IP Library Granted Patent US 12,223,047
Granted Patent B2
US 12,223,047 · App. 18/130,182 · Granted Feb 11, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: ReliaQuest Holdings, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,047
App. No.
18/130,182
Granted
Feb 11, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for defining a first query for a first security-relevant subsystem within a computing platform; processing the first query on the first security-relevant subsystem to generate a first data set concerning security events occurring on the first security-relevant subsystem; and receiving the first data set concerning the security events occurring on the first security-relevant subsystem.

Claims (72)

1. A computer-implemented method, executed on a computing device, comprising:

defining a first query for a first security-relevant subsystem within a computing platform, including defining a single search in a universal language, and translating the single search in the universal language into a plurality of technology-specific searches, including a first security-relevant subsystem specific search executable by the first security-relevant subsystem, including translating a syntax of the unified query into a syntax of each of the plurality of plurality of technology-specific searches;

processing the first query on the first security-relevant subsystem to generate a first data set concerning security events occurring on the first security-relevant subsystem; and

receiving the first data set concerning the security events occurring on the first security-relevant subsystem.

2. The computer-implemented method of claim 1 further comprising:

identifying two or more associated detection events defined within the first data set; and

grouping the two or more associated detection events to define a security incident.

3. The computer-implemented method of claim 2 wherein one or more artifacts/log entries are associated with each of the first data set.

4. The computer-implemented method of claim 3 wherein identifying two or more associated detection events defined within the first data set includes:

identifying two or more detection events defined within the first data set that have common artifacts/log entries.

5. The computer-implemented method of claim 4 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

6. The computer-implemented method of claim 1 further comprising:

defining a second query for a second security-relevant subsystem within the computing platform;

processing the second query on the second security-relevant subsystem to generate a second data set concerning security events occurring on the second security-relevant subsystem; and

receiving the second data set concerning the security events occurring on the second security-relevant subsystem.

7. The computer-implemented method of claim 6 further comprising:

identifying two or more associated detection events defined within the second data set; and

grouping the two or more associated detection events to define a security incident.

8. The computer-implemented method of claim 7 wherein one or more artifacts/log entries are associated with each of the second data set.

9. The computer-implemented method of claim 8 wherein identifying two or more associated detection events defined within the second data set includes:

identifying two or more detection events defined within the second data set that have common artifacts/log entries.

10. The computer-implemented method of claim 9 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

11. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

defining a first query for a first security-relevant subsystem within a computing platform, including defining a single search in a universal language, and translating the single search in the universal language into a plurality of technology-specific searches, including a first security-relevant subsystem specific search executable by the first security-relevant subsystem, including translating a syntax of the unified query into a syntax of each of the plurality of plurality of technology-specific searches;

processing the first query on the first security-relevant subsystem to generate a first data set concerning security events occurring on the first security-relevant subsystem; and

receiving the first data set concerning the security events occurring on the first security-relevant subsystem.

12. The computer program product of claim 11 further comprising:

identifying two or more associated detection events defined within the first data set; and

grouping the two or more associated detection events to define a security incident.

13. The computer program product of claim 12 wherein one or more artifacts/log entries are associated with each of the first data set.

14. The computer program product of claim 13 wherein identifying two or more associated detection events defined within the first data set includes:

identifying two or more detection events defined within the first data set that have common artifacts/log entries.

15. The computer program product of claim 14 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

16. The computer program product of claim 11 further comprising:

defining a second query for a second security-relevant subsystem within the computing platform;

processing the second query on the second security-relevant subsystem to generate a second data set concerning security events occurring on the second security-relevant subsystem; and

receiving the second data set concerning the security events occurring on the second security-relevant subsystem.

17. The computer program product of claim 16 further comprising:

identifying two or more associated detection events defined within the second data set; and

grouping the two or more associated detection events to define a security incident.

18. The computer program product of claim 17 wherein one or more artifacts/log entries are associated with each of the second data set.

19. The computer program product of claim 18 wherein identifying two or more associated detection events defined within the second data set includes:

identifying two or more detection events defined within the second data set that have common artifacts/log entries.

20. The computer program product of claim 19 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

21. A computing system including a processor and memory configured to perform operations comprising:

defining a first query for a first security-relevant subsystem within a computing platform, including defining a single search in a universal language, and translating the single search in the universal language into a plurality of technology-specific searches, including a first security-relevant subsystem specific search executable by the first security-relevant subsystem, including translating a syntax of the unified query into a syntax of each of the plurality of plurality of technology-specific searches;

processing the first query on the first security-relevant subsystem to generate a first data set concerning security events occurring on the first security-relevant subsystem; and

receiving the first data set concerning the security events occurring on the first security-relevant subsystem.

22. The computing system of claim 21 further comprising:

identifying two or more associated detection events defined within the first data set; and

grouping the two or more associated detection events to define a security incident.

23. The computing system of claim 22 wherein one or more artifacts/log entries are associated with each of the first data set.

24. The computing system of claim 23 wherein identifying two or more associated detection events defined within the first data set includes:

identifying two or more detection events defined within the first data set that have common artifacts/log entries.

25. The computing system of claim 24 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

26. The computing system of claim 21 further comprising:

defining a second query for a second security-relevant subsystem within the computing platform;

processing the second query on the second security-relevant subsystem to generate a second data set concerning security events occurring on the second security-relevant subsystem; and

receiving the second data set concerning the security events occurring on the second security-relevant subsystem.

27. The computing system of claim 26 further comprising:

identifying two or more associated detection events defined within the second data set; and

grouping the two or more associated detection events to define a security incident.

28. The computing system of claim 27 wherein one or more artifacts/log entries are associated with each of the second data set.

29. The computing system of claim 28 wherein identifying two or more associated detection events defined within the second data set includes:

identifying two or more detection events defined within the second data set that have common artifacts/log entries.

30. The computing system of claim 29 wherein grouping the two or more associated detection events to define a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →
Continuity (2)
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20230319074A1 · Oct 5, 2023
References Cited (67)
US 7797419B2 · Bhattacharya et al. · 2010 [cited by applicant]
US 9027120B1 · Tidwell et al. · 2015 [cited by applicant]
US 9069954B2 · Anurag · 2015 [cited by examiner]
US 10003605B2 · Muddu et al. · 2018 [cited by applicant]
US 10574700B1 · Dell'Amico et al. · 2020 [cited by applicant]
US 10728263B1 · Neumann · 2020 [cited by applicant]
US 11258825B1 · Yang et al. · 2022 [cited by applicant]
US 11316887B2 · Murphy et al. · 2022 [cited by applicant]
US 11483337B2 · Murphy et al. · 2022 [cited by applicant]
US 11652833B2 · Neuvirth et al. · 2023 [cited by applicant]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20030206099A1 · Richman · 2003 [cited by examiner]
US 20050254654A1 · Rockwell · 2005 [cited by examiner]
US 20160156664A1 · Nagaratnam et al. · 2016 [cited by applicant]
US 20170063905A1 · Muddu et al. · 2017 [cited by applicant]
US 20170134415A1 · Muddu et al. · 2017 [cited by applicant]
US 20190158517A1 · Muddu et al. · 2019 [cited by applicant]
US 20190260785A1 · Jenkinson et al. · 2019 [cited by applicant]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20210126938A1 · Trost et al. · 2021 [cited by applicant]
US 20210160274A1 · Murphy et al. · 2021 [cited by applicant]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210250369A1 · Avist et al. · 2021 [cited by applicant]
US 20210273970A1 · Alshech et al. · 2021 [cited by applicant]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220103575A1 · Fokker · 2022 [cited by applicant]
US 20220150268A1 · Herwono et al. · 2022 [cited by applicant]
US 20230164158A1 · Fellows et al. · 2023 [cited by applicant]
CA 2428192A1 · 2004 [cited by applicant]
WO 2017193036A1 · 2017 [cited by applicant]
WO 2023192677A1 · 2023 [cited by applicant]
WO 2023192680A1 · 2023 [cited by applicant]
WO 2023192682A1 · 2023 [cited by applicant]
WO 2023192683A1 · 2023 [cited by applicant]
WO 2023192684A1 · 2023 [cited by applicant]
WO 2023192685A1 · 2023 [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jun. 13, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017339 on Jun. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jun. 23, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,167 on Jun. 27, 2023. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,152 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,167 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on issue Date; Jan. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on issue Date; Feb. 26, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017336 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017341 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017342 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017343 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017344 on Issue Date; Jun. 15, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jun. 29, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,231 on Aug. 28, 2023. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,231 on issue Date; Apr. 29, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jul. 11, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jul. 18, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jul. 29, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Aug. 7, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Aug. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Oct. 30, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 14, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Oct. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Oct. 16, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Nov. 1, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Sep. 18, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on Dec. 19, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Dec. 11, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Dec. 6, 2024. [cited by applicant]