IP Library Granted Patent US 10,462,178
Granted Patent B2
US 10,462,178 · App. 14/450,509 · Granted Oct 29, 2019

Security countermeasure management platform

Inventors: Michael S. Curtis (Coppell, TX); Audian H. Paxson (Allen, TX); Eva E. Bunker (Richardson, TX); Nelson W. Bunker (Plano, TX); Kevin M. Mitchell (Plano, TX)
Assignee: Alert Logic, Inc.
H04L63/1441G06F21/577H04L63/0263H04L63/1433G06F2221/2151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,462,178
App. No.
14/450,509
Granted
Oct 29, 2019
Kind
B2
Abstract

A management platform that allows security and compliance users to view risks and vulnerabilities in their environment with the added context of what other mitigating security countermeasures are associated with that vulnerability and that are applicable and/or available within the overall security architecture. Additionally, the platform allows users to take one or more actions from controlling the operation of a security countermeasure for mitigation purposes to documenting the awareness of a security countermeasure that is in place.

Claims (31)

1. A method to improve an operation of a countermeasure computing system in a computing environment, comprising:

configuring a set of agents to collect information security risk data from one or more sources in the computing environment;

implementing a security countermeasure workflow to address a security exposure identified by the information security risk data from one or more sources by:

receiving the information security risk data from one or more sources in each of one or more distinct risk categories, each risk category associated with a distinct type;

augmenting the received information security risk data with other data to generate an aggregate risk entity, the other data being one of: information security standards data, and risk impact attribute data;

processing the aggregate risk entity against a vulnerability-to-countermeasure knowledge base that includes countermeasure attribute data to discover, with respect to the aggregate risk entity, one or more countermeasures applicable to address a security exposure as represented in the aggregate risk entity, the vulnerability-to-countermeasure knowledge base grouping vulnerabilities to impact categories that correspond to countermeasures; and

with respect to particular security exposure represented in the aggregate risk entity, presenting information regarding the one or more countermeasures, the information identifying (i) an expected cost of implementing a countermeasure, (ii) an expected effectiveness of implementing a countermeasure, (iii) an indication of whether a countermeasure is available in the computing environment, (iv) a list of one or more recommended countermeasure configuration settings, and (v) when multiple countermeasures are identified, an ordered ranking of the multiple countermeasures according to their respective effectiveness; and

based at least in part on the security countermeasure workflow, controlling a countermeasure mechanism in the countermeasure computing system to address the security exposure by performing at least one of the one or more presented countermeasures.

2. The method as described in claim 1 further including:

receiving additional data defining a policy-based countermeasure workflow associated with the one or more countermeasures to address the particular security exposure represented in the aggregate risk; and

implementing the policy-based countermeasure workflow.

3. The method as described in claim 2 wherein the policy based countermeasure workflow provides for one of: control of the particular countermeasure for remediation of mitigation of the vulnerability risk, documentation of the particular countermeasure for awareness purposes, and documentation of the particular countermeasure for configuration, compliance, audit and reporting purposes.

4. The method as described in claim 1 wherein the vulnerability-to-countermeasure knowledge base comprises a set of countermeasure data that is organized as a taxonomy.

5. The method as described in claim 1 wherein the information security risk data is received from one or more sources in each of two or more distinct risk categories, the information security risk data from at least a source in a first risk category being distinct from an uncorrelated to the information security risk data from a source in a second risk category.

6. The method as described in claim 5 wherein at least two of the sources are located across multiple layers of the multi-later OSI protocol stack.

7. The method as described in claim 2 where in policy-based countermeasure workflow automates a process of discovering a risk and addressing the risk using one of the available countermeasures based on a defined policy.

8. The method as described in claim 1 wherein the sources are one of: a network vulnerability scanner, a web application scanner, a software security testing tool, a database scanner, a malware detector, an anti-virus scanner, a zero-day intelligence source, and a configuration assessment tool.

9. The method as described in claim 1 wherein the countermeasure mechanism is one of: a network-based IDS/IPS, a host-based IDS/IPS, a secure e-mail gateway, a secure web gateway, an integrated security appliance, a web application firewall, a network access control, an endpoint protection platform, a virtual private network, a switch, a router, an application control device, a data loss prevention (DLP) device, a managed file transfer device, a file integrity monitor, an e-mail encryption device, a database encryption device, and an application hardening and shield device.

10. The method as described in claim 1 wherein the indication of whether the countermeasure is available in the computing environment includes presenting as greyed-out an applicable but unavailable countermeasure.

11. A method to improve an operation of countermeasure computing system in a computing environment, comprising:

configuring a set of agents to collect information security risk data from one or more sources in the computing environment;

implementing a security countermeasure workflow to address a security exposure identified by the information security risk data collected from the one or more sources by:

receiving the information security risk data from one or more sources in each of one or more distinct risk categories, each risk category associated with a distinct type;

augmenting the received information security risk data with other data to generate an aggregate risk entity, the other data being one of: information security standards data, and risk impact attribute data;

processing the aggregate risk entity against a vulnerability-to-countermeasure knowledge base that includes countermeasure attribute data to discover, with respect to the aggregate risk entity, one or more countermeasures applicable to address a security exposure as represented in the aggregate risk entity, the vulnerability-to-countermeasure knowledge base grouping vulnerabilities to impact categories that correspond to countermeasures; and

with respect to a particular security exposure represented in the aggregate risk entity, providing information regarding the one or more countermeasures, the information identifying one of: (i) an expected cost of implementing a countermeasure, (ii) an expected effected of implementing a countermeasure, (iii) an indication of whether a countermeasure is available in the computing environment, (iv) a list of one or more recommended countermeasure configuration settings, and (v) when multiple countermeasures are identified, an ordered ranking of the multiple countermeasures according to their respective effectiveness; and

receiving additional data defining a policy-based countermeasure workflow associated with the one or more countermeasures to attempt to address the particular security exposure represented in the aggregate risk; and

based at least in the part on the policy-based security countermeasure workflow, controlling a countermeasure mechanism in the countermeasure computing system to address the security exposure by performing at least one of the one or more countermeasures.

12. The method as described in claim 11 wherein the sources are one of: a network vulnerability scanner, a web application scanner, a software security testing tool, a database scanner, a malware detector, an anti-virus scanner, a zero-day intelligence source, and a configuration assessment tool.

13. The method as described in claim 11 wherein the countermeasure mechanism is one of: a network-based IDS/IPS, a host-based IDS/IPS, a secure e-mail gateway, a secure web gateway, an integrated security appliance, a web application firewall, a network access control, an endpoint protection platform, a virtual private network, a switch, a router, an application control device, a data loss prevention (DLP) device, a managed file transfer device, a file integrity monitor, an e-mail encryption device, a database encryption device, and an application hardening and shielding device.

14. The method as described in claim 11 wherein the indication of whether the countermeasure is available in the computing environment includes presenting as greyed-out an applicable but unavailable countermeasure.

Assignments (16)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST Recorded Jan 27, 2026
From: ARES CAPITAL CORPORATION
To: ALERT LOGIC LLC
Reel/Frame 073599/0576 →
RELEASE OF SECURITY INTEREST Recorded Jan 27, 2026
From: JEFFERIES FINANCE LLC
To: ALERT LOGIC LLC
Reel/Frame 073599/0498 →
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0001 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0758 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: ALERT LOGIC, INC.
Reel/Frame 073664/0050 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0757 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0555 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: ALERT LOGIC, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0758 →
SECURITY INTEREST Recorded Mar 20, 2020
From: ALERT LOGIC, INC.
To: PACIFIC WESTERN BANK
Reel/Frame 052203/0073 →
MERGER Recorded Jul 10, 2019
From: ACHILLES GUARD, INC. (D/B/A CRITICAL WATCH)
To: ALERT LOGIC, INC.
Reel/Frame 049717/0097 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2014
From: CURTIS, MICHAEL S; PAXSON, AUDIAN H.; BUNKER, EVA E.; BUNKER, NELSON W.; MITCHELL, KEVIN M.
To: ACHILLES GUARD, INC. D/B/A CRITICAL WATCH
Reel/Frame 033455/0186 →
Continuity (3)
Continuation 13371405 · Feb 11, 2012
Provisional Application 61441673 · Feb 11, 2011
Related Publication 20140344940A1 · Nov 20, 2014