IP Library Granted Patent US 12,355,799
Granted Patent B2
US 12,355,799 · App. 17/857,461 · Granted Jul 8, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/1433G06F11/3409G06F21/577G06N5/04G06N20/00H04L63/1416H04L63/1441H04L67/34H04L67/60G06F2221/034H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,799
App. No.
17/857,461
Granted
Jul 8, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: defining a threat mitigation platform for a client, wherein the threat mitigation platform includes a plurality of threat detection capability modules; defining a rollout schedule for at least a portion of the plurality of threat detection capability modules; and presenting the rollout schedule to the client.

Claims (57)

1. A computer-implemented method, executed on a computing device, comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform;

generating at least a first set of platform information based upon, at least in part, the monitored activity of at least a portion of the plurality of security-relevant subsystems;

defining a threat mitigation platform for a client based upon, at least in part, the first set of platform information, so as to define at least one threat detection capability module for future installation on the computing platform, including applying a probabilistic process including artificial intelligence/machine learning to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules;

determining a difference between current security-relevant capabilities of the computing platform and possible security-relevant capabilities of the computing platform, including:

determining possible security-relevant capabilities of the computing platform using currently-deployed security relevant subsystem; and

determining possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems; and

presenting the rollout schedule to the client and an identification of one or more security-relevant deficiencies of the computing platform.

2. The computer-implemented method of claim 1 wherein the rollout schedule is a graphical rollout schedule.

3. The computer-implemented method of claim 1 wherein the rollout schedule is a text-based rollout schedule.

4. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

5. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

6. The computer-implemented method of claim 1 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

7. The computer-implemented method of claim 1 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

8. The computer-implemented method of claim 1 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

9. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform;

generating at least a first set of platform information based upon, at least in part, the monitored activity of at least a portion of the plurality of security-relevant subsystems;

defining a threat mitigation platform for a client based upon, at least in part, the first set of platform information, so as to define at least one threat detection capability module for future installation on the computing platform, including applying a probabilistic process including artificial intelligence/machine learning to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules;

determining a difference between current security-relevant capabilities of the computing platform and possible security-relevant capabilities of the computing platform, including:

determining possible security-relevant capabilities of the computing platform using currently-deployed security relevant subsystem; and

determining possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems; and

presenting the rollout schedule to the client and an identification of one or more security-relevant deficiencies of the computing platform.

10. The computer program product of claim 9 wherein the rollout schedule is a graphical rollout schedule.

11. The computer program product of claim 9 wherein the rollout schedule is a text-based rollout schedule.

12. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

13. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

14. The computer program product of claim 9 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

15. The computer program product of claim 9 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

16. The computer program product of claim 9 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

17. A computing system including a processor and memory configured to perform operations comprising:

monitoring, by a plurality of security-relevant subsystems, the activity of each respective security-relevant subsystem with respect to a computing platform, wherein the plurality of security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform;

generating at least a first set of platform information based upon, at least in part, the monitored activity of at least a portion of the plurality of security-relevant subsystems;

defining a threat mitigation platform for a client based upon, at least in part, the first set of platform information, so as to define at least one threat detection capability module for future installation on the computing platform, including applying a probabilistic process including artificial intelligence/machine learning to the first set of platform information, so as to define at least one threat detection capability module for installation on the computing platform;

defining a rollout schedule for at least a portion of the plurality of threat detection capability modules;

determining a difference between current security-relevant capabilities of the computing platform and possible security-relevant capabilities of the computing platform, including:

determining possible security-relevant capabilities of the computing platform using currently-deployed security relevant subsystem; and

determining possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems; and

presenting the rollout schedule to the client and an identification of one or more security-relevant deficiencies of the computing platform.

18. The computing system of claim 17 wherein the rollout schedule is a graphical rollout schedule.

19. The computing system of claim 17 wherein the rollout schedule is a text-based rollout schedule.

20. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as a periodic platform status update.

21. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

providing the rollout schedule to the client as an ad hoc platform status update.

22. The computing system of claim 17 wherein presenting the rollout schedule to the client includes:

enabling the client to view the rollout schedule via a user interface.

23. The computing system of claim 17 wherein the rollout schedule defines a date for each of the plurality of threat detection capability modules.

24. The computing system of claim 17 wherein the rollout schedule defines a content for each of the plurality of threat detection capability modules.

Assignments (1)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
Continuity (3)
Continuation 17016000 · Sep 9, 2020
Provisional Application 62897703 · Sep 9, 2019
Related Publication 20220353290A1 · Nov 3, 2022
References Cited (116)
US 7451488B2 · Cooper et al. · 2008 [cited by applicant]
US 7895643B2 · Yung · 2011 [cited by examiner]
US 8087087B1 · van Oorschot et al. · 2011 [cited by applicant]
US 8332947B1 · Bregman et al. · 2012 [cited by applicant]
US 8776229B1 · Aziz · 2014 [cited by examiner]
US 9369431B1 · Kirby et al. · 2016 [cited by applicant]
US 9665713B2 · Avasaraia · 2017 [cited by applicant]
US 9841882B2 · Wilkinson et al. · 2017 [cited by applicant]
US 9888024B2 · Roundy et al. · 2018 [cited by applicant]
US 9942249B2 · Gatti · 2018 [cited by applicant]
US 10032020B2 · Reybok et al. · 2018 [cited by applicant]
US 10033764B1 · Nachenberg · 2018 [cited by applicant]
US 10075466B1 · Oliphant et al. · 2018 [cited by applicant]
US 10154057B2 · Webb et al. · 2018 [cited by applicant]
US 10341377B1 · Dell'Amico et al. · 2019 [cited by applicant]
US 10547616B2 · Carter · 2020 [cited by examiner]
US 10594722B2 · Boggs et al. · 2020 [cited by applicant]
US 10614214B2 · McMurdie · 2020 [cited by applicant]
US 11170334B1 · Orzechowski et al. · 2021 [cited by applicant]
US 11297092B2 · Murphy et al. · 2022 [cited by applicant]
US 20030009696A1 · Bunker et al. · 2003 [cited by applicant]
US 20030028803A1 · Bunker et al. · 2003 [cited by applicant]
US 20030056116A1 · Bunker et al. · 2003 [cited by applicant]
US 20040003266A1 · Moshir et al. · 2004 [cited by applicant]
US 20090024663A1 · McGovern · 2009 [cited by applicant]
US 20090216588A1 · Coyne et al. · 2009 [cited by applicant]
US 20120124422A1 · Hsiao et al. · 2012 [cited by applicant]
US 20130055399A1 · Zaitsev · 2013 [cited by applicant]
US 20130247185A1 · Viscuso et al. · 2013 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20150067844A1 · Brandt · 2015 [cited by examiner]
US 20160149939A1 · Call · 2016 [cited by examiner]
US 20160191547A1 · Zafar · 2016 [cited by examiner]
US 20160196735A1 · Clayman · 2016 [cited by applicant]
US 20160314417A1 · Jayaraman · 2016 [cited by examiner]
US 20160352640A1 · Kompella et al. · 2016 [cited by applicant]
US 20170171231A1 · Reybok et al. · 2017 [cited by applicant]
US 20170185783A1 · Brucker et al. · 2017 [cited by applicant]
US 20170272458A1 · Muddu et al. · 2017 [cited by applicant]
US 20180025157A1 · Titonis · 2018 [cited by examiner]
US 20180069888A1 · Muddu et al. · 2018 [cited by applicant]
US 20180302303A1 · Skovron · 2018 [cited by examiner]
US 20180309642A1 · Rutten et al. · 2018 [cited by applicant]
US 20180309794A1 · Eskridge et al. · 2018 [cited by applicant]
US 20180316706A1 · Tsironis · 2018 [cited by applicant]
US 20180375892A1 · Ganor · 2018 [cited by applicant]
US 20190021004A1 · Shanmugavadivel et al. · 2019 [cited by applicant]
US 20190052660A1 · Cassidy et al. · 2019 [cited by applicant]
US 20190124104A1 · Apostolopoulos · 2019 [cited by applicant]
US 20190163469A1 · Sreenivasa · 2019 [cited by examiner]
US 20190163916A1 · Steele et al. · 2019 [cited by applicant]
US 20190243749A1 · Rutten et al. · 2019 [cited by applicant]
US 20190260795A1 · Ariaza et al. · 2019 [cited by applicant]
US 20190273760A1 · Jacobs · 2019 [cited by applicant]
US 20190377867A1 · Murphy et al. · 2019 [cited by applicant]
US 20200014711A1 · Rego et al. · 2020 [cited by applicant]
US 20200057953A1 · Livny et al. · 2020 [cited by applicant]
US 20200059451A1 · Huang et al. · 2020 [cited by applicant]
US 20200228570A1 · Strosaker et al. · 2020 [cited by applicant]
US 20210168161A1 · Dunn · 2021 [cited by examiner]
US 20210273957A1 · Boyer · 2021 [cited by applicant]
EP 3166279A1 · 2017 [cited by applicant]
EP 4028916A4 · 2023 [cited by applicant]
EP 4028917A4 · 2023 [cited by applicant]
EP 4028918A4 · 2023 [cited by applicant]
EP 4028919A4 · 2023 [cited by applicant]
EP 4028964A4 · 2023 [cited by applicant]
WO 2004086168A2 · 2004 [cited by applicant]
WO 2016123238A1 · 2016 [cited by applicant]
WO 2019152503A1 · 2019 [cited by applicant]
WO 2019152505A1 · 2019 [cited by applicant]
WO 2021050516A1 · 2021 [cited by applicant]
WO 2021050519A1 · 2021 [cited by applicant]
WO 2021050525A1 · 2021 [cited by applicant]
WO 2021050539A1 · 2021 [cited by applicant]
WO 2021050544A1 · 2021 [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,057 on Dec. 10, 2020. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,078 on Nov. 5, 2020. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,108 on Nov. 9, 2020. [cited by applicant]
NPL: Moran, et al. “Key Performance Indicators (KPIs) for Security Operations and Incident Response: Identifying Which KPIs Should Be Set, Monitored and Measured.” Internet: https://www.dflabs.com/wp-content/uploads/201… [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,000 on Jan. 8, 2021. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,031 on Nov. 23, 2020. [cited by applicant]
International Search Report and Written Opinion issued on Dec. 4, 2020 in PCT Application Serial No. PCT/US2020/049903. [cited by applicant]
International Search Report and Written Opinion issued on Dec. 3, 2020 in PCT Application Serial No. PCT/US2020/049912. [cited by applicant]
International Search Report and Written Opinion issued on Dec. 3, 2020 in PCT Application Serial No. PCT/US2020/049899. [cited by applicant]
International Search Report and Written Opinion issued on Jan. 7, 2021 in PCT Application Serial No. PCT/US2020/049936. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 17/016,108 on Mar. 8, 2021. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 17/016,078 on Mar. 8, 2021. [cited by applicant]
International Search Report and Written Opinion issued on Dec. 4, 2020 in PCT Application Serial No. PCT/US2020/049930. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 17/016,057 on May 3, 2021. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 17/016,031 on May 11, 2021. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 17/016,000 on Jun. 11, 2021. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,078 on Jun. 17, 2021. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 17/016,078 on Oct. 7, 2021. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,000 on Nov. 2, 2021. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,078 on Jan. 31, 2022. [cited by applicant]
Final Office Action issued in U.S. Appl. No. 17/016,078 on May 16, 2022. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 17/016,078 on Aug. 26, 2022. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 17/016,000 dated Nov. 9, 2020, 16 pages. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 17/016,031 dated Sep. 29, 2021. [cited by applicant]
Supplementary European Search Report and Search Opinion issued in related Application Serial No. 20862766.1 on Aug. 30, 2023. [cited by applicant]
Supplementary European Search Report and Search Opinion issued in related Application Serial No. 20863784.3 on Aug. 30, 2023. [cited by applicant]
Supplementary European Search Report and Search Opinion issued in related Application Serial No. 20864221.5 on Aug. 30, 2023. [cited by applicant]
European Search Report issued in the related Application Serial No. 20862682.0 on Aug. 30, 2023. [cited by applicant]
European Search Report issued in Application Serial No. 20863548.2 on Aug. 30, 2023. [cited by applicant]
Supplementary European Search Report issued in Application Serial No. 20863548.2 on Sep. 19, 2023. [cited by applicant]
Office Action issued in related Canadian Application Serial No. 3,150,288 on Jan. 17, 2025. [cited by applicant]
European Office Action issued in the related Application Serial No. 20862682.0 on Apr. 17, 2025. [cited by applicant]
European Office Action issued in the related Application Serial No. 20863548.2 on Apr. 17, 2025. [cited by applicant]
European Office Action issued in the related Application Serial No. 20864221.5 on Apr. 17, 2025. [cited by applicant]
Canadian Office Action issued in the related Application Serial No. 3150278 on Apr. 15, 2025. [cited by applicant]
Intention to grant issued related Application Serial No. 20862766.1 on May 8, 2025. [cited by applicant]
Intention to grant issued related Application Serial No. 20863784.3 on May 8, 2025. [cited by applicant]
Canadian Office Action issued in related Application Serial No. 3150293 on Apr. 24, 2025. [cited by applicant]
Canadian Office Action issued in related Application Serial No. 3150280 on Apr. 29, 2025. [cited by applicant]
Canadian Office Action issued in related Application Serial No. 3150293 on Apr. 29, 2025. [cited by applicant]