IP Library Granted Patent US 12,413,603
Granted Patent B2
US 12,413,603 · App. 18/148,743 · Granted Sep 9, 2025

Risk based priority processing of data

Inventors: Christopher L. Petersen (Boulder, CO); Mark Vankempen (Boulder, CO)
Assignee: LogRhythm, Inc.
H04L63/1408H04L63/1416H04L63/1425H04L63/1433G06F21/552G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,603
App. No.
18/148,743
Granted
Sep 9, 2025
Kind
B2
Abstract

Utilities (e.g., methods, systems, apparatuses, etc.) for use in generating and making use of priority scores for data generated by one or more data systems that more accurately prioritize those events and other pieces of data to be addressed by analysts and troubleshooters before others (e.g., collectively taking into account threats posed by origin host components and risks to impacted host components) to work the highest risk events and alarms first and to effectively and efficiently spend their alarm monitoring time.

Claims (26)

1. A computer-based system for use in monitoring data generated by one or more data systems, the system comprising:

a processor; and

non-transitory computer readable media accessible by the processor, wherein the non-transitory computer readable media includes:

a database including:

a first list of known hosts of the one or more data systems and respective relative risk or threat levels for the known hosts;

a second list of known network ranges of the one or more data systems and respective relative risk or threat levels for the known network ranges;

a third list of default relative risk or threat levels for origin host components responsible for initiating an occurrence on the one or more data systems; wherein the third list of default relative risk or threat levels for origin host components responsible for initiating an occurrence on the one or more data systems includes an external host default threat level for when an origin host component is inferred to be an external host and an internal host default threat level for when the origin host component is inferred to be an internal host and

a fourth list of default relative risk or threat levels for impacted host components that are affected by an occurrence on the one or more data systems; and

a set of computer-readable instructions that are executable by the processor to:

receive data generated by one or more data systems over at least one network;

parse, from the received data, at least one of an origin host identifier associated with an origin host component responsible for initiating an occurrence on the one or more data systems and an impacted host identifier associated with an impacted host component that is affected by an occurrence on the one or more data systems;

determine that the at least one of the parsed origin host identifier or impacted host identifier cannot be used to obtain a relative risk or threat level from the first list; and

access one or more of the second, third and fourth lists to obtain a relative risk or threat level with the at least one of the parsed origin host identifier or impacted host identifier.

2. A computer-based system for use in monitoring data generated by one or more data systems, the system comprising:

a processor; and

non-transitory computer readable media accessible by the processor, wherein the non-transitory computer readable media includes:

a database including:

a first list of known hosts of the one or more data systems and respective relative risk or threat levels for the known hosts;

a second list of known network ranges of the one or more data systems and respective relative risk or threat levels for the known network ranges;

a third list of default relative risk or threat levels for origin host components responsible for initiating an occurrence on the one or more data systems; and

a fourth list of default relative risk or threat levels for impacted host components that are affected by an occurrence on the one or more data systems; wherein the fourth list of default relative risk or threat levels for impacted host components that are affected by an occurrence on the one or more data systems includes an external host default threat level for when the impacted host component is inferred to be an external host and an internal host default threat level for when the impacted host component is inferred to be an internal host; and

a set of computer-readable instructions that are executable by the processor to:

receive data generated by one or more data systems over at least one network;

parse, from the received data, at least one of an origin host identifier associated with an origin host component responsible for initiating an occurrence on the one or more data systems and an impacted host identifier associated with an impacted host component that is affected by an occurrence on the one or more data systems;

determine that the at least one of the parsed origin host identifier or impacted host identifier cannot be used to obtain a relative risk or threat level from the first list; and

access one or more of the second, third and fourth lists to obtain a relative risk or threat level with the at least one of the parsed origin host identifier or impacted host identifier.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 063295/0308 Recorded Jul 3, 2024
From: TRUIST BANK SUCCESSOR BY MERGER TO SUNTRUST BANK
To: LOGRHYTHM, INC.
Reel/Frame 068106/0846 →
SECURITY INTEREST Recorded Jul 3, 2024
From: LOGRHYTHM, INC.; EXABEAM, INC.
To: 26N DL SERVICING LP, AS THE COLLATERAL AGENT
Reel/Frame 068105/0797 →
PATENT SECURITY AGREEMENT Recorded Mar 31, 2023
From: LOGRHYTHM, INC.
To: TRUIST BANK
Reel/Frame 063295/0308 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2022
From: PETERSEN, CHRISTOPHER L.; VANKEMPEN, MARK
To: LOGRHYTHM, INC.
Reel/Frame 062245/0929 →
Continuity (4)
Continuation 16889579 · Jun 1, 2020
Continuation 16116335 · Aug 29, 2018
Continuation 15187947 · Jun 21, 2016
Related Publication 20230254325A1 · Aug 10, 2023
References Cited (31)
US 7221671B2 · Jeong · 2007 [cited by applicant]
US 7418733B2 · Connary · 2008 [cited by examiner]
US 7594270B2 · Church · 2009 [cited by applicant]
US 7653633B2 · Villela et al. · 2010 [cited by applicant]
US 7937353B2 · Bernoth · 2011 [cited by applicant]
US 8543694B2 · Petersen et al. · 2013 [cited by applicant]
US 9300679B1 · Martin et al. · 2016 [cited by applicant]
US 9384112B2 · Petersen et al. · 2016 [cited by applicant]
US 9386078B2 · Reno · 2016 [cited by applicant]
US 9503472B2 · Laidlaw · 2016 [cited by applicant]
US 9560066B2 · Visbal · 2017 [cited by applicant]
US 9729558B2 · Liu et al. · 2017 [cited by applicant]
US 9769688B2 · Li · 2017 [cited by applicant]
US 9787709B2 · Doubleday · 2017 [cited by applicant]
US 9800604B2 · Knapp · 2017 [cited by applicant]
US 9800605B2 · Baikalov et al. · 2017 [cited by applicant]
US 10091217B2 · Petersen et al. · 2018 [cited by applicant]
US 10348739B2 · Greenspan · 2019 [cited by applicant]
US 10454959B2 · Ikeda · 2019 [cited by applicant]
US 10521358B2 · Nambiar · 2019 [cited by applicant]
US 10673868B2 · Petersen et al. · 2020 [cited by applicant]
US 20040044912A1 · Connary · 2004 [cited by examiner]
US 20060265746A1 · Farley · 2006 [cited by applicant]
US 20070169194A1 · Church · 2007 [cited by examiner]
US 20130166667A1 · Carr · 2013 [cited by applicant]
US 20140325670A1 · Singh · 2014 [cited by applicant]
US 20160092684A1 · Langton · 2016 [cited by examiner]
US 20170263092A1 · Rankin · 2017 [cited by applicant]
“national cyber incident scoring system”, Jun. 6, 2016, obtained online from <https://www.cisa.gov/sites/default/files/2023-01/cisa_national_cyber_incident_scoring_system_s508c.pdf>, retrieved on Oct. 5, 2024 (Year: 201… [cited by examiner]
S. Xiao, J. Guo and D. Xiao, “Risk Calculation Based on Source and Destination of Attack Events,” 2009 First International Conference on Information Science and Engineering, Nanjing, 2009, pp. 1835-1837. [cited by applicant]
Malik Shahzad Kaleem Awan, Pete Burnap, Omer Rana, “Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk,” Computers & Security, vol. 57, pp. 31-46 (Year: 2016). [cited by applicant]