IP Library Granted Patent US 11,651,074
Granted Patent B2
US 11,651,074 · App. 16/864,102 · Granted May 16, 2023

Methods and apparatus to accelerate security threat investigation

Inventor: Wayne Anderson (Greeley, CO)
Assignee: MUSARUBRA US LLC
G06F21/554G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,651,074
App. No.
16/864,102
Granted
May 16, 2023
Kind
B2
Abstract

Methods, apparatus, systems and articles of manufacture are disclosed herein to accelerate security threat investigation. An example apparatus includes a model trainer to train a security investigation model, a game engine to determine a source security software product and a destination security software product of a security threat object, an actions database to store at least one of the previous security response action, the source security software product, the destination security software product, and the security threat object, an action generator to generate at least one suggested security response action in response to a user security investigation action, wherein the suggested security response action is based on an execution of the security investigation model, and a software product controller to adjust a display of the destination security software product of the security threat object in response to the security response action.

Claims (30)

1. An apparatus to accelerate security threat investigation, the apparatus comprising:

at least one memory;

machine-readable instructions; and

processor circuitry to execute the machine-readable instructions to:

cause display of a virtual security operations center in a virtual environment, the virtual security operations center to include visual representations of a plurality of security software products, wherein at least one of the plurality of security software products includes a security threat object, the security threat object selectable by a user of the virtual security operations center;

generate a plurality of suggested security response actions in response to a user interaction with a visual representation of the security threat object, the user interaction to cause the visual representation of the security threat object to at least move from a visual representation of a first security software product to a visual representation of a second security software product, the plurality of suggested security response actions to be generated based on an execution of a security investigation model and inputs to the security investigation model, the inputs including at least the first security software product, the second security software product, and the security threat object, the plurality of suggested security response actions to be displayed as menu options selectable by the user; and

cause adjustment to display of the visual representation of the second security software product in response to a selection of one of the plurality of suggested security response actions.

2. The apparatus of claim 1 , wherein the user interaction is to be implemented by one or more gestures performed by a user via one or more hand tracking devices.

3. The apparatus of claim 1 , wherein the plurality of security software products include at least one of an endpoint detection and response product, a security information and event management product, a centralized security manager, and a security innovation alliance product.

4. The apparatus of claim 1 , wherein the processor circuitry is to tag a location of the visual representation of the security threat object within the virtual environment in response to a user selecting the security threat object via the user interaction.

5. The apparatus of claim 1 , wherein the processor circuitry is to detect a collision of the visual representation of the security threat object with the visual representation of the second security software product, the collision to further cause the plurality of suggested security response actions to be generated.

6. The apparatus of claim 5 , wherein the processor circuitry is to execute the security investigation model based on at least one of the security threat object, the first security software product, the second security software product, and the collision.

7. A method comprising:

causing display of a virtual security operations center in a virtual environment, the virtual security operations center to include visual representations of a plurality of security software products, wherein at least one of the plurality of security software products includes a security threat object, the security threat object selectable by a user of the virtual security operations center;

generating a plurality of suggested security response actions in response to a user interaction with a visual representation of the security threat object, the user interaction to cause the visual representation of the security threat object to at least move from a visual representation of a first security software product to a visual representation of a second security software product, the plurality of suggested security response actions to be generated based on an execution of a security investigation model and inputs to the security investigation model, the inputs including at least the first security software product, the second security software product, and the security threat object, the plurality of suggested security response actions to be displayed as menu options selectable by the user; and

causing adjustment to display of the visual representation of the second security software product in response to a selection of one of the plurality of suggested security response actions.

8. The method of claim 7 , wherein the user interaction is to be implemented by one or more gestures performed by a user via one or more hand tracking devices.

9. The method of claim 7 , wherein the plurality of security software products include at least one of an endpoint detection and response product, a security information and event management product, a centralized security manager, and a security innovation alliance product.

10. The method of claim 7 , further including tagging a location of the visual representation of the security threat object within the virtual environment in response to a user selecting the security threat object via the user interaction.

11. The method of claim 7 , further including detecting a collision of the visual representation of the security threat object with the visual representation of the second security software product, the collision to further cause the plurality of suggested security response actions to be generated.

12. The method of claim 11 , further including executing the security investigation model based on at least one of the security threat object, the first security software product, the second security software product, and the collision.

13. At least one non-transitory computer readable medium comprising instructions that, when executed, cause at least one processor to at least:

cause display of a virtual security operations center in a virtual environment, the virtual security operations center to include visual representations of a plurality of security software products, wherein at least one of the plurality of security software products includes a security threat object, the security threat object selectable by a user of the virtual security operations center;

generate a plurality of suggested security response actions in response to a user interaction with a visual representation of the security threat object, the user interaction to cause the visual representation of the security threat object to at least move from a visual representation of a first security software product to a visual representation of a second security software product, the plurality of suggested security response actions to be generated based on an execution of a security investigation model and inputs to the security investigation model, the inputs including at least the first security software product, the second security software product, and the security threat object, the plurality of suggested security response actions to be displayed as menu options selectable by the user; and

cause adjustment to display of the visual representation of the second security software product in response to a selection of one of the plurality of suggested security response actions.

14. The at least one non-transitory computer readable medium of claim 13 , wherein the user interaction is to be implemented by one or more gestures performed by a user via one or more hand tracking devices.

15. The at least one non-transitory computer readable medium of claim 13 , wherein the plurality of security software products include at least one of an endpoint detection and response product, a security information and event management product, a centralized security manager, and a security innovation alliance product.

16. The at least one non-transitory computer readable medium of claim 13 , wherein the instructions, when executed, cause the at least one processor to tag a location of the visual representation of the security threat object within the virtual environment in response to a user selecting the security threat object via the user interaction.

17. The at least one non-transitory computer readable medium of claim 13 , wherein the instructions, when executed, cause the at least one processor to detect a collision of the visual representation of the security threat object with the visual representation of the second security software product, the collision to further cause the plurality of suggested security response actions to be generated.

18. The at least one non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, cause the at least one processor to execute the security investigation model based on at least one of the security threat object, the first security software product, the second security software product, and the collision.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 057393/0546 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2020
From: ANDERSON, WAYNE
To: MCAFEE, LLC
Reel/Frame 054843/0374 →