IP Library Granted Patent US 11,921,864
Granted Patent B2
US 11,921,864 · App. 17/951,690 · Granted Mar 5, 2024

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/577G06F8/65G06F18/214G06F21/53G06F21/55G06F21/554G06F21/56G06F21/561G06F21/562G06F21/566G06F21/568G06F30/20G06N20/00H04L63/0227H04L63/0263H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/145H04L63/164H04L63/20G06F2221/034G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,921,864
App. No.
17/951,690
Granted
Mar 5, 2024
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: obtaining first system-defined platform information concerning a first security-relevant subsystem within a computing platform; obtaining at least a second system-defined platform information concerning at least a second security-relevant subsystem within the computing platform; combining the first system-defined platform information and the at least a second system-defined platform information to form system-defined consolidated platform information; and generating a security profile based, at least in part, upon the system-defined consolidated platform information.

Claims (39)

1. A computer-implemented method for threat mitigation, executed on a computing device, comprising:

obtaining first system-defined platform information concerning a first security-relevant subsystem of a plurality of security-relevant subsystems within a computing platform based upon, at least in part, monitored activity of the first security-relevant subsystem with respect to the computing platform;

obtaining at least second system-defined platform information concerning at least a second security-relevant subsystem of the plurality of security-relevant subsystems within the computing platform based upon, at least in part, monitored activity of the second security-relevant subsystem with respect to the computing platform;

combining the first system-defined platform information and the at least second system-defined platform information to form system-defined consolidated platform information, the system-defined consolidated platform information independently defining the security-relevant subsystems that are present within the computing platform;

obtaining client-defined consolidated platform information from a client information source, the client-defined consolidated platform information identifying the security-relevant subsystems that the client believes are present within the computing platform;

comparing the system-defined consolidated platform information and the client-defined consolidated platform information to define differential consolidated platform information that identifies the difference between the independently identified security-relevant subsystems and the security-relevant subsystems believed to be present by the client; and

presenting the differential consolidated platform information of the computing platform to a third-party.

2. The computer-implemented method of claim 1 further comprising:

generating a security profile based, at least in part, upon the system-defined consolidated platform information.

3. The computer-implemented method of claim 1 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from one or more log files defined for the computing platform.

4. The computer-implemented method of claim 1 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from the first security-relevant subsystem and the at least a second security-relevant subsystem.

5. The computer-implemented method of claim 1 wherein the client-defined consolidated platform information is obtained from one or more client-completed questionnaires.

6. The computer-implemented method of claim 1 wherein the client-defined consolidated platform information is obtained from one or more client-deployed platform monitors.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations for threat mitigation, the operations comprising:

obtaining first system-defined platform information concerning a first security-relevant subsystem of a plurality of security-relevant subsystems within a computing platform based upon, at least in part, monitored activity of the first security-relevant subsystem with respect to the computing platform;

obtaining at least second system-defined platform information concerning at least a second security-relevant subsystem of the plurality of security-relevant subsystems within the computing platform based upon, at least in part, monitored activity of the second security-relevant subsystem with respect to the computing platform;

combining the first system-defined platform information and the at least second system-defined platform information to form system-defined consolidated platform information, the system-defined consolidated platform information independently defining the security-relevant subsystems that are present within the computing platform;

obtaining client-defined consolidated platform information from a client information source, the client-defined consolidated platform information identifying the security-relevant subsystems that the client believes are present within the computing platform;

comparing the system-defined consolidated platform information and the client-defined consolidated platform information to define differential consolidated platform information that identifies the difference between the independently identified security-relevant subsystems and the security-relevant subsystems believed to be present by the client; and

presenting the differential consolidated platform information of the computing platform to a third-party.

8. The computer program product of claim 7 further comprising:

generating a security profile based, at least in part, upon the system-defined consolidated platform information.

9. The computer program product of claim 7 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from one or more log files defined for the computing platform.

10. The computer program product of claim 7 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from the first security-relevant subsystem and the at least a second security-relevant subsystem.

11. The computer program product of claim 7 wherein the client-defined consolidated platform information is obtained from one or more client-completed questionnaires.

12. The computer program product of claim 7 wherein the client-defined consolidated platform information is obtained from one or more client-deployed platform monitors.

13. A computing system including a processor and memory configured to perform operations for threat mitigation, the operations comprising:

obtaining first system-defined platform information concerning a first security-relevant subsystem of a plurality of security-relevant subsystems within a computing platform based upon, at least in part, monitored activity of the first security-relevant subsystem with respect to the computing platform;

obtaining at least second system-defined platform information concerning at least a second security-relevant subsystem of the plurality of security-relevant subsystems within the computing platform based upon, at least in part, monitored activity of the second security-relevant subsystem with respect to the computing platform;

combining the first system-defined platform information and the at least second system-defined platform information to form system-defined consolidated platform information, the system-defined consolidated platform information independently defining the security-relevant subsystems that are present within the computing platform;

obtaining client-defined consolidated platform information from a client information source, the client-defined consolidated platform information identifying the security-relevant subsystems that the client believes are present within the computing platform;

comparing the system-defined consolidated platform information and the client-defined consolidated platform information to define differential consolidated platform information that identifies the difference between the independently identified security-relevant subsystems and the security-relevant subsystems believed to be present by the client; and

presenting the differential consolidated platform information of the computing platform to a third-party.

14. The computing system of claim 13 further comprising:

generating a security profile based, at least in part, upon the system-defined consolidated platform information.

15. The computing system of claim 13 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from one or more log files defined for the computing platform.

16. The computing system of claim 13 wherein the first system-defined platform information and the at least second system-defined platform information are obtained from the first security-relevant subsystem and the at least a second security-relevant subsystem.

17. The computing system of claim 13 wherein the client-defined consolidated platform information is obtained from one or more client-completed questionnaires.

18. The computing system of claim 13 wherein the client-defined consolidated platform information is obtained from one or more client-deployed platform monitors.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 065380/0552 →
Continuity (5)
Continuation 16432488 · Jun 5, 2019
Provisional Application 62817943 · Mar 13, 2019
Provisional Application 62737558 · Sep 27, 2018
Provisional Application 62681279 · Jun 6, 2018
Related Publication 20230018895A1 · Jan 19, 2023
Cited By (3)
US 12,299,116 US 12,373,566 US 12,717,931