IP Library Granted Patent US 12,464,028
Granted Patent B2
US 12,464,028 · App. 17/793,381 · Granted Nov 4, 2025

Systems and methods for network monitoring, reporting, and risk mitigation

Inventor: Andrew Loschmann (Ottawa, CA)
Assignee: Field Effect Software Inc.
H04L63/205H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,028
App. No.
17/793,381
Granted
Nov 4, 2025
Kind
B2
Abstract

A network monitoring, reporting and risk mitigation system collects events at a computing device within the local network to provide improved network security. The events are aggregated into alerts, which may be processed according to triggering definitions in order to create ARO (action, recommendations and observations) reports providing required or recommended actions to take or observations to a network administrator. The ARO reports may be processed by a remote server in order to generate contextual feedback for updating the triggering definitions.

Claims (45)

1 . A method of network security monitoring comprising:

receiving at a computing device sensor data pertaining to respective network events within a local computing network and generating corresponding events;

generating by the computing device one or more alerts from the generated events, each of the one or more alerts associated with alert information and an alert level;

processing at the computing device each of the one or more alerts according to a plurality of triggering definitions to trigger an action, recommendation or observation (ARO) security report comprising one or more of:

a required action to take to address a potential issue indicated by the ARO;

a recommended action to take to address a potential security issue indicated by the ARO; and

an observation related to the network security;

providing the ARO to a remote server external to the local network;

at the remote server, collecting contextual information from one or more external contextual sources;

at the remote server, generating feedback relating to at least one of the plurality of triggering definitions, wherein the feedback is generated based on at least the received ARO and the collected contextual information; and

at the computing device, receiving the feedback from the remote server and adjusting at least one of the plurality of triggering definitions based on the feedback,

wherein each of the one or more triggering definitions comprises:

an indication of a type of alert to be triggered; and

at least one condition that, when true, causes the triggering of the type of alert.

2 . The method of claim 1 , wherein each of the events comprise a respective event type selected from a predefined number of event types.

3 . The method of claim 2 , wherein each of the events further comprise received sensor data used in generating the respective event.

4 . The method of claim 1 , wherein the sensor data is received from one or more of a network source, an endpoint source, a log source, or a 3rd party application.

5 . The method of claim 1 , wherein each of the alerts include a respective alert type selected from a predefined number of alert types.

6 . The method of claim 5 , wherein each of the alerts further comprise an indication of the events used in generating the respective alert.

7 . The method of claim 1 , further comprising storing the events and alerts in one or more data stores.

8 . The method of claim 7 , further comprising generating a user interface for displaying events and/or alerts stored in the one or more data stores.

9 . The method of claim 1 , further comprising automatically performing the required action of the ARO or the recommended action of the ARO and providing feedback that the action has been performed.

10 . The method of claim 1 , further comprising notifying an operator of the required action of the ARO or the recommended action of the ARO and providing an interface to the operator for providing feedback that the action has been performed.

11 . The method of claim 1 , further comprising, at the remote server, receiving multiple AROs, wherein the feedback is generated based on the multiple AROs.

12 . The method of claim 1 , wherein processing the one or more alerts according to the plurality of triggering definitions comprises retrieving additional data associated with the one or more alerts and validating the triggering definitions using the additional data.

13 . The method of claim 1 , wherein the computing device is located within the local network and the network events, corresponding events, and generated alerts remain within the local network.

14 . The method of claim 1 , wherein the sensor data pertaining to respective network events are associated with one or more of login events, firewall logs, endpoint device log data, application events, activity logs or file access logs.

15 . The method of claim 1 , wherein the sensor data is received from a device selected from the group comprising a router, a switch, a hub, an access point, a file or data repository, a document management system, an application server, a web application server, an application logs, a domain server, a directory server, a data loss prevention endpoint process, domain name service, and a client computer process.

16 . A method comprising:

at a remote server, receiving one or more action, recommendation or observation (ARO);

at the remote server, collecting contextual information from one or more external contextual sources;

at the remote server, generating feedback related to one or more triggering definitions used in triggering AROs; and

providing the feedback to a computing device, the feedback being for use by the computing device in adjusting the one or more triggering definitions,

wherein each of the one or more triggering definitions comprises:

an indication of a type of alert to be triggered; and

at least one condition that, when true, causes the triggering of the type of alert.

17 . A computing device comprising:

a processor for executing instructions; and

a memory storing instructions which configure the computing device when executed by the processor to perform the method according to claim 1 .

18 . A server comprising:

a processor for executing instructions; and

a memory storing instructions which when executed by the processor configure the computing device to perform the method according to claim 17 .

19 . A system comprising:

a computing device according to claim 18 located within a local network; and

a server according to claim 18 located external to the local network.

Assignments (2)
SECURITY INTEREST Recorded Jul 21, 2023
From: FIELD EFFECT SOFTWARE INC.
To: THE BANK OF NOVA SCOTIA
Reel/Frame 064341/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: LOSCHMANN, ANDREW
To: FIELD EFFECT SOFTWARE INC.
Reel/Frame 064217/0024 →
Continuity (2)
Provisional Application 62962519 · Jan 17, 2020
Related Publication 20230051016A1 · Feb 16, 2023
References Cited (20)
US 10552615B2 · Cornell · 2020 [cited by examiner]
US 20080148398A1 · Mezack · 2008 [cited by examiner]
US 20170171231A1 · Reybok, Jr. · 2017 [cited by examiner]
US 20170171235A1 · Mulchandani · 2017 [cited by examiner]
US 20170223039A1 · Mont et al. · 2017 [cited by applicant]
US 20170230412A1 · Thomas · 2017 [cited by examiner]
US 20170279835A1 · Di Pietro · 2017 [cited by examiner]
US 20170346846A1 · Findlay · 2017 [cited by examiner]
US 20180255099A1 · Chen · 2018 [cited by examiner]
US 20190098037A1 · Shenoy, Jr. · 2019 [cited by examiner]
US 20190220580A1 · Brison · 2019 [cited by examiner]
US 20190318100A1 · Bhatia · 2019 [cited by examiner]
US 20200027096A1 · Cooner · 2020 [cited by examiner]
US 20200320845A1 · Livny · 2020 [cited by examiner]
US 20210103808A1 · Armstrong · 2021 [cited by examiner]
US 20210194785A1 · Raghuramu · 2021 [cited by examiner]
EP 1405187A1 · 2004 [cited by applicant]
International Search Report and Written Opinion in PCT/CA2021/050046, mailed Apr. 16, 2021, 7 pages. [cited by applicant]
Extended European Search Report dated Jan. 24, 2024, issued in related European Patent Application No. 21741523.1 (12 pages). [cited by applicant]
PCT International Preliminary Report on Patentability mailed Jul. 28, 2022, issued in related International Application No. PCT/CA2021/050046 (6 pages). [cited by applicant]