Threat mitigation system and method
Concept 13) A computer-implemented method, computer program product and computing system for: receiving updated threat event information concerning a computing platform; enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform; and scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems.
1. A computer-implemented method, executed on a computing device, comprising:
receiving updated threat event information concerning a computing platform, wherein the updated threat event information includes one or more of: updated threat listings; updated threat definitions; updated threat methodologies; updated threat sources;
and updated threat strategies;
enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform;
scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems, wherein scheduling the application of the updated threat event information to the newly-generated information associated with the one or more security-relevant subsystems includes scheduling the application of the updated threat event information to one or more newly-generated log files associated with the one or more security-relevant subsystems.
2. The computer-implemented method of claim 1 wherein enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform includes:
installing the updated threat event information on the one or more security-relevant subsystems within the computing platform.
3. The computer-implemented method of claim 1 wherein scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems includes one or more of:
scheduling the application of the updated threat event information to one or more previously-generated log files associated with the one or more security-relevant subsystems;
scheduling the application of the updated threat event information to one or more previously-generated data files associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to one or more previously-generated application files associated with the one or more security-relevant subsystems.
4. The computer-implemented method of claim 1 wherein scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems includes one or more of: scheduling the application of the updated threat event information to one or more newly-generated data files associated with the one or more security-relevant subsystems; and scheduling the application of the updated threat event information to one or more newly-generated application files associated with the one or more security-relevant subsystems.
5. The computer-implemented method of claim 1 wherein the one or more security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.
6. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:
receiving updated threat event information concerning a computing platform, wherein the updated threat event information includes one or more of: updated threat listings; updated threat definitions; updated threat methodologies; updated threat sources;
and updated threat strategies;
enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform;
scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems, wherein scheduling the application of the updated threat event information to the newly-generated information associated with the one or more security-relevant subsystems includes scheduling the application of the updated threat event information to one or more newly-generated log files associated with the one or more security-relevant subsystems.
7. The computer program product of claim 6 wherein enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform includes:
installing the updated threat event information on the one or more security-relevant subsystems within the computing platform.
8. The computer program product of claim 6 wherein scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems includes one or more of:
scheduling the application of the updated threat event information to one or more previously-generated log files associated with the one or more security-relevant subsystems;
scheduling the application of the updated threat event information to one or more previously-generated data files associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to one or more previously-generated application files associated with the one or more security-relevant subsystems.
9. The computer program product of claim 6 wherein scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems includes one or more of: scheduling the application of the updated threat event information to one or more newly-generated data files associated with the one or more security-relevant subsystems; and scheduling the application of the updated threat event information to one or more newly-generated application files associated with the one or more security-relevant subsystems.
10. The computer program product of claim 6 wherein the one or more security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.
11. A computing system including a processor and memory configured to perform operations comprising:
receiving updated threat event information concerning a computing platform, wherein the updated threat event information includes one or more of: updated threat listings; updated threat definitions; updated threat methodologies; updated threat sources;
and updated threat strategies;
enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform;
scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems, wherein scheduling the application of the updated threat event information to the newly-generated information associated with the one or more security-relevant subsystems includes scheduling the application of the updated threat event information to one or more newly-generated log files associated with the one or more security-relevant subsystems.
12. The computing system of claim 11 wherein enabling the updated threat event information for use with one or more security-relevant subsystems within the computing platform includes:
installing the updated threat event information on the one or more security-relevant subsystems within the computing platform.
13. The computing system of claim 11 wherein scheduling the application of the updated threat event information to previously-generated information associated with the one or more security-relevant subsystems includes one or more of:
scheduling the application of the updated threat event information to one or more previously-generated log files associated with the one or more security-relevant subsystems;
scheduling the application of the updated threat event information to one or more previously-generated data files associated with the one or more security-relevant subsystems; and
scheduling the application of the updated threat event information to one or more previously-generated application files associated with the one or more security-relevant subsystems.
14. The computing system of claim 11 wherein scheduling the application of the updated threat event information to newly-generated information associated with the one or more security-relevant subsystems includes one or more of: scheduling the application of the updated threat event information to one or more newly-generated data files associated with the one or more security-relevant subsystems; and scheduling the application of the updated threat event information to one or more newly-generated application files associated with the one or more security-relevant subsystems.
15. The computing system of claim 11 wherein the one or more security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.