US20160057166A1

Cyber-security system and methods thereof for detecting and mitigating advanced persistent threats

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method and system for adaptively securing a protected entity against a potential advanced persistent threat (APT) are provided. The method includes probing a plurality of resources in a network prone to be exploited by an APT attacker; operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generating at least one security event respective of the output signals; determining if the at least one security event satisfies at least one workflow rule; and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.

US20160057166A1, drawing sheet 1
Sheet 1 of 13

Term

9.8 yearsto projected expiry

Projected expiry 9 July 2036, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

31 claims: 2 independent, 29 dependent

  1. 1
    Broadest claimClaim Score 59, broad(NHIP)A method for adaptively securing a protected entity against a potential advanced persistent threat (APT), comprising:probing a plurality of resources in a network prone to be exploited by an APT attacker;operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources;generating at least one security event respective of the output signals;determining if the at least one security event satisfies at least one workflow rule;and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.
  2. 17
    A system for adaptively securing a protected entity against a potential advanced persistent threat (APT), comprising:a processor;and a memory, the memory containing instructions that, when executed by the processor, configure the system to: probe a plurality of resources in a network prone to be exploited by an APT attacker;operate at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources;generate at least one security event respective of the output signals;determine if the at least one security event satisfies at least one workflow rule;and generate at least one action with respect to the potential APT attack, upon determining that the at least one security event satisfies the at least one workflow rule.