IP Library Granted Patent US 12,223,048
Granted Patent B2
US 12,223,048 · App. 18/130,231 · Granted Feb 11, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,048
App. No.
18/130,231
Granted
Feb 11, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms; storing the plurality of detection events to form an event repository; and processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository, thus defining one or more identified attack patterns.

Claims (155)

1. A computer-implemented method, executed on a computing device, comprising:

monitoring and logging, by multiple security-relevant subsystems, activity with respect to one or more computing platforms;

receiving a plurality of detection events concerning a plurality of security events occurring on the multiple security-relevant subsystems within the one or more computing platforms;

storing the plurality of detection events to form an event repository;

analyzing one or more current detection rules using machine learning;

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository, thus defining one or more identified attack patterns;

defining a new detection rule based, at least in part, upon the one or more identified attack patterns and the one or more current detection rules, wherein defining the new detection rule includes:

defining a universal rule; and

translating the universal rule into customer specific technology rules;

directly executing the customer specific technology rules on one or more pieces of customer technology;

directly detecting security events on the one or more pieces of customer technology; and

directly executing a remedial action plan via the one or more pieces of customer technology.

2. The computer-implemented method of claim 1 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

3. The computer-implemented method of claim 1 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

4. The computer-implemented method of claim 1 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

5. The computer-implemented method of claim 1 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

6. The computer-implemented method of claim 5 wherein processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository includes:

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events and their associated artifacts/log entries stored within the event repository.

7. The computer-implemented method of claim 1 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

8. The computer-implemented method of claim 1 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

9. The computer-implemented method of claim 1 further comprising:

initiating an investigation of current activity within the one or more computing platforms based, at least in part, upon the current activity being similar to the one or more identified attack patterns.

10. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

monitoring and logging, by multiple security-relevant subsystems, activity with respect to one or more computing platforms;

receiving a plurality of detection events concerning a plurality of security events occurring on the multiple security-relevant subsystems within the one or more computing platforms;

storing the plurality of detection events to form an event repository;

analyzing one or more current detection rules using machine learning;

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository, thus defining one or more identified attack patterns;

defining a new detection rule based, at least in part, upon the one or more identified attack patterns and the one or more current detection rules, wherein defining the new detection rule includes:

defining a universal rule; and

translating the universal rule into customer specific technology rules;

directly executing the customer specific technology rules on one or more pieces of customer technology;

directly detecting security events on the one or more pieces of customer technology; and

directly executing a remedial action plan via the one or more pieces of customer technology.

11. The computer program product of claim 10 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

12. The computer program product of claim 10 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

13. The computer program product of claim 10 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

14. The computer program product of claim 10 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

15. The computer program product of claim 14 wherein processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository includes:

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events and their associated artifacts/log entries stored within the event repository.

16. The computer program product of claim 10 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

17. The computer program product of claim 10 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

18. The computer program product of claim 10 further comprising:

initiating an investigation of current activity within the one or more computing platforms based, at least in part, upon the current activity being similar to the one or more identified attack patterns.

19. A computing system including a processor and memory configured to perform operations comprising:

monitoring and logging, by multiple security-relevant subsystems, activity with respect to one or more computing platforms;

receiving a plurality of detection events concerning a plurality of security events occurring on the multiple security-relevant subsystems within the one or more computing platforms;

storing the plurality of detection events to form an event repository;

analyzing one or more current detection rules using machine learning;

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository, thus defining one or more identified attack patterns;

defining a new detection rule based, at least in part, upon the one or more identified attack patterns and the one or more current detection rules, wherein defining the new detection rule includes:

defining a universal rule; and translating the universal rule into customer specific technology rules;

directly executing the customer specific technology rules on one or more pieces of customer technology;

directly detecting security events on the one or more pieces of customer technology; and

directly executing a remedial action plan via the one or more pieces of customer technology.

20. The computing system of claim 19 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

21. The computing system of claim 19 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

22. The computing system of claim 19 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

23. The computing system of claim 19 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

24. The computing system of claim 23 wherein processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository includes:

processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events and their associated artifacts/log entries stored within the event repository.

25. The computing system of claim 19 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

26. The computing system of claim 19 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

27. The computing system of claim 19 further comprising:

initiating an investigation of current activity within the one or more computing platforms based, at least in part, upon the current activity being similar to the one or more identified attack patterns.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →
Continuity (2)
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20230315852A1 · Oct 5, 2023
References Cited (63)
US 7797419B2 · Bhattacharya et al. · 2010 [cited by applicant]
US 9027120B1 · Tidwell et al. · 2015 [cited by applicant]
US 9069954B2 · Anurag · 2015 [cited by applicant]
US 10003605B2 · Muddu et al. · 2018 [cited by applicant]
US 10574700B1 · Dell'Amico et al. · 2020 [cited by applicant]
US 10728263B1 · Neumann · 2020 [cited by applicant]
US 11258825B1 · Yang et al. · 2022 [cited by applicant]
US 11316887B2 · Murphy et al. · 2022 [cited by applicant]
US 11483337B2 · Murphy et al. · 2022 [cited by applicant]
US 11652833B2 · Neuvirth et al. · 2023 [cited by applicant]
US 20030188189A1 · Desai · 2003 [cited by examiner]
US 20030206099A1 · Richman · 2003 [cited by applicant]
US 20050254654A1 · Rockwell et al. · 2005 [cited by applicant]
US 20160156664A1 · Nagaratnam et al. · 2016 [cited by applicant]
US 20170063905A1 · Muddu et al. · 2017 [cited by applicant]
US 20170134415A1 · Muddu et al. · 2017 [cited by applicant]
US 20190158517A1 · Muddu et al. · 2019 [cited by applicant]
US 20190260785A1 · Jenkinson et al. · 2019 [cited by applicant]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20210126938A1 · Trost et al. · 2021 [cited by applicant]
US 20210160274A1 · Murphy et al. · 2021 [cited by applicant]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210250369A1 · Avist et al. · 2021 [cited by applicant]
US 20210273970A1 · Alshech et al. · 2021 [cited by applicant]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220103575A1 · Fokker · 2022 [cited by applicant]
US 20220150268A1 · Herwono et al. · 2022 [cited by applicant]
US 20230164158A1 · Fellows et al. · 2023 [cited by applicant]
CA 2428192A1 · 2004 [cited by examiner]
WO WO2017193036A1 · 2017 [cited by examiner]
WO 2023192677A1 · 2023 [cited by applicant]
WO 2023192680A1 · 2023 [cited by applicant]
WO 2023192682A1 · 2023 [cited by applicant]
WO 2023192683A1 · 2023 [cited by applicant]
WO 2023192684A1 · 2023 [cited by applicant]
WO 2023192685A1 · 2023 [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017339 on Jun. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jun. 13, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jun. 23, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,167 on Jun. 27, 2023. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,182 on issue Date; Mar. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,152 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,167 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on issue Date; Jan. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on issue Date; Feb. 26, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017336 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017341 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017342 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017343 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017344 on Issue Date; Jun. 15, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jun. 29, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,182 on Jul. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jul. 11, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jul. 18, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Aug. 7, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Oct. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Oct. 16, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Sep. 9, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Oct. 30, 2024. [cited by applicant]
Final Office issued in related U.S. Appl. No. 18/130,271 on Dec. 19, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 14, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Dec. 11, 2024. [cited by applicant]