IP Library Granted Patent US 12,652,310
Granted Patent B2
US 12,652,310 · App. 18/231,715 · Granted Jun 9, 2026

Selecting actions responsive to computing environment incidents based on related processes

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
H04L63/1441G06F16/285G06F21/554H04L63/0236H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L47/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,310
App. No.
18/231,715
Granted
Jun 9, 2026
Kind
B2
Abstract

Systems, methods, and software described herein provide enhancements for implementing security actions in a computing environment. In one example, a method of operating an advisement system to provide actions in a computing environment includes identifying a security incident in the computing environment, identifying a criticality rating for the asset, and obtaining enrichment information for the security incident from one or more internal or external sources. The method also provides identifying a severity rating for the security incident based on the enrichment information, and determining one or more security actions based on the enrichment information. The method further includes identifying effects of the one or more security actions on operations of the computing environment based on the criticality rating and the severity rating, and identifying a subset of the one or more security actions to respond to the security incident based on the effects.

Claims (38)

1 . A computer-implemented method comprising:

receiving data indicating an occurrence of a security incident involving a computing asset of a computing environment;

obtaining enrichment information associated with the security incident from one or more internal or external sources;

determining, consequent to receiving the data indicating the occurrence of the security incident, a related process related to the security incident requires access to an application that is executing on the computing asset;

identifying, based on the enrichment information and the related process, a rule set for the security incident;

determining, based on the rule set, one or more action suggestions to respond to the security incident; and

providing the one or more action suggestions to an administration system.

2 . The method of claim 1 , wherein the determining the related process comprises analyzing information about processes or applications that are currently executing in the computing environment and that are associated with or require access to the application implicated in the security incident.

3 . The method of claim 1 , wherein at least one of the one or more action suggestions allows the related process to continue to access the application.

4 . The method of claim 1 , wherein the one or more action suggestions include taking a snapshot of the application, taking a snapshot of the computing asset, limiting a type of data that may be communicated by the computing asset, or preventing the application from initiating communications with external systems and processes.

5 . The method of claim 1 , further comprising determining that the security incident is related to communications with a particular IP address.

6 . The method of claim 5 , wherein obtaining enrichment information associated with the security incident from one or more internal or external sources comprises querying a database to determine whether the particular IP address is related to malicious activity.

7 . An apparatus comprising:

one or more non-transitory computer-readable storage media;

a processing system operatively coupled to the one or more non-transitory computer-readable storage media; and

computer-readable instructions stored on the one or more non-transitory computer-readable storage media that, when executed by the processing system, direct the processing system to perform operations comprising:

receiving data indicating an occurrence of a security incident involving a computing asset of a computing environment;

obtaining enrichment information associated with the security incident from one or more internal or external sources;

determining, consequent to receiving the data indicating the occurrence of the security incident, a related process related to the security incident requires access to an application that is executing on the computing asset;

identifying, based on the enrichment information and the related process, a rule set for the security incident;

determining, based on the rule set, one or more action suggestions to respond to the security incident; and

providing the one or more action suggestions to an administration system.

8 . The apparatus of claim 7 , wherein the determining the related process comprises analyzing information about processes or applications that are currently executing in the computing environment and that are associated with or require access to the application implicated in the security incident.

9 . The apparatus of claim 7 , wherein at least one of the one or more action suggestions allows the related process to continue to access the application.

10 . The apparatus of claim 7 , wherein the one or more action suggestions include taking a snapshot of the application, taking a snapshot of the computing asset, limiting a type of data that may be communicated by the computing asset, or preventing the application from initiating communications with external systems and processes.

11 . The apparatus of claim 7 , wherein the computer-readable instructions comprise further computer-readable instructions stored on the one or more non-transitory computer-readable storage media that, when executed by the processing system, further direct the processing system to determine that the security incident is related to communications with a particular IP address.

12 . The apparatus of claim 11 , wherein obtaining enrichment information associated with the security incident from one or more internal or external sources comprises querying a database to determine whether the particular IP address is related to malicious activity.

13 . A non-transitory, computer-readable storage medium storing instructions that, when executed by one or more processors, cause performance of operations comprising:

receiving data indicating an occurrence of a security incident involving a computing asset of a computing environment;

obtaining enrichment information associated with the security incident from one or more internal or external sources;

determining, consequent to receiving the data indicating the occurrence of the security incident, a related process related to the security incident requires access to an application that is executing on the computing asset;

identifying, based on the enrichment information and the related process, a rule set for the security incident;

determining, based on the rule set, one or more action suggestions to respond to the security incident; and

providing the one or more action suggestions to an administration system.

14 . The non-transitory, computer-readable storage medium of claim 13 , wherein the determining the related process comprises analyzing information about processes or applications that are currently executing in the computing environment and that are associated with or require access to the application implicated in the security incident.

15 . The non-transitory, computer-readable storage medium of claim 13 , wherein at least one of the one or more action suggestions allows the related process to continue to access the application.

16 . The non-transitory, computer-readable storage medium of claim 13 , wherein the one or more action suggestions include taking a snapshot of the application, taking a snapshot of the computing asset, limiting a type of data that may be communicated by the computing asset, or preventing the application from initiating communications with external systems and processes.

17 . The non-transitory, computer-readable storage medium of claim 13 , wherein the operations further comprise determining that the security incident is related to communications with a particular IP address.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2024
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND
To: PHANTOM CYBER CORPORATION
Reel/Frame 067186/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2024
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 067186/0749 →
Continuity (8)
Continuation 17185612 · Feb 25, 2021
Continuation 16568949 · Sep 12, 2019
Continuation 15924759 · Mar 19, 2018
Continuation 14956615 · Dec 2, 2015
Provisional Application 62106830 · Jan 23, 2015
Provisional Application 62106837 · Jan 23, 2015
Provisional Application 62087025 · Dec 3, 2014
Related Publication 20240031397A1 · Jan 25, 2024
References Cited (277)
US 6405318B1 · Rowland · 2002 [cited by applicant]
US 7076803B2 · Bruton et al. · 2006 [cited by applicant]
US 7127743B1 · Khanolkar et al. · 2006 [cited by applicant]
US 7174566B2 · Yadav · 2007 [cited by applicant]
US 7469301B2 · Daniell et al. · 2008 [cited by applicant]
US 7617533B1 · Hernacki · 2009 [cited by applicant]
US 7657927B2 · Tajalli et al. · 2010 [cited by applicant]
US 7900259B2 · Jeschke et al. · 2011 [cited by applicant]
US 7950056B1 · Satish et al. · 2011 [cited by applicant]
US 8042171B1 · Nordstrom et al. · 2011 [cited by applicant]
US 8103875B1 · Ramzan et al. · 2012 [cited by applicant]
US 8146147B2 · Litvin et al. · 2012 [cited by applicant]
US 8185953B2 · Rothstein et al. · 2012 [cited by applicant]
US 8261317B2 · Litvin et al. · 2012 [cited by applicant]
US 8271642B1 · Sankararaman et al. · 2012 [cited by applicant]
US 8291495B1 · Burns et al. · 2012 [cited by applicant]
US 8336094B2 · Litvin et al. · 2012 [cited by applicant]
US 8380828B1 · Schlichter et al. · 2013 [cited by applicant]
US 8402540B2 · Kapoor et al. · 2013 [cited by applicant]
US 8484338B2 · Paster · 2013 [cited by applicant]
US 8516575B2 · Burnside et al. · 2013 [cited by applicant]
US 8590035B2 · Aaron · 2013 [cited by applicant]
US 8627466B2 · Fisher et al. · 2014 [cited by applicant]
US 8676970B2 · Boyns et al. · 2014 [cited by applicant]
US 8756697B2 · Ocepek et al. · 2014 [cited by applicant]
US 8856910B1 · Rostami-Hesarsorkh et al. · 2014 [cited by applicant]
US 8881282B1 · Aziz et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 8924469B2 · Raleigh et al. · 2014 [cited by applicant]
US 8943123B2 · Miyazaki et al. · 2015 [cited by applicant]
US 8949931B2 · Ermagan et al. · 2015 [cited by applicant]
US 8955107B2 · Eyada · 2015 [cited by applicant]
US 9009814B1 · Wertz et al. · 2015 [cited by applicant]
US 9009824B1 · Chen et al. · 2015 [cited by applicant]
US 9049226B1 · Duane · 2015 [cited by applicant]
US 9137258B2 · Haugsnes · 2015 [cited by applicant]
US 9166995B1 · Roundy · 2015 [cited by applicant]
US 9231964B2 · Cross et al. · 2016 [cited by applicant]
US 9256739B1 · Roundy et al. · 2016 [cited by applicant]
US 9258319B1 · Rubin · 2016 [cited by applicant]
US 9306965B1 · Grossman et al. · 2016 [cited by applicant]
US 9311479B1 · Manni et al. · 2016 [cited by applicant]
US 9313211B1 · Lototskiy · 2016 [cited by applicant]
US 9325733B1 · Kolman et al. · 2016 [cited by applicant]
US 9336385B1 · Spencer et al. · 2016 [cited by applicant]
US 9338181B1 · Burns et al. · 2016 [cited by applicant]
US 9344445B2 · Burns et al. · 2016 [cited by applicant]
US 9378361B1 · Yen et al. · 2016 [cited by applicant]
US 9396592B2 · Chapman et al. · 2016 [cited by applicant]
US 9489516B1 · Lu et al. · 2016 [cited by applicant]
US 9606995B2 · Nucci · 2017 [cited by examiner]
US 9680846B2 · Haugsnes · 2017 [cited by applicant]
US 9712555B2 · Satish et al. · 2017 [cited by applicant]
US 9729572B1 · Adams et al. · 2017 [cited by applicant]
US 9762607B2 · Satish et al. · 2017 [cited by applicant]
US 9871818B2 · Satish et al. · 2018 [cited by applicant]
US 9888029B2 · Satish · 2018 [cited by examiner]
US 9954888B2 · Satish · 2018 [cited by examiner]
US 10158663B2 · Satish et al. · 2018 [cited by applicant]
US 10257227B1 · Stickle et al. · 2019 [cited by applicant]
US 10412117B2 · Forte et al. · 2019 [cited by applicant]
US 10425440B2 · Satish et al. · 2019 [cited by applicant]
US 10425441B2 · Satish et al. · 2019 [cited by applicant]
US 10476905B2 · Satish · 2019 [cited by examiner]
US 10862905B2 · Zettel et al. · 2020 [cited by applicant]
US 10986120B2 · Satish · 2021 [cited by examiner]
US 11019092B2 · Satish · 2021 [cited by examiner]
US 11019093B2 · Satish et al. · 2021 [cited by applicant]
US 11165812B2 · Satish · 2021 [cited by examiner]
US 11765198B2 · Satish · 2023 [cited by examiner]
US 20040003286A1 · Kaler et al. · 2004 [cited by applicant]
US 20040054498A1 · Shipp · 2004 [cited by applicant]
US 20040111637A1 · Baffes et al. · 2004 [cited by applicant]
US 20040250133A1 · Lim · 2004 [cited by applicant]
US 20050055578A1 · Wright et al. · 2005 [cited by applicant]
US 20050216956A1 · Orr et al. · 2005 [cited by applicant]
US 20050235360A1 · Pearson · 2005 [cited by applicant]
US 20050273857A1 · Freund · 2005 [cited by applicant]
US 20060010493A1 · Piesco et al. · 2006 [cited by applicant]
US 20060048209A1 · Shelest · 2006 [cited by examiner]
US 20060059568A1 · Smith-Mickelson et al. · 2006 [cited by applicant]
US 20060095965A1 · Phillips et al. · 2006 [cited by applicant]
US 20060117386A1 · Gupta et al. · 2006 [cited by applicant]
US 20060174342A1 · Zaheer et al. · 2006 [cited by applicant]
US 20070168874A1 · Kloeffer et al. · 2007 [cited by applicant]
US 20070169194A1 · Church et al. · 2007 [cited by applicant]
US 20070180490A1 · Renzi et al. · 2007 [cited by applicant]
US 20070255724A1 · Jung et al. · 2007 [cited by applicant]
US 20080005782A1 · Aziz · 2008 [cited by applicant]
US 20080082662A1 · Dandliker et al. · 2008 [cited by applicant]
US 20080289028A1 · Jansen et al. · 2008 [cited by applicant]
US 20090037548A1 · Ordille et al. · 2009 [cited by applicant]
US 20090044277A1 · Aaron · 2009 [cited by applicant]
US 20090165132A1 · Jain et al. · 2009 [cited by applicant]
US 20100100962A1 · Boren · 2010 [cited by applicant]
US 20100162347A1 · Barile · 2010 [cited by applicant]
US 20100169973A1 · Kim et al. · 2010 [cited by applicant]
US 20100251329A1 · Wei · 2010 [cited by applicant]
US 20100281539A1 · Burns et al. · 2010 [cited by applicant]
US 20100319004A1 · Hudson et al. · 2010 [cited by applicant]
US 20100319069A1 · Granstedt et al. · 2010 [cited by applicant]
US 20100325412A1 · Norrman et al. · 2010 [cited by applicant]
US 20100325685A1 · Sanbower · 2010 [cited by applicant]
US 20110161452A1 · Poornachandran et al. · 2011 [cited by applicant]
US 20110238979A1 · Harp et al. · 2011 [cited by applicant]
US 20120210434A1 · Curtis et al. · 2012 [cited by applicant]
US 20120224057A1 · Gill et al. · 2012 [cited by applicant]
US 20120311121A1 · Shafrir et al. · 2012 [cited by applicant]
US 20120331553A1 · Aziz et al. · 2012 [cited by applicant]
US 20130007882A1 · Devarajan · 2013 [cited by examiner]
US 20130081138A1 · Rados et al. · 2013 [cited by applicant]
US 20130081141A1 · Anurag · 2013 [cited by applicant]
US 20130091584A1 · Liebmann et al. · 2013 [cited by applicant]
US 20130104203A1 · Davis et al. · 2013 [cited by applicant]
US 20130111592A1 · Zhu et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130276108A1 · Blackwell · 2013 [cited by applicant]
US 20130291106A1 · Simonoff et al. · 2013 [cited by applicant]
US 20130298230A1 · Kumar et al. · 2013 [cited by applicant]
US 20130298244A1 · Kumar et al. · 2013 [cited by applicant]
US 20130312092A1 · Parker · 2013 [cited by applicant]
US 20130333032A1 · Delatorre et al. · 2013 [cited by applicant]
US 20140007222A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140013107A1 · Clair · 2014 [cited by applicant]
US 20140059641A1 · Chapman et al. · 2014 [cited by applicant]
US 20140082726A1 · Dreller et al. · 2014 [cited by applicant]
US 20140089039A1 · Mcclellan · 2014 [cited by applicant]
US 20140137257A1 · Martinez et al. · 2014 [cited by applicant]
US 20140165200A1 · Singla · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140199663A1 · Sadeh-Koniecpol et al. · 2014 [cited by applicant]
US 20140237599A1 · Gertner et al. · 2014 [cited by applicant]
US 20140245374A1 · Deerman et al. · 2014 [cited by applicant]
US 20140259170A1 · Amsler · 2014 [cited by applicant]
US 20140283049A1 · Shnowske et al. · 2014 [cited by applicant]
US 20140310811A1 · Hentunen · 2014 [cited by applicant]
US 20140344926A1 · Cunningham et al. · 2014 [cited by applicant]
US 20140351441A1 · Madani et al. · 2014 [cited by applicant]
US 20140351940A1 · Loder et al. · 2014 [cited by applicant]
US 20150040217A1 · Abuelsaad et al. · 2015 [cited by applicant]
US 20150143516A1 · Sharpe et al. · 2015 [cited by applicant]
US 20150207813A1 · Reybok et al. · 2015 [cited by applicant]
US 20150215325A1 · Ogawa · 2015 [cited by applicant]
US 20150222647A1 · Lietz et al. · 2015 [cited by applicant]
US 20150222656A1 · Haugsnes · 2015 [cited by applicant]
US 20150264077A1 · Berger et al. · 2015 [cited by applicant]
US 20150304169A1 · Milman et al. · 2015 [cited by applicant]
US 20150334132A1 · Zombik et al. · 2015 [cited by applicant]
US 20150341384A1 · Mandayam et al. · 2015 [cited by applicant]
US 20150347751A1 · Card et al. · 2015 [cited by applicant]
US 20150347949A1 · Dwyer et al. · 2015 [cited by applicant]
US 20150365438A1 · Carver et al. · 2015 [cited by applicant]
US 20150381641A1 · Cabrera et al. · 2015 [cited by applicant]
US 20150381649A1 · Schultz et al. · 2015 [cited by applicant]
US 20160006749A1 · Cohen et al. · 2016 [cited by applicant]
US 20160044058A1 · Schlauder · 2016 [cited by applicant]
US 20160065608A1 · Futty · 2016 [cited by applicant]
US 20160072836A1 · Hadden et al. · 2016 [cited by applicant]
US 20160103992A1 · Roundy et al. · 2016 [cited by applicant]
US 20160119379A1 · Nadkarni · 2016 [cited by applicant]
US 20160164893A1 · Levi · 2016 [cited by applicant]
US 20160164916A1 · Satish et al. · 2016 [cited by applicant]
US 20160164917A1 · Friedrichs · 2016 [cited by examiner]
US 20160241580A1 · Watters et al. · 2016 [cited by applicant]
US 20160241581A1 · Watters et al. · 2016 [cited by applicant]
US 20170214702A1 · Moscovici et al. · 2017 [cited by applicant]
US 20170230412A1 · Thomas et al. · 2017 [cited by applicant]
US 20170237762A1 · Ogawa · 2017 [cited by applicant]
US 20180255073A1 · Sifford et al. · 2018 [cited by applicant]
US 20200396237A1 · Cohen et al. · 2020 [cited by applicant]
US 20220060508A1 · Crabtree et al. · 2022 [cited by applicant]
Abandonment Notice, U.S. Appl. No. 14/675,075, Feb. 8, 2017, 2 pages. [cited by applicant]
Advisory Action, U.S. Appl. No. 14/868,553, Jan. 24, 2019, 3 pages. [cited by applicant]
Aguirre, Idoia; Alonso, Sergio; “Improving the Automation of Security Information Management: A Collaborative Approach”, IEEE Security & Privacy, vol. 10, Issue 1, Oct. 25, 2011, pp. 55-59. [cited by applicant]
Final Office Action from U.S. Appl. No. 14/677,493, Aug. 24, 2017, 29 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 14/674,679, Sep. 22, 2016, 19 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 14/677,493, Nov. 13, 2018, 20 pages. [cited by applicant]
Final Office Action from U.S. Appl. No. 16/107,979, Jun. 13, 2019, 14 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/675,176, Nov. 25, 2016, 21 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/675,176, Sep. 25, 2017, 31 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/675,176, Jan. 26, 2021, 18 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/677,493, Nov. 25, 2016, 23 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/677,493, Jan. 16, 2020, 16 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/824,262, Apr. 6, 2017, 22 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/868,553, Oct. 15, 2018, 19 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/868,553, Oct. 18, 2017, 19 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 14/956,589, Nov. 22, 2017, 27 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 15/924,759, Aug. 1, 2018, 13 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/182,914, Sep. 18, 2019, 6 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/568,949, Oct. 28, 2020, 19 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/736,120, Jan. 6, 2021, 15 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 16/863,557, Apr. 7, 2022, 18 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/185,612, Mar. 28, 2023, 7 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/326,070, Jan. 19, 2023, 19 pages. [cited by applicant]
Hasegawa et al., “A Countermeasure Recommendation System against Targeted Attacks with Preserving Continuity of Internal Networks”, 38th Annual Computer Software and Applications Conference, IEEE, Jul. 21-25, 2014, pp. … [cited by applicant]
Hershey et al., “Procedure for Detection of and Response to Distributed Denial of Service Cyber Attacks on Complex Enterprise Systems”, International Systems Conference SysCon, IEEE, Mar. 19-22, 2012, 6 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/677,493, Jul. 11, 2016, 17 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/677,493, May 1, 2017, 25 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/677,493, May 14, 2018, 23 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/689,973, Jan. 25, 2017, 18 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/868,553, Mar. 26, 2018, 22 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 14/868,553, May 26, 2017, 16 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 15/924,759, Feb. 26, 2019, 20 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 16/107,975, Jan. 4, 2019, 11 pages. [cited by applicant]
Non-Final Office Action from U.S. Appl. No. 16/107,979, Oct. 18, 2018, 14 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/674,679, Jun. 2, 2016, 16 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/675,075, Jul. 11, 2016, 13 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/675,176, Apr. 17, 2017, 22 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/675,176, Jul. 18, 2016, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/675,176, Jul. 14, 2020, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/677,493, Aug. 2, 2019, 26 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/677,493, Jul. 14, 2020, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/689,926, May 8, 2017, 34 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/824,262, Jul. 13, 2017, 20 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/824,262, Oct. 7, 2016, 16 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/956,589, May 31, 2017, 33 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 14/956,615, Jul. 28, 2017, 46 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 15/699,454, Feb. 8, 2018, 19 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 15/845,963, Feb. 12, 2018, 27 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 15/886,183, Mar. 22, 2018, 21 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/228,982, Mar. 6, 2024, 14 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/228,982, May 14, 2024, 9 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/042,283, Jan. 24, 2020, 25 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/107,972, Dec. 31, 2018, 11 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/142,913, Apr. 30, 2019, 33 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/182,914, May 30, 2019, 23 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/539,918, Jul. 16, 2020, 14 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/568,949, Mar. 19, 2020, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/863,557, Nov. 24, 2021, 17 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/863,557, Aug. 25, 2022, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/104,537, Jul. 20, 2022, 16 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/185,612, Sep. 16, 2022, 10 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/242,165, Jan. 25, 2023, 15 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/306,703, Sep. 9, 2022, 15 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/326,070, Aug. 16, 2022, 20 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/513,595, Dec. 30, 2022, 15 pages. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 14/956,589, Apr. 23, 2018, 21 pages. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 14/956,615, Dec. 18, 2017, 19 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/677,493, Jan. 22, 2021, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/674,679, Apr. 18, 2017, 20 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/674,679, Jun. 20, 2017, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/674,679, May 12, 2017, 4 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/675,176, Dec. 30, 2019, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/675,176, Jul. 7, 2021, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/689,926, Dec. 20, 2017, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/689,926, Nov. 8, 2017, 22 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/689,973, Aug. 10, 2017, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/689,973, Jul. 27, 2017, 33 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/824,262, Jan. 5, 2018, 4 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/824,262, Nov. 22, 2017, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 14/868,553, Jun. 26, 2020, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/699,454, Aug. 9, 2018, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/699,454, Nov. 20, 2018, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/845,963, Jun. 26, 2018, 11 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/886,183, Sep. 19, 2018, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 15/924,759, Jun. 13, 2019, 21 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/042,283, Jul. 28, 2020, 17 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/107,972, May 9, 2019, 18 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/107,975, May 13, 2019, 18 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/107,979, Oct. 7, 2019, 14 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/142,913, Aug. 30, 2019, 21 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/182,914, Dec. 4, 2019, 5 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/539,918, Jan. 22, 2021, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/568,949, Jan. 7, 2021, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 16/863,557, Jan. 12, 2023, 6 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/033,146, Jan. 10, 2022, 10 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/185,612, May 22, 2023, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/306,703, Jan. 11, 2023, 7 pages. [cited by applicant]
Paudice, Andrea; Sarkar; Santonu; Cotroneo, Dominco; “An Experiment with Conceptual Clustering for the Analysis of Security Alerts”, IEEE International Symposium on Software Reliability Engineering Workshops, Nov. 3-6, … [cited by applicant]
Tejay, Gurvirender P.S.; Zadig, Sean M.; “Investigating the Effectiveness of IS Security Countermeasures Towards Cyber Attacker Deterrence”, 45th Hawaii International Conference on System Sciences, IEEE, Jan. 4-7, 2012,… [cited by applicant]
Final Office Action, U.S. Appl. No. 17/513,595, May 11, 2023, 14 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/326,070, Jun. 7, 2023, 20 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/710,523, May 25, 2023, 15 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/242,165, May 11, 2023, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/326,070, Sep. 20, 2023, 7 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/710,523, Sep. 5, 2023, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/513,595, Jul. 7, 2023, 7 pages. [cited by applicant]