US 12,464,010 B2
Devices, systems, and methods for autonomous threat response and security enhancement
Ayal Reich, Ra'anana (IL); Leo Sojref, Jerusalem (IL); and Tal Blaustein, Ramat Gan (IL)
Assigned to BlueVoyant LLC, New York, NY (US)
Appl. No. 18/880,904
Filed by BlueVoyant LLC, New York, NY (US)
PCT Filed Jul. 26, 2023, PCT No. PCT/US2023/071061
§ 371(c)(1), (2) Date Jan. 3, 2025,
PCT Pub. No. WO2024/026371, PCT Pub. Date Feb. 1, 2024.
Claims priority of provisional application 63/369,582, filed on Jul. 27, 2022.
Prior Publication US 2025/0260715 A1, Aug. 14, 2025
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1441 (2013.01) [H04L 63/1433 (2013.01); H04L 2463/146 (2013.01)] 19 Claims
OG exemplary drawing
 
1. A method for autonomous security enhancement of a tenant network via a managed security service provider (MSSP) server comprising a processor and a memory, with information from a plurality of data sources, the method comprising:
querying, via the processor, a database or server, upon an encounter with an indicator of compromise (IoC) by a security system, to identify data sources of a plurality of data sources, wherein the data sources comprise references to the IoC;
generating, via the processor, based on an output of the querying, an IoC threat score for the IoC, wherein the generating comprises:
identifying, for each data source of the data sources, an IoC threat value provided by the data source;
assigning, for each data source of the data sources, a multiplier to the IoC threat value provided by the data source to produce an adjusted IoC threat value, wherein the multiplier is based on a reliability score associated with the data source; and
normalizing adjusted IoC threat values from the data sources to output the IoC threat score;
generating, via the processor, at least one actionable security enhancement notification based on the IoC threat score; and
displaying, via a user interface, the IoC threat score and the actionable security enhancement notification to a user, allowing triggering or disabling of at least one action in the at least one actionable security enhancement notification, the at least one action based on the IoC threat score.