IP Library Granted Patent US 11,108,798
Granted Patent B2
US 11,108,798 · App. 16/432,762 · Granted Aug 31, 2021

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/1425G06F8/65G06F21/53G06F21/55G06F21/554G06F21/56G06F21/561G06F21/562G06F21/566G06F21/568G06F21/577G06F30/20G06K9/6256G06N20/00H04L63/0227H04L63/0263H04L63/145H04L63/1416H04L63/1433H04L63/1441H04L63/164H04L63/20G06F2221/034G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,798
App. No.
16/432,762
Granted
Aug 31, 2021
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; obtaining at least one security-relevant information set from each of the plurality of security-relevant subsystems, thus defining a plurality of security-relevant information sets; and processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets.

Claims (78)

1. A computer-implemented method, executed on a computing device, comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, the plurality of security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, User Behavior Analytic systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query concerning the plurality of security-relevant subsystems;

parsing the unified query to define a plurality of queries for at least a portion of each of the security-relevant subsystems;

executing the plurality of queries on the respective security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of security-relevant subsystems, based upon, at least in part, the plurality of queries, thus defining a plurality of security-relevant information sets;

processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets, wherein processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets includes:

utilizing a decision tree based, at least in part, upon one or more previously-acquired security-relevant information sets; and

defining an initial probabilistic model based upon, at least in part:

the plurality of security-relevant information sets, and

one or more user-specified probabilistic model variables;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified, wherein combining the plurality of security-relevant information sets to form the aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified includes homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set;

enabling third-party access to the aggregated security-relevant information set; and

generating a security profile based, at least in part, upon the aggregated security-relevant information set for the computing platform.

2. The computer-implemented method of claim 1 wherein establishing connectivity with a plurality of security-relevant subsystems includes:

utilizing at least one application program interface to access at least one of the plurality of security-relevant subsystems.

3. The computer-implemented method of claim 1 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

4. The computer-implemented method of claim 1 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

5. The computer-implemented method of claim 1 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

6. The computer-implemented method of claim 1 wherein the plurality of security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

7. A computer program product comprising a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, the plurality of security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, User Behavior Analytic systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query concerning the plurality of security-relevant subsystems;

parsing the unified query to define a plurality of queries for at least a portion of each of the security-relevant subsystems;

executing the plurality of queries on the respective security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of security-relevant subsystems, based upon, at least in part, the plurality of queries, thus defining a plurality of security-relevant information sets;

processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets, wherein processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets includes:

utilizing a decision tree based, at least in part, upon one or more previously-acquired security-relevant information sets; and

defining an initial probabilistic model based upon, at least in part:

the plurality of security-relevant information sets, and

one or more user-specified probabilistic model variables;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified, wherein combining the plurality of security-relevant information sets to form the aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified includes homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set;

enabling third-party access to the aggregated security-relevant information set; and

generating a security profile based, at least in part, upon the aggregated security-relevant information set for the computing platform.

8. The computer program product of claim 7 wherein establishing connectivity with a plurality of security-relevant subsystems includes:

utilizing at least one application program interface to access at least one of the plurality of security-relevant subsystems.

9. The computer program product of claim 7 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

10. The computer program product of claim 7 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

11. The computer program product of claim 7 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

12. The computer program product of claim 7 wherein the plurality of security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

13. A computing system including a processor and memory configured to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform, the plurality of security-relevant subsystems including one or more of Content Delivery Network systems, Database Activity Monitoring systems, User Behavior Analytic systems, Mobile Device Management systems, Identity and Access Management systems, Domain Name Server systems, antivirus systems, operating systems;

receiving a unified query concerning the plurality of security-relevant subsystems;

parsing the unified query to define a plurality of queries for at least a portion of each of the security-relevant subsystems;

executing the plurality of queries on the respective security-relevant subsystems;

obtaining at least one security-relevant information set from each of the plurality of security-relevant subsystems, based upon, at least in part, the plurality of queries, thus defining a plurality of security-relevant information sets;

processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets, wherein processing the plurality of security-relevant information sets using artificial learning/machine learning to identify one or more commonalities amongst the plurality of security-relevant information sets includes:

utilizing a decision tree based, at least in part, upon one or more previously-acquired security-relevant information sets; and

defining an initial probabilistic model based upon, at least in part:

the plurality of security-relevant information sets, and

one or more user-specified probabilistic model variables;

combining the plurality of security-relevant information sets to form an aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified, wherein combining the plurality of security-relevant information sets to form the aggregated security-relevant information set for the computing platform based, at least in part, upon the one or more commonalities identified includes homogenizing the plurality of security-relevant information sets to form the aggregated security-relevant information set;

enabling third-party access to the aggregated security-relevant information set; and

generating a security profile based, at least in part, upon the aggregated security-relevant information set for the computing platform.

14. The computing system of claim 13 wherein establishing connectivity with a plurality of security-relevant subsystems includes:

utilizing at least one application program interface to access at least one of the plurality of security-relevant subsystems.

15. The computing system of claim 13 further comprising:

enabling third-party searching of the aggregated security-relevant information set.

16. The computing system of claim 13 wherein the plurality of security-relevant information sets utilize a plurality of different formats.

17. The computing system of claim 13 wherein the plurality of security-relevant information sets utilize a plurality of different nomenclatures.

18. The computing system of claim 13 wherein the plurality of security-relevant subsystems includes one or more of:

a data lake;

a data log;

a security-relevant software application;

a security-relevant hardware system; and

a resource external to the computing platform.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 052333/0915 →
Continuity (4)
Provisional Application 62681279 · Jun 6, 2018
Provisional Application 62737558 · Sep 27, 2018
Provisional Application 62817943 · Mar 13, 2019
Related Publication 20190379680A1 · Dec 12, 2019