IP Library Patent Application 18130218
Patent Application
App. No. 18/130,218

THREAT MITIGATION SYSTEM AND METHOD

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/130,218
Abstract

A computer-implemented method, computer program product and computing system for defining a universal detection rule for execution on a computing platform; processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform; providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem; processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and providing the second detection rule to the second security-relevant subsystem for execution on the first security-relevant subsystem.

Claims (114)

1 . A computer-implemented method, executed on a computing device, comprising:

defining a universal detection rule for execution on a computing platform;

processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;

providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;

processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and

providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.

2 . The computer-implemented method of claim 1 further comprising:

receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.

3 . The computer-implemented method of claim 2 further comprising:

identifying two or more associated detection events included within the first plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

4 . The computer-implemented method of claim 3 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.

5 . The computer-implemented method of claim 4 wherein:

identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

6 . The computer-implemented method of claim 1 further comprising:

receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.

7 . The computer-implemented method of claim 6 further comprising:

identifying two or more associated detection events included within the second plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

8 . The computer-implemented method of claim 7 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.

9 . The computer-implemented method of claim 8 wherein:

identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

10 . The computer-implemented method of claim 1 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

11 . A computer program product residing on a computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

defining a universal detection rule for execution on a computing platform;

processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;

providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;

processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and

providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.

12 . The computer program product of claim 11 further comprising:

receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.

13 . The computer program product of claim 12 further comprising:

identifying two or more associated detection events included within the first plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

14 . The computer program product of claim 13 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.

15 . The computer program product of claim 14 wherein:

identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

16 . The computer program product of claim 11 further comprising:

receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.

17 . The computer program product of claim 16 further comprising:

identifying two or more associated detection events included within the second plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

18 . The computer program product of claim 17 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.

19 . The computer program product of claim 18 wherein:

identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

20 . The computer program product of claim 11 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

21 . A computing system including a processor and memory configured to perform operations comprising:

defining a universal detection rule for execution on a computing platform;

processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;

providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;

processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and

providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.

22 . The computing system of claim 21 further comprising:

receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.

23 . The computing system of claim 22 further comprising:

identifying two or more associated detection events included within the first plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

24 . The computing system of claim 23 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.

25 . The computing system of claim 24 wherein:

identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

26 . The computing system of claim 21 further comprising:

receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.

27 . The computing system of claim 26 further comprising:

identifying two or more associated detection events included within the second plurality of detection events; and

grouping the two or more associated detection events to define a security incident.

28 . The computing system of claim 27 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.

29 . The computing system of claim 28 wherein:

identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and

grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

30 . The computing system of claim 21 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →