IP Library Granted Patent US 12,261,860
Granted Patent B2
US 12,261,860 · App. 18/093,862 · Granted Mar 25, 2025

Cybersecurity state change buffer service

Inventors: Joshua McCarthy (Morgan Hill, CA); Nicholas Graves (Fresno, CA); David B McKinley (Dartmouth, MA); William Wilson (Fremont, CA)
Assignee: Arctic Wolf Networks, Inc.
H04L63/1416H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,860
App. No.
18/093,862
Granted
Mar 25, 2025
Kind
B2
Abstract

Disclosed techniques include integrated cybersecurity state change buffer service. A plurality of network-connected cybersecurity threat protection applications is accessed. A background synchronization service is initiated. The background synchronization service receives status from at least one of the plurality of cybersecurity threat protection applications. The status comprises high-volume incoming status data. The status is monitored, using the background synchronization service. A real-time state change in the status is identified, based on the monitoring. The identifying a real-time state change includes quantifying incoming data associated with the status. An actionable response is triggered, based on the state change that was identified. The actionable response enables self-healing of a connected security orchestration, automation, and response (SOAR) application system. The status is processed, using the background synchronization service, to provide the actionable response. The processing the status includes determining a classification of the state change.

Claims (40)

1. A computer-implemented method for cybersecurity management comprising:

accessing a plurality of network-connected cybersecurity threat protection applications;

initiating a background synchronization service, wherein the background synchronization service receives status from at least one of the plurality of cybersecurity threat protection applications, and wherein the background synchronization service comprises a multidirectional synchronization server;

monitoring the status, using the background synchronization service;

identifying a real-time state change in the status, based on the monitoring; and

triggering an actionable response, based on the state change that was identified.

2. The method of claim 1 further comprising processing the status, using the background synchronization service, to provide the actionable response.

3. The method of claim 2 wherein the processing the status enables filtering incoming status data.

4. The method of claim 2 wherein the processing the status includes determining a classification of the state change.

5. The method of claim 2 wherein the processing the status informs the actionable response.

6. The method of claim 2 wherein the identifying a real-time state change includes quantifying incoming data associated with the status.

7. The method of claim 1 wherein the status comprises high-volume incoming status data.

8. The method of claim 7 wherein the actionable response enables self-healing of a connected security orchestration, automation, and response (SOAR) application system.

9. The method of claim 8 wherein the self-healing prevents SOAR downtime.

10. The method of claim 7 wherein the actionable response enables scalability of a connected security orchestration, automation, and response (SOAR) system.

11. The method of claim 1 further comprising synchronizing operation of two or more of the plurality of cybersecurity threat protection applications.

12. The method of claim 11 wherein the synchronizing is based on the state change that was identified.

13. The method of claim 1 wherein the actionable response comprises a recommendation for a cybersecurity professional.

14. The method of claim 13 wherein the recommendation includes information on classification of the state change.

15. The method of claim 1 wherein the actionable response comprises an autonomic network reconfiguration.

16. The method of claim 1 wherein the actionable response comprises an autonomic cybersecurity threat protection application reconfiguration.

17. The method of claim 1 wherein the background synchronization service comprises a security orchestration, automation, and response (SOAR) microservice.

18. The method of claim 17 wherein the microservice implements the multidirectional synchronization server.

19. The method of claim 1 wherein the background synchronization service monitors cybersecurity threat protection application health.

20. The method of claim 1 wherein the background synchronization service communicates to the plurality of network-connected cybersecurity threat protection applications using cloud services.

21. The method of claim 20 wherein the cloud services and the background synchronization service enable redeployment of cybersecurity threat protection assets.

22. A computer program product embodied in a non-transitory computer readable medium for cybersecurity management, the computer program product comprising code which causes one or more processors to perform operations of:

accessing a plurality of network-connected cybersecurity threat protection applications;

initiating a background synchronization service, wherein the background synchronization service receives status from at least one of the plurality of cybersecurity threat protection applications, and wherein the background synchronization service comprises a multidirectional synchronization server;

monitoring the status, using the background synchronization service;

identifying a real-time state change in the status, based on the monitoring; and

triggering an actionable response, based on the state change that was identified.

23. A computer system for cybersecurity comprising:

a memory which stores instructions;

one or more processors coupled to the memory, wherein the one or more processors, when executing the instructions which are stored, are configured to:

access a plurality of network-connected cybersecurity threat protection applications;

initiate a background synchronization service, wherein the background synchronization service receives status from at least one of the plurality of cybersecurity threat protection applications, and wherein the background synchronization service comprises a multidirectional synchronization server;

monitor the status, using the background synchronization service;

identify a real-time state change in the status, based on the monitoring; and

trigger an actionable response, based on the state change that was identified.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: REVELSTOKE SECURITY, INC.
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 067291/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2023
From: MCCARTHY, JOSHUA; GRAVES, NICHOLAS; MCKINLEY, DAVID B; WILSON, WILLIAM
To: REVELSTOKE SECURITY, INC.
Reel/Frame 064751/0420 →
Continuity (9)
Continuation In Part 17825024 · May 26, 2022
Provisional Application 63404983 · Sep 9, 2022
Provisional Application 63350891 · Jun 10, 2022
Provisional Application 63327853 · Apr 6, 2022
Provisional Application 63297273 · Jan 7, 2022
Provisional Application 63274302 · Nov 1, 2021
Provisional Application 63234729 · Aug 19, 2021
Provisional Application 63193615 · May 27, 2021
Related Publication 20230156020A1 · May 18, 2023
References Cited (34)
US 8392218B2 · Becker et al. · 2013 [cited by applicant]
US 10534971B2 · Huber, Jr. et al. · 2020 [cited by applicant]
US 10621172B2 · Azaria et al. · 2020 [cited by applicant]
US 10776316B2 · Baggeroer et al. · 2020 [cited by applicant]
US 10838709B2 · Eapen et al. · 2020 [cited by applicant]
US 10901863B2 · Lukkoor et al. · 2021 [cited by applicant]
US 10922452B2 · Liu et al. · 2021 [cited by applicant]
US 10924527B2 · Miller · 2021 [cited by applicant]
US 10936234B2 · Su · 2021 [cited by applicant]
US 10938706B1 · Zacks et al. · 2021 [cited by applicant]
US 10938951B2 · White et al. · 2021 [cited by applicant]
US 10956880B2 · Towle · 2021 [cited by applicant]
US 11611590B1 · Amar · 2023 [cited by examiner]
US 20130318542A1 · Zamora · 2013 [cited by applicant]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20160330219A1 · Hasan · 2016 [cited by examiner]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20180121316A1 · Ismael et al. · 2018 [cited by applicant]
US 20190297118A1 · Haugsnes · 2019 [cited by examiner]
US 20200244412A1 · Kalhan · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20200305011A1 · Yaniv et al. · 2020 [cited by applicant]
US 20200342552A1 · Sulit et al. · 2020 [cited by applicant]
US 20200363781A1 · Mangels et al. · 2020 [cited by applicant]
US 20200380006A1 · Rockwell et al. · 2020 [cited by applicant]
US 20210014153A1 · Amend et al. · 2021 [cited by applicant]
US 20210042589A1 · Tokarev Sela et al. · 2021 [cited by applicant]
US 20210070333A1 · Chen · 2021 [cited by applicant]
US 20210099420A1 · Zhang · 2021 [cited by applicant]
KR 1020200083874A · 2020 [cited by applicant]
Axel Buecker et al. “IBM Security Solutions Architecture for Network, Server and Endpoint” Published Feb. 2011 (pp. 1-484) https://www.redbooks.ibm.com/redbooks/pdfs/sg247581.pdf (Year: 2011). [cited by examiner]
Sangani, Nilaykumar Kiran, and Haroot Zarger. “Machine learning in application security.” Advances in Security in Computing and Communications. IntechOpen, 2017. [cited by applicant]
Boutaba, Raouf, et al. “A comprehensive survey on maching learning for networking: evolution, applications and research opportunities.” Journal of Internet Services and Applications 9.1 (2018): 1-99. [cited by applicant]
International Search Report dated Aug. 31, 2022 for PCT 2022/031003. [cited by applicant]