IP Library Granted Patent US 12,229,263
Granted Patent B2
US 12,229,263 · App. 18/130,167 · Granted Feb 18, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O′Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,263
App. No.
18/130,167
Granted
Feb 18, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on two or more security-relevant subsystems within a computing platform; identifying two or more associated detection events included within the plurality of detection events; and grouping the two or more associated detection events to define a security incident.

Claims (138)

1. A computer-implemented method, executed on a computing device, comprising:

monitoring and logging activity with respect to a computing platform by a plurality of security-relevant subsystems;

detecting a plurality of detection events by the plurality of security-relevant subsystems;

receiving the plurality of detection events concerning a plurality of security events occurring on two or more of the plurality of security-relevant subsystems within the computing platform, wherein the plurality of security events are detected on the plurality of security-relevant subsystems via detection rules native to, and executed on, each of the respective plurality of security-relevant subsystems;

associating one or more artifacts with each of the plurality of detection events;

identifying two or more associated detection events included within the plurality of detection events, including identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries;

grouping the two or more associated detection events to define a security incident, including:

grouping the one or more overlapping artifacts/log entries associated with each of the two or more associated detection events resulting in identifying the two or more associated detection events; and

grouping differing artifacts/log entries associated with each of the two or more associated detection events that did not result in identifying the two or more associated detection events;

processing an event repository including at least a portion of the grouped associated detection events to define one or more identified attack patterns;

one or more of defining a new detection rule and modifying an existing detection rule based upon one or more identified attack patterns; and

automatically initiating an investigation of current activity within the computing platform based upon the current activity being similar to one or more of the identified attack patterns as part of remedial action.

2. The computer-implemented method of claim 1 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

3. The computer-implemented method of claim 1 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

4. The computer-implemented method of claim 1 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the two or more security-relevant subsystems within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

5. The computer-implemented method of claim 1 further comprising:

normalizing the plurality of detection events into a common ontology.

6. The computer-implemented method of claim 5 wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax.

7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring and logging activity with respect to a computing platform by a plurality of security-relevant subsystems;

detecting a plurality of detection events by the plurality of security-relevant subsystems;

receiving the plurality of detection events concerning a plurality of security events occurring on two or more of the plurality of security-relevant subsystems within the computing platform, wherein the plurality of security events are detected on the plurality of security-relevant subsystems via detection rules native to, and executed on, each of the respective plurality of security-relevant subsystems;

associating one or more artifacts with each of the plurality of detection events;

identifying two or more associated detection events included within the plurality of detection events, including identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries;

grouping the two or more associated detection events to define a security incident, including:

grouping the one or more overlapping artifacts/log entries associated with each of the two or more associated detection events resulting in identifying the two or more associated detection events; and

grouping differing artifacts/log entries associated with each of the two or more associated detection events that did not result in identifying the two or more associated detection events;

processing an event repository including at least a portion of the grouped associated detection events to define one or more identified attack patterns;

one or more of defining a new detection rule and modifying an existing detection rule based upon one or more identified attack patterns; and

automatically initiating an investigation of current activity within the computing platform based upon the current activity being similar to one or more of the identified attack patterns as part of remedial action.

8. The computer program product of claim 7 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

9. The computer program product of claim 7 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

10. The computer program product of claim 7 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the two or more security-relevant subsystems within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

11. The computer program product of claim 7 further comprising:

normalizing the plurality of detection events into a common ontology.

12. The computer program product of claim 11 wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax.

13. A computing system including a processor and memory configured to perform operations comprising:

monitoring and logging activity with respect to a computing platform by a plurality of security-relevant subsystems;

detecting a plurality of detection events by the plurality of security-relevant subsystems;

receiving the plurality of detection events concerning a plurality of security events occurring on two or more of the plurality of security-relevant subsystems within the computing platform, wherein the plurality of security events are detected on the plurality of security-relevant subsystems via detection rules native to, and executed on, each of the respective plurality of security-relevant subsystems;

associating one or more artifacts with each of the plurality of detection events;

identifying two or more associated detection events included within the plurality of detection events, including identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries;

grouping the two or more associated detection events to define a security incident, including:

grouping the one or more overlapping artifacts/log entries associated with each of the two or more associated detection events resulting in identifying the two or more associated detection events; and

grouping differing artifacts/log entries associated with each of the two or more associated detection events that did not result in identifying the two or more associated detection events;

processing an event repository including at least a portion of the grouped associated detection events to define one or more identified attack patterns;

one or more of defining a new detection rule and modifying an existing detection rule based upon one or more identified attack patterns; and

automatically initiating an investigation of current activity within the computing platform based upon the current activity being similar to one or more of the identified attack patterns as part of remedial action.

14. The computing system of claim 13 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

15. The computing system of claim 13 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

16. The computing system of claim 13 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the two or more security-relevant subsystems within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

17. The computing system of claim 13 further comprising:

normalizing the plurality of detection events into a common ontology.

18. The computing system of claim 17 wherein normalizing the plurality of detection events into a common ontology includes:

translating a syntax of each of the plurality of detection events into a common syntax.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →
Continuity (2)
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20230353594A1 · Nov 2, 2023
References Cited (60)
US 7797419B2 · Bhattacharya · 2010 [cited by examiner]
US 9027120B1 · Tidwell · 2015 [cited by examiner]
US 9069954B2 · Anurag · 2015 [cited by applicant]
US 10003605B2 · Muddu et al. · 2018 [cited by applicant]
US 10574700B1 · Dell'Amico · 2020 [cited by examiner]
US 10728263B1 · Neumann · 2020 [cited by applicant]
US 11258825B1 · Yang · 2022 [cited by examiner]
US 11316887B2 · Murphy et al. · 2022 [cited by applicant]
US 11483337B2 · Murphy et al. · 2022 [cited by applicant]
US 11652833B2 · Neuvirth · 2023 [cited by examiner]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20030206099A1 · Richman · 2003 [cited by applicant]
US 20050254654A1 · Rockwell et al. · 2005 [cited by applicant]
US 20160156664A1 · Nagaratnam · 2016 [cited by examiner]
US 20170063905A1 · Muddu · 2017 [cited by examiner]
US 20170134415A1 · Muddu et al. · 2017 [cited by applicant]
US 20190158517A1 · Muddu et al. · 2019 [cited by applicant]
US 20190260785A1 · Jenkinson et al. · 2019 [cited by applicant]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20210126938A1 · Trost · 2021 [cited by examiner]
US 20210160274A1 · Murphy et al. · 2021 [cited by applicant]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210250369A1 · Åvist · 2021 [cited by examiner]
US 20210273970A1 · Alshech · 2021 [cited by examiner]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220103575A1 · Fokker · 2022 [cited by examiner]
US 20220150268A1 · Herwono et al. · 2022 [cited by applicant]
US 20230164158A1 · Fellows · 2023 [cited by examiner]
CA 2428192A1 · 2004 [cited by applicant]
WO 2017193036A1 · 2017 [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jun. 13, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017339 on Jun. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jun. 29, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,182 on Jul. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,231 on Aug. 28, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jun. 23, 2023. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,152 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,182 on issue Date; Mar. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on issue Date; Jan. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,231 on issue Date; Apr. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on issue Date; Feb. 26, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017336 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017341 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017342 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017343 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017344 on Issue Date; Jun. 15, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jul. 11, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jul. 18, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Aug. 7, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jul. 29, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Sep. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Aug. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Oct. 30, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 14, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Oct. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Nov. 1, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Sep. 18, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on Dec. 19, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Dec. 6, 2024. [cited by applicant]