IP Library Granted Patent US 11,297,080
Granted Patent B2
US 11,297,080 · App. 16/432,733 · Granted Apr 5, 2022

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
H04L63/1425G06F8/65G06F21/53G06F21/55G06F21/554G06F21/56G06F21/561G06F21/562G06F21/566G06F21/568G06F21/577G06F30/20G06K9/6256G06N20/00H04L63/0227H04L63/0263H04L63/145H04L63/1416H04L63/1433H04L63/1441H04L63/164H04L63/20G06F2221/034G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,297,080
App. No.
16/432,733
Granted
Apr 5, 2022
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; obtaining at least one security-relevant information set from each of the plurality of security-relevant subsystems, thus defining a plurality of security-relevant information sets; and combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform.

Claims (75)

1. A computer-implemented method, executed on a computing device, comprising:

obtaining consolidated platform information for a computing platform from a Security Information and Event Management (SIEM) system to identify a plurality of deployed security-relevant subsystems, including monitoring and logging activity of the plurality of deployed security-relevant subsystems by the SIEM system;

establishing connectivity with the plurality of deployed security-relevant subsystems within the computing platform based upon the identifying the plurality of deployed security-relevant subsystems, including utilizing at least one application program interface to access at least one of the plurality of deployed security-relevant subsystems, the plurality of deployed security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query from a third party;

distributing at least a portion of the unified query to the plurality of deployed security-relevant subsystems;

effectuating at least a portion of the unified query on each of the plurality of deployed security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of deployed security-relevant subsystems, thus defining a plurality of security-relevant information sets;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform, including:

one or more of iteratively and continuously modifying and revising a probabilistic model;

identifying one or more commonalities amongst the plurality of security-relevant information sets using the probabilistic model; and

homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set based on the identified commonalities;

enabling the third-party access to the aggregated security-relevant information set including initial security-relevant information;

allowing the third party to manipulate the initial security-relevant information with automation information including:

allowing the third party to select automation information to add to the initial security-relevant information, including allowing the third party to select a specific type of automation information from a plurality of automation information types to add to the initial security-relevant; and

generating revised security-relevant information based upon, at least in part, the initial security-relevant information and the automation information.

2. The computer-implemented method of claim 1 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

3. The computer-implemented method of claim 1 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

4. The computer-implemented method of claim 1 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

5. The computer-implemented method of claim 1 wherein the plurality of deployed security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

6. A computer program product comprising a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

obtaining consolidated platform information for a computing platform from a Security Information and Event Management (SIEM) system to identify a plurality of deployed security-relevant subsystems, including monitoring and logging activity of the plurality of deployed security-relevant subsystems by the SIEM system;

establishing connectivity with the plurality of deployed security-relevant subsystems within the computing platform based upon the identifying the plurality of deployed security-relevant subsystems, including utilizing at least one application program interface to access at least one of the plurality of deployed security-relevant subsystems, the plurality of deployed security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query from a third party;

distributing at least a portion of the unified query to the plurality of deployed security-relevant subsystems;

effectuating at least a portion of the unified query on each of the plurality of deployed security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of deployed security-relevant subsystems, thus defining a plurality of security-relevant information sets;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform, including:

one or more of iteratively and continuously modifying and revising a probabilistic model;

identifying one or more commonalities amongst the plurality of security-relevant information sets using the probabilistic model; and

homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set based on the identified commonalities;

enabling the third-party access to the aggregated security-relevant information set including initial security-relevant information;

allowing the third party to manipulate the initial security-relevant information with automation information including:

allowing the third party to select automation information to add to the initial security-relevant information, including allowing the third party to select a specific type of automation information from a plurality of automation information types to add to the initial security-relevant; and

generating revised security-relevant information based upon, at least in part, the initial security-relevant information and the automation information.

7. The computer program product of claim 6 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

8. The computer program product of claim 6 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

9. The computer program product of claim 6 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

10. The computer program product of claim 6 wherein the plurality of deployed security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

11. A computing system including a processor and memory configured to perform operations comprising:

obtaining consolidated platform information for a computing platform from a Security Information and Event Management (SIEM) system to identify a plurality of deployed security-relevant subsystems, including monitoring and logging activity of the plurality of deployed security-relevant subsystems by the SIEM system;

establishing connectivity with the plurality of deployed security-relevant subsystems within the computing platform based upon the identifying the plurality of deployed security-relevant subsystems, including utilizing at least one application program interface to access at least one of the plurality of deployed security-relevant subsystems, the plurality of deployed security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query from a third party;

distributing at least a portion of the unified query to the plurality of deployed security-relevant subsystems;

effectuating at least a portion of the unified query on each of the plurality of deployed security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of deployed security-relevant subsystems, thus defining a plurality of security-relevant information sets;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform, including:

one or more of iteratively and continuously modifying and revising a probabilistic model;

identifying one or more commonalities amongst the plurality of security-relevant information sets using the probabilistic model; and

homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set based on the identified commonalities;

enabling the third-party access to the aggregated security-relevant information set including initial security-relevant information;

allowing the third party to manipulate the initial security-relevant information with automation information including:

allowing the third party to select automation information to add to the initial security-relevant information, including allowing the third party to select a specific type of automation information from a plurality of automation information types to add to the initial security-relevant; and

generating revised security-relevant information based upon, at least in part, the initial security-relevant information and the automation information.

12. The computing system of claim 11 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

13. The computing system of claim 11 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

14. The computing system of claim 11 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

15. The computing system of claim 11 wherein the plurality of deployed security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 052333/0915 →
Continuity (4)
Provisional Application 62817943 · Mar 13, 2019
Provisional Application 62737558 · Sep 27, 2018
Provisional Application 62681279 · Jun 6, 2018
Related Publication 20190379704A1 · Dec 12, 2019