IP Library Granted Patent US 10,735,444
Granted Patent B2
US 10,735,444 · App. 16/432,711 · Granted Aug 4, 2020

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/1416G06F8/65G06F21/53G06F21/55G06F21/554G06F21/56G06F21/561G06F21/562G06F21/566G06F21/568G06F21/577G06F30/20G06K9/6256G06N20/00H04L63/0227H04L63/0263H04L63/145H04L63/1425H04L63/1433H04L63/1441H04L63/164H04L63/20G06F2221/034G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,735,444
App. No.
16/432,711
Granted
Aug 4, 2020
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: detecting a security event within a computing platform based upon identified suspect activity; gathering artifacts concerning the security event; and assigning a threat level to the security event based, at least in part, upon the gathered artifacts.

Claims (66)

1. A computer-implemented method, executed on a computing device, comprising:

detecting a security event within a computing platform based upon identified suspect activity;

gathering artifacts concerning the security event;

assigning a threat level to the security event based, at least in part, upon the gathered artifacts; and

allowing a third-party to manually search the artifacts concerning the security event after the artifacts have been gathered, including:

obtaining at least one security-relevant information set from each of a plurality of security-relevant subsystems; and

combining the plurality of security-relevant information sets, including homogenizing the plurality of security-relevant information sets to have one or more of a common format, a common nomenclature, and a common structure.

2. The computer-implemented method of claim 1 wherein detecting a security event within a computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

3. The computer-implemented method of claim 1 wherein gathering artifacts concerning the security event includes:

gathering artifacts concerning the security event from a plurality of sources associated with the computing platform.

4. The computer-implemented method of claim 1 wherein assigning a threat level to the security event includes:

assigning a threat level using artificial intelligence and machine learning.

5. The computer-implemented method of claim 1 further comprising:

executing a remedial action plan based, at least in part, upon the assigned threat level.

6. The computer-implemented method of claim 5 wherein executing a remedial action plan includes:

allowing the suspect activity to continue.

7. The computer-implemented method of claim 5 wherein executing a remedial action plan includes:

generating a security event report based, at least in part, upon the gathered artifacts; and

providing the security event report to an analyst for further review.

8. The computer-implemented method of claim 5 wherein executing a remedial action plan includes:

autonomously executing a threat mitigation plan.

9. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

detecting a security event within a computing platform based upon identified suspect activity;

gathering artifacts concerning the security event;

assigning a threat level to the security event based, at least in part, upon the gathered artifacts; and

allowing a third-party to manually search the artifacts concerning the security event after the artifacts have been gathered, including:

obtaining at least one security-relevant information set from each of a plurality of security-relevant subsystems; and

combining the plurality of security-relevant information sets, including homogenizing the plurality of security-relevant information sets to have one or more of a common format, a common nomenclature, and a common structure.

10. The computer program product of claim 9 wherein detecting a security event within a computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

11. The computer program product of claim 9 wherein gathering artifacts concerning the security event includes:

gathering artifacts concerning the security event from a plurality of sources associated with the computing platform.

12. The computer program product of claim 9 wherein assigning a threat level to the security event includes:

assigning a threat level using artificial intelligence and machine learning.

13. The computer program product of claim 9 further comprising:

executing a remedial action plan based, at least in part, upon the assigned threat level.

14. The computer program product of claim 13 wherein executing a remedial action plan includes:

allowing the suspect activity to continue.

15. The computer program product of claim 13 wherein executing a remedial action plan includes:

generating a security event report based, at least in part, upon the gathered artifacts; and

providing the security event report to an analyst for further review.

16. The computer program product of claim 13 wherein executing a remedial action plan includes:

autonomously executing a threat mitigation plan.

17. A computing system including a processor and memory configured to perform operations comprising:

detecting a security event within a computing platform based upon identified suspect activity;

gathering artifacts concerning the security event;

assigning a threat level to the security event based, at least in part, upon the gathered artifacts; and

allowing a third-party to manually search the artifacts concerning the security event after the artifacts have been gathered, including:

obtaining at least one security-relevant information set from each of a plurality of security-relevant subsystems; and

combining the plurality of security-relevant information sets, including homogenizing the plurality of security-relevant information sets to have one or more of a common format, a common nomenclature, and a common structure.

18. The computing system of claim 17 wherein detecting a security event within a computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

19. The computing system of claim 17 wherein gathering artifacts concerning the security event includes:

gathering artifacts concerning the security event from a plurality of sources associated with the computing platform.

20. The computing system of claim 17 wherein assigning a threat level to the security event includes:

assigning a threat level using artificial intelligence and machine learning.

21. The computing system of claim 17 further comprising:

executing a remedial action plan based, at least in part, upon the assigned threat level.

22. The computing system of claim 21 wherein executing a remedial action plan includes:

allowing the suspect activity to continue.

23. The computing system of claim 21 wherein executing a remedial action plan includes:

generating a security event report based, at least in part, upon the gathered artifacts; and

providing the security event report to an analyst for further review.

24. The computing system of claim 21 wherein executing a remedial action plan includes:

autonomously executing a threat mitigation plan.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 052333/0915 →
Continuity (4)
Provisional Application 62817943 · Mar 13, 2019
Provisional Application 62737558 · Sep 27, 2018
Provisional Application 62681279 · Jun 6, 2018
Related Publication 20190377876A1 · Dec 12, 2019