IP Library Granted Patent US 11,411,981
Granted Patent B2
US 11,411,981 · App. 17/016,000 · Granted Aug 9, 2022

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
H04L63/1433G06F11/3409G06F21/577G06N5/04G06N20/00H04L63/1416H04L63/1441H04L67/32H04L67/34G06F2221/034H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,981
App. No.
17/016,000
Granted
Aug 9, 2022
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: defining a threat mitigation platform for a client, wherein the threat mitigation platform includes a plurality of threat detection capability modules; defining a rollout schedule for at least a portion of the plurality of threat detection capability modules; and presenting the rollout schedule to the client.

Claims (57)

1. A computer-implemented method, executed on a computing device, comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of a CDN (i.e., Content Delivery Network) system; a DAM (i.e., Database Activity Monitoring) system; a UBA (i.e., User Behavior Analytics) system; a MDM (i.e., Mobile Device Management) system; an IAM (i.e., Identity and Access Management) system; a DNS (i.e., Domain Name Server) system, an antivirus system, an operating system, a data lake; a data log; a security-relevant software application; a security-relevant hardware system; and a resource external to the computing platform;

monitoring, by a Security Information and Event Management (SIEM) system, activity of the plurality security-relevant subsystems on the computing platform and generating at least a first set of platform information;

defining a threat mitigation platform for a client, by applying a probabilistic process, including artificial intelligence/machine learning, to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

detecting a security event by applying a probabilistic process to the first set of platform information and developing artifacts of said security event;

assigning a threat level, via a probabilistic process, to the security event based in part on said artifacts;

defining a security threat remedial action based in part on the threat level;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules; and

presenting the rollout schedule to the client.

2. The computer-implemented method of claim 1 wherein the rollout schedule is a graphical rollout schedule.

3. The computer-implemented method of claim 1 wherein the rollout schedule is a text-based rollout schedule.

4. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

5. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

6. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

7. The computer-implemented method of claim 1 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

8. The computer-implemented method of claim 1 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

9. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of a CDN (i.e., Content Delivery Network) system; a DAM (i.e., Database Activity Monitoring) system; a UBA (i.e., User Behavior Analytics) system; a MDM (i.e., Mobile Device Management) system; an IAM (i.e., Identity and Access Management) system; a DNS (i.e., Domain Name Server) system, an antivirus system, an operating system, a data lake; a data log; a security-relevant software application; a security-relevant hardware system; and a resource external to the computing platform;

monitoring, by a Security Information and Event Management (SIEM) system, activity of the plurality security-relevant subsystems on the computing platform and generating at least a first set of platform information;

defining a threat mitigation platform for a client, by applying a probabilistic process, including artificial intelligence/machine learning, to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

detecting a security event by applying a probabilistic process to the first set of platform information and developing artifacts of said security event;

assigning a threat level, via a probabilistic process, to the security event based in part on said artifacts;

defining a security threat remedial action based in part on the threat level;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules; and

presenting the rollout schedule to the client.

10. The computer program product of claim 9 wherein the rollout schedule is a graphical rollout schedule.

11. The computer program product of claim 9 wherein the rollout schedule is a text-based rollout schedule.

12. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

13. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

14. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

15. The computer program product of claim 9 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

16. The computer program product of claim 9 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

17. A computing system including a processor and memory configured to perform operations comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of a CDN (i.e., Content Delivery Network) system; a DAM (i.e., Database Activity Monitoring) system; a UBA (i.e., User Behavior Analytics) system; a MDM (i.e., Mobile Device Management) system; an IAM (i.e., Identity and Access Management) system; a DNS (i.e., Domain Name Server) system, an antivirus system, an operating system, a data lake; a data log; a security-relevant software application; a security-relevant hardware system; and a resource external to the computing platform;

monitoring, by a Security Information and Event Management (SIEM) system, activity of the plurality security-relevant subsystems on the computing platform and generating at least a first set of platform information;

defining a threat mitigation platform for a client, by applying a probabilistic process, including artificial intelligence/machine learning, to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

detecting a security event by applying a probabilistic process to the first set of platform information and developing artifacts of said security event;

assigning a threat level, via a probabilistic process, to the security event based in part on said artifacts;

defining a security threat remedial action based in part on the threat level;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules; and

presenting the rollout schedule to the client.

18. The computing system of claim 17 wherein the rollout schedule is a graphical rollout schedule.

19. The computing system of claim 17 wherein the rollout schedule is a text-based rollout schedule.

20. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

21. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

22. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

23. The computing system of claim 17 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

24. The computing system of claim 17 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2021
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 055717/0666 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
Continuity (2)
Provisional Application 62897703 · Sep 9, 2019
Related Publication 20210075818A1 · Mar 11, 2021