Associations among data records in a security information sharing platform

    公开(公告)号:US10764329B2

    公开(公告)日:2020-09-01

    申请号:US15760983

    申请日:2015-09-25

    Abstract: Examples disclosed herein relate to associations among data records in a security information sharing platform. Some examples may enable creating, in the security information sharing platform that enables sharing of security information among a plurality of users, an association between a first security indicator comprising a first observable and a first data record based on sightings of the first observable by at least one source entity associated with the first data record. Some examples may further enable obtaining a search query that specifies the first security indicator, and identifying a set of data records that satisfy the search query. The set of data records may include the first data record.

    Threat score determination
    2.
    发明授权

    公开(公告)号:US10896259B2

    公开(公告)日:2021-01-19

    申请号:US15763253

    申请日:2015-09-28

    Abstract: In one example in accordance with the present disclosure, a method for threat score determination includes detecting a change in malicious activity for a security object. The method also includes identifying an indicator that provides contextual information for the security object and determining a linked resource that is associated with a database record of the security object. The method also includes determining a first threat score associated with the security object and determining a relationship between the linked resource and the security object. The method also includes determining a second threat score associated with the linked resource based on the indicator, the threat score of the linked object and the relationship between the linked resource and the security object.

    ALERTS FOR COMMUNITIES OF A SECURITY INFORMATION SHARING PLATFORM

    公开(公告)号:US20180234458A1

    公开(公告)日:2018-08-16

    申请号:US15737878

    申请日:2015-06-26

    Abstract: Examples disclosed herein relate to alerts for communities of a security information sharing platform. Some examples may enable obtaining a security indicator from a user of a first community of a security information sharing platform that enables sharing of security information among a plurality of communities; including the security indicator in community-based security information associated with the first community, the first security indicator comprising a first observable; sharing the first security indicator with the security information sharing platform; obtaining, from the security information sharing platform, information related to sightings of the first observable; and providing a first alert to the first community based on the information related to the sightings of the first observable.

    SOURCE ENTITIES OF SECURITY INDICATORS
    4.
    发明申请

    公开(公告)号:US20200351292A1

    公开(公告)日:2020-11-05

    申请号:US16076274

    申请日:2016-02-12

    Abstract: Examples disclosed herein relate to source entities of security indicators. Some examples disclosed herein enable identifying, in a security information sharing platform, a security indicator that is originated from a source entity where the security indicator comprises an observable. Some examples further enable determining a reliability level of the source entity based on at least one of: security events, sightings of the observable, a first set of user feedback information that is submitted for the security indicator by users of the security information sharing platform, or a second set of user feedback information that is collected from external resources that are external to the security information sharing platform.

    Source entities of security indicators

    公开(公告)号:US11962609B2

    公开(公告)日:2024-04-16

    申请号:US16076274

    申请日:2016-02-12

    CPC classification number: H04L63/1433 H04L63/1408 H04L63/20

    Abstract: Examples disclosed herein relate to source entities of security indicators. Some examples disclosed herein enable identifying, in a security information sharing platform, a security indicator that is originated from a source entity where the security indicator comprises an observable. Some examples further enable determining a reliability level of the source entity based on at least one of: security events, sightings of the observable, a first set of user feedback information that is submitted for the security indicator by users of the security information sharing platform, or a second set of user feedback information that is collected from external resources that are external to the security information sharing platform.

    VISUALIZATION OF ASSOCIATIONS AMONG DATA RECORDS IN A SECURITY INFORMATION SHARING PLATFORM

    公开(公告)号:US20190050563A1

    公开(公告)日:2019-02-14

    申请号:US16076948

    申请日:2016-02-12

    Abstract: Examples disclosed herein relate to visualization of associations among data records in a security information sharing platform. Some examples may enable creating, in the security information sharing platform, an association between a first data record comprising a security indicator, and a second data record. Some examples may further enable providing a visual representation of the first data record, the second data record, and the association, wherein the first data record represents a first node in the visual representation, the second data record represents a second node in the visual representation, and the association represents an edge that connects the first node and the second node.

    Alerts for communities of a security information sharing platform

    公开(公告)号:US10693914B2

    公开(公告)日:2020-06-23

    申请号:US15737878

    申请日:2015-06-26

    Abstract: Examples disclosed herein relate to alerts for communities of a security information sharing platform. Some examples may enable obtaining a security indicator from a user of a first community of a security information sharing platform that enables sharing of security information among a plurality of communities; including the security indicator in community-based security information associated with the first community, the first security indicator comprising a first observable; sharing the first security indicator with the security information sharing platform; obtaining, from the security information sharing platform, information related to sightings of the first observable; and providing a first alert to the first community based on the information related to the sightings of the first observable.

Patent Agency Ranking