IP Library Granted Patent US 12,506,767
Granted Patent B2
US 12,506,767 · App. 17/825,024 · Granted Dec 23, 2025

Cybersecurity threat management using element mapping

Inventors: David B McKinley (Dartmouth, MA); Romans Bermans (Cadiz, ES); Joshua McCarthy (Morgan Hill, CA)
Assignee: Arctic Wolf Networks, Inc.
H04L63/1441G06F21/577H04L63/1433G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,767
App. No.
17/825,024
Granted
Dec 23, 2025
Kind
B2
Abstract

Disclosed techniques include cybersecurity threat management using element mapping. A plurality of cybersecurity threat protection applications is accessed. The cybersecurity threat protection applications include at least two different data management schemas. A first mapping of each of the plurality of cybersecurity threat protection applications is integrated. The first mapping includes a transformation of outputs of each of the plurality of cybersecurity threat protection applications. A second mapping of each of the plurality of cybersecurity threat protection applications is integrated. The second mapping includes a transformation of inputs of each of the plurality of cybersecurity threat protection applications. Cybersecurity is managed for a data network, based on data collected through the first mapping and data transmitted through the second mapping. The integrating a first mapping and a second mapping comprises a universal data layer for cybersecurity management. The universal data layer enables automation workflows for the data network.

Claims (43)

1. A computer-implemented method for cybersecurity management comprising:

accessing a plurality of cybersecurity threat protection applications, wherein the plurality of cybersecurity threat protection applications includes at least two different data management schemas;

integrating a first mapping of each of the plurality of cybersecurity threat protection applications, wherein the first mapping includes a transformation of outputs of each of the plurality of cybersecurity threat protection applications;

integrating a second mapping of each of the plurality of cybersecurity threat protection applications, wherein the second mapping includes a transformation of inputs of each of the plurality of cybersecurity threat protection applications;

dynamically swapping in, based on initially detecting a cryptojacking event in a data network, a cryptojacking cybersecurity threat protection application amongst the plurality of cybersecurity threat protection applications to enable the cryptojacking cybersecurity threat protection application to detect and respond to cryptojacking events without halting or disrupting current cybersecurity protections for the data network;

based on the swapping in of the cryptojacking cybersecurity threat protection application, updating the first mapping and second mapping with terms particular to the cryptojacking cybersecurity threat protection application, wherein the first mapping and second mapping map to a universal data layer; and

managing the current cybersecurity protections for the data network to detect and respond to the cryptojacking events in the data network, based on data collected through the first mapping and data transmitted through the second mapping.

2. The method of claim 1 wherein the integrating a first mapping and the integrating a second mapping comprises the universal data layer for cybersecurity management.

3. The method of claim 2 wherein the universal data layer enables automation workflows for the data network.

4. The method of claim 2 wherein the universal data layer enables additional cybersecurity threat protection applications to be managed for the data network.

5. The method of claim 1 wherein the managing cybersecurity includes graphical control of the plurality of cybersecurity threat protection applications.

6. The method of claim 1 further comprising developing one or more workflows to control the managing.

7. The method of claim 6 wherein the one or more workflows provide data stimuli to at least one of the plurality of cybersecurity threat protection applications, based on the second mapping.

8. The method of claim 7 wherein the one or more workflows receive data stimuli from at least one of the plurality of cybersecurity threat protection applications, based on the first mapping.

9. The method of claim 8 wherein the received data stimuli and provided data stimuli include at least two different applications within the plurality of cybersecurity threat protection applications.

10. The method of claim 1 further comprising activating one or more data enrichment protocols for a threat, based on data stimuli received from at least one of the plurality of cybersecurity threat protection applications.

11. The method of claim 10 wherein the one or more data enrichment protocols include accessing a website.

12. The method of claim 10 wherein the one or more data enrichment protocols enable enhanced functionality on at least one enriched application within the plurality of cybersecurity threat protection applications.

13. The method of claim 10 wherein the one or more data enrichment protocols enable modification of a typical response for the threat.

14. The method of claim 1 further comprising simulating cybersecurity threat scenarios by activating inputs of the first mapping independently of the plurality of cybersecurity threat protection applications.

15. The method of claim 14 wherein the simulating virtually activates cybersecurity measures in a simulation mode.

16. The method of claim 14 wherein the simulating actually activates cybersecurity measures in the data network.

17. The method of claim 16 wherein the actually activating cybersecurity measures in the data network is accomplished by activating outputs of the second mapping.

18. The method of claim 1 wherein the managing the current cybersecurity protections further includes managing one or more of antivirus analysis, phishing attacks, security information and event management (SIEM) triage, threat hunting, insider threat protection, threat intelligence, identity verification reinforcement, endpoint protection, forensic investigation, vulnerability management, cloud security orchestration, and end-to-end incident lifecycle case management.

19. The method of claim 1 wherein the first mapping and the second mapping are enabled using machine learning.

20. A computer program product embodied in a non-transitory computer readable medium for cybersecurity management, the computer program product comprising code which causes one or more processors to perform operations of:

accessing a plurality of cybersecurity threat protection applications, wherein the plurality of cybersecurity threat protection applications includes at least two different data management schemas;

integrating a first mapping of each of the plurality of cybersecurity threat protection applications, wherein the first mapping includes a transformation of outputs of each of the plurality of cybersecurity threat protection applications;

integrating a second mapping of each of the plurality of cybersecurity threat protection applications, wherein the second mapping includes a transformation of inputs of each of the plurality of cybersecurity threat protection applications;

dynamically swapping in, based on initially detecting a cryptojacking event in a data network, a cryptojacking cybersecurity threat protection application amongst the plurality of cybersecurity threat protection applications to enable the cryptojacking cybersecurity threat protection application to detect and respond to cryptojacking events without halting or disrupting current cybersecurity protections for the data network;

based on the swapping in of the cryptojacking cybersecurity threat protection application, updating the first mapping and second mapping with terms particular to the new cybersecurity threat protection application, wherein the first mapping and second mapping map to a universal data layer; and

managing the current cybersecurity protections for the data network to detect and respond to the cryptojacking events in the data network, based on data collected through the first mapping and data transmitted through the second mapping.

21. The computer program product of claim 20 , wherein the universal data layer enables automation workflows for the data network.

22. A computer system for cybersecurity comprising:

a memory which stores instructions;

one or more processors coupled to the memory wherein the one or more processors, when executing the instructions which are stored, are configured to:

access a plurality of cybersecurity threat protection applications, wherein the plurality of cybersecurity threat protection applications includes at least two different data management schemas;

integrate a first mapping of each of the plurality of cybersecurity threat protection applications, wherein the first mapping includes a transformation of outputs of each of the plurality of cybersecurity threat protection applications;

integrate a second mapping of each of the plurality of cybersecurity threat protection applications, wherein the second mapping includes a transformation of inputs of each of the plurality of cybersecurity threat protection applications;

dynamically swapping in, based on initially detecting a cryptojacking event in a data network, a cryptojacking cybersecurity threat protection application amongst the plurality of cybersecurity threat protection applications to enable the cryptojacking cybersecurity threat protection application to detect and respond to cryptojacking events without halting or disrupting current cybersecurity protections for the data network;

based on the swapping in of the cryptojacking cybersecurity threat protection application, updating the first mapping and second mapping with terms particular to the cryptojacking cybersecurity threat protection application, wherein the first mapping and second mapping map to a universal data layer; and

manage the current cybersecurity protections for the data network to detect and respond to the cryptojacking events in the data network, based on data collected through the first mapping and data transmitted through the second mapping.

23. The computer system of claim 22 , wherein the universal data layer enables automation workflows for the data network.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: REVELSTOKE SECURITY, INC.
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 067291/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: MCKINLEY, DAVID B; BERMANS, ROMANS; MCCARTHY, JOSHUA
To: REVELSTOKE SECURITY, INC.
Reel/Frame 064701/0780 →
Continuity (6)
Provisional Application 63327853 · Apr 6, 2022
Provisional Application 63297273 · Jan 7, 2022
Provisional Application 63274302 · Nov 1, 2021
Provisional Application 63234729 · Aug 19, 2021
Provisional Application 63193615 · May 27, 2021
Related Publication 20220385687A1 · Dec 1, 2022
References Cited (33)
US 10534971B2 · Huber, Jr. et al. · 2020 [cited by applicant]
US 10621172B2 · Azaria et al. · 2020 [cited by applicant]
US 10776316B2 · Baggeroer et al. · 2020 [cited by applicant]
US 10901863B2 · Lukkoor et al. · 2021 [cited by applicant]
US 10922452B2 · Liu et al. · 2021 [cited by applicant]
US 10924527B2 · Miller · 2021 [cited by applicant]
US 11611590B1 · Amar · 2023 [cited by examiner]
US 20060021045A1 · Cook · 2006 [cited by applicant]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20180041533A1 · Chesla · 2018 [cited by applicant]
US 20180121316A1 · Ismael et al. · 2018 [cited by applicant]
US 20180357422A1 · Telang · 2018 [cited by examiner]
US 20190089732A1 · Thomas · 2019 [cited by examiner]
US 20190297118A1 · Haugsnes · 2019 [cited by examiner]
US 20200053109A1 · Lancioni · 2020 [cited by examiner]
US 20200143060A1 · Tineo · 2020 [cited by examiner]
US 20200244412A1 · Kalhan · 2020 [cited by applicant]
US 20200244696A1 · Thomas · 2020 [cited by examiner]
US 20200252421A1 · Pendergast · 2020 [cited by examiner]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20200342552A1 · Sulit et al. · 2020 [cited by applicant]
US 20200380006A1 · Rockwell et al. · 2020 [cited by applicant]
US 20210042589A1 · Tokarev Sela et al. · 2021 [cited by applicant]
US 20210070333A1 · Chen · 2021 [cited by applicant]
US 20220053006A1 · O'Hara · 2022 [cited by examiner]
US 20220094705A1 · Tineo · 2022 [cited by examiner]
GB 2594248A · 2021 [cited by examiner]
KR 1020200083874A · 2020 [cited by applicant]
Sangani, Nilaykumar Kiran, and Haroot Zarger. “Machine learning in application security.” Advances in Security in Computing and Communications. IntechOpen, 2017. [cited by applicant]
Boutaba, Raouf, et al. “A comprehensive survey on machine learning for networking: evolution, applications and research opportunities.” Journal of Internet Services and Applications 9.1 (2018): 1-99. [cited by applicant]
International Search Report dated Aug. 31, 2022 for PCT 2022/031003. [cited by applicant]
Anonymous, “Cybersecurity in the Age of the Cloud”, Feb. 1, 2020 (Feb. 1, 2020) XP093131485, Retrieved from the Internet: URL:https://www.sans.org/media/cloud-security/eBook_cloud-security.pdf?msc=cloudsecuritylp, on Fe… [cited by applicant]
European Extended Search Report dated Feb. 3, 2025, 10 pages. [cited by applicant]