IP Library Granted Patent US 11,550,907
Granted Patent B2
US 11,550,907 · App. 17/671,881 · Granted Jan 10, 2023

Systems and methods for intelligent cyber security threat detection and intelligent verification-informed handling of cyber security events through automated verification workflows

Inventors: Peter Silberman (Rockville, MD); Jonathan Hencinski (Herndon, VA); Dan Whalen (Herndon, VA); Roger Studner (Herndon, VA)
Assignee: Expel, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,907
App. No.
17/671,881
Granted
Jan 10, 2023
Kind
B2
Abstract

A system and method for automated verification of a cybersecurity event includes identifying a cybersecurity event of a subscriber; automatically constructing a response-enabled verification communication based on one or more features of the cybersecurity event satisfying verification-initiating criteria of an automated verification-initiation workflow, and transmitting the response-enabled verification communication to the subscriber associated with the cybersecurity event, wherein the response-enabled verification communication includes: one or more pieces of event-descriptive content; a first selectable interface object that, when selected by the subscriber, automatically increases a threat severity level of the cybersecurity event; and a second selectable interface object that, when selected by the subscriber, automatically de-escalates the threat severity level of the cybersecurity event causing a disposal of the cybersecurity event; and automatically routing the cybersecurity event to one of a cybersecurity threat escalation route and a cybersecurity threat de-escalation route based on subscriber input.

Claims (52)

1. A method for automated verification-informed handling of cybersecurity activity, the method comprising:

at a cybersecurity event detection and response service:

identifying a cybersecurity event based on event data or activity data associated with one or more computing or digital assets of a subscriber to the cybersecurity event detection and response service;

automatically constructing, by one or more computers, a response-enabled verification communication for the cybersecurity event based on (1) one or more features of the cybersecurity event satisfying verification-initiating criteria and (2) receiving, during a cybersecurity investigation, a verification-triggering input selecting a first selectable object displayed on a graphical user interface of the cybersecurity event detection and response service, wherein the first selectable object, when selected, causes an execution of an automated verification-initiation workflow that includes the automatically constructing of the response-enabled verification communication,

transmitting the response-enabled verification communication to the subscriber associated with the cybersecurity event, wherein the response-enabled verification communication includes:

(a) one or more pieces of event-descriptive content that include event-specific characteristics of the cybersecurity event;

(b) a second selectable interface object that, when selected by the subscriber, automatically increases a threat severity level of the cybersecurity event;

(c) a third selectable interface object that, when selected by the subscriber, automatically de-escalates the threat severity level of the cybersecurity event for an accelerated disposal of the cybersecurity event; and

(d) a text box data field that is configured to receive, as input, one or more text strings of cybersecurity event handling instructions from the subscriber;

identifying, by the one or more computers, a subscriber input selecting the second selectable interface object or the third selectable interface object of the response-enabled verification communication that confirms the cybersecurity event as either an authorized cybersecurity event or a non-authorized cybersecurity event and the one or more text strings of cybersecurity event handling instructions from the subscriber;

designating, based on the subscriber input, the cybersecurity event as one of:

(i) a cybersecurity incident if the subscriber input corresponds to the subscriber selecting the second selectable interface object of the response-enabled verification communication, wherein the designating the cybersecurity event as the cybersecurity incident includes converting the threat severity level of the cybersecurity event to a cybersecurity incident threat severity level; and

(ii) a disposable cybersecurity event if the subscriber input corresponds to the subscriber selecting the third selectable interface object of the response-enabled verification communication, wherein the designating the cybersecurity event as the disposable cybersecurity event includes converting the threat severity level of the cybersecurity event to a cybersecurity disposal threat severity level; and

automatically routing, based on the designation of the cybersecurity event, the cybersecurity event to one of (1) a cybersecurity threat escalation route of the cybersecurity event detection and response service if the cybersecurity event corresponds to the cybersecurity incident threat severity level and (2) a cybersecurity threat de-escalation route of the cybersecurity event detection and response service if the cybersecurity event corresponds to the cybersecurity disposal threat severity level.

2. The method according to claim 1 , further comprising:

automatically constructing an illustrative cybersecurity event graphic based on likely security critical event data associated with the cybersecurity event, wherein automatically constructing the response-enabled verification communication further includes installing the illustrative cybersecurity event graphic as one of the one or more pieces of event-descriptive content of the response-enabled verification communication.

3. The method according to claim 1 , further comprising:

automatically deriving text-based content that includes one or more text strings that textually communicate the event-specific characteristics based on likely security critical event data associated with the cybersecurity event,

wherein automatically constructing the response-enabled verification communication includes installing the text-based content as one of the one or more pieces of event-descriptive content of the response-enabled verification communication.

4. The method according to claim 1 , wherein

in response to automatically constructing the response-enabled verification communication:

electronically transmitting the response-enabled verification communication to a digital verification queue of the cybersecurity event detection and response service;

displaying, via a web-based user interface of the cybersecurity event detection and response service, a representation of the digital verification queue that includes the response-enabled verification communication; and

displaying, via the web-based user interface of the cybersecurity event detection and response service, the response-enabled verification communication.

5. The method according to claim 4 , further comprising:

while displaying the response-enabled verification communication:

receiving the subscriber input directed to the second selectable interface object of the response-enabled verification communication.

6. The method according to claim 4 , further comprising:

while displaying the response-enabled verification communication:

receiving the subscriber input directed to the third selectable interface object of the response-enabled verification communication.

7. The method according to claim 1 , wherein

the transmitting the response-enabled verification communication to the subscriber includes electronically sending the response-enabled verification communication to the subscriber during the cybersecurity investigation of the cybersecurity event.

8. The method according to claim 1 , wherein

the transmitting of the response-enabled verification communication includes electronically sending the response-enabled verification communication to an impartial administrator of the subscriber for selecting a response to the response-enabled verification communication.

9. The method according to claim 1 , wherein

in response to automatically constructing the response-enabled verification communication:

electronically transmitting the response-enabled verification communication to the subscriber via a bi-directional third-party messaging channel; and

at the bi-directional third-party messaging channel identifying the subscriber input comprising a selection of the second selectable interface object or selection of the third selectable interface object.

10. The method according to claim 1 , further comprising:

mitigating, via executing one or more cybersecurity threat mitigation actions, a cybersecurity threat associated with the cybersecurity event based on identifying the subscriber input directed to the second selectable interface object of the response-enabled verification communication.

11. The method according to claim 1 , wherein

in response to automatically constructing the response-enabled verification communication:

selectively identifying a communication transmission destination from a plurality of distinct communication transmission destinations based on a subscriber-defined cybersecurity policy; and

transmitting the response-enabled verification communication to the identified communication transmission destination based on the identification of the communication transmission destination.

12. The method according to claim 1 , wherein:

the verification-initiation criteria includes a cybersecurity event-type criterion; and

automatically constructing the response-enabled verification communication is based on a probable cybersecurity event-type associated with the cybersecurity event satisfying the cybersecurity event-type criterion.

13. The method according to claim 1 , wherein:

the cybersecurity event is routed to the cybersecurity threat escalation route of the cybersecurity event detection and response service, and

the cybersecurity threat escalation route automatically generates one or more service-proposed remediation actions for the cybersecurity event.

14. The method according to claim 13 , further comprising:

implementing, based on receiving the one or more text strings of cybersecurity event handling instructions from the subscriber, one or more programmable security heuristics that modifies an event detection and response policy of the subscriber and a current detection and response state of the cybersecurity event detection and response service for the one or more computing or digital assets of the subscriber.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2026
From: EXPEL, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 075041/0970 →
RELEASE OF SECURITY INTEREST Recorded Feb 23, 2026
From: JPMORGAN CHASE BANK, N.A.
To: EXPEL, INC.
Reel/Frame 073866/0099 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 13, 2023
From: EXPEL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 062741/0584 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2022
From: WHALEN, DAN; SILBERMAN, PETER; STUDNER, ROGER; HENCINSKI, JONATHAN
To: EXPEL, INC.
Reel/Frame 059043/0129 →
Continuity (2)
Provisional Application 63159895 · Mar 11, 2021
Related Publication 20220292189A1 · Sep 15, 2022
Cited By (10)
US 12,189,787 US 12,206,688 US 12,231,460 US 12,236,491 US 12,244,703 US 12,333,612 US 12,335,282 US 12,395,505 US 12,513,167 US 12,694,104