The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 29, 2025

Filed:

Apr. 05, 2017
Applicants:

Staffan Truvé, Alingsås, SE;

Bill Ladd, Watertown, MA (US);

Inventors:

Staffan Truvé, Alingsås, SE;

Bill Ladd, Watertown, MA (US);

Assignee:

Recorded Future, Inc., Somerville, MA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2021.12); G06N 20/00 (2018.12); G06N 20/10 (2018.12); H04L 41/12 (2021.12); H04L 43/045 (2021.12); H04L 43/06 (2021.12); H04L 61/2503 (2021.12); H04L 61/4511 (2021.12); H04L 69/22 (2021.12);
U.S. Cl.
CPC ...
H04L 63/1416 (2012.12); G06N 20/00 (2018.12); G06N 20/10 (2018.12); H04L 41/12 (2012.12); H04L 43/045 (2012.12); H04L 43/06 (2012.12); H04L 61/2503 (2012.12); H04L 61/4511 (2022.04); H04L 63/1425 (2012.12); H04L 63/1433 (2012.12); H04L 63/20 (2012.12); H04L 69/22 (2012.12);
Abstract

A network security system includes a network interface configured to connect to a public wide area network and a first malicious activity detection subsystem configured to extract from textual sources on the network different threat levels in a first threat category for addresses on the wide area network. One or more further malicious activity detection subsystems are configured to extract from textual sources on the network different threat levels in one or more further threat categories. A weighting subsystem is configured to provide weighted threat levels for addresses on the wide area network for the first and further malicious activity detection subsystems. A scoring subsystem is responsive to the weighting subsystem to derive an aggregated, weighted threat score for each of the network addresses. An address proximity engine can determine a measure of logical proximity of network addresses independently of any measure of physical proximity between them.


Find Patent Forward Citations

Loading…