IP Library Granted Patent US 12,079,331
Granted Patent B2
US 12,079,331 · App. 16/940,020 · Granted Sep 3, 2024

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/554G06F3/04842G06N7/01G06N20/00H04L63/1416H04L63/1425H04L63/1433H04L63/1441G06F2221/034G06F2221/2115H04L2463/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,331
App. No.
16/940,020
Granted
Sep 3, 2024
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: a computer-implemented method is executed on a computing device and includes: rendering a threat mitigation user interface that identifies objects within a computing platform in response to a security event; and enabling a third-party to gather artifacts concerning an object within the threat mitigation user interface.

Claims (84)

1. A computer-implemented method, executed on a computing device, comprising: monitoring and logging, by a plurality of security-relevant subsystems, respective activity of the plurality of security-relevant subsystems with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems;

monitoring a plurality of sources to identify suspect activity within the computing platform, the plurality of sources including log files maintained by one or more of the plurality of security-relevant subsystems, wherein a probabilistic process, contains a probabilistic model and a trained neural network, constructs a decision tree and provides branch weights and probabilities;

detecting a security event within the computing platform based upon the identified suspect activity, wherein threat mitigation process compares current security-relevant capabilities of computing platform to the comparative platform information determined for the comparative platform to identify a threat context indicator for computing platform, wherein comparison information includes graphical comparison information which includes a client threat context score, a maximum possible client threat context score, a vendor threat context score, and a industrial threat context score forming an aggregated security relevant information set;

rendering a threat mitigation user interface that identifies objects within the computing platform in response to the security event;

enabling a third-party to select an object within the threat mitigation user interface, thus defining a selected object; and rendering an inspection window that defines object information concerning the selected object;

enabling the third-party to gather artifacts concerning an object within the threat mitigation user interface; providing suggestions concerning additional artifacts to be gathered; and

assigning a threat level to the security event based upon, at least in part, the gathered artifacts;

detecting the security event within the computing platform based upon the aggregated security relevant information set and identified suspect activity, wherein detecting the security event within the computing platform based upon identified suspect activity includes: monitoring a plurality of sources to identify suspect activity within the computing platform and effectuate a threat mitigation for the identified suspect activity.

2. The computer-implemented method of claim 1 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

3. The computer-implemented method of claim 1 further comprising:

enabling the third-party to store the artifacts within a defined storage location.

4. The computer-implemented method of claim 1 further comprising:

enabling the third-party to provide the artifacts to another party.

5. The computer-implemented method of claim 1 wherein the inspection window is a popup inspection window.

6. The computer-implemented method of claim 1 wherein the inspection window is a slide out inspection window.

7. The computer-implemented method of claim 1 wherein enabling a third-party to gather artifacts concerning an object within the threat mitigation user interface includes:

enabling the third-party to gather artifacts concerning an object within the inspection window.

8. The computer-implemented method of claim 1 further comprising:

detecting the security event within the computing platform based upon identified suspect activity.

9. The computer-implemented method of claim 8 wherein detecting the security event within the computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

10. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring and logging, by a plurality of security-relevant subsystems, respective activity of the plurality of security-relevant subsystems with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems;

monitoring a plurality of sources to identify suspect activity within the computing platform, the plurality of sources including log files maintained by one or more of the plurality of security-relevant subsystems;

detecting a security event within the computing platform based upon the identified suspect activity;

rendering a threat mitigation user interface that identifies objects within the computing platform in response to the security event;

enabling a third-party to gather artifacts concerning an object within the threat mitigation user interface;

providing suggestions concerning additional artifacts to be gathered; and

assigning a threat level to the security event based upon, at least in part, the gathered artifacts.

11. The computer program product of claim 10 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

12. The computer program product of claim 10 further comprising:

enabling the third-party to store the artifacts within a defined storage location.

13. The computer program product of claim 10 further comprising:

enabling the third-party to provide the artifacts to another party.

14. The computer program product of claim 10 wherein the inspection window is a popup inspection window.

15. The computer program product of claim 10 wherein the inspection window is a slide out inspection window.

16. The computer program product of claim 10 wherein enabling a third-party to gather artifacts concerning at least one object within the threat mitigation user interface includes:

enabling the third-party to gather artifacts concerning the at least one object within the inspection window.

17. The computer program product of claim 10 further comprising:

detecting the security event within the computing platform based upon identified suspect activity.

18. The computer program product of claim 17 wherein detecting the security event within the computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

19. A computing system including a processor and memory configured to perform operations comprising:

monitoring and logging, by a plurality of security-relevant subsystems, respective activity of the plurality of security-relevant subsystems with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems;

monitoring a plurality of sources to identify suspect activity within the computing platform, the plurality of sources including log files maintained by one or more of the plurality of security-relevant subsystems;

detecting a security event within the computing platform based upon the identified suspect activity;

rendering a threat mitigation user interface that identifies objects within the computing platform in response to the security event;

enabling a third-party to gather artifacts concerning an object within the threat mitigation user interface;

providing suggestions concerning additional artifacts to be gathered; and

assigning a threat level to the security event based upon, at least in part, the gathered artifacts.

20. The computing system of claim 19 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

21. The computing system of claim 19 further comprising:

enabling the third-party to store the artifacts within a defined storage location.

22. The computing system of claim 19 further comprising:

enabling the third-party to provide the artifacts to another party.

23. The computing system of claim 19 wherein the inspection window is a popup inspection window.

24. The computing system of claim 19 wherein the inspection window is a slide out inspection window.

25. The computing system of claim 19 wherein enabling a third-party to gather artifacts concerning at least one object within the threat mitigation user interface includes:

enabling the third-party to gather artifacts concerning the at least one object within the inspection window.

26. The computing system of claim 19 further comprising:

detecting the security event within the computing platform based upon identified suspect activity.

27. The computing system of claim 26 wherein detecting the security event within the computing platform based upon identified suspect activity includes:

monitoring a plurality of sources to identify suspect activity within the computing platform.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 061232/0440 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
Continuity (3)
Provisional Application 62883797 · Aug 7, 2019
Provisional Application 62879105 · Jul 26, 2019
Related Publication 20210029159A1 · Jan 28, 2021