IP Library Granted Patent US 12,457,223
Granted Patent B2
US 12,457,223 · App. 17/389,704 · Granted Oct 28, 2025

System and method for aggregating and securing managed detection and response connection interfaces between multiple networked sources

Inventors: Randy Clayton (Frederick, MD); Jason Crabtree (Vienna, VA); Angadbir Salaria (Herndon, VA); Andrew Sellers (Monument, CO); Marian Trnkus (Chevy Chase, MD)
Assignee: QOMPLX LLC
H04L63/1408G06F16/2477G06F16/951H04L63/1425H04L63/1441H04L63/20H04L41/149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,223
App. No.
17/389,704
Granted
Oct 28, 2025
Kind
B2
Abstract

A system and method for a flexible, high-speed Managed Detection and Response platform that ingests, parses, normalizes, monitors, and correlates nearly any log source or security tool output. The MDR comprising of a declarative connector service that tags events with appropriate data source labels to facilitating data isolation, proper handling, and provenance across multiple customers and security products but otherwise aggregate alerts into a single data stream for consumption by the MDR SOC operators. A connector service further provides a programmatic (API-based) means to interchange data securely across environments. Event data is aggregated by the Managed Detection and Response platform that then utilizes enhanced log ingest capabilities to process the data allowing SOC operators to be able to write rules against the alerts.

Claims (26)

1. A system for facilitating data isolation across multiple entities and security products comprising:

a computing device comprising a plurality of programming instructions cause the computing device to:

receive a service configuration for a service from a plurality of different managed detection and response client services, wherein the service configuration comprises authentication information, access information, and processing information for the service, wherein the processing information specifies data processing and storage requirements for events associated with the service, wherein the processing information includes regulatory compliance requirements specifying isolation requirements for computing and networking events;

retrieve data from the service using at least the authentication information and the access information in the service configuration, wherein the retrieved data comprises computing and networking events;

tag the retrieved data by embedding a tag into each computing and networking event of the retrieved data according to the respective processing information, wherein the embedded tag is used to enforce the data processing and storage requirements specified by the processing information during subsequent processing, wherein the embedded tag comprises an indication of the regulatory compliance requirements for the computing and networking event;

organize the tagged data into a single data stream;

encrypt the single data stream; and

send the encrypted data stream comprising the tagged data over a network to a secure processing facility;

a secure processing facility configured to receive the encrypted data stream and use the embedded tags to process the computing and networking events according to their respective requirements by isolating access to the computing and networking events based on the regulatory compliance requirements indicated in the embedded tags.

2. The system of claim 1 , wherein the tag further comprises data provenance information.

3. The system of claim 1 , wherein the computing device comprises multiple computing systems forming a distributed system.

4. The system of claim 1 , wherein the retrieval of data from more than one service is accomplished via a connector workflow configuration.

5. The system of claim 4 , wherein the connector workflow configuration is a data processing workflow generated from a distributed computational graph.

6. The system of claim 1 , wherein the data is exchanged using a RESTful API that facilitates data exchange between and among cloud-based services.

7. A method for facilitating data isolation across multiple entities and security products, comprising the steps of:

receiving a service configuration for a service from a plurality of different managed detection and response client services, wherein the service configuration comprises authentication information, access information, and processing information for the service, wherein the processing information specifies data processing and storage requirements for events associated with the service, wherein the processing information includes regulatory compliance requirements specifying isolation requirements for computing and networking events;

retrieving data from the service using at least the authentication information and the access information in the service configuration, wherein the retrieved data comprises computing and networking events;

tagging the retrieved data by embedding a tag into each computing and networking event of the retrieve data according to the respective processing information, wherein the embedded tag is used to enforce the data processing and storage requirements specified by the processing information during subsequent processing, wherein the embedded tag comprises an indication of the regulatory compliance requirements for the computing and networking event;

organizing the tagged data into a single data stream;

encrypting the single data stream; and

sending the encrypted data stream comprising the tagged data over a network to a secure processing facility;

a secure processing facility configured to receive the encrypted data stream and use the embedded tags to process the computing and networking events according to their respective requirements by isolating access to the computing and networking events based on the regulatory compliance requirements indicated in the embedded tags.

8. The method of claim 7 , wherein the tag further comprises data provenance information.

9. The method of claim 7 , wherein the retrieval of data from more than one service is accomplished via a connector workflow configuration.

10. The method of claim 9 , wherein the connector workflow configuration is a data processing workflow generated from a distributed computational graph.

11. The method of claim 7 , wherein the data is exchanged using a RESTful API that facilitates data exchange between and among cloud-based services.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: CRABTREE, JASON; SALARIA, ANGADBIR; SELLERS, ANDREW; TRNKUS, MARIAN; CLAYTON, RANDY
To: QOMPLX, INC.
Reel/Frame 060006/0995 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2022
From: CRABTREE, JASON; SELLERS, ANDREW; SALARIA, ANGADBIR; TRNKUS, MARIAN; CLAYTON, RANDY L.
To: QOMPLX, INC.
Reel/Frame 059924/0340 →
Continuity (57)
Continuation In Part 17074882 · Oct 20, 2020
Continuation In Part 17035029 · Sep 28, 2020
Continuation In Part 17008276 · Aug 31, 2020
Continuation In Part 17000504 · Aug 24, 2020
Continuation In Part 16855724 · Apr 22, 2020
Continuation In Part 16836717 · Mar 31, 2020
Continuation In Part 16777270 · Jan 30, 2020
Continuation In Part 16720383 · Dec 19, 2019
Continuation In Part 16412340 · May 14, 2019
Continuation In Part 16267893 · Feb 5, 2019
Continuation In Part 16248133 · Jan 15, 2019
Continuation In Part 15887496 · Feb 2, 2018
Continuation In Part 15849901 · Dec 21, 2017
Continuation In Part 15835436 · Dec 7, 2017
Continuation In Part 15835312 · Dec 7, 2017
Continuation 15823363 · Nov 27, 2017
Continuation In Part 15823285 · Nov 27, 2017
Continuation In Part 15818733 · Nov 20, 2017
Continuation In Part 15813097 · Nov 14, 2017
Continuation In Part 15806697 · Nov 8, 2017
Continuation In Part 15790457 · Oct 23, 2017
Continuation In Part 15790327 · Oct 23, 2017
Continuation In Part 15788718 · Oct 19, 2017
Continuation In Part 15788002 · Oct 19, 2017
Continuation In Part 15787601 · Oct 18, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15673368 · Aug 9, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15376657 · Dec 13, 2016
Continuation In Part 15343209 · Nov 4, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15229476 · Aug 5, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62568298 · Oct 4, 2017
Provisional Application 62568312 · Oct 4, 2017
Provisional Application 62568305 · Oct 4, 2017
Provisional Application 62568291 · Oct 4, 2017
Provisional Application 62568307 · Oct 4, 2017
Related Publication 20220060510A1 · Feb 24, 2022
References Cited (103)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7072863B1 · Phillips et al. · 2006 [cited by applicant]
US 7657406B2 · Tolone et al. · 2010 [cited by applicant]
US 7698213B2 · Lancaster · 2010 [cited by applicant]
US 7739653B2 · Venolia · 2010 [cited by applicant]
US 8065257B2 · Kuecuekyan · 2011 [cited by applicant]
US 8145761B2 · Liu et al. · 2012 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8788306B2 · Delurgio et al. · 2014 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8997233B2 · Green et al. · 2015 [cited by applicant]
US 9134966B2 · Brock et al. · 2015 [cited by applicant]
US 9141360B1 · Chen et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9672355B2 · Titonis et al. · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 9946517B2 · Talby et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10102480B2 · Dirac et al. · 2018 [cited by applicant]
US 10210246B2 · Stojanovic et al. · 2019 [cited by applicant]
US 10210255B2 · Crabtree et al. · 2019 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10318882B2 · Brueckner et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10511498B1 · Narayan et al. · 2019 [cited by applicant]
US 11392422B1 · Filiz · 2022 [cited by examiner]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton et al. · 2003 [cited by applicant]
US 20040030775A1 · Lauzon · 2004 [cited by examiner]
US 20050289072A1 · Sabharwal · 2005 [cited by applicant]
US 20060149575A1 · Varadarajan et al. · 2006 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20080034036A1 · Takeshima · 2008 [cited by examiner]
US 20090064088A1 · Barcia et al. · 2009 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20090293128A1 · Lippmann et al. · 2009 [cited by applicant]
US 20110060821A1 · Loizeaux et al. · 2011 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20110154341A1 · Pueyo et al. · 2011 [cited by applicant]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130191416A1 · Lee et al. · 2013 [cited by applicant]
US 20130246996A1 · Duggal et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140046691A1 · Malec · 2014 [cited by examiner]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140244612A1 · Bhasin et al. · 2014 [cited by applicant]
US 20140279762A1 · Kaypanya et al. · 2014 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150236935A1 · Bassett · 2015 [cited by applicant]
US 20150281225A1 · Schoen et al. · 2015 [cited by applicant]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Ata et al. · 2015 [cited by applicant]
US 20150347414A1 · Xiao et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160004858A1 · Chen et al. · 2016 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160099960A1 · Gerritz et al. · 2016 [cited by applicant]
US 20160105454A1 · Li et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160342606A1 · Mouel et al. · 2016 [cited by applicant]
US 20160350442A1 · Crosby · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170063896A1 · Muddu et al. · 2017 [cited by applicant]
US 20170083380A1 · Bishop et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170206360A1 · Brucker et al. · 2017 [cited by applicant]
US 20170322959A1 · Tidwell et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180053328A1 · Simonovic · 2018 [cited by examiner]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20190095533A1 · Levine et al. · 2019 [cited by applicant]
US 20200076772A1 · Kapp · 2020 [cited by examiner]
US 20200241962A1 · Dain · 2020 [cited by examiner]
US 20200404082A1 · Shcherbakov · 2020 [cited by examiner]
CN 105302532B · 2018 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]