IP Library Granted Patent US 12,328,342
Granted Patent B2
US 12,328,342 · App. 18/318,338 · Granted Jun 10, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: ReliaQuest Holdings, LLC
H04L63/20H04L41/024H04L63/1416H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,342
App. No.
18/318,338
Granted
Jun 10, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; defining a plurality of subsystem-specific queries on a unified platform concerning the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

Claims (111)

1. A computer-implemented method, executed on a computing device, comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform;

defining a unified query on a unified platform concerning the plurality of security-relevant subsystems;

defining a plurality of subsystem-specific queries on the unified platform concerning the plurality of security-relevant subsystems, including denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries, and mapping one or more data fields of the unified platform to one or more data fields of each of the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

2. The computer-implemented method of claim 1 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

3. The computer-implemented method of claim 1 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

4. The computer-implemented method of claim 1 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

5. The computer-implemented method of claim 1 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

6. The computer-implemented method of claim 1 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

7. The computer-implemented method of claim 6 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

8. The computer-implemented method of claim 7 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

9. The computer-implemented method of claim 1 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

10. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform;

defining a unified query on a unified platform concerning the plurality of security-relevant subsystems;

defining a plurality of subsystem-specific queries on the unified platform concerning the plurality of security-relevant subsystems, including denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries, and mapping one or more data fields of the unified platform to one or more data fields of each of the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

11. The computer program product of claim 10 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

12. The computer program product of claim 10 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

13. The computer program product of claim 10 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

14. The computer program product of claim 10 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

15. The computer program product of claim 10 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

16. The computer program product of claim 15 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

17. The computer program product of claim 16 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

18. The computer program product of claim 10 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

19. A computing system including a processor and memory configured to perform operations comprising:

establishing connectivity with a plurality of security-relevant subsystems within a computing platform;

defining a unified query on a unified platform concerning the plurality of security-relevant subsystems;

defining a plurality of subsystem-specific queries on the unified platform concerning the plurality of security-relevant subsystems, including denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries, and mapping one or more data fields of the unified platform to one or more data fields of each of the plurality of security-relevant subsystems, wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule; and

providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems.

20. The computing system of claim 19 wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party.

21. The computing system of claim 19 wherein the defined execution schedule includes one or more of:

a defined execution time;

a defined execution date;

a defined execution frequency; and

a defined execution scope.

22. The computing system of claim 19 further comprising:

determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries; and

reexecuting the one or more failed subsystem-specific queries.

23. The computing system of claim 19 wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes:

translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries.

24. The computing system of claim 19 further comprising:

receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries.

25. The computing system of claim 24 further comprising:

normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; and

providing the unified result set to a third-party.

26. The computing system of claim 25 wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes:

translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set.

27. The computing system of claim 19 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2023
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 064901/0984 →
Continuity (3)
Continuation 17532764 · Nov 22, 2021
Provisional Application 63117180 · Nov 23, 2020
Related Publication 20230291771A1 · Sep 14, 2023
References Cited (12)
US 9069930B1 · Hart · 2015 [cited by applicant]
US 20110125642A1 · Kamal · 2011 [cited by examiner]
US 20170006058A1 · Murphy · 2017 [cited by examiner]
US 20180241767A1 · Crabtree · 2018 [cited by examiner]
US 20210136120A1 · Crabtree · 2021 [cited by examiner]
US 20210136121A1 · Crabtree · 2021 [cited by examiner]
US 20210160288A1 · Crabtree · 2021 [cited by examiner]
CA 3102810A1 · 2019 [cited by examiner]
EP 4248316A1 · 2023 [cited by applicant]
WO 2022109417A1 · 2022 [cited by applicant]
International Search Report and Written Opinion issued on Feb. 8, 2022 in related application Serial No. PCT/US2021/60392. [cited by applicant]
Extended European Search Report issued in related Application Serial No. 21895774.4 on Aug. 27, 2024. [cited by applicant]