IP Library Granted Patent US 12,505,225
Granted Patent B2
US 12,505,225 · App. 17/890,304 · Granted Dec 23, 2025

Cybersecurity threat management using impact scoring

Inventors: Joshua McCarthy (Morgan Hill, CA); Romans Bermans (Cadiz, ES); David B McKinley (Dartmouth, MA)
Assignee: Arctic Wolf Networks, Inc.
G06F21/577G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,225
App. No.
17/890,304
Granted
Dec 23, 2025
Kind
B2
Abstract

Disclosed techniques include cybersecurity threat management using impact scoring. A plurality of cybersecurity threat protection applications is accessed. A first cybersecurity threat notification is received from one of the plurality of cybersecurity threat protection applications. An impact score is dynamically assigned to the first cybersecurity threat notification, wherein the assigning an impact score is based on information about a device for which the first cybersecurity threat notification was received. The impact score is weighted based on an evaluation of a user of the device for which the first cybersecurity threat notification was received. The weighting is further based on evaluation of device owners and evaluation of an asset. The information about a device and information about one or more users of the device comprise impact score metadata. The first cybersecurity threat notification is responded to, based on the impact score. The dynamically assigning includes the impact score metadata.

Claims (55)

1 . A computer-implemented method for cybersecurity management comprising:

accessing a plurality of cybersecurity threat protection applications;

detecting, based on applying an anti-cryptojacking application, a cryptojacking event of a first device, wherein the cryptojacking event corresponds to mining cryptocurrency using the first device;

receiving a first cybersecurity threat notification from one of the plurality of cybersecurity threat protection applications based on the detected cryptojacking event;

dynamically assigning an impact score to the first cybersecurity threat notification using a machine learning neural network, wherein the assigning an impact score is based on information about the first device for which the first cybersecurity threat notification was received, wherein the information about the first device for which the first cybersecurity threat notification was received comprises a security metric that comprises a mean-time-to-respond to the threat notification for the device;

detecting, based on applying an insider threat protection application, an insider threat event of a second device, wherein the insider threat event corresponds to one or more users of the second device moving data from the first device to the second device;

receiving an additional cybersecurity threat notification based on the detected insider threat event, wherein the additional cybersecurity threat notification includes a management level designation for at least one of the one or more users of the second device, wherein the second device is distinct from the first device for which the first cybersecurity threat notification was received;

adjusting the impact score assigned to the first cybersecurity threat notification for the cryptojacking event of the first device based on the additional cybersecurity threat notification, wherein the adjusting comprises multiplying the impact score by a weighting value based on the management level designation for the at least one of the one more users of the second device received in the additional cybersecurity threat notification based on the detected insider threat event;

determining whether the impact score satisfies a threshold value; and

executing, based on a determination that the impact score satisfies the threshold value, a cryptojacking countermeasure to respond to the first cybersecurity threat notification.

2 . The method of claim 1 wherein the information about the device and information about one or more users of the device comprise impact score metadata.

3 . The method of claim 1 wherein the dynamically assigning includes impact score metadata.

4 . The method of claim 1 further comprising weighting the impact score based on an evaluation of the device for which the first cybersecurity threat notification was received.

5 . The method of claim 1 further comprising weighting the impact score based on an evaluation of a user of the device for which the first cybersecurity threat notification was received.

6 . The method of claim 1 further comprising weighting the impact score based on an evaluation of an owner of the device for which the first cybersecurity threat notification was received.

7 . The method of claim 1 further comprising weighting the impact score based on an evaluation of an asset for which the first cybersecurity threat notification was received.

8 . The method of claim 1 wherein the impact score is generated automatically.

9 . The method of claim 1 wherein the impact score is generated by human intervention.

10 . The method of claim 9 wherein the human intervention is performed with computer-assisted information.

11 . The method of claim 1 wherein the device comprises a group of devices.

12 . The method of claim 11 wherein the group of devices comprises a network infrastructure.

13 . The method of claim 11 wherein the group of devices comprises multiple end-user devices.

14 . The method of claim 11 wherein the group of devices comprises a portable, network-connected device.

15 . The method of claim 1 wherein the additional cybersecurity threat notification includes information regarding the device for which the first cybersecurity threat notification was received.

16 . The method of claim 1 wherein the additional cybersecurity threat notification includes impact score metadata.

17 . The method of claim 1 wherein the impact score informs one or more workflows controlling cybersecurity threat management.

18 . The method of claim 1 wherein the information about a device for which the first cybersecurity threat notification was received includes a management level designation for the device or a user of the device.

19 . The method of claim 1 wherein the information about a device for which the first cybersecurity threat notification was received includes a usage location designation.

20 . The method of claim 1 wherein the information about a device for which the first cybersecurity threat notification was received includes a security clearance designation for the device or a user of the device.

21 . A computer program product embodied in a non-transitory computer readable medium for cybersecurity management, the computer program product comprising code which causes one or more processors to perform operations of:

accessing a plurality of cybersecurity threat protection applications;

detecting, based on applying an anti-cryptojacking application, a cryptojacking event of a first device, wherein the cryptojacking event corresponds to mining cryptocurrency using the first device;

receiving a first cybersecurity threat notification from one of the plurality of cybersecurity threat protection applications based on the detected cryptojacking event;

dynamically assigning an impact score to the first cybersecurity threat notification using a machine learning neural network, wherein the assigning an impact score is based on information about the first device for which the first cybersecurity threat notification was received, wherein the information about the first device for which the first cybersecurity threat notification was received comprises a security metric that comprises a mean-time-to-respond to the threat notification for the first device;

detecting, based on applying an insider threat protection application, an insider threat event of a second device, wherein the insider threat event corresponds to one or more users of the second device moving data from the first device to the second device;

receiving an additional cybersecurity threat notification based on the detected insider threat event, wherein the additional cybersecurity threat notification includes a management level designation for at least one of the one or more users of the second device, wherein the second device is distinct from the first device for which the first cybersecurity threat notification was received;

adjusting the impact score assigned to the first cybersecurity threat notification for the cryptojacking event of the first device based on the additional cybersecurity threat notification, wherein the adjusting comprises multiplying the impact score by a weighting value based on the management level designation for the at least one of the one more users of the second device received in the additional cybersecurity threat notification based on the detected insider threat event;

determining whether the impact score satisfies a threshold value; and

executing, based on a determination that the impact score satisfies the threshold value, a cryptojacking countermeasure to respond to the first cybersecurity threat notification.

22 . The computer program product of claim 21 , wherein the computer program product comprises code which causes the one or more processors to perform further operations of:

weighting the impact score based on an evaluation of the device for which the first cybersecurity threat notification was received.

23 . A computer system for cybersecurity comprising:

a memory which stores instructions;

one or more processors coupled to the memory wherein the one or more processors, when executing the instructions which are stored, are configured to:

access a plurality of cybersecurity threat protection applications;

detect, based on applying an anti-cryptojacking application, a cryptojacking event of a first device, wherein the cryptojacking event corresponds to mining cryptocurrency using the first device;

receive a first cybersecurity threat notification from one of the plurality of cybersecurity threat protection applications based on the detected cryptojacking event;

dynamically assign an impact score to the first cybersecurity threat notification using a machine learning neural network, wherein the assigning an impact score is based on information about the first device for which the first cybersecurity threat notification was received, wherein the information about the first device for which the first cybersecurity threat notification was received comprises a security metric that comprises a mean-time-to-respond to the threat notification for the first device;

detecting, based on applying an insider threat protection application, an insider threat event of a second device, wherein the insider threat event corresponds to one or more users of the second device moving data from the first device to the second device;

receiving an additional cybersecurity threat notification based on the detected insider threat event, wherein the additional cybersecurity threat notification includes a management level designation for at least one of the one or more users of the second device, wherein the second device is distinct from the first device for which the first cybersecurity threat notification was received;

adjusting the impact score assigned to the first cybersecurity threat notification for the cryptojacking event of the first device based on the additional cybersecurity threat notification, wherein the adjusting comprises multiplying the impact score by a weighting value based on the management level designation for the at least one of the one more users of the second device received in the additional cybersecurity threat notification based on the detected insider threat event;

determine whether the impact score satisfies a threshold value; and

execute, based on a determination that the impact score satisfies the threshold value, a cryptojacking countermeasure to respond to the first cybersecurity threat notification.

24 . The computer system of claim 23 , wherein the one or more processors, when executing the instructions which are stored, are further configured to:

weight the impact score based on an evaluation of the device for which the first cybersecurity threat notification was received.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: REVELSTOKE SECURITY, INC.
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 067291/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: MCCARTHY, JOSHUA; BERMANS, ROMANS; MCKINLEY, DAVID B
To: REVELSTOKE SECURITY, INC.
Reel/Frame 064709/0305 →
Continuity (8)
Continuation In Part 17825024 · May 26, 2022
Provisional Application 63350891 · Jun 10, 2022
Provisional Application 63327853 · Apr 6, 2022
Provisional Application 63297273 · Jan 7, 2022
Provisional Application 63274302 · Nov 1, 2021
Provisional Application 63234729 · Aug 19, 2021
Provisional Application 63193615 · May 27, 2021
Related Publication 20220405401A1 · Dec 22, 2022
References Cited (41)
US 10534971B2 · Huber, Jr. et al. · 2020 [cited by applicant]
US 10621172B2 · Azaria et al. · 2020 [cited by applicant]
US 10776316B2 · Baggeroer et al. · 2020 [cited by applicant]
US 10901863B2 · Lukkoor et al. · 2021 [cited by applicant]
US 10922452B2 · Liu et al. · 2021 [cited by applicant]
US 10924527B2 · Miller · 2021 [cited by applicant]
US 11411980B2 · Triantafillos · 2022 [cited by examiner]
US 11444974B1 · Shakhzadyan · 2022 [cited by examiner]
US 11611590B1 · Amar · 2023 [cited by examiner]
US 20060021045A1 · Cook · 2006 [cited by applicant]
US 20100154027A1 · Sobel · 2010 [cited by examiner]
US 20140137257A1 · Martinez · 2014 [cited by examiner]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20180041533A1 · Chesla · 2018 [cited by applicant]
US 20180121316A1 · Ismael et al. · 2018 [cited by applicant]
US 20180357422A1 · Telang et al. · 2018 [cited by applicant]
US 20190297118A1 · Haugsnes · 2019 [cited by examiner]
US 20200053109A1 · Lancioni · 2020 [cited by examiner]
US 20200143060A1 · Tineo · 2020 [cited by applicant]
US 20200233955A1 · Ramzan · 2020 [cited by examiner]
US 20200244412A1 · Kalhan · 2020 [cited by applicant]
US 20200244696A1 · Thomas et al. · 2020 [cited by applicant]
US 20200252421A1 · Pendergast et al. · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20200342552A1 · Sulit et al. · 2020 [cited by applicant]
US 20200380006A1 · Rockwell et al. · 2020 [cited by applicant]
US 20200412758A1 · Trivellato · 2020 [cited by examiner]
US 20210021644A1 · Crabtree · 2021 [cited by examiner]
US 20210042589A1 · Tokarev Sela et al. · 2021 [cited by applicant]
US 20210070333A1 · Chen · 2021 [cited by applicant]
US 20210117251A1 · Cristofi · 2021 [cited by examiner]
US 20210136089A1 · Costea · 2021 [cited by examiner]
US 20220053006A1 · O'Hara · 2022 [cited by applicant]
US 20220094705A1 · Tineo · 2022 [cited by examiner]
GB 2594248A · 2021 [cited by applicant]
KR 1020200083874 · 2020 [cited by applicant]
Anonymous, “Cybersecurity in the Age of the Cloud”, Feb. 1, 2020 (Feb. 1, 2020) XP093131485, Retrieved from the Internet: URL:https://www.sans.org/m edi a/cloud-security /eBook_ cloud-security. pdf?msc=cloudsecu rityl p… [cited by applicant]
Boutaba, Raouf, et al. “A comprehensive survey on machine learning for networking: evolution, applications and research opportunities.” Journal of Internet Services and Applications 9.1 (2018): 1-99. [cited by applicant]
European Extended Search Report dated Feb. 3, 2025, 10 pages. [cited by applicant]
Intemational Search Report dated Aug. 31, 2022 for PCT 2022/031003. [cited by applicant]
Sangani, Nilaykumar Kiran, and Haroot Zarger. “Machine learning in application security.” Advances in Security in Computing and Communications. IntechOpen, 2017. [cited by applicant]