GLOBAL BLOCKLIST CURATION BASED ON CROWDSOURCED INDICATORS OF COMPROMISE

    公开(公告)号:US20240333671A1

    公开(公告)日:2024-10-03

    申请号:US18621695

    申请日:2024-03-29

    申请人: KnowBe4, Inc.

    IPC分类号: H04L51/212 H04L51/42

    CPC分类号: H04L51/212 H04L51/42

    摘要: Systems and methods are described herein for global blocklist curation based on crowdsourced indicators of compromise (IoC). One or more servers store the messages reported as suspicious into a message collection system. The server(s) classify he messages as one of clean, spam or threat. The server(s)) tag the messages responsive to the classification and determine a plurality of IoC from the messages classified and tagged as a threat. The server(s) determine one or more metrics for each of the plurality of IoC and selected, based at least on the one or more metrics, one or more of the plurality of IoC as blocklist entry (BLE) candidates.

    BLOCKLIST GENERATION SYSTEM BASED ON REPORTED THREATS

    公开(公告)号:US20240236098A1

    公开(公告)日:2024-07-11

    申请号:US18533517

    申请日:2023-12-08

    申请人: KnowBe4, Inc.

    IPC分类号: H04L9/40

    CPC分类号: H04L63/101

    摘要: Described herein are systems and methods to provide for blocklist recommendations based on reported threats. In an example embodiment, a method is described for receiving a selection of one or more messages from a plurality of messages identified as threats and identifying, based at least on the one or more messages, one or more candidate blocklist entries (BLEs). The method further includes determining, based at least on the one or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist. The method includes adding, by the one or more servers, the one or more BLEs to the blocklist, where the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.