IP Library Granted Patent US 11,297,092
Granted Patent B2
US 11,297,092 · App. 17/016,031 · Granted Apr 5, 2022

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
H04L63/1433G06F11/3409G06F21/577G06N5/04G06N20/00H04L63/1416H04L63/1441H04L67/32H04L67/34G06F2221/034H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,297,092
App. No.
17/016,031
Granted
Apr 5, 2022
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: obtaining consolidated platform information to identify current security-relevant capabilities for a computing platform; determining possible security-relevant capabilities for the computing platform; and rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.

Claims (46)

1. A computer-implemented method, executed on a computing device, comprising:

obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the SIEM system, activity of a plurality of security-relevant subsystems of the computing platform;

determining possible security-relevant capabilities for the computing platform;

rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform;

identifying coverage gaps in the current security-relevant capabilities, wherein identifying the coverage gaps in the current security-relevant capabilities includes identifying a plurality of inefficiencies in one or more portions of the computing platform; and

providing one or more recommendations for mitigating the identified coverage gaps, wherein providing the one or more recommendations for mitigating the identified coverage gaps includes:

in response to identifying the plurality of inefficiencies in the one or more portions of the computing platform, determining an efficiency increase for each of the one or more portions of the computing platform that would result from mitigating the identified coverage gaps.

2. The computer-implemented method of claim 1 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using the currently-deployed security-relevant subsystems.

3. The computer-implemented method of claim 1 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems.

4. The computer-implemented method of claim 1 wherein the graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform includes:

multi-axial comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.

5. The computer-implemented method of claim 1 wherein the consolidated platform information is obtained from an independent information source.

6. The computer-implemented method of claim 1 wherein the consolidated platform information is obtained from a client information source.

7. The computer-implemented method of claim 1 , wherein providing the one or more recommendations for mitigating the identified coverage gaps includes:

identifying a plurality of undeployed rules that are deployable in the computing platform, and

ranking the plurality of undeployed rules that are deployable in the computing platform.

8. The computer-implemented method of claim 7 , wherein each of the plurality of undeployed rules are associated with one or more of:

a kill chain phase;

a severity level; and

a performance score based, at least in part, on a probability of detecting one or more false positives.

9. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the SIEM system, activity of a plurality of security-relevant subsystems of the computing platform;

determining possible security-relevant capabilities for the computing platform;

rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform;

identifying coverage gaps in the current security-relevant capabilities, wherein identifying the coverage gaps in the current security-relevant capabilities includes identifying a plurality of inefficiencies in one or more portions of the computing platform; and

providing one or more recommendations for mitigating the identified coverage gaps, wherein providing the one or more recommendations for mitigating the identified coverage gaps includes:

in response to identifying the plurality of inefficiencies in the one or more portions of the computing platform, determining an efficiency increase for each of the one or more portions of the computing platform that would result from mitigating the identified coverage gaps.

10. The computer program product of claim 9 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using the currently-deployed security-relevant subsystems.

11. The computer program product of claim 9 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems.

12. The computer program product of claim 9 wherein the graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform includes:

multi-axial comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.

13. The computer program product of claim 9 wherein the consolidated platform information is obtained from an independent information source.

14. The computer program product of claim 9 wherein the consolidated platform information is obtained from a client information source.

15. A computing system including a processor and memory configured to perform operations comprising:

obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the STEM system, activity of a plurality of security-relevant subsystems of the computing platform;

determining possible security-relevant capabilities for the computing platform;

rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform;

identifying coverage gaps in the current security-relevant capabilities, wherein identifying the coverage gaps in the current security-relevant capabilities includes identifying a plurality of inefficiencies in one or more portions of the computing platform; and

providing one or more recommendations for mitigating the identified coverage gaps, wherein providing the one or more recommendations for mitigating the identified coverage gaps includes:

in response to identifying the plurality of inefficiencies in the one or more portions of the computing platform, determining an efficiency increase for each of the one or more portions of the computing platform that would result from mitigating the identified coverage gaps.

16. The computing system of claim 15 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using the currently-deployed security-relevant subsystems.

17. The computing system of claim 15 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems.

18. The computing system of claim 15 wherein the graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform includes:

multi-axial comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.

19. The computing system of claim 15 wherein the consolidated platform information is obtained from an independent information source.

20. The computing system of claim 15 wherein the consolidated platform information is obtained from a client information source.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 1, 2024
From: SIXTH STREET SPECIALTY LENDING, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 067277/0607 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2021
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 055717/0666 →
SECURITY INTEREST Recorded Oct 8, 2020
From: RELIAQUEST HOLDINGS, LLC
To: SIXTH STREET SPECIALTY LENDING, INC., AS COLLATERAL AGENT
Reel/Frame 054013/0548 →
Continuity (2)
Provisional Application 62897703 · Sep 9, 2019
Related Publication 20210073389A1 · Mar 11, 2021
Cited By (1)
US 12,355,799