IP Library Granted Patent US 12,182,266
Granted Patent B2
US 12,182,266 · App. 18/130,152 · Granted Dec 31, 2024

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,182,266
App. No.
18/130,152
Granted
Dec 31, 2024
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform; identifying two or more associated detection events included within the plurality of detection events; and grouping the two or more associated detection events to define a security incident.

Claims (132)

1. A computer-implemented method, executed on a computing device, comprising:

monitoring and logging, by a security-relevant subsystem, activity with respect to a computing platform;

detecting, by the security-relevant subsystem, a plurality of detection events;

receiving the plurality of detection events concerning a plurality of security events occurring on the security-relevant subsystem within the computing platform; wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem, including defining a universal detection rule and translating the universal detection rule into a technology-specific detection rule for the security-relevant subsystem;

identifying two or more associated detection events included within the plurality of detection events;

grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform;

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax;

generating comparison information that compares current security-relevant capabilities of the computing platform to comparative platform information determined for a comparative platform to identify a threat context indicator and assign a threat level; and

effectuating one or more remedial operations concerning one or more know conditions and assigned threat level.

2. The computer-implemented method of claim 1 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

3. The computer-implemented method of claim 1 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

4. The computer-implemented method of claim 1 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

5. The computer-implemented method of claim 4 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

6. The computer-implemented method of claim 4 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring and logging, by a security-relevant subsystem, activity with respect to a computing platform;

detecting, by the security-relevant subsystem, a plurality of detection events;

receiving the plurality of detection events concerning a plurality of security events occurring on the security-relevant subsystem within the computing platform; wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem, including defining a universal detection rule and translating the universal detection rule into a technology-specific detection rule for the security-relevant subsystem;

identifying two or more associated detection events included within the plurality of detection events;

grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform;

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax;

generating comparison information that compares current security-relevant capabilities of the computing platform to comparative platform information determined for a comparative platform to identify a threat context indicator and assign a threat level; and

effectuating one or more remedial operations concerning one or more know conditions and assigned threat level.

8. The computer program product of claim 7 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

9. The computer program product of claim 7 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

10. The computer program product of claim 7 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

11. The computer program product of claim 10 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

12. The computer program product of claim 10 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

13. A computing system including a processor and memory configured to perform operations comprising:

monitoring and logging, by a security-relevant subsystem, activity with respect to a computing platform;

detecting, by the security-relevant subsystem, a plurality of detection events;

receiving the plurality of detection events concerning a plurality of security events occurring on the security-relevant subsystem within the computing platform; wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem, including defining a universal detection rule and translating the universal detection rule into a technology-specific detection rule for the security-relevant subsystem;

identifying two or more associated detection events included within the plurality of detection events;

grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform;

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax;

generating comparison information that compares current security-relevant capabilities of the computing platform to comparative platform information determined for a comparative platform to identify a threat context indicator and assign a threat level; and

effectuating one or more remedial operations concerning one or more know conditions and assigned threat level.

14. The computing system of claim 13 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

15. The computing system of claim 13 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

16. The computing system of claim 13 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

17. The computing system of claim 16 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

18. The computing system of claim 16 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →
Continuity (2)
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20230319073A1 · Oct 5, 2023