable customization of that content and provide features that allow for customized introductions based on the specific needs of the tenant 1010 n . In other words, the SOAR management server 1002 can provide a modular and scalable approach that references a stored library of code and content (e.g., the content library 2002) so that options can be automatically determined at the time of introduction.
[0045] For example, the user can deploy a series of artifacts stored in the content library 2002, such as playbooks, code, integrations, and / or dashboards, that enable the integration of next-generation antivirus (「NGAV」) products, email security products, and / or identity protection products, and then automate the detection, investigation, and response phases based on controls received from the user via the graphical user interface 2010. Additionally and / or alternatively, the SOAR management server 1002 can enable the user to automate a part of the architecture or environment of tenant 1010 n . Further, the graphical user interface 2010 can enable the user to 「opt-in」 and / or 「opt-out」 of automation features as presented by the automation scheme 2008, via wizard-like tracking, walkthroughs, and application simplification. The user can further customize the reports and / or dashboard functions and preferences to be applied via the dashboard / report module 2022, which can be packaged for introduction along with the automation content.
[0046] According to some non-limiting aspects, the applications launched by the SOAR management server 1002 may be scalable, i.e., tenant 1010 having a SOAR platform 2018 that can be remotely managed (e.g., scalability) nIt can be configured with the ability to expand or extend in terms of the number of, and / or the number of SOAR management functions provided. In other words, the application, including the content library 2002, variable store 2004, and automation scheme 2008, can be designed to minimize the level of effort required for the SOAR management server 1002 to be extended for future use. For example, an extension mechanism provided by an application launched by the SOAR management server 1002 and pluggable add-ons configured to enable additional service components and features of the SOAR management server 1002 can be introduced in the future.
[0047] According to some non-limiting aspects, the extension mechanism can be implemented in various ways to enable plugging into additional SOAR service components. For example, authentication mechanisms such as DUO, Okta, etc. can be supported simultaneously (as shown via the graphical user interface 4000 of FIG. 4). These authentication mechanisms do not have to be hard-coded, but configuration files can be detectable (e.g., the main "config" file for each of the authentication mechanisms can be placed in a well-known repository location that is scanned for new or deleted files). If new configurations such as Azure AD are also supported, the configuration file corresponding to Azure AD is placed in the same repository location as the Duo and Okta configurations, discovered by the application management server, and presented to the user for selection and setting from the client as needed. The configuration files can conform to a scheme defined and understood by this application management tool, and the user interface 4000 (FIG. 4) elements 4002, 4004, 4006 (FIG. 4) can be generated and automatically populated accordingly. In particular, the SOAR applications discussed herein are not hard-coded in the source code but are constructed in a way that can be easily extended with additional configuration capabilities dynamically plugged in through new configurations according to this method.
[0048] When a user introduces these add-ons via automation, it triggers an application launched by the SOAR management server 1002, enabling additional subscription-based services instead of an MSSP, and enhancing the security and health monitoring of tenant 1010 n Additionally and / or alternatively, the application introduced by the SOAR management server 1002 can operate on existing "unmanaged" content that can discover and mildly manage at least some of the previously introduced SOAR assets by tenant 1010, rather than generating a completely new customized tenant 1010 architecture as illustrated in FIG. 2 n tenant 1010 n
[0049] As described above, when executed by the processor 1004 (FIG. 1), the application can be configured to abstractly and / or dynamically manage the SOAR platform 2018 of the client organization. For example, in an abstract implementation, as disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed on June 3, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", the SOAR management server 1002 may employ generally defined artifacts stored in the content library 2002, the disclosure of which is hereby incorporated by reference in its entirety. Generally defined artifacts may include, for example, blocks of executable code. However, platform-specific implementations can then be provided (e.g., Azure Defender, Crowdstrike, etc.). The summary automation / playbook is written in a general format and can then be translated into a specific format upon introduction. For example, an automation / playbook can be created that is specifically configured to disable a user's email account if a business email is leaked. However, at the actual implementation of the automation / playbook in a particular customer environment, the system 1000 (FIG. 1) and the functional architecture 2000 (FIG. 2) disclosed herein can translate the generally described content into a version that is specifically implemented for the particular email application used by the tenant. In this way, unlike conventional systems and architectures, content can be generated that can be programmatically adapted to multiple environments without rewriting it.Accordingly, the system 1000 (FIG. 1) and the functional architecture 2000 (FIG. 2) disclosed herein provide a significant technical solution flexibility format and interface to the technical problems of conventional automation / playbook, whereby a user can extend services to a number of tenants and their authentication mechanisms.
[0050] Alternatively, in a dynamic implementation, the SOAR management server 1002 can dynamically generate new automation types via the content library 2002, which can be automatically detected by the graphical user interface 2010 and displayed for selection for subsequent introduction. Similarly, new automation such as an endpoint monitoring solution (e.g., CarbonBlack, etc.) can be added to the content library 2002 for a given automation type, such as one that blocks the execution of malicious programs detected by the automation (e.g., blocks executable file automation). Similarly, it may become automatically available in the GUI and can be deployed to appropriate client SOARs (which use these security tools).
[0051] Upon introduction via the SOAR management server 1002, tenant 1010 nOr a client, certain change points can be detected by the variable store 2004 and correlated with the artifacts stored in the content library 2002. For example, the SOAR management server 1002 has the ability to configure an automated response / corrective action (e.g., a playbook) for a given configuration. These corrective actions may require optional steps. For example, the tenant may have to approve the action first. Thus, the configuration of repair automation may involve a similar configuration for the actual task (e.g., blocking an account), but the approval step may be performed manually via phone, or email, or a workflow form (e.g., integration via a service ticket). Thus, the approval step can be variable (e.g., it may or may not exist, and if it exists, it may be achieved in several ways), and it is necessary to retrieve the appropriate code and configuration from the automation repository to configure for this client and SOAR automation.
[0052] Therefore, at the time of introduction, the change points are the tenant 1010 n Based on the network architecture of, the tenant 1010 n Can be configured for its own SOAR needs. According to one non-limiting aspect, the SOAR management server 1002 can automate the SOAR platform 2018 to block a user account upon detection of a security event based on the input received by the security tool APIs 2020a - d. For example, the automation may include several steps or conditions, such as approval from the tenant 1010 n Management account. During the introduction, for example, via a wizard presented through the graphical user interface 2010, the automation is for the tenant 1010 nThe user may be requested to provide information associated with one or more administrative accounts (e.g., phone number, Short Message Service (「SMS」) address, email address, etc.). Thus, certain steps and / or conditions, such as the contact and / or facilitation of actions from the administrative account, may be programmed for automation via the graphical user interface 2010.
[0053] According to one non - limiting aspect, when custom automation is executed, the SOAR management server 1002, more specifically, the custom automation generated by the SOAR management server 1002, manages the SOAR platform 2018 and can detect security events based on inputs / alerts received from one or more security tool APIs 2020a - d and determine that it is necessary to block a user account. The SOAR management server 1002 manages the SOAR platform 2018, notifies the administrative account, and the automation can wait for approval. Upon receiving approval, it continues to the subsequent steps of the automation and finally deletes the suspect account from the tenant 1010 n network. As described above, this can be abstracted to the automation type using specific implementations for each security tool API 2020a - d and / or notification methods. Removing a suspect account is just one example of a measure that the SOAR platform 2018 can take to enhance the security of the tenant 1010 n network. For example, in addition to blocking an account, the SOAR platform 2018 can also delete suspect files, among other measures, and send an email to the security administrator.
[0054] Once introduced by the SOAR management server 1002, the artifact 2032 (e.g., automation) is for the tenant 1010 nIt may exist within the architecture, and depending on non-limiting aspects, the MSSP and / or the client may modify the introduced configuration. For example, according to some non-limiting aspects, the client may wish to control the configuration introduced across the tenant 1010 n across the network. However, according to other non-limiting aspects, the client may wish for the MSSP to have exclusive control of the configuration. In any case, the application introduced by the SOAR management server 1002 may be configured to automatically detect changes made by the MSSP and / or the client and use them for the management of future introductions and / or updates to the already introduced artifacts 2032. According to some non-limiting aspects, such changes may be utilized by the artificial intelligence stored in the memory 1006 (Figure 1) of the SOAR management server 1002 to adapt one or more artifacts 2032 (e.g., templates, workflows, etc.) within the content library 2002 for similar clients and / or for extended introductions of the architecture.
[0055] Therefore, when introduced by an application on the SOAR management server 1002, the content library 2020 can function as a contributing mechanism that can abstractly and / or dynamically detect updates to both the content library 2002 and the client SOAR platform 2018, along with the graphical user interface 2010 and the API broker 2006. These updates can be collectively managed via the SOAR management server 1002, which functions as the central console of the system 1000 (FIG. 1), enabling unprecedented scalability and the management of a large number of clients. In this way, the SOAR management server 1002 can remotely manage another client's SOAR platform 2018 with reliability and consistency. Due to its modular design, as third-party vendor solutions evolve, users and third-party applications can contribute to and / or update existing artifacts 2032, enabling it to be "future-proofed."
[0056] FIG. 3 shows a diagram of a method 100 for autonomously enhancing the security of a tenant network via a managed security service provider. The method 100 in various aspects can be initiated by a SIEM autonomous security system or an MSSP server (hereinafter collectively referred to as the "security system"), and the query 105, database, or server can be initiated when the security system encounters an IoC in the tenant network, generally. The security system database is stored and indexed and contains or receives historical and contextual data or information from data sources or feeds available to the security system in response to requests. Thus, when querying the security system database or network with query 105, the system can search for data and information that it can access for each source or feed to identify information regarding the encountered or other relevant IoCs.
[0057] Each data source or feed from which an IoC is received may include a pre-set reliability score or value, or a reliability score calculated and / or updated by a security system. This reliability score defines the reliability of each data source or feed and may be automatically determined by the security system based on known or available data, which may include the level and / or quality of human involvement, the number of IoCs identified by the source or feed, the history of the reliability of the source or feed (e.g., the number of false positives or false negatives generated from data obtained from the source or feed), the number of years the source or feed has been in existence, the number of years or date of the IoCs in the source or feed, the evaluation of the information source or feed in the community or based on community / user reviews, the relevance of the source or feed to a particular tenant or tenant network, the type of tenant network managed by the security system, and the scope of information available to the security system on the source or feed. Query 105 may match or identify the encountered IoC with the same or similar IoCs in the SIEM autonomous security system database and identify related or relevant sources or feeds that contain references or information to the encountered IoC.
[0058] After matching or identifying the source related to the encountered IoC, the security system calculates and / or generates 110 a single IoC threat score / IoC threat score for the purpose of indicating the level or severity of the threat. After the IoC threat score is calculated by the system, an actionable security enhancement notification is generated 115 based on the IoC threat score. The actionable security enhancement notification may be sent to a security analyst or other user of the security system and may include recommendations regarding security management measures that may be taken to protect networks, databases, servers, or other nodes that belong to a tenant or are under the management of an MSSP.
[0059] In various aspects, an actionable security enhancement notification may require that a calculated IoC threat score meet or exceed a specified or pre-set security threat threshold. In some aspects, different thresholds may be set, and meeting or exceeding them may result in different security enhancement notifications, responses, or actionable recommendations, some of which may be sent to users of the security system or security analysts. On the other hand, another part of it may create other automated measures such as event recording or database updates, or other parts of the tenant network or security system. In various embodiments of the present disclosure, the IoC threat score, security threshold, and / or security enhancement notification or alert may be displayed to a user of the security system via a user interface. The user interface may utilize color coding or other visual effects or techniques for different IoC threat scores, actionable recommendations, etc.
[0060] Optionally, the indicators of compromise may also be classified into one or more categories by a SIEM autonomous security system, or classified as one or more types of threats. The classification may be based on its IoC threat score, threat level, the threshold it meets, exceeds, or otherwise fails to meet, and the generated confidence score for the IoC score. The IoC may be given different classifications such as malicious, benign, unknown, or another category or type. The classification may also be sent or displayed to a user of the security system or security analyst. The classification level may also affect the type of recommendations or actionable security enhancements displayed, generated, or sent by the system in various embodiments.
[0061] In some optional embodiments, a new malware variant or threat type may be identified based on one or more of factors such as IoC classification, calculated IoC threat score, calculated IoC confidence interval or value, security threshold level that the IoC meets or exceeds, years of existence of the IoC, spread and / or distribution of the IoC. In a preferred embodiment, the IoC shares some but not all of the characteristics of previously encountered IoCs or threats. For example, if the IoC shares the origin server with a previous malware strain or variant, a new malware variant may be identified, provided that it does not contain the same or identical code itself. Further, the malware may share some but not all of the behaviors or characteristics (or code) as a previous strain, which may, individually or in combination with the factors listed herein, enable the autonomous security system to identify new malware variants or other threats.
[0062] In response to the identification of IoCs, calculation of IoC threat scores, and / or classification of IoCs, and to improve the functionality of the security system, the security system may perform an automatic change or update of the false / true positive / negative scores of the sources and feeds used to receive IoC data. Optionally, the security system may autonomously adjust by determining one or more ratios consisting of at least two of the number of false positives, number of true positives, number of false negatives, and number of true negatives, and update one or more security threat thresholds and levels, and / or the reliability scores of the sources or feeds. This response improves the accuracy and usefulness of the scores for the system, enables better deployment of response and processing resources, improves the response time by more quickly identifying threats with more accurate scores and information, more effectively manages system resources based on the immediacy of each encountered threat, and employs processing and memory resources for more urgent tasks, for example, in response to more immediate threats.
[0063] In various aspects, the security system may autonomously initiate an automated security response to identified IoCs, identified malware variants, IoC threat scores, and / or one or more security threat thresholds based on calculated scores, IoCs, or identified value / threshold levels. The automated security response may include automatically adjusting the security threat threshold levels, automatically reconfiguring a database to include identified malware variants, automatically identifying, additionally adding identified malware variants, automatically sending notifications to multiple users or security analysts of the security system, exposing one or more tenant networks to identified IoCs or new malware variants, or determining the risk of future exposure, and isolating one or more tenant networks or portions of the network to prevent the spread of malware, viruses, or other threats, and may include one or more of any of these responses.
[0064] Reconfiguring the database can include automatically, continuously, and dynamically updating the database, and this update or reconfiguration of the database may be based on multiple factors such as, but not limited to, automatic periodic ingestion of information about new malware variants and new threats based on commercial and community threat intelligence, data feeds by industry standard mechanisms (e.g., STIX, API, YARA), malicious or potentially unwanted activities observed in the monitored environment via deployed sensors, or feeds of manually curated Indicators of Compromise (IOCs) maintained by threat intelligence analysts handling various data sources or feeds. This database reconfiguration enables more rapid identification, collation, and / or response to threats and malware possibilities.
[0065] Automatically sending notifications to a network or other parts of a SIEM, or to multiple users or analysts of a security system, can be achieved in various ways, including, but not limited to, creating a time-sensitive output list (e.g., a lookup table) of currently valid IoCs and their respective risk scores, enabling the security system to automatically correlate raw information obtained from the monitored environment with the risk score results calculated by the system. The scoring output is periodically exported to a set of structured data, which is then fed into a data log analysis and management system that continuously evaluates incoming data against new findings from the scoring output. Thus, if something matching a risk score exceeding a certain threshold is observed within the network, one of various automatic security responses can be triggered, including generating an automatic alert or an automatic isolation of a database or network (the automatic isolation may be limited in time or scope, e.g., the number of databases / isolated networks, or parts of the network's database depending on the IoC threat score), allowing, for example, time for a human analyst to review and take further action.
[0066] The output list and real-time data lookup capabilities enable both automatic and manual lookups of various metrics and factors, including metrics or IoC history, risk scoring, and the source of specific metrics as part of ongoing security incidents. In various aspects, this is achieved through API integration between a security orchestration platform used for incident management and a database hosting the metric risk scoring results. For example, if an artifact is observed as part of an investigation regarding a specific activity type within an environment, the orchestration system is permitted to autonomously (and in some aspects, by the security analyst) query the data stored within the risk calculation system for further information regarding this artifact, such as when the artifact was first detected, what evaluation the system gave, and what the associated risks or risk scope for the artifact are based on the assigned / calculated risk score.
[0067] Determining the risk that other tenants or tenant networks are or will be exposed to can be done via an API connection between the orchestration layer of the security system and a database hosting the scoring algorithm. If an IoC is observed in a client environment and determined to be a reliable indicator of unwanted or potentially malicious activity, that finding is transferred to the scoring algorithm via an API call that memoizes this finding within the database. As a result, this causes the risk score assigned to this specific metric within the database by the next time point to be calculated for the IoC in question. Also, the capture of one or more tenant networks or portions of a network can provide benefits to multiple network segments or multiple discrete networks without requiring a connection between them or knowledge of each other.
[0068] In most embodiments, when the risk score exceeds a set threshold, the overall incident severity assessment increases accordingly. As a result, the incident is assigned a higher priority to be processed as a more urgent issue with dedicated resources in either a review by a security analyst or in any of the potential responses described above. Further, if the client and service provider have agreed on an arrangement that includes automated response and threat mitigation capabilities, a higher risk score assigned to an indicator associated with a particular incident may trigger an automated response (e.g., endpoint isolation, interruption of network traffic, and the automated responses described above), and that determination may have been less accurate otherwise. In different scenarios, the ability to confirm that a particular indicator is known to be associated with legitimate activity can result in a delay of automated or semi-automated response and threat mitigation activities to avoid potential interruption of legitimate activity related to the approved business use of the environment.
[0069] Figure 4 shows a diagram of an autonomous method for calculating the encountered intrusion indicator (IoC) threat score. When an IoC is encountered and the security system database is queried as shown in Figure 1, for each source or feed identified as being related to the encountered IoC, the threat value / level provided or classified by the relevant source or feed is identified 205 for that IoC. For example, some security feeds may classify an IoC with a threat level of 55 / 100, 8 / 10, moderately malicious, or benign, or through any other classification system. The security system can autonomously identify the threat level assigned by each security source or supply it to each IoC related to the current query. In many aspects, even if the sources or feeds use different types or classification methods, a standardized source or feed IoC threat value is generated across different sources or feeds. Based on the reliability score of each source of the feed identified as being related to the IoC, a multiplier is added / assigned to the threat value provided by the source or feed 210 to generate an adjusted threat value for the IoC. The multiplier may be directly based on the established or assigned reliability score of the source or feed, or may be partially based on other factors such as the distribution and / or variance between the threat values provided by the source, compared to other threat values provided by other sources or feeds, or alternatively / additionally, may be based on internal metrics of the security system related to the source or feed, or the IoC, or the type of IoC.
[0070] In various aspects of the present technology, irregular or outlier threat values (irregular or outlier threat values can include adjusted threat values or irregular adjusted threat values that can be identified as irregular before and / or after adjustment) can be identified and / or removed from calculations. In the present disclosure, reference to "threat value" in its broadest sense encompasses adjusted or unadjusted threat values, and / or irregular or non-irregular threat values, and / or normalized or non-normalized threat values. In some embodiments, different types of sources can generate or provide different threat values for a particular IoC, and these differences may stem from differences in the feed or the source itself. For example, threat values that are publicly generated and freely provided across a large number of IoCs may be classified as having a low threat value for an IoC, while a few exclusive and paid-for specialized security services may provide a high threat value for the same IoC. In such examples, the security system may weight the differences between the two groups and provide a threat value that takes into account both publicly generated data and privately generated data, and the weighting may depend on the particular IoC, its type, the number of IoCs in each source or feed, the threat values provided, the reliability of the source or feed, the size of each group of closely related sources or feeds, as well as the goals of the security system itself, and the weighting may be done to generate or produce a weighted and adjusted threat value. In this optional step, the security system can take into account both cloud source information from the public and information privately generated by specialized security companies, and in some cases, the system may weight the threat value or adjusted threat value more heavily for one group of data sources than the other, depending on the particular IoC and the factors enumerated herein.Based on publicly available cloud-sourced information, a security system can be flexibly utilized to take into account information that has not yet been curated, specialized organized, or reconciled. On the other hand, with privately generated proprietary sources, the security system can take into account the perspectives of industry and experts in the area of threats faced.
[0071] In accordance with aspects of the present invention, various threat values and / or various adjusted threat values can be normalized 225 across all relevant sources or feeds. Next, a single threat score is generated 230 for the encountered IoC. In some embodiments, an optional reliability score may also be generated 235, which may be provided with or incorporated within the single threat score. In some aspects, the reliability score may also be within a certain threshold for the security system to provide the threat score generated for a security analyst or other user of the system, or to take any other additional measures shown in FIG. 1. Aspects of the systems and methods presented herein, including methods for collecting and validating the reliability of data sources and feeds, determining and calculating the importance or significance of identified data, and scoring that data, utilize large amounts of data and information and can be used in various industries and applications that require the data and its reliability to meet certain threshold levels.
[0072] FIG. 5 shows a graphical user interface of an autonomous SIEM threat scoring and management application dashboard that shows an overview of detected and managed threats, according to some non-limiting aspects of the present disclosure. This user dashboard 300 may include a side panel 301 that allows a user, such as a security analyst, to select another interface dedicated to cases 302 that the system is addressing or has addressed. The dashboard side panel 301 may also include links to other screens including security alerts 303, a list of assets 304, a list of vulnerabilities 305, reports 306, compliance 307, and a clickable logout button 308. An exemplary dashboard may include several selectable headers including a general overview header 309, an environment header 310, a vulnerability header 311, a trend header 312, an event header 313, and an external threat header 314 for providing an overview or activity of the system. When the overview header 309 is selected, a screen may be displayed that includes an information group regarding the number of pending items waiting for the user's action 315, in-progress items 316, recent escalations 317, recent service requests 318, recent alerts and incidents 319, recently implemented actions 320, recent investigation results 321, recent security cases 322, the number of protected assets 233, bypassed assets 324, as well as a list of security incidents 325. Many of these tabs, lists, and information groups may include graphical views, charts, tables, and graphs.
[0073] FIG. 6 presents another graphical user interface and incident screen 400 that displays details of detected threats or indicators of compromise, according to some non-limiting aspects of the present disclosure. In one aspect, incident number 401 is provided with a description or name of the incident or indicator of compromise 402. Incident status 403 may also be set within the incident screen, which can present, for example, states such as action required by the user, incident closed, incident resolved, and the like. An IoC category 404 may also be provided, including, for example, "disruption", or "DNS anomaly", "login red flag", and the like. The alert source 405 may also be listed, i.e., the source of the detected threat or alert trigger may also be listed. Also, any actions taken 406 may be presented. Incident screen 400 may also include a summary header 407, an evidence header 408, and a message header 409. The summary header 407 may include information regarding the date / time when the incident was created 410, an update 411, the total time the incident was active 412, the host name 413, the severity or importance of the device 414, the location of the assets involved 415, the device IP 416, a device type 417 that may be related to the software or hardware of the device, the associated user name 418, a device category 419 (e.g., the device is an endpoint), and a device type version 420 that may be related to both the hardware and software executed on the device.
[0074] Figure 7 presents a graphical user interface that displays details of encountered threat indicators for the IoC screen 500, according to some non-limiting aspects of the present disclosure. The IoC screen 500 includes a list of encountered IoCs 501, including their names 502 and their types 503, such as a list of "file", "domain", "IP", "URL", "secure hash algorithm", etc. The IoC screen 500 may also include a list of reputations 504 for each IoC, which may be directly linked to a single IoC score generated by the security system and / or may be, for example, classified as unknown, suspicious, malicious, or clean. The IoC evaluation 504 may also be directly associated with or derived from or involved in a score, or value, that is calculated or determined or involved in a way that derives a single generated threat score, or may be an evaluation provided by a source or feed containing information about the IoC. The IoC screen 500 may also include a designation 505 for each IoC that may include its identity, for example, as a specific variant of malware or a bot.
[0075] Figure 8 presents a graphical user interface that provides investigation notes for each investigated threat indicator, according to some non-limiting aspects of the present disclosure. The investigation screen 600 may include investigation results 601 that are from a human user or security analyst, or from the automated system itself generated by any of the methods and systems described herein. The investigation screen 600 may also include investigation notes 602 that may summarize the nature of the IoC, its current status, the history of the IoC, and the way the alert was triggered, as well as any actions taken by the system or the users of the system. A measure note 603 related to the actions taken to counter the IoC, as well as a guidance section 604 regarding any measures or steps that the end user or client may need to take, or any other information that may be relevant to the client or tenant, may also be provided.
[0076] FIG. 9 is a schematic diagram of an exemplary machine in the form of computer system 1, within which a set of instructions for causing a machine to execute any one or more of the methodologies discussed herein may be executed. In various exemplary embodiments, the machine may operate as a stand-alone device or may be connected (e.g., networked) to other machines. In a network deployment, the machine may operate in the capacity of a server or a client machine in a server-client network environment or as a peer machine in a peer-to-peer (or distributed) network environment. The machine may be a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), cellular phone, portable music player (e.g., a portable hard drive audio device such as a Move Picture Experts Group Audio Layer 3 (MP3) player), web appliance, network router, switch, or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, although only a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set of (or multiple sets of) instructions to perform any one or more of the methodologies discussed herein.
[0077] The exemplary computer system 1 includes a processor or processors 5 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both) and a main memory 10 and a static memory 15 that communicate with each other via a bus 20. The computer system 1 may further include a video display 35 (e.g., a liquid crystal display (LCD)). The computer system 1 may also include an alphanumeric input device 30 (e.g., a keyboard), a cursor control device (e.g., a mouse), a voice recognition or biometric verification unit (not shown), a drive unit 37 (also referred to as a disk drive unit), a signal generating device 40 (e.g., a speaker), and a network interface device 45. The computer system 1 may further include a data encryption module (not shown) for encrypting data.
[0078] The components provided in the computer system 1 are components typically found in a computer system that may be suitable for use in embodiments of the present disclosure and are intended to represent a broad category of such computer components known in the art. Thus, the computer system 1 can be a server, a minicomputer, a mainframe computer, or any other computer system. The computer may also include different bus configurations, network platforms, multiprocessor platforms, etc. Various operating systems can be used, including UNIX (registered trademark), LINUX, WINDOWS (registered trademark), QNX ANDROID (registered trademark), IOS, CHROME, TIZEN, and other suitable operating systems.
[0079] The disk drive unit 37 includes a computer or machine-readable medium 50 on which one or more sets of instructions and data structures (e.g., instruction 55) that implement or utilize any one or more of the methodologies or functions described herein are stored. Instruction 55 may also be fully or at least partially present in main memory 10 and / or in processor 5 during its execution by computer system 1. Main memory 10 and processor 5 may also constitute a machine-readable medium.
[0080] Instruction 55 may be further transmitted or received via network 70 via network interface device 45 using any one of several well-known transfer protocols (e.g., the Hypertext Transfer Protocol (e.g., HTTP)). Although machine-readable medium 50 is shown as a single medium in the exemplary embodiment, the term "computer-readable medium" should be taken to include a single medium or multiple media (e.g., a centralized or distributed database and / or associated cache and server) that store one or more sets of instructions. The term "computer-readable medium" should also be taken to include any medium that can store, encode, or carry a set of instructions for execution by a machine and that cause the machine to perform any one or more of the methodologies of this application, or that can be used by or associated with such a set of instructions to store, encode, or carry a data structure related thereto. Thus, the term "computer-readable medium" includes, but is not limited to, solid state memories, optical and magnetic media, and carrier wave signals. Such media may also include, but are not limited to, hard disks, floppy disks, flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc. The exemplary embodiments described herein may be implemented in an operating environment that includes software, hardware, or a combination of software and hardware installed on a computer.
[0081] One skilled in the art would recognize that an Internet service may be configured to provide Internet access to one or more computing devices connected to the Internet service, and that the computing devices may include one or more processors, buses, memory devices, display devices, input / output devices, and the like. Further, one skilled in the art may recognize that the Internet service may be coupled to one or more databases, repositories, servers, etc. that may be utilized to implement any of the embodiments of the present disclosure described herein.
[0082] Computer program instructions may also be loaded onto a computer, server, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to generate a computer-implemented process, whereby the software instructions executed on the computer or other programmable apparatus provide a process for implementing the functions / acts specified in the blocks of the flowchart and / or block diagram.
[0083] Suitable networks include, for example, a local intranet, PAN (Personal Area Network), LAN (Local Area Network), WAN (Wide Area Network), MAN (Metropolitan Area Network), virtual private network (VPN), storage area network (SAN), frame relay connection, advanced intelligent network (AIN) connection, synchronous optical network (SONET) connection, digital T1, T3, E1 or E3 line, digital data service (DDS) connection, DSL (Digital Subscriber Line) connection, Ethernet connection, ISDN (Integrated Services Digital Network) line, dial-up port such as V.90, V.34 or V.34 bis analog modem connection, cable modem, ATM (Asynchronous Transfer Mode) connection, or one or more of FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connections, or may interface therewith. Further, the communication may also include a link to any of various wireless networks such as WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access) or TDMA (Time Division Multiple Access), cellular phone network, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), RIM (Research in Motion, Limited) two-way paging network, Bluetooth wireless, or IEEE 802.11-based radio frequency network. Network 215 may further include or interface with any one or more of RS-232 serial connection, IEEE-1394 (Firewire) connection, fiber channel connection, IrDA (Infrared) port, SCSI (Small Computer System Interface) connection, USB (Universal Serial Bus) connection, or other wired or wireless, digital or analog interface or connection, mesh or Digi (registered trademark) networking.
[0084] Generally, a cloud-based computing environment is a resource that typically combines the computing power of a large group of processors (such as within a web server) and / or combines the storage capacity of a large grouping of computer memories or storage devices. A system that provides cloud-based resources may be exclusively utilized by its owner, or such a system may be accessible to external users in order to deploy applications within the computing infrastructure to take advantage of large computing or storage resources.
[0085] The cloud is formed, for example, by a web server network that includes a plurality of computing devices such as computing device 1, and each server (or at least a plurality of servers) provides a processor and / or storage resources. These servers manage the load provided by a plurality of users (such as customers of cloud resources or other users). Typically, each user imposes a workload requirement on the cloud that varies in real time and sometimes dramatically. The nature and extent of these variations typically depend on the type of business associated with the user.
[0086] It is worth noting that any hardware platform suitable for implementing the processes described herein is suitable for use in the art. As used herein, the terms "computer-readable storage medium" and "computer-readable storage medium" refer to any medium or media involved in providing instructions to a CPU for execution. Such media can take many forms, including but not limited to non-volatile media, volatile media, and transmission media. Examples of non-volatile media include optical or magnetic disks such as fixed disks. Volatile media includes dynamic memory such as system RAM. Transmission media includes coaxial cables, copper wire, and fiber optics, and in particular, wires with an embodiment of a bus. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, flexible disks, hard disks, magnetic tape, any other magnetic media, CD-ROM disks, digital video disks (DVDs), any other optical media, any other physical media having a pattern of marks or holes, RAM, PROM, EPROM, EEPROM, FLASHEPROM, any other memory chip or data exchange adapter, carrier waves, or any other media readable by a computer.
[0087] Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to a CPU for execution. The bus carries data to system RAM, from which the CPU fetches and executes instructions. Instructions received by system RAM may optionally be stored on a fixed disk before or after execution by the CPU.
[0088] The computer program code for performing the operations of the aspects of the present technology may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as the "C" programming language, Go, Python, or assembly language. The program code may be executed on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer, partly on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet service provider).
Example
[0089] Examples of clauses The various aspects of the subject matter described in this specification are set forth in the following numbered clauses.
[0090] Clause 1: A method for autonomously enhancing the security of a tenant network via a Managed Security Service Provider (MSSP) server comprising a processor and a memory, the method comprising using information from a plurality of data sources to query a database or server via the processor by the security system to identify a data source among the plurality of data sources upon encountering an Indicator of Compromise (IoC), the data source including a reference to the IoC; generating an IoC threat score for the IoC based on the output of the query via the processor, the generating comprising identifying an IoC threat value provided by the data source for each data source among the data sources; generating an adjusted IoC threat value for each data source among the data sources by assigning a multiplier to the IoC threat value provided by the data source, the multiplier being based on a reliability score associated with the data source; normalizing the adjusted IoC threat values from the data sources to output an IoC threat score; generating at least one executable security enhancement notification based on the IoC threat score via the processor; and displaying the IoC threat score and the executable security enhancement notification to a user via a user interface to enable triggering or disabling of at least one measure in the at least one executable security enhancement notification, the at least one measure being based on the IoC threat score.
[0091] Clause 2: The method of Clause 1, further comprising deploying an automated security response, the deploying including at least one of automatically adjusting a security threat threshold level, automatically reconfiguring a database or server to identify potential malware variants, sending notifications to a plurality of other users, exposing to IoCs of other tenant networks, determining a risk of future exposure, or isolating one or more tenant networks or portions of a network, or combinations thereof.
[0092] Clause 3: Classifying an IoC as malicious, unknown, or benign based on at least one of an IoC threat score, a generated confidence score, or a security threat threshold level, or a combination thereof, wherein the user interface can display the classification, further including the step of classifying, the method according to any one of Clauses 1 to 2.
[0093] Clause 4: The security threat threshold is automatically adjusted based on a ratio representing the accuracy or precision of the classification of the IoC as malicious or benign by using a ratio including at least two of the number of false positives, the number of true positives, the number of false negatives, and the number of true negatives, the method according to any one of Clauses 1 to 3.
[0094] Clause 5: Determining that an IoC is classified as a malicious threat and that the encountered IoC indicator shares a part of a set of features with other IoCs stored in the database or server, and identifying a new malware variant based on at least one of an IoC threat score, a part of the set of features, a generated confidence score, and a security threat threshold level, or a combination thereof, when determining the IoC as a malicious threat, further including the step of identifying, the method according to any one of Clauses 1 to 4.
[0095] Clause 6: Reconfiguring the database to identify a new malware variant based on at least one of an IoC feature, an IoC threat score, a generated confidence score, a security threat threshold level, or an IoC classification, or a combination thereof, further including the step of identifying, the method according to any one of Clauses 1 to 5.
[0096] Clause 7: An executable security enhancement notification includes an indicator of a new malware variant on the tenant network, and the new malware variant may be determined based on data of other malware, the method according to any one of Clauses 1 to 6.
[0097] Clause 8: Receiving data from a data source, wherein each data source of the data source is associated with at least one IoC, each data source defines a reliability score, the receiving, and indexing the data source and at least one IoC associated therewith in a database or a memory component, further comprising the method according to any one of Clauses 1 to 7.
[0098] Clause 9: The reliability score of each data source of the data source is determined by at least one of human involvement, the number of IoCs identified by the data source, the reliability history of the data source, the number of data inputs to the data source, the age of the data source, the age of the IoCs within the data source, the evaluation associated with the data source, the relevance to the client or user of the security system of the data source, and the amount of information available on the data source, the method according to any one of Clauses 1 to 8.
[0099] Clause 10: At least one executable security enhancement notification is based on at least one of an IoC threat score, a generated reliability score, or a security threat threshold level, or a combination thereof, the method according to any one of Clauses 1 to 9.
[0100] Clause 11: A query cross-references the identified DNS queries and IP addresses with a plurality of IoCs stored in a database, the plurality of IoCs including the IoCs, the cross-referencing, and identifying the associated data sources of the data source, the relevance of the associated data source being determined by association with the identified DNS queries and IP addresses of the associated data source, the identifying, the method according to any one of Clauses 1 to 10.
[0101] Clause 12: The method according to any one of Clauses 1 to 11, further comprising identifying DNS queries and IP addresses that are machine-contacted in a defined computing environment by querying.
[0102] Clause 13: The method according to any one of Clauses 1 to 12, further comprising generating an IoC threat score by identifying irregular IoC threat values and discarding the irregular IoC threat values.
[0103] Clause 14: The method according to any one of Clauses 1 to 13, wherein generating an IoC threat score includes weighting various IoC threat values from a data source having a specific reliability score relative to IoC threat values from a data source having a lower reliability score.
[0104] Clause 15: The method according to any one of Clauses 1 to 14, wherein generating an IoC threat score is performed by at least one of machine learning neural networks, and the input to the machine learning network includes the reliability score of the data source and the IoC threat values provided by the data source.
[0105] Clause 16: The method according to any one of Clauses 1 to 15, further comprising generating a convergence score associated with the IoC threat score based on the distribution of threat values provided by the data source.
[0106] Clause 17: A self - regulating security system directed to continuously enhancing one or more tenant networks, the system comprising a plurality of tenant networks and at least one Managed Security Service Provider (MSSP) server having a processor and a memory, wherein when the memory is executed by the processor, the processor queries at least one database or server upon encountering an Indicator of Compromise (IoC) by the security system, identifies a data feed using a reference to the IoC, generates an IoC threat score for the IoC based on the output of the query, the generating comprising, for each data feed of the data feeds, identifying an IoC threat value classified by the data feed, and for each data feed of the data feeds, adding a multiplier to the IoC threat value to generate an adjusted IoC threat value, the multiplier being determined based on a reliability score associated with the data feed, generating, normalizing the adjusted IoC threat values of the data feeds, outputting the IoC threat score, generating at least one executable security enhancement notification based on the IoC threat score, and displaying, on at least one display device connected to the MSSP server via a user interface, the IoC threat score and the executable security enhancement notification to a user of the security system, enabling triggering or disabling of at least one measure in the at least one executable security enhancement notification, the at least one measure being based on the IoC threat score, a method comprising storing instructions effective to cause the performance of the foregoing.
[0107] Clause 18: The self - regulating security system of claim 17, wherein the executable security enhancement notification includes a display of a new malware variant on at least one of the plurality of tenant networks, the new malware variant being determined based on other malware data.
[0108] Clause 19: When executed by a processor, the stored instructions cause the processor to automatically adjust a security threat threshold level, automatically reconfigure a database or server to identify other potential malware variants, send notifications to multiple other users of the security system, determine the exposure or risk of exposure to new malware variants in other tenant networks, and isolate at least one of the multiple tenant networks, and introduce an automated security response including at least one of the foregoing, for the autonomous security system of claim 17, configured to perform the foregoing.
[0109] Clause 20: A method for autonomously enhancing the security of a tenant network, the method comprising, upon encountering an Indicator of Compromise (IoC) by a security system within the tenant network of multiple tenant networks, querying a security server to identify a data feed including at least one reference to the IoC, generating an IoC threat score for the IoC based on the result of the query via a processor, deploying an automated security response by the security system based on the IoC threat score, and displaying to a user of the security system at least one of the IoC threat score, the status of the automated security response, or an actionable security enhancement notification via a user interface, the actionable security enhancement notification facilitating a trigger for additional security responses.
[0110] All patents, patent applications, publications, or other disclosure materials described herein are hereby incorporated by reference in their entirety as if each individual reference were explicitly incorporated by reference. All references, and any materials or portions thereof, that are said to be incorporated by reference herein are incorporated herein only to the extent that the incorporated materials do not conflict with existing definitions, descriptions, or other disclosure materials set forth in this disclosure. Therefore, and to the extent necessary, the disclosure set forth herein supersedes any conflicting materials incorporated by reference herein, and the disclosure is set forth explicitly within the context of this application.
[0111] Various exemplary and illustrative aspects are described. The aspects described herein are to be understood as providing exemplary features of various details of the various aspects of the disclosure, and thus, unless otherwise specified, it is of course possible to combine, separate, exchange, and / or re-arrange one or more features, elements, components, ingredients, raw materials, structures, modules, and / or aspects of the aspects of the disclosure, without departing from the scope of the disclosure, to the extent possible. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the exemplary aspects can be made without departing from the claimed subject matter. Furthermore, those skilled in the art can recognize or confirm many equivalents to the various aspects of the disclosure using only routine experimentation by reexamining this specification. Therefore, the disclosure is not limited by the description of the various aspects, but only by the claims.
[0112] Those skilled in the art will generally recognize that terms used herein, and particularly in the appended claims (e.g., the body of the appended claims), are generally intended to be terms that are "open-ended" (e.g., the term "including" should be construed as "including but not limited to", the term "having" should be construed as "having at least", the term "includes" should be construed as "including but not limited to", etc.). It will be further understood by those skilled in the art that where a specific number of introduced claim limitations is intended, such intent is expressly recited in the claims, and where there is no such recitation, no such intent exists. For example, by way of illustration, the following appended claims may include the use of introductory phrases "at least one" and "one or more" to introduce claim limitations. However, the use of such phrases should not be construed as implying that the introduction of a claim limitation by the indefinite article "a" or "an" limits any particular claim that includes such introduced claim limitation to a claim that includes only one such limitation, and the same is true for the use of definite articles used to introduce claim limitations even where the same claim includes introductory phrases "one or more" or "at least one", and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should generally be construed as meaning "at least one" or "one or more").
[0113] Furthermore, even if a specific number of the recited introduced claims is explicitly recited, one of ordinary skill in the art will recognize that such a recitation should typically be interpreted to mean at least the recited number (e.g., a mere recitation of "two recitations" would normally mean at least two recitations or more than two recitations without other qualifying language). Further, in these instances where a convention similar to "at least one of A, B, and C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). In instances where a convention similar to "at least one of A, B, or C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). It will be further understood by those of skill in the art that in any of the description, claims, or drawings, disjunctive and / or phrases presenting two or more alternative terms will typically be understood to contemplate the possibility of including one of the terms, any of the terms, or both terms, unless the context indicates otherwise. For example, the phrase "A or B" would typically be understood to include the possibility of "A" or "B" or "A and B".
[0114] Regarding the appended claims, those skilled in the art will understand that the operations listed therein may generally be performed in any order. Also, although the claims are presented in sequential order, it should be understood that the various operations may be performed in other orders than those described, or simultaneously. Examples of such alternative orders include, unless the context otherwise indicates, repetition, interleaving, interruption, reordering, incrementing, preparation, supplementation, simultaneity, reversal, or other variant orders. Further, unless the context otherwise indicates, terms such as "responding", "relating", or other past participles generally do not intend to exclude such variants.
[0115] It should be noted that any reference to "an aspect", "an embodiment", "one embodiment", "aspect", "exemplification", "one exemplification", and the like means that the particular features, structures, or characteristics described in relation to the aspect are included in at least one aspect. Thus, the appearances of the phrases "in one aspect", "in an aspect", "in an exemplification", and "in one exemplification" at various places throughout this specification do not necessarily all refer to the same aspect. Further, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.
[0116] As used herein, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" include plural references.
[0117] For example, without limitation, directional terms used herein such as up, down, left, right, below, above, front, back, and variations thereof relate to the orientation of the elements shown in the accompanying drawings and are not limiting with respect to the claims unless otherwise explicitly stated.
[0118] As used herein, the terms "about" or "approximately" mean an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the terms "about" or "approximately" mean within 1, 2, 3, or 4 standard deviations. In certain embodiments, the terms "about" or "approximately" mean within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.
[0119] As used herein, unless otherwise indicated, all numerical parameters are to be construed as being preceded by the term "about," which in all cases means that the numerical parameter has the inherent variability of the underlying measurement technique used to determine the value of the parameter. At a minimum, and not as an attempt to limit the application of the doctrine of equivalents to the claims, each numerical parameter herein should at least be construed in light of the reported number of significant digits and by applying ordinary rounding techniques.
[0120] Any numerical range recited herein includes all sub-ranges subsumed within the recited range. For example, a range of "1 to 100" includes all sub-ranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., all sub-ranges having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the endpoints of the recited range. For example, a range of 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, Applicants reserve the right to amend this specification, including the claims, to expressly recite sub-ranges that are subsumed within the ranges expressly recited herein. All such ranges are inherently described herein.
[0121] Any patent application, patent, non-patent publication, or other disclosure material mentioned in this specification and / or listed in any application data sheet is incorporated herein by reference to the extent that the incorporated material is not inconsistent with this specification. Accordingly, and to the extent necessary, the present disclosure as expressly set forth herein prevails over any conflicting material incorporated herein by reference. Although said to be incorporated herein by reference, any material or portion thereof that conflicts with an existing definition, statement, or other disclosure material set forth herein is incorporated only to the extent that no conflict arises between the incorporated material and the existing disclosure material.
[0122] The terms "comprise" (and any form of comprise such as "comprises", "comprising", etc.), "have" (and any form of have such as "has", "having", etc.), "include" (and any form of include such as "includes", "including", etc.), and "contain" (and any form of contain such as "contains", "containing", etc.) are open-ended conjunctive verbs. As a result, a system that "comprises", "has", "includes", or "contains" one or more elements possesses those one or more elements but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises", "has", "includes", or "contains" one or more features possesses those one or more features but is not limited to possessing only those one or more features.
[0123] The foregoing detailed description has described various forms of devices and / or processes by use of block diagrams, flowcharts, and / or examples. Where such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each such function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented individually and / or collectively by a wide variety of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented as one or more computer programs operating on one or more computers (e.g., as one or more programs operating on one or more computer systems), as one or more programs operating on one or more processors (e.g., as one or more programs operating on one or more microprocessors), as firmware, or can be integrated circuit implemented in whole or in part equivalently as substantially any combination thereof, and that circuit design, and / or description of software code, and also firmware, are within the scope of the skill of those skilled in the art in light of the present disclosure. Further, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal carrying medium used to actually carry out the distribution.
[0124] The instructions used to program the logic to implement the various disclosed aspects may be stored in memory within a system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Further, the instructions may be distributed via a network or via other computer-readable media. Thus, a machine-readable medium is any mechanism, but not limited to, for storing or transmitting information in a form readable by a machine (e.g., a computer), such as floppy disks, optical disks, compact disks, read only memory (CD-ROM), and magneto-optical disks, read only memory (ROM), random access memory (RAM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), magnetic or optical cards, flash memory, or tangible machine-readable storage devices used to transmit information over the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Thus, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).
[0125] When used in any aspect of this specification, the term "control circuit" can refer to, for example, a wired circuit, a programmable circuit (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA)), a state machine circuit, firmware that stores instructions executed by a programmable circuit, and any combination thereof. The control circuit can be embodied, collectively or individually, as part of a larger system, such as an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuit" includes, but is not limited to, an electrical circuit having at least one discrete electrical circuit, an electrical circuit having at least one integrated circuit, an electrical circuit having at least one application specific integrated circuit, an electrical circuit forming a general purpose computing device configured by a computer program (e.g., a general purpose computer configured by a computer program that at least partially executes a process, and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process, and / or a device described herein), an electrical circuit forming a memory device (e.g., in the form of a random access memory), and / or an electrical circuit forming a communication device (e.g., a modem, a communication switch, or an optoelectronic device). One of ordinary skill in the art will recognize that the subject matter described herein can be implemented in an analog or digital manner or some combination thereof.
[0126] When used in any aspect of this specification, the term "logic" can refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software can be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware can be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) within a memory device.
[0127] When used in any aspect of this specification, terms such as "component", "system", "module", etc. can refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.
[0128] When used in any aspect of this specification, "algorithm" refers to a self-consistent order of steps that produces a desired result, and "step" refers to an operation on a physical quantity and / or a logical state that can, although not necessarily, take the form of an electrical or magnetic signal that can be stored, moved, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms may be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.
Claims
1. A method for autonomously enhancing the security of a tenant network via a managed security service provider (MSSP) server comprising a processor and a memory, the method comprising: using information from a plurality of data sources, querying a database or server via the processor to identify a data source among the plurality of data sources upon encountering an indicator of compromise (IoC) by a security system, the data source including a reference to the IoC; generating an IoC threat score for the IoC based on the output of the query via the processor; identifying an IoC threat value provided by each data source among the plurality of data sources; generating an adjusted IoC threat value for each data source among the plurality of data sources by assigning a multiplier to the IoC threat value provided by the data source, the multiplier being based on a reliability score associated with the data source; normalizing the adjusted IoC threat values from the data sources to output the IoC threat score; comprising the generating; generating, via the processor, at least one executable security enhancement notification based on the IoC threat score; displaying, via a user interface, the IoC threat score and the executable security enhancement notification to a user, enabling triggering or invalidation of at least one measure in the at least one executable security enhancement notification, the at least one measure being based on the IoC threat score; comprising the method.
2. The method further comprises deploying an automated security response, the deploying comprising: automatically adjusting a security threat threshold level; automatically reconfiguring the database or server to identify potential malware variants; sending notifications to a plurality of other users; determining whether other tenant networks are or will be exposed to the IoC; or isolating one or more tenant networks or portions of a network. including at least one of, or a combination of, them The method according to claim 1.
3. The method further comprises classifying the IoC as malicious, unknown, or benign based on at least one of the IoC threat score, the generated reliability score, or the security threat threshold level, or a combination of them, The user interface can display the classification. The method according to claim 1.
4. The security threat threshold level is automatically adjusted based on a ratio representing the accuracy or precision of the classification of the IoC as malicious or benign by using a ratio including at least two of the number of false positives, the number of true positives, the number of false negatives, and the number of true negatives. The method according to claim 3.
5. The method determining that the IoC is classified as a malicious threat and that the encountered IoC indicator shares a portion of a set of features with other IoCs stored in the database or server, identifying a new malware variant based on at least one of the IoC threat score, the portion of the set of features, the generated reliability score, and the security threat threshold level, or a combination of them when determining the IoC as the malicious threat, The method according to claim 1, further comprising.
6. The method according to claim 5, further comprising reconfiguring the database to identify the new malware variant based on at least one of one of the features of the IoC, the IoC threat score, the generated reliability score, the security threat threshold level, or the classification of the IoC, or a combination of them.
7. The executable security enhancement notification includes an indicator of a new malware variant on the tenant network, and the new malware variant can be determined based on data of other malware. The method according to claim 1.
8. The method receiving data from each data source of the data sources, each data source being associated with at least one IoC, and each data source defining a reliability score. Indexing the data sources and at least one IoC associated therewith in a database or a memory component; The method according to claim 1, further comprising. Claim 9 The reliability score of each data source of the data sources is determined by at least one of human involvement, the number of IoCs identified by the data source, the reliability history of the data source, the number of data inputs to the data source, the number of years of the data source, the number of years of the IoCs in the data source, the evaluation associated with the data source, the relevance to the client or the user of the security system of the data source, and the amount of information available on the data source. The method according to claim 1. Claim 10 The at least one executable security enhancement notification is based on at least one of the IoC threat score, the generated reliability score, or a security threat threshold level, or a combination thereof. The method according to claim 1. Claim 11 Said querying is Cross-referencing the identified DNS queries and IP addresses with a plurality of IoCs stored in the database, wherein the plurality of IoCs includes the IoCs; Identifying related data sources of the data source, wherein the relevance of the related data sources is determined by the association of the related data sources with the identified DNS queries and IP addresses; The method according to claim 1, comprising. Claim 12 The method according to claim 11, wherein said querying further comprises identifying DNS queries and IP addresses contacted by a machine in a defined computing environment. Claim 13 The generation of the IoC threat score is Identifying irregular IoC threat values; Discarding the irregular IoC threat values; The method according to claim 1, further comprising. Claim 14 The generation of the IoC threat score comprises weighting various IoC threat values from data sources having a specific reliability score against IoC threat values from data sources having a lower reliability score. The method according to claim 1. Claim 15 The generation of the IoC threat score is performed by at least one of the machine learning neural networks, and the input to the machine learning neural network comprises the reliability score of the data source and the IoC threat value provided by the data source. The method according to claim 1.
16. The method further comprises generating a convergence score associated with the IoC threat score based on the distribution of the IoC threat values provided by the data source. The method according to claim 1.
17. An autonomous security system directed to continuously strengthen one or more tenant networks, the system comprising: A plurality of tenant networks; At least one managed security service provider (MSSP) server comprising a processor and a memory; Comprising; When executed by the processor, the memory causes the processor to: Query at least one database or server upon encountering an indicator of compromise (IoC) with the security system and identify a data feed using the reference to the IoC; Generating an IoC threat score for the IoC based on the output of the query; For each data feed of the data feed, identifying an IoC threat value classified by the data feed; For each data feed of the data feed, adding a multiplier to the IoC threat value to generate an adjusted IoC threat value, the multiplier being determined based on a reliability score associated with the data feed; generating; and Normalizing the adjusted IoC threat values of the data feed; and Outputting the IoC threat score; Comprising the generation; Generating at least one executable security enhancement notification based on the IoC threat score; Displaying, via a user interface, on at least one display device connected to the MSSP server, the IoC threat score and the executable security enhancement notification to a user of the security system, enabling triggering or invalidation of at least one measure in the at least one executable security enhancement notification, wherein the at least one measure is based on the IoC threat score; Storing instructions for execution; A method.
18. The executable security enhancement notification includes display of a new malware variant on at least one tenant network of the plurality of tenant networks; The new malware variant is determined based on other malware data; The autonomous security system according to claim 17.
19. When executed by the processor, the stored instructions are further configured to cause the processor to perform an automatic security response deployment, the deployment including: Automatically adjusting a security threat threshold level; Automatically reconfiguring a database or server to identify other potential malware variants; Sending notifications to a plurality of other users of the security system; Determining that other tenant networks are exposed to or at risk of being exposed to the new malware variant; Isolating at least one of the plurality of tenant networks; Including at least one of; The autonomous security system according to claim 17.
20. A method for autonomously enhancing the security of a tenant network, the method comprising: Querying a security server to identify a data feed with at least one reference to the IoC upon encountering an Indicator of Compromise (IoC) by a security system within a tenant network of a plurality of tenant networks; Generating, via a processor, an IoC threat score for the IoC based on the result of the query; Deploying an automatic security response by the security system based on the IoC threat score; Displaying, via a user interface, to a user of the security system, at least one of the IoC threat score, the status of the automated security response, or an actionable security enhancement notification; comprising; wherein the actionable security enhancement notification facilitates a trigger for an additional security response; a method.
Citation Information
Patent Citations
Tenant self-service troubleshooting for multi-tenant identity and data security management cloud services
JP2019531534A
Network surveillance and security system
US20030051026A1
Automatically preventing and remediating network abuse
US20170006053A1
Device vulnerability management
US20180351987A1
Autonomous monitoring of applications in a cloud environment
US20220174097A1