IP Library Granted Patent US 9,892,270
Granted Patent B2
US 9,892,270 · App. 14/952,069 · Granted Feb 13, 2018

System and method for programmably creating and customizing security applications via a graphical user interface

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,892,270
App. No.
14/952,069
Granted
Feb 13, 2018
Kind
B2
Abstract

A system and method for programmably creating a security application via a graphical user interface. The method comprises: causing a display of a service stage GUI window including at least one security phase zone; receiving a selection of at least one security service including at least one security decision engine; causing a display of an event rule stage window including at least one event rule parameters zone; receiving a selection of at least one event rule related to the at least one SDE; causing a display of an event relationship stage GUI window including at least one rule selection zone; receiving a selection of at least one workflow rule and at least one action; and configuring the security application based on the selected at least one work rule and the selected at least one action.

Claims (56)

1. A method for programmably creating a security application via a graphical user interface (GUI), comprising:

causing a display of a service stage GUI window including at least one security phase zone;

receiving, by the at least one security phase zone, a selection of at least one security service including at least one security decision engine (SDE);

causing a display of an event rule stage window including at least one event rule parameters zone;

receiving, by the at least one event rule parameters zone, a selection of at least one event rule related to the at least one SDE;

causing a display of an event relationship stage GUI window including at least one rule selection zone;

receiving, by the rule selection zone, a selection of at least one workflow rule and at least one action, wherein the at least one workflow rule and the at least one action defines the event relationship as determined by the at least one event rule; and

configuring the security application based on the selected at least one workflow rule and the selected at least one action.

2. The method of claim 1 , further comprising:

upon receiving the selections, generating the security application.

3. The method of claim 1 , wherein each security phase zone is associated with any of: a detection phase, an investigation phase, and a mitigation phase.

4. The method of claim 1 , wherein each selection is received via a user gesture by the user, wherein the user gesture includes at least one dragging and dropping of an icon into one of the zones.

5. The method of claim 1 , wherein each of the at least one action is any of: executing a security phase, executing one of the at least one security service, executing one of the at least one SDE, reporting information related to a potential security threat, ceasing execution of the at least one security service or the at least one SDE, creating a group event, terminating operation of the application, and resetting operation of the application.

6. The method of claim 5 , wherein the group event defines a correlation of events, further comprising:

receiving, by the rule selection zone, a selection of the group event.

7. The method of claim 1 , wherein the rule selection zone further allows a selection of at least one correlation rule, wherein each correlation rule defines the correlation between events generated by the at least one SDE.

8. The method of claim 7 , wherein the at least one action is performed based on the at least one workflow rule and the at least one correlation rule.

9. The method of claim 1 , further comprising:

generating a high-level programmable code based on the at least one security service, the at least one SDE, and the at least one rule selected via the GUI;

translating, by a security stack, the high-level programmable code into a set of instructions compatible with a plurality of network elements participating in each security phase associated with the at least one security phase zone; and

communicating the set of instructions to a plurality of respective drivers of the plurality of network elements.

10. The method of claim 1 , further comprising:

customizing the security application via the GUI.

11. A non-transitory computer readable medium having stored thereon instructions for causing one or more processing units to execute a method for programmably creating a security application via a graphical user interface (GUI), comprising:

causing a display of a service stage GUI window including at least one security phase zone;

receiving, by the at least one security phase zone, a selection of at least one security service including at least one security decision engine (SDE);

causing a display of an event rule stage window including at least one event rule parameters zone;

receiving, by the at least one event rule parameters zone, a selection of at least one event rule related to the at least one SDE;

causing a display of an event relationship stage GUI window including at least one rule selection zone;

receiving, by the rule selection zone, a selection of at least one workflow rule and at least one action, wherein the at least one workflow rule and the at least one action defines the event relationship as determined by the at least one event rule; and

configuring the security application based on the selected at least one workflow rule and the selected at least one action.

12. A system for programmably creating a security application via a graphical user interface (GUI), comprising:

a processing unit; and

a memory, the memory containing instructions that, when executed by the processing unit, configure the system to:

cause a display of a service stage GUI window including at least one security phase zone;

receive, by the at least one security phase zone, a selection of at least one security service including at least one security decision engine (SDE);

cause a display of an event rule stage window including at least one event rule parameters zone;

receive, by the at least one event rule parameters zone, a selection of at least one event rule related to the at least one SDE;

cause a display of an event relationship stage GUI window including at least one rule selection zone;

receive, by the rule selection zone, a selection of at least one workflow rule and at least one action, wherein the at least one workflow rule and the at least one action defines the event relationship as determined by the at least one event rule; and

configure the security application based on the selected at least one work rule and the selected at least one action.

13. The system of claim 12 , wherein the system is further configured to:

upon receiving the selections, generate the security application.

14. The system of claim 12 , wherein each security phase zone is associated with any of: a detection phase, an investigation phase, and a mitigation phase.

15. The system of claim 12 , wherein each selection is received via a user gesture by the user, wherein the user gesture includes at least one dragging and dropping of an icon into one of the zones.

16. The system of claim 12 , wherein each of the at least one action is any of: executing a security phase, executing one of the at least one security service, executing one of the at least one SDE, reporting information related to a potential security threat, ceasing execution of the at least one security service or the at least one SDE, creating a group event, terminating operation of the application, and resetting operation of the application.

17. The system of claim 16 , wherein the system is further configured to:

receive, by the rule selection zone, a selection of the group event.

18. The system of claim 12 , wherein the rule selection zone further allows a selection of at least one correlation rule, wherein each correlation rule defines the correlation between events generated by the at least one SDE.

19. The system of claim 18 , wherein the at least one action is performed based on the at least one workflow rule and the at least one correlation rule.

20. The system of claim 12 , wherein the system is further configured to:

generate a high-level programmable code based on the at least one security service, the at least one SDE, and the at least one rule selected via the GUI;

translate, by a security stack, the high-level programmable code into a set of instructions compatible with a plurality of network elements participating in each security phase associated with the at least one security phase zone; and

communicate the set of instructions to a plurality of respective drivers of the plurality of network elements.

21. The system of claim 12 , wherein the system is further configured to:

customize the security application via the GUI.

Assignments (8)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: EMPOW CYBER SECURITY LTD.; EMPOW CYBER SECURITY INC.
To: CYBEREASON INC.
Reel/Frame 056792/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2015
From: CHESLA, AVI
To: EMPOW CYBER SECURITY LTD.
Reel/Frame 037141/0122 →