IP Library Granted Patent US 12,505,209
Granted Patent B2
US 12,505,209 · App. 18/130,934 · Granted Dec 23, 2025

Cybersecurity workflow management using autodetection

Inventors: Joshua McCarthy (Morgan Hill, CA); David B McKinley (Dartmouth, MA); Lance Rund (San Jose, CA)
Assignee: Arctic Wolf Networks, Inc.
G06F21/554G06F21/566G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,209
App. No.
18/130,934
Granted
Dec 23, 2025
Kind
B2
Abstract

Disclosed techniques include cybersecurity workflow management using autodetection. A cybersecurity threat protection workflow is accessed. At least one cybersecurity threat protection application notification is received. The cybersecurity threat protection application notification causes an irreversible action to be scheduled by the workflow. The irreversible action comprises a destructive response. The destructive response includes killing a process, deleting an account, shutting down a computer, wiping a computer, or shutting down a router. The irreversible action is detected before it is implemented by the workflow. The irreversible action in the workflow is mitigated using a supervisory workflow element. The mitigating the irreversible action comprises initiating a machine learning algorithm. The machine learning algorithm enables a near real-time response. The machine learning algorithm self-triggers the actionable response. An actionable response is triggered based on an analysis of the irreversible action. The actionable response comprises notifying a cybersecurity professional. The notification includes a recommendation.

Claims (38)

1. A computer-implemented method for cybersecurity management comprising:

accessing a cybersecurity threat protection workflow;

receiving at least one cybersecurity threat protection application notification, wherein the cybersecurity threat protection application notification causes an irreversible action to be scheduled by the workflow;

detecting the irreversible action before it is implemented by the workflow, wherein the detecting the irreversible action includes parsing verbs in the cybersecurity threat protection application notification; and

mitigating the irreversible action in the workflow, using a supervisory workflow element.

2. The method of claim 1 wherein the detecting is based on analysis of at least one additional cybersecurity threat protection application notification.

3. The method of claim 1 wherein the irreversible action comprises a destructive response.

4. The method of claim 3 wherein the destructive response includes killing a process, deleting an account, shutting down a computer, wiping a computer, or shutting down a router.

5. The method of claim 1 wherein the mitigating the irreversible action comprises initiating a machine learning algorithm.

6. The method of claim 5 wherein the machine learning algorithm enables near real-time response or an actionable response.

7. The method of claim 1 wherein the workflow and the supervisory workflow element are managed by a security orchestration, automation, and response (SOAR) system.

8. The method of claim 1 wherein the supervisory workflow element is structured to perform a test on the cybersecurity threat protection application notification.

9. The method of claim 8 wherein the test comprises an if/then analysis, a table lookup analysis, an if/then/else analysis, or a machine learning algorithm-based analysis.

10. The method of claim 1 further comprising triggering an actionable response, based on an analysis of the irreversible action.

11. The method of claim 10 wherein the actionable response comprises notifying a cybersecurity professional.

12. The method of claim 11 wherein the notifying a cybersecurity professional includes a recommendation.

13. The method of claim 12 wherein the recommendation includes ignoring the cybersecurity threat protection application notification.

14. The method of claim 10 wherein the actionable response comprises an autonomic network reconfiguration.

15. The method of claim 10 wherein the actionable response comprises an autonomic cybersecurity threat protection application reconfiguration.

16. The method of claim 1 wherein the verbs are contained in cybersecurity threat protection application outbound commands.

17. The method of claim 1 wherein the detecting the irreversible action is based on metadata from a cybersecurity threat protection application.

18. The method of claim 1 wherein the mitigating includes pausing the irreversible action until a subsequent cybersecurity threat protection application notification is received.

19. The method of claim 18 wherein the subsequent cybersecurity threat protection application notification is received from a different cybersecurity threat protection application.

20. The method of claim 18 wherein the subsequent cybersecurity threat protection application notification is received from the same cybersecurity threat protection application.

21. A computer program product embodied in a non-transitory computer readable medium for cybersecurity management, the computer program product comprising code which causes one or more processors to perform operations of:

accessing a cybersecurity threat protection workflow;

receiving at least one cybersecurity threat protection application notification, wherein the cybersecurity threat protection application notification causes an irreversible action to be scheduled by the workflow;

detecting the irreversible action before it is implemented by the workflow, wherein the detecting the irreversible action includes parsing verbs in the cybersecurity threat protection application notification; and

mitigating the irreversible action in the workflow, using a supervisory workflow element.

22. The computer program product of claim 21 , further comprising triggering an actionable response, based on an analysis of the irreversible action, wherein the actionable response comprises at least one of (i) notifying a cybersecurity professional and (ii) a recommendation for responding.

23. A computer system for cybersecurity comprising:

a memory which stores instructions;

one or more processors coupled to the memory, wherein the one or more processors, when executing the instructions which are stored, are configured to:

access a cybersecurity threat protection workflow;

receive at least one cybersecurity threat protection application notification, wherein the cybersecurity threat protection application notification causes an irreversible action to be scheduled by the workflow;

detect the irreversible action before it is implemented by the workflow, wherein the detecting the irreversible action includes parsing verbs in the cybersecurity threat protection application notification; and

mitigate the irreversible action in the workflow, using a supervisory workflow element.

24. The computer system of claim 23 , wherein the one or more processors are further configured to trigger an actionable response, based on an analysis of the irreversible action, wherein the actionable response comprises at least one of (i) notifying a cybersecurity professional and (ii) a recommendation for responding.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2024
From: REVELSTOKE SECURITY, INC.
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 067291/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2023
From: MCCARTHY, JOSHUA; MCKINLEY, DAVID B; RUND, LANCE
To: REVELSTOKE SECURITY, INC.
Reel/Frame 064712/0288 →
Continuity (10)
Continuation In Part 17825024 · May 26, 2022
Provisional Application 63451249 · Mar 10, 2023
Provisional Application 63404983 · Sep 9, 2022
Provisional Application 63350891 · Jun 10, 2022
Provisional Application 63327853 · Apr 6, 2022
Provisional Application 63297273 · Jan 7, 2022
Provisional Application 63274302 · Nov 1, 2021
Provisional Application 63234729 · Aug 19, 2021
Provisional Application 63193615 · May 27, 2021
Related Publication 20230252138A1 · Aug 10, 2023
References Cited (35)
US 8392218B2 · Becker et al. · 2013 [cited by applicant]
US 10534971B2 · Huber, Jr. et al. · 2020 [cited by applicant]
US 10621172B2 · Azaria et al. · 2020 [cited by applicant]
US 10776316B2 · Baggeroer et al. · 2020 [cited by applicant]
US 10838709B2 · Eapen et al. · 2020 [cited by applicant]
US 10901863B2 · Lukkoor et al. · 2021 [cited by applicant]
US 10922452B2 · Liu et al. · 2021 [cited by applicant]
US 10924527B2 · Miller · 2021 [cited by applicant]
US 10936234B2 · Su · 2021 [cited by applicant]
US 10938706B1 · Zacks et al. · 2021 [cited by applicant]
US 10938951B2 · White et al. · 2021 [cited by applicant]
US 10956880B2 · Towle · 2021 [cited by applicant]
US 11463463B1 · Phung · 2022 [cited by examiner]
US 20130318542A1 · Zamora · 2013 [cited by applicant]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20180121316A1 · Ismael et al. · 2018 [cited by applicant]
US 20190098025A1 · Lim · 2019 [cited by examiner]
US 20200143060A1 · Tineo · 2020 [cited by examiner]
US 20200244412A1 · Kalhan · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20200305011A1 · Yaniv et al. · 2020 [cited by applicant]
US 20200342552A1 · Sulit et al. · 2020 [cited by applicant]
US 20200363781A1 · Mangels et al. · 2020 [cited by applicant]
US 20200380006A1 · Rockwell et al. · 2020 [cited by applicant]
US 20210014153A1 · Amend et al. · 2021 [cited by applicant]
US 20210042589A1 · Tokarev Sela et al. · 2021 [cited by applicant]
US 20210070333A1 · Chen · 2021 [cited by applicant]
US 20210099420A1 · Zhang · 2021 [cited by applicant]
US 20210312058A1 · Chiarelli · 2021 [cited by examiner]
US 20220309166A1 · Shenoy · 2022 [cited by examiner]
KR 1020200083874A · 2020 [cited by applicant]
WO WO2021028060A1 · 2021 [cited by examiner]
Sangani, Nilaykumar Kiran, and Haroot Zarger. “Machine learning in application security.” Advances in Security in Computing and Communications. IntechOpen, 2017. [cited by applicant]
Boutaba, Raouf, et al. “A comprehensive survey on maching learning for networking: evolution, applications and research opportunities.” Journal of Internet Services and Applications 9.1 (2018): 1-99. [cited by applicant]
International Search Report dated Aug. 31, 2022 for PCT 2022/031003. [cited by applicant]