Patent 10397273 was granted and assigned to Amazon on August, 2019 by the United States Patent and Trademark Office.
Systems are provided for collecting threat intelligence to use in monitoring network activity in computing environments for malicious activity. The systems load sensors into compute resources associated with particular users of a compute resource virtualization platform. The systems receive network activity information sent by first and second sensors, identify an IP address as being a suspected source of malicious computing activity using aggregated the first and second network activity, and generate threat information that includes the IP address as a suspected source of malicious computing activity.