IP Library Granted Patent US 11,509,692
Granted Patent B2
US 11,509,692 · App. 16/020,287 · Granted Nov 22, 2022

Creation and optimization of security applications for cyber threats detection, investigation and mitigation

Inventors: Rami Cohen (Haifa, IL); Avi Chesla (Tel-Aviv, IL)
Assignee: Cybereason Inc.
H04L63/20H04L41/0823H04L41/0893H04L63/14H04L41/0816H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,692
App. No.
16/020,287
Granted
Nov 22, 2022
Kind
B2
Abstract

A system and method for optimizing a defense model using available security capabilities are provided. The method includes obtaining a defense model and an optimal security application implementation associated with the defense model; evaluating available security capabilities deployed in an enterprise environment to determine a plurality of variant security applications implementing the defense model; determining a quality score for each of the plurality of the variant security applications; selecting, from the plurality of variant security applications, a variant security application having a highest quality score; and executing the selected variant security application.

Claims (44)

1. A method for optimizing a defense model using available security capabilities, comprising:

obtaining a defense model, wherein the defense model defines a defense behavior with respect to an identified threat;

obtaining a security application implementation of the defense model comprising a probability of success above a predetermined value, wherein an optimal security application implementation defines an optimal set of security engines;

evaluating available security capabilities deployed in an enterprise environment to determine a plurality of variant security applications implementing the defense model by generating a list of currently available security engines and their respective quality scores based on a performance score of each security engine defined in each of the variant security applications, wherein each variant security application includes at least one of a subset of the optimal set of the security engines and alternative for security engines included the optimal set of the security engines, wherein the performance score is based on at least one of an offline score determined by an attack database of a respective security product, a runtime score determined by attack logs provided by the respective security product, or a unified score determined by the offline score and the runtime score;

determining a quality score for each variant security application of the plurality of variant security applications, the quality score reflecting a level of protection each variant security application offers against the identified threat;

selecting, from the plurality of variant security applications, a variant security application having a highest quality score; and

executing the selected variant security application to respond to the identified threat.

2. The method of claim 1 , further comprising: deploying the selected variant security application in the enterprise environment.

3. The method of claim 1 , wherein the defense model is predefined and stored in a data repository.

4. The method of claim 2 , wherein each variant security application maintains a logical structure of the security application implementation of the defense model.

5. The method of claim 1 , wherein the selected variant security application provides a unified abstract representation that is agnostic to security products used for detection and mitigation of cyber threats.

6. The method of claim 1 , further comprising:

monitoring the available security capabilities periodically during the execution of the selected variant security application to identify any changes; and

optimizing the selected variant security application during the execution when changes in the available security capabilities are detected.

7. The method of claim 1 , wherein the optimal set of security engines are operable in an orchestration system deployed in the enterprise environment, wherein each security engine is associate with a security capability executed by a security product deployed in the enterprise environment.

8. The method of claim 7 , further comprising:

optimizing the defense model upon a failure of the security product.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for optimizing a defense model using available security capabilities, the process comprising:

obtaining a defense model, wherein the defense model defines a defense behavior with respect to an identified threat;

obtaining a security application implementation of the defense model comprising a probability of success above a predetermined value, wherein an optimal security application implementation defines an optimal set of security engines;

evaluating available security capabilities deployed in an enterprise environment to determine a plurality of variant security applications implementing the defense model by generating a list of currently available security engines and their respective quality scores based on a performance score of each security engine defined in each of the variant security applications, wherein each variant security application includes at least one of a subset of the optimal set of the security engines and alternative for security engines included the optimal set of the security engines, wherein the performance score is based on at least one of an offline score determined by an attack database of a respective security product, a runtime score determined by attack logs provided by the respective security product, or a unified score determined by the offline score and the runtime score;

determining a quality score for each variant security application of the plurality of variant security applications, the quality score reflecting a level of protection each variant security application offers against the identified threat;

selecting, from the plurality of variant security applications, a variant security application having a highest quality score; and

executing the selected variant security application to respond to the identified threat.

10. A system for optimizing a defense model using available security capabilities, comprising:

a processing circuitry; and

a memory coupled to the processing circuitry, the memory contains therein instructions that when executed by the processing circuitry configure the system to:

obtain a defense model, wherein the defense model defines a defense behavior with respect to an identified threat;

obtain a security application implementation of the defense model comprising a probability of success above a predetermined value, wherein an optimal security application implementation defines an optimal set of security engines;

evaluate available security capabilities deployed in an enterprise environment to determine a plurality of variant security applications implementing the defense model by generating a list of currently available security engines and their respective quality scores based on a performance score of each security engine defined in each of the variant security applications, wherein each variant security application includes at least one of a subset of the optimal set of the security engines and alternative for security engines included the optimal set of the security engines, wherein the performance score is based on at least one of an offline score determined by an attack database of a respective security product, a runtime score determined by attack logs provided by the respective security product, or a unified score determined by the offline score and the runtime score;

determine a quality score for each variant security application of the plurality of variant security applications, the quality score reflecting a minimum level of protection each variant security application offers against the identified threat;

select, from the plurality of variant security applications, a variant security application having a highest quality score; and

execute the selected variant security application to respond to the identified threat.

11. The system of claim 10 , wherein the system is further configured to:

deploy the selected variant security application in the enterprise environment.

12. The system of claim 10 , wherein the defense model is predefined and stored in a data repository.

13. The system of claim 11 , wherein each variant security application maintains a logical structure of the security application implementation of the defense model.

14. The system of claim 10 , wherein the selected variant security application provides a unified abstract representation that is agnostic to security products used for detection and mitigation of cyber threats.

15. The system of claim 10 , wherein the system is further configured to:

monitor the available security capabilities periodically during the execution of the selected variant security application to identify any changes; and

optimize the selected variant security application when changes in the available security capabilities are detected.

16. The system of claim 10 , wherein the security engines are operable in an orchestration system deployed in the enterprise environment, wherein each security engine is associate with a security capability executed by a security product deployed in the enterprise environment.

17. The system of claim 16 , wherein the system is further configured to:

optimize the defense model upon a failure of the security product.

Assignments (10)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 065316/0551 ) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0852 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
SUPPLEMENT NO. 2 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 23, 2023
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065316/0551 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: EMPOW CYBER SECURITY LTD.; EMPOW CYBER SECURITY INC.
To: CYBEREASON INC.
Reel/Frame 056792/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2018
From: COHEN, RAMI; CHESLA, AVI
To: EMPOW CYBER SECURITY LTD.
Reel/Frame 046217/0380 →
Continuity (2)
Provisional Application 62532130 · Jul 13, 2017
Related Publication 20190020686A1 · Jan 17, 2019
Cited By (1)
US 12,218,919