IP Library Granted Patent US 11,637,847
Granted Patent B2
US 11,637,847 · App. 17/337,132 · Granted Apr 25, 2023

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/1425G06F8/65G06F21/53G06F21/55G06F21/554G06F21/56G06F21/561G06F21/562G06F21/566G06F21/568G06F21/577G06F30/20G06K9/6256G06N20/00H04L63/0227H04L63/0263H04L63/145H04L63/1416H04L63/1433H04L63/1441H04L63/164H04L63/20G06F2221/034G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,637,847
App. No.
17/337,132
Granted
Apr 25, 2023
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: obtaining system-defined consolidated platform information for a computing platform from an independent information source; obtaining client-defined consolidated platform information for the computing platform from a client information source; and comparing the system-defined consolidated platform information to the client-defined consolidated platform information to define differential consolidated platform information for the computing platform.

Claims (64)

1. A computer-implemented method, executed on a computing device, comprising:

obtaining consolidated platform information for a computing platform;

analyzing the consolidated platform information to evaluate one or more current security relevant capabilities for the computer platform;

identifying one or more security assets which are available but not utilized by the computing platform including one or more of: features of the one or more security assets that are available but not utilized, features of the one or more security assets that are available but disabled, and expanded features of the one or more security assets;

determining possible security-relevant capabilities for the computing platform, wherein the possible security-relevant capabilities accounts for the one or more security assets which are available but not utilized by the computing platform;

generating comparison information that compares the current security-relevant capabilities of the computing platform to the possible security-relevant capabilities of the computing platform to identify security-relevant deficiencies; and

generating a list of at least a portion of the one or more security assets that are available but not utilized by the computing platform to address at least a portion of the security-relevant deficiencies.

2. The computer-implemented method of claim 1 , wherein generating the list of the at least a portion of the one or more security assets includes:

generating a list of ranked and recommended security assets that ranks the one or more available but not utilized security assets.

3. The computer-implemented method of claim 2 wherein generating the list of ranked and recommended security assets that ranks the one or more available but not utilized security assets includes:

ranking the one or more security assets based upon the anticipated use of the one or more security assets.

4. The computer-implemented method of claim 1 , further comprising providing the ability/option to implement one or more security assets which are available but not utilized by the computing platform.

5. The computer-implemented method of claim 1 , wherein identifying the one or more security assets which are available but not utilized includes:

utilizing artificial intelligence/machine learning to process the consolidated platform information to identify the one or more security assets which are available but not utilized.

6. The computer-implemented method of claim 1 , wherein the consolidated platform information includes client-defined consolidated platform information.

7. The computer-implemented method of claim 1 , wherein the consolidated platform information is received from a client, the client including one or more of a user, an owner, and an operator of the computing platform.

8. The computer-implemented method of claim 1 , wherein one or more of the current security-relevant capabilities and the possible security-relevant capabilities are provided by one or more of Content Delivery Network (CDN) systems; Database Activity Monitoring (DAM) systems; User Behavior Analytics (UBA) systems; Mobile Device Management (MDM) systems; Identity and Access Management (IAM) systems; Domain Name Server (DNS) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform.

9. The computer-implemented method of claim 1 , further including:

determining comparative platform information that identifies security-relevant capabilities for a comparative platform, wherein the comparative platform concerns one or more vendor customers.

10. The computer-implemented method of claim 9 , further including:

providing a score for the computing platform based upon, at least in part, the current security-relevant capabilities; and

providing a score based upon, at least in part, the security-relevant capabilities for the comparative platform.

11. The computer-implemented method of claim 10 , wherein the comparative platform information concerns vendor customers in a specific industry.

12. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon, which, when executed by a processor, cause the processor to perform operations comprising:

obtaining consolidated platform information for a computing platform;

analyzing the consolidated platform information to evaluate one or more current security relevant capabilities for the computer platform;

identifying one or more security assets which are available but not utilized by the computing platform including one or more of: features of the one or more security assets that are available but not utilized, features of the one or more security assets that are available but disabled, and expanded features of the one or more security assets;

determining possible security-relevant capabilities for the computing platform, wherein the possible security-relevant capabilities accounts for the one or more security assets which are available but not utilized by the computing platform;

generating comparison information that compares the current security-relevant capabilities of the computing platform to the possible security-relevant capabilities of the computing platform to identify security-relevant deficiencies; and

generating a list of at least a portion of the one or more security assets that are available but not utilized by the computing platform to address at least a portion of the security-relevant deficiencies.

13. The computer program product of claim 12 , wherein generating the list of the at least a portion of the one or more security assets includes:

generating a list of ranked and recommended security assets that ranks the one or more available but not utilized security assets.

14. The computer program product of claim 13 wherein generating the list of ranked and recommended security assets that ranks the one or more available but not utilized security assets includes:

ranking the one or more security assets based upon the anticipated use of the one or more security assets.

15. The computer program product of claim 12 , further comprising instructions for providing the ability/option to implement one or more security assets which are available but not utilized by the computing platform.

16. The computer program product of claim 12 , wherein identifying the one or more security assets which are available but not utilized includes:

utilizing artificial intelligence/machine learning to process the consolidated platform information to identify the one or more security assets which are available but not utilized.

17. The computer program product of claim 12 , wherein the consolidated platform information includes client-defined consolidated platform information.

18. The computer program product of claim 12 , wherein the consolidated platform information is received from a client, the client including one or more of a user, an owner, and an operator of the computing platform.

19. The computer program product of claim 12 , wherein one or more of the current security-relevant capabilities and the possible security-relevant capabilities are provided by one or more of Content Delivery Network (CDN) systems; Database Activity Monitoring (DAM) systems; User Behavior Analytics (UBA) systems; Mobile Device Management (MDM) systems;

Identity and Access Management (IAM) systems; Domain Name Server (DNS) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform.

20. The computer program product of claim 12 , further including instructions for:

determining comparative platform information that identifies security-relevant capabilities for a comparative platform, wherein the comparative platform concerns one or more vendor customers.

21. The computer program product of claim 20 , further including instructions for:

providing a score for the computing platform based upon, at least in part, the current security-relevant capabilities; and

providing a score based upon, at least in part, the security-relevant capabilities for the comparative platform.

22. The computer program product of claim 21 , wherein the comparative platform information concerns vendor customers in a specific industry.

23. A computing system including a processor and memory configured to perform operations comprising:

obtaining consolidated platform information for a computing platform;

analyzing the consolidated platform information to evaluate one or more current security relevant capabilities for the computer platform;

identifying one or more security assets which are available but not utilized by the computing platform including one or more of: features of the one or more security assets that are available but not utilized, features of the one or more security assets that are available but disabled, and expanded features of the one or more security assets;

determining possible security-relevant capabilities for the computing platform, wherein the possible security-relevant capabilities accounts for the one or more security assets which are available but not utilized by the computing platform;

generating comparison information that compares the current security-relevant capabilities of the computing platform to the possible security-relevant capabilities of the computing platform to identify security-relevant deficiencies; and

generating a list of at least a portion of the one or more security assets that are available but not utilized by the computing platform to address at least a portion of the security-relevant deficiencies.

24. The computing system of claim 23 , wherein generating the list of the at least a portion of the one or more security assets includes:

generating a list of ranked and recommended security assets that ranks the one or more available but not utilized security assets.

25. The computing system of claim 24 wherein generating the list of ranked and recommended security assets that ranks the one or more available but not utilized security assets includes:

ranking the one or more security assets based upon the anticipated use of the one or more security assets.

26. The computing system of claim 23 , further comprising providing the ability/option to implement one or more security assets which are available but not utilized by the computing platform.

27. The computing system of claim 23 , wherein identifying the one or more security assets which are available but not utilized includes:

utilizing artificial intelligence/machine learning to process the consolidated platform information to identify the one or more security assets which are available but not utilized.

28. The computing system of claim 23 , wherein the consolidated platform information includes client-defined consolidated platform information.

29. The computing system of claim 23 , wherein the consolidated platform information is received from a client, the client including one or more of a user, an owner, and an operator of the computing platform.

30. The computing system of claim 23 , wherein one or more of the current security-relevant capabilities and the possible security-relevant capabilities are provided by one or more of Content Delivery Network (CDN) systems; Database Activity Monitoring (DAM) systems; User Behavior Analytics (UBA) systems; Mobile Device Management (MDM) systems; Identity and Access Management (IAM) systems; Domain Name Server (DNS) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2021
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 056418/0326 →
Continuity (5)
Continuation 16432556 · Jun 5, 2019
Provisional Application 62817943 · Mar 13, 2019
Provisional Application 62737558 · Sep 27, 2018
Provisional Application 62681279 · Jun 6, 2018
Related Publication 20210288987A1 · Sep 16, 2021