The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 10, 2020

Filed:

Jan. 18, 2016
Applicant:

Secureworks Corp., Wilmington, DE (US);

Inventors:

Doug M. Steelman, Woodstock, GA (US);

Todd Wiedman, Acworth, GA (US);

Kenneth A. Deitz, Atlanta, GA (US);

Berlene Herren, Fairburn, GA (US);

Edgar L. Deal, Gainsville, GA (US);

Thomas Clements, Kennesaw, GA (US);

Brian Miller, Woodstock, GA (US);

Assignee:

SecureWorks Corp., Wilmington, DE (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 17/18 (2006.01); G06F 21/55 (2013.01); G06F 21/57 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1433 (2013.01); G06F 17/18 (2013.01); G06F 21/552 (2013.01); G06F 21/577 (2013.01); H04L 63/0209 (2013.01); H04L 63/1491 (2013.01); H04L 2463/146 (2013.01);
Abstract

An information handling system performs a method for analyzing attacks against a networked system of information handling systems. The method includes detecting a threat indicator, representing the threat indicator in part by numerical parameters, normalizing the numerical parameters, calculating one or more measures of association between the threat indicator and other threat indicators, finding an association of the threat indicator with another threat indicator based upon the normalized numerical parameters, and assigning to the threat indicator a probability that a threat actor group caused the attack, wherein the threat actor group was assigned to the other threat indicator. In some embodiments, the normalizing may include transforming a distribution of the numerical parameters to a distribution with a standard deviation of 1 and a mean of 0. In some embodiments, the normalizing may include applying an empirical cumulative distribution function. In some embodiments, the one or more measures of association between the threat indicator and other threat indicators may include a Kendall's tau between the threat indicator and the other threat indicators, a covariance between the threat indicator and the other threat indicators; or a conditional entropy between the threat indicator and the other threat indicators.


Find Patent Forward Citations

Loading…