IP Library Granted Patent US 12,505,208
Granted Patent B2
US 12,505,208 · App. 17/976,924 · Granted Dec 23, 2025

Integrated cybersecurity threat management

Inventors: Joshua McCarthy (Morgan Hill, CA); Romans Bermans (Cadiz, ES); David B McKinley (Dartmouth, MA)
Assignee: Arctic Wolf Networks, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,208
App. No.
17/976,924
Granted
Dec 23, 2025
Kind
B2
Abstract

Disclosed techniques include integrated cybersecurity threat management. A plurality of network-connected cybersecurity threat protection applications is accessed. A plurality of heterogeneous log files is ingested, wherein the log files are generated by at least two of the cybersecurity threat protection applications. The plurality of heterogeneous log files that were ingested is evaluated to enable identification of cybersecurity threat protection application capabilities. Each of the plurality of log files is sorted. The sorting enables identification of cybersecurity threat protection elements among the plurality of log files. The cybersecurity threat protection elements that were identified are integrated. The integrated cybersecurity threat protection elements are evaluated. At least one response for cybersecurity threat management is generated, based on a result of the evaluating. The response is provided to a cybersecurity threat management entity. The cybersecurity threat management entity is a security orchestration automation and response application.

Claims (47)

1. A computer-implemented method for cybersecurity management comprising:

accessing a plurality of network-connected cybersecurity threat protection applications, wherein the cybersecurity threat protection application capabilities include endpoint protection, anti-phishing protection, antivirus protection, firewall protection, man-in-the-middle protection, denial of service protection, distributed denial of service protection, and ransomware protection;

ingesting a plurality of heterogeneous log files, wherein the log files are generated by at least two of the plurality of cybersecurity threat protection applications;

sorting each of the plurality of log files, wherein the sorting enables identification of cybersecurity threat protection elements among the plurality of log files;

integrating the cybersecurity threat protection elements that were identified;

evaluating the cybersecurity threat protection elements that were integrated; and

generating at least one response for cybersecurity threat management, based on a result of the evaluating.

2. The method of claim 1 further comprising evaluating the plurality of heterogeneous log files that were ingested to enable identification of cybersecurity threat protection application capabilities.

3. The method of claim 1 wherein the response is provided to a cybersecurity threat management entity.

4. The method of claim 3 wherein the cybersecurity threat management entity is a cybersecurity professional.

5. The method of claim 3 wherein the cybersecurity threat management entity is a security orchestration automation and response (SOAR) application.

6. The method of claim 1 wherein the plurality of cybersecurity threat protection applications comprises security information and event management (SIEM) applications.

7. The method of claim 1 further comprising generating a set of rules to enable the sorting, the integrating, the evaluating, and the generating.

8. The method of claim 7 wherein the set of rules is determined using human input.

9. The method of claim 7 wherein the set of rules is determined using machine learning.

10. The method of claim 7 wherein the set of rules is determined using a combination of human input and machine learning.

11. The method of claim 1 wherein the ingesting is based on a query to the plurality of cybersecurity threat protection applications.

12. The method of claim 1 wherein the ingesting occurs on a regular time interval.

13. The method of claim 12 wherein the regular time interval is user configurable.

14. The method of claim 1 wherein the ingesting occurs on a cybersecurity threat protection application push basis.

15. The method of claim 1 wherein the accessing a plurality of cybersecurity threat protection applications is enabled by digitally providing credentials to the plurality of cybersecurity threat protection applications.

16. The method of claim 1 wherein the integrating the cybersecurity threat protection elements is controlled by integration configuration.

17. The method of claim 16 wherein the integration configuration is performed by a cybersecurity professional.

18. The method of claim 16 wherein the integration configuration is obtained from a configuration library.

19. The method of claim 16 wherein the integration configuration is learned through machine learning.

20. The method of claim 1 wherein the threat protection elements include non-cybersecurity, network-related elements.

21. The method of claim 20 wherein the non-cybersecurity, network-related elements include information technology (IT) tool output, network configuration data, cybersecurity threat protection application metadata, network-related metadata, network client physical location data, network client internet protocol (IP) identification data, and user entered data.

22. The method of claim 1 further comprising concentrating the plurality of heterogeneous log files by a security information and event management (SIEM) application.

23. A computer program product embodied in a non-transitory computer readable medium for cybersecurity management, the computer program product comprising code which causes one or more processors to perform operations of:

accessing a plurality of network-connected cybersecurity threat protection applications, wherein the cybersecurity threat protection application capabilities include endpoint protection, anti-phishing protection, antivirus protection, firewall protection, man-in-the-middle protection, denial of service protection, distributed denial of service protection, and ransomware protection;

ingesting a plurality of heterogeneous log files, wherein the log files are generated by at least two of the plurality of cybersecurity threat protection applications;

sorting each of the plurality of log files, wherein the sorting enables identification of cybersecurity threat protection elements among the plurality of log files;

integrating the cybersecurity threat protection elements that were identified;

evaluating the cybersecurity threat protection elements that were integrated; and

generating at least one response for cybersecurity threat management, based on a result of the evaluating.

24. The computer program product of claim 23 , wherein the computer program product comprises code which causes the one or more processors to perform further operations of:

evaluating the plurality of heterogeneous log files that were ingested to enable identification of cybersecurity threat protection application capabilities.

25. A computer system for cybersecurity comprising:

a memory which stores instructions;

one or more processors coupled to the memory, wherein the one or more processors, when executing the instructions which are stored, are configured to:

access a plurality of network-connected cybersecurity threat protection applications, wherein the cybersecurity threat protection application capabilities include endpoint protection, anti-phishing protection, antivirus protection, firewall protection, man-in-the-middle protection, denial of service protection, distributed denial of service protection, and ransomware protection;

ingest a plurality of heterogeneous log files, wherein the log files are generated by at least two of the plurality of cybersecurity threat protection applications;

sort each of the plurality of log files, wherein the sorting enables identification of cybersecurity threat protection elements among the plurality of log files;

integrate the cybersecurity threat protection elements that were identified;

evaluate the cybersecurity threat protection elements that were integrated; and generate at least one response for cybersecurity threat management, based on a result of the evaluating.

26. The computer system of claim 25 , wherein the one or more processors, when executing the instructions which are stored, are further configured to:

evaluate the plurality of heterogeneous log files that were ingested to enable identification of cybersecurity threat protection application capabilities.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: REVELSTOKE SECURITY, INC.
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 067291/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2023
From: MCCARTHY, JOSHUA; BERMANS, ROMANS; MCKINLEY, DAVID B
To: REVELSTOKE SECURITY, INC.
Reel/Frame 064710/0129 →
Continuity (9)
Continuation In Part 17825024 · May 26, 2022
Provisional Application 63404983 · Sep 9, 2022
Provisional Application 63350891 · Jun 10, 2022
Provisional Application 63327853 · Apr 6, 2022
Provisional Application 63297273 · Jan 7, 2022
Provisional Application 63274302 · Nov 1, 2021
Provisional Application 63234729 · Aug 19, 2021
Provisional Application 63193615 · May 27, 2021
Related Publication 20230068946A1 · Mar 2, 2023
References Cited (36)
US 8392218B2 · Becker et al. · 2013 [cited by applicant]
US 10250619B1 · Park · 2019 [cited by examiner]
US 10394802B1 · Porath · 2019 [cited by examiner]
US 10534971B2 · Huber, Jr. et al. · 2020 [cited by applicant]
US 10621172B2 · Azaria et al. · 2020 [cited by applicant]
US 10776316B2 · Baggeroer et al. · 2020 [cited by applicant]
US 10838709B2 · Eapen et al. · 2020 [cited by applicant]
US 10901863B2 · Lukkoor et al. · 2021 [cited by applicant]
US 10922452B2 · Liu et al. · 2021 [cited by applicant]
US 10924527B2 · Miller · 2021 [cited by applicant]
US 10936234B2 · Su · 2021 [cited by applicant]
US 10938706B1 · Zacks et al. · 2021 [cited by applicant]
US 10938951B2 · White et al. · 2021 [cited by applicant]
US 10956880B2 · Towle · 2021 [cited by applicant]
US 11714823B1 · Breeden · 2023 [cited by examiner]
US 20130318542A1 · Zamora · 2013 [cited by applicant]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20150156213A1 · Baker · 2015 [cited by examiner]
US 20180121316A1 · Ismael et al. · 2018 [cited by applicant]
US 20200244412A1 · Kalhan · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20200305011A1 · Yaniv et al. · 2020 [cited by applicant]
US 20200342552A1 · Sulit et al. · 2020 [cited by applicant]
US 20200363781A1 · Mangels et al. · 2020 [cited by applicant]
US 20200380006A1 · Rockwell et al. · 2020 [cited by applicant]
US 20210014153A1 · Amend et al. · 2021 [cited by applicant]
US 20210042589A1 · Tokarev Sela et al. · 2021 [cited by applicant]
US 20210070333A1 · Chen · 2021 [cited by applicant]
US 20210099420A1 · Zhang · 2021 [cited by applicant]
US 20230087309A1 · Pietila · 2023 [cited by examiner]
KR 1020200083874A · 2020 [cited by applicant]
Robiah, Y. & Selamat, Siti Rahayu & Sahib, Shahrin. (2008). Intrusion Alert Correlation Technique Analysis for Heterogeneous Log. International Journal of Computer Science and Network Security. vol. 8, No. 9, Sep. 2008.… [cited by examiner]
Ning, Xia, Geoff Jiang, Haifeng Chen and Kenji Yoshihira. “HLAer : a System for Heterogeneous Log Analysis.” (22 pages) https://www.semanticscholar.org/paper/HLAer-%3A-a-System-for-Heterogeneous-Log-Analysis-Ning-Jiang/… [cited by examiner]
Sangani, Nilaykumar Kiran, and Haroot Zarger. “Machine learning in application security.” Advances in Security in Computing and Communications. IntechOpen, 2017. [cited by applicant]
Boutaba, Raouf, et al. “A comprehensive survey on maching learning for networking: evolution, applications and research opportunities.” Journal of Internet Services and Applications 9.1 (2018): 1-99. [cited by applicant]
International Search Report dated Aug. 31, 2022 for PCT 2022/031003. [cited by applicant]