IP Library Granted Patent US 12,259,972
Granted Patent B2
US 12,259,972 · App. 18/390,658 · Granted Mar 25, 2025

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: ReliaQuest Holdings, LLC
G06F21/554G06F21/56H04L63/1441G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,259,972
App. No.
18/390,658
Granted
Mar 25, 2025
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for: a computer-implemented method is executed on a computing device and includes: obtaining object information concerning one or more initial objects within a computing platform in response to a security event; identifying an event type for the security event; and executing a response script based, at least in part, upon the event type.

Claims (132)

1. A computer-implemented method, executed on a computing device, comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring actions taken by a third party during an investigation of the security event, including:

monitoring artifacts gathered by the third party during the investigation of the security event; and

monitoring objects reviewed by the third party during the investigation of the security event;

executing a response script based, at least in part, upon the event type; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

2. The computer-implemented method of claim 1 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

3. The computer-implemented method of claim 2 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

4. The computer-implemented method of claim 3 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

5. The computer-implemented method of claim 3 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

6. The computer-implemented method of claim 1 wherein executing a response script includes:

obtaining object information concerning one or more additional objects.

7. The computer-implemented method of claim 1 wherein executing a response script includes:

obtaining artifacts concerning the security event.

8. The computer-implemented method of claim 7 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

9. The computer-implemented method of claim 1 wherein executing a response script includes:

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

10. The computer-implemented method of claim 1 wherein executing a response script includes:

executing a remedial action in response to the security event.

11. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring actions taken by a third party during an investigation of the security event, including:

monitoring artifacts gathered by the third party during the investigation of the security event; and

monitoring objects reviewed by the third party during the investigation of the security event;

executing a response script based, at least in part, upon the event type; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

12. The computer program product of claim 11 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

13. The computer program product of claim 12 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

14. The computer program product of claim 13 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

15. The computer program product of claim 13 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

16. The computer program product of claim 11 wherein executing a response script includes:

obtaining object information concerning one or more additional objects.

17. The computer program product of claim 11 wherein executing a response script includes:

obtaining artifacts concerning the security event.

18. The computer program product of claim 17 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

19. The computer program product of claim 11 wherein executing a response script includes:

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

20. The computer program product of claim 11 wherein executing a response script includes:

executing a remedial action in response to the security event.

21. A computing system including a processor and memory configured to perform operations comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring actions taken by a third party during an investigation of the security event, including:

monitoring artifacts gathered by the third party during the investigation of the security event; and

monitoring objects reviewed by the third party during the investigation of the security event;

executing a response script based, at least in part, upon the event type; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

22. The computing system of claim 21 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

23. The computing system of claim 22 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

24. The computing system of claim 23 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

25. The computing system of claim 23 wherein the plurality of security-relevant subsystems includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

26. The computing system of claim 21 wherein executing a response script includes:

obtaining object information concerning one or more additional objects.

27. The computing system of claim 21 wherein executing a response script includes:

obtaining artifacts concerning the security event.

28. The computing system of claim 27 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

29. The computing system of claim 21 wherein executing a response script includes:

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

30. The computing system of claim 21 wherein executing a response script includes:

executing a remedial action in response to the security event.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2024
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 068352/0605 →
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
Continuity (3)
Continuation 17532783 · Nov 22, 2021
Provisional Application 63117193 · Nov 23, 2020
Related Publication 20240119144A1 · Apr 11, 2024
References Cited (27)
US 9069930B1 · Hart · 2015 [cited by applicant]
US 9306962B1 · Pinto · 2016 [cited by applicant]
US 9838405B1 · Guo et al. · 2017 [cited by applicant]
US 10242187B1 · Roundy et al. · 2019 [cited by applicant]
US 10333898B1 · Moore et al. · 2019 [cited by applicant]
US 10666666B1 · Saurabh · 2020 [cited by applicant]
US 11861001B2 · Murphy · 2024 [cited by examiner]
US 20160088000A1 · Siva Kumar et al. · 2016 [cited by applicant]
US 20160164917A1 · Friedrichs et al. · 2016 [cited by applicant]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20190379705A1 · Murphy et al. · 2019 [cited by applicant]
US 20200004960A1 · Karasovsky · 2020 [cited by examiner]
US 20200186569A1 · Milazzo · 2020 [cited by examiner]
US 20200327222A1 · Chhabra et al. · 2020 [cited by applicant]
US 20210029159A1 · Murphy et al. · 2021 [cited by applicant]
US 20210126938A1 · Trost et al. · 2021 [cited by applicant]
US 20210176257A1 · Yavo et al. · 2021 [cited by applicant]
US 20210288979A1 · Colvin et al. · 2021 [cited by applicant]
US 20210320941A1 · e Silva · 2021 [cited by examiner]
US 20210409439A1 · Engelberg et al. · 2021 [cited by applicant]
US 20220131894A1 · Hassanzadeh et al. · 2022 [cited by applicant]
US 20220417263A1 · Hinkle · 2022 [cited by examiner]
US 20230259632A1 · Marciano · 2023 [cited by examiner]
US 20240179175A1 · Tomic · 2024 [cited by examiner]
WO WO2023192682A1 · 2023 [cited by examiner]
Hariyani et al, Forensic Evidence Collection From Windows Host Using Python Based Tool, 2022 IEEE 4th International Conference of Cybernetics, Cognition, and Machine Learning Applications, p. 85-90 (Year: 2022). [cited by examiner]
Extended European Search Report issued in related Application Serial No. 21895775.1 on Aug. 27, 2024. [cited by applicant]