IP Library Granted Patent US 12,499,232
Granted Patent B2
US 12,499,232 · App. 18/130,271 · Granted Dec 16, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,232
App. No.
18/130,271
Granted
Dec 16, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms; processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events; and storing the processed detection events within a graph content repository.

Claims (156)

1 . A computer-implemented method, executed on a computing device, comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms;

normalizing the plurality of detection events into a common ontology, including translating a syntax of each of the plurality of detection events into a common syntax;

processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events;

storing the processed detection events within a graph content repository;

defining a probabilistic model to assign a threat level to one or more of the plurality of security events;

processing the graph content repository using a machine learning model to identify attack patterns defined within the processed detection events stored within the graph content repository, thus defining one or more identified attack patterns;

defining a universal detection rule in a common language based on the one or more identified attack patterns;

translating the universal detection rule into a plurality of technology-specific rules executable on a plurality of discrete pieces of customer technology;

analyzing the one or more identified attack patterns to identify a plurality of steps associated with at least one of the one or more identified attack patterns;

identifying current platform activity within the one or more computing platforms including a portion of the plurality of steps associated with the at least one of the one or more identified attack patterns;

initiating an investigation the of current activity within the one or more computing platforms; and

grouping the current activity with one or more prior detection events to define a security incident based upon, at least in part, common artifacts associated with the current activity and with the one or more prior detection events.

2 . The computer-implemented method of claim 1 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

3 . The computer-implemented method of claim 1 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

4 . The computer-implemented method of claim 1 wherein processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events include

identifying nodes and edges within the plurality of detection events to make them compatible with the graph database.

5 . The computer-implemented method of claim 1 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

6 . The computer-implemented method of claim 1 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

7 . The computer-implemented method of claim 1 further comprising:

defining a new detection rule based, at least in part, upon the one or more identified attack patterns.

8 . The computer-implemented method of claim 1 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

9 . A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms;

normalizing the plurality of detection events into a common ontology, including translating a syntax of each of the plurality of detection events into a common syntax;

processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events;

storing the processed detection events within a graph content repository;

defining a probabilistic model to assign a threat level to one or more of the plurality of security events;

processing the graph content repository using a machine learning model to identify attack patterns defined within the processed detection events stored within the graph content repository, thus defining one or more identified attack patterns;

defining a universal detection rule in a common language based on the one or more identified attack patterns;

translating the universal detection rule into a plurality of technology-specific rules executable on a plurality of discrete pieces of customer technology;

analyzing the one or more identified attack patterns to identify a plurality of steps associated with at least one of the one or more identified attack patterns;

identifying current platform activity within the one or more computing platforms including a portion of the plurality of steps associated with the at least one of the one or more identified attack patterns;

initiating an investigation the of current activity within the one or more computing platforms; and

grouping the current activity with one or more prior detection events to define a security incident based upon, at least in part, common artifacts associated with the current activity and with the one or more prior detection events.

10 . The computer program product of claim 9 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

11 . The computer program product of claim 9 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

12 . The computer program product of claim 9 wherein processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events include

identifying nodes and edges within the plurality of detection events to make them compatible with the graph database.

13 . The computer program product of claim 9 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

14 . The computer program product of claim 9 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

15 . The computer program product of claim 9 further comprising:

defining a new detection rule based, at least in part, upon the one or more identified attack patterns.

16 . The computer program product of claim 9 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

17 . A computing system including a processor and memory configured to perform operations comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms;

normalizing the plurality of detection events into a common ontology, including translating a syntax of each of the plurality of detection events into a common syntax;

processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events;

storing the processed detection events within a graph content repository;

defining a probabilistic model to assign a threat level to one or more of the plurality of security events;

processing the graph content repository using a machine learning model to identify attack patterns defined within the processed detection events stored within the graph content repository, thus defining one or more identified attack patterns;

defining a universal detection rule in a common language based on the one or more identified attack patterns;

translating the universal detection rule into a plurality of technology-specific rules executable on a plurality of discrete pieces of customer technology;

analyzing the one or more identified attack patterns to identify a plurality of steps associated with at least one of the one or more identified attack patterns;

identifying current platform activity within the one or more computing platforms including a portion of the plurality of steps associated with the at least one of the one or more identified attack patterns;

initiating an investigation the of current activity within the one or more computing platforms; and

grouping the current activity with one or more prior detection events to define a security incident based upon, at least in part, common artifacts associated with the current activity and with the one or more prior detection events.

18 . The computing system of claim 17 wherein the plurality of security events includes one or more of:

Denial of Service (DOS) events;

Distributed Denial of Service DDOS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

19 . The computing system of claim 17 wherein the security-relevant subsystems include one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

20 . The computing system of claim 17 wherein processing the plurality of detection events to make them compatible with a graph database, thus defining processed detection events include

identifying nodes and edges within the plurality of detection events to make them compatible with the graph database.

21 . The computing system of claim 17 wherein the one or more computing platforms includes:

a first computing platform of a first client; and

at least a second computer platform of at least a second client.

22 . The computing system of claim 17 further comprising:

soliciting human feedback concerning the one or more identified attack patterns; and

utilizing the human feedback to train the machine learning model.

23 . The computing system of claim 17 further comprising:

defining a new detection rule based, at least in part, upon the one or more identified attack patterns.

24 . The computing system of claim 17 further comprising:

modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 063208/0941 →
Continuity (2)
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20230315853A1 · Oct 5, 2023
References Cited (67)
US 7797419B2 · Bhattacharya · 2010 [cited by examiner]
US 9027120B1 · Tidwell et al. · 2015 [cited by applicant]
US 9069954B2 · Anurag · 2015 [cited by examiner]
US 10003605B2 · Muddu · 2018 [cited by examiner]
US 10574700B1 · Dell'Amico · 2020 [cited by examiner]
US 10728263B1 · Neumann · 2020 [cited by examiner]
US 11258825B1 · Yang · 2022 [cited by examiner]
US 11316887B2 · Murphy et al. · 2022 [cited by applicant]
US 11483337B2 · Murphy et al. · 2022 [cited by applicant]
US 11652833B2 · Neuvirth et al. · 2023 [cited by applicant]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20030206099A1 · Richman · 2003 [cited by examiner]
US 20050254654A1 · Rockwell · 2005 [cited by examiner]
US 20130332473A1 · Ryman · 2013 [cited by applicant]
US 20160156664A1 · Nagaratnam · 2016 [cited by examiner]
US 20170063905A1 · Muddu · 2017 [cited by examiner]
US 20170134415A1 · Muddu · 2017 [cited by examiner]
US 20170364694A1 · Jacob et al. · 2017 [cited by applicant]
US 20190158517A1 · Muddu · 2019 [cited by examiner]
US 20190260785A1 · Jenkinson · 2019 [cited by examiner]
US 20190327271A1 · Saxena · 2019 [cited by examiner]
US 20210126938A1 · Trost et al. · 2021 [cited by applicant]
US 20210160274A1 · Murphy · 2021 [cited by examiner]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210250369A1 · Avist et al. · 2021 [cited by applicant]
US 20210273970A1 · Alshech · 2021 [cited by examiner]
US 20210352100A1 · Barai · 2021 [cited by examiner]
US 20220103575A1 · Fokker · 2022 [cited by applicant]
US 20220150268A1 · Herwono · 2022 [cited by examiner]
US 20230164158A1 · Fellows · 2023 [cited by examiner]
CA 2428192A1 · 2004 [cited by applicant]
WO 2017193036A1 · 2017 [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jun. 13, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jun. 29, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,182 on Jul. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,231 on Aug. 28, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017339 on Jun. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,167 on Jun. 27, 2023. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,152 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,167 on issue Date; Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,182 on issue Date; Mar. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,231 on issue Date; Apr. 29, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017336 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017341 on Issue Date; Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017342 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017343 on Issue Date; Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017344 on Issue Date; Jun. 15, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jul. 11, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Aug. 7, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Aug. 8, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jul. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Oct. 30, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 14, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Oct. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Oct. 16, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Sep. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Nov. 1, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Sep. 18, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Dec. 11, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Jan. 16, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Jan. 15, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Dec. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jan. 13, 2025. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Feb. 14, 2025. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on May 23, 2025. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Sep. 18, 2025. [cited by applicant]