IP Library Granted Patent US 12712891
Granted Patent B2
US 12712891 · App. 18/640,805 · Granted Aug 18, 2026

Systems and methods for mitigation and remediation of cybersecurity threats

Inventors: Javier Fernando Vargas (Doral, FL); Claudio Deiro (Doral, FL); Mario Lobo (Doral, FL); Angelica Castañeda (Doral, FL); Ricardo Villadiego (Doral, FL)
Assignee: LUMU TECHNOLGIES, INC.
H04L63/1416H04L41/16H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712891
App. No.
18/640,805
Granted
Aug 18, 2026
Kind
B2
Abstract

A cybersecurity system for autonomous threat management within network environments may utilize one or more computing devices equipped with processors to operate a security agent. The security agent may receive indications of potential cybersecurity threats and conduct an analysis based on the threat's characteristics and context within the network. The security agent may evaluate one or more of the threat's type, risk level, and persistence, and determine associated conditions. Responsive actions (e.g., isolating network segments, blocking malicious traffic, deploying patches, modifying firewall rules, and/or alerting administrators, without requiring manual approval) may be autonomously determined and executed based on the evaluations. The security agent's adaptability may be enhanced by machine learning algorithms that refine threat assessments and responses over time, providing a dynamic defense mechanism against evolving cybersecurity threats.

Claims (43)

1 . One or more computing devices, comprising one or more processors, configured to:

receive, by a security agent of a cybersecurity system associated with a network, an indication of a cybersecurity threat associated with the network;

determine a type of the cybersecurity threat based on one or more characteristics associated with the cybersecurity threat and a context associated with the cybersecurity threat;

determine a risk level of the cybersecurity threat based on the one or more characteristics associated with the cybersecurity threat and the context associated with the cybersecurity threat;

determine a persistence of the cybersecurity threat based on detection of recurring activities or repeated attempts associated with the cybersecurity threat;

determine one or more conditions associated with the cybersecurity threat, wherein the one or more conditions comprises one or more conditional logic evaluating characteristics;

determine one or more actions based on a combination of the one or more conditions, the type, the risk level, and the persistence; and

execute, by the security agent, the one or more actions.

2 . The one or more computing devices of claim 1 , wherein the one or more actions include isolating one or more network segments associated with the cybersecurity threat.

3 . The one or more computing devices of claim 1 , wherein the one or more actions include blocking traffic to or from one or more identified malicious sources associated with the cybersecurity threat.

4 . The one or more computing devices of claim 1 , wherein the one or more actions are determined based on an artificial intelligence model.

5 . The one or more computing devices of claim 1 , wherein the one or more actions include modifying a firewall rule to block or allow traffic associated with the cybersecurity threat.

6 . The one or more computing devices of claim 1 , wherein the execution of the one or more actions is performed autonomously without requiring manual approval from a human operator.

7 . The one or more computing devices of claim 1 , wherein the determination of the type of the cybersecurity threat is based on a machine learning algorithm trained on characteristics of known cybersecurity threats.

8 . The one or more computing devices of claim 1 , wherein the one or more computing devices are further configured to update one or more operational parameters associated with the security agent.

9 . The one or more computing devices of claim 1 , wherein determining the persistence of the cybersecurity threat comprises monitoring ongoing activities related to the cybersecurity threat for a predefined period to identify recurring patterns or behaviors.

10 . The one or more computing devices of claim 1 , wherein determining the persistence of the cybersecurity threat comprises comparing the cybersecurity threat with a database of known cybersecurity threats.

11 . The one or more computing devices of claim 1 , wherein determining the persistence of the cybersecurity threat comprises analyzing historical data related to similar cybersecurity threats previously encountered in the network.

12 . The one or more computing devices of claim 1 , wherein the one or more computing devices are further configured to determine a time period associated with the indication of the cybersecurity threat, wherein determining the one or more actions is further based on the time period.

13 . The one or more computing devices of claim 1 , wherein the one or more conditions associated with the cybersecurity threat are determined based on one or more real-time analytics.

14 . The one or more computing devices of claim 1 , wherein the indication of the cybersecurity threat is received from one or more of an intrusion detection system, an intrusion prevention system, an endpoint detection and response system, or a security information and event management system.

15 . The one or more computing devices of claim 1 , wherein the one or more characteristics comprise one or more of a method of attack, a payload of the cybersecurity threat, or a target associated with the cybersecurity threat.

16 . The one or more computing devices of claim 1 , wherein the context associated with the cybersecurity threat comprises one or more of a network topology, a security configuration, active security measures, or a time of detection.

17 . A method performed by one or more computing devices, the method comprising:

receiving, by a security agent of a cybersecurity system associated with a network, an indication of a cybersecurity threat associated with the network;

determining a type of the cybersecurity threat based on one or more characteristics associated with the cybersecurity threat and a context associated with the cybersecurity threat;

determining a risk level of the cybersecurity threat based on the one or more characteristics associated with the cybersecurity threat and the context associated with the cybersecurity threat;

determining a persistence of the cybersecurity threat based on detection of recurring activities or repeated attempts associated with the cybersecurity threat;

determining one or more conditions associated with the cybersecurity threat, wherein the one or more conditions comprises one or more conditional logic evaluating characteristics;

determining one or more actions based on a combination of the one or more conditions, the type, the risk level, and the persistence; and

executing, by the security agent, the one or more actions.

18 . The method of claim 17 , wherein the one or more actions are determined based on an artificial intelligence model.

19 . The method of claim 17 , wherein the determination of the type of the cybersecurity threat is based on a machine learning algorithm trained on characteristics of known cybersecurity threats.

20 . A system comprising:

one or more processors; and

memory coupled with the one or more processors, the memory storing executable instructions that when executed by the one or more processors cause the one or more processors to effectuate operations comprising:

receiving, by a security agent of a cybersecurity system associated with a network, an indication of a cybersecurity threat associated with the network;

determining a type of the cybersecurity threat based on one or more characteristics associated with the cybersecurity threat and a context associated with the cybersecurity threat;

determining a risk level of the cybersecurity threat based on the one or more characteristics associated with the cybersecurity threat and the context associated with the cybersecurity threat;

determining a persistence of the cybersecurity threat based on detection of recurring activities or repeated attempts associated with the cybersecurity threat;

determining one or more conditions associated with the cybersecurity threat, wherein the one or more conditions comprises one or more conditional logic evaluating characteristics;

determining one or more actions based on a combination of the one or more conditions, the type, the risk level, and the persistence; and

executing, by the security agent, the one or more actions.