IP Library › Granted Patent US 12,225,043
Granted Patent B2
US 12,225,043 · App. 18/667,464 · Granted Feb 11, 2025

Systems and methods for security process analysis

Inventors: Ben Bernstein (New York, NY); John Morello (Baton Rouge, LA); Dima Stopel (Herzliya, IL)
Assignee: Gutsy.IO, LTD
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,043
App. No.
18/667,464
Granted
Feb 11, 2025
Kind
B2
Abstract

A method and system for cyber-security processes mining are provided. The method comprises correlating events received from a plurality of data sources into a plurality of flows, wherein a flow of the plurality of flows is a sequence of events having a same identifier, and wherein at least one of the plurality of data sources is a cyber-security system; correlating the plurality of flows into a plurality of variants, wherein a variant out of the plurality of variants includes one or more flows having the same repeatable pattern; associating the plurality of variants with at least one cyber-security process based on a predefined template defining the cyber-security process; and causing a display of the least one cyber-security process and its plurality of variants.

Claims (48)

1. A method for cyber-security processes mining, comprising:

correlating events received from a plurality of data sources into a plurality of flows, wherein a flow of the plurality of flows is a sequence of events having a same identifier, and wherein at least one of the plurality of data sources is a cyber-security system;

correlating the plurality of flows into a plurality of variants, wherein a variant out of the plurality of variants includes one or more flows having the same repeatable pattern;

correlating flows having a repeatable pattern into a variant, wherein a repeatable pattern includes a same number of events of the same type;

associating the plurality of variants with at least one cyber-security process based on a predefined template defining the cyber-security process; and

causing a display of the least one cyber-security process and its plurality of variants.

2. The method of claim 1 , further comprising:

tagging a variant of the plurality of variants with at least one of a cyber-security risk.

3. The method of claim 1 , further comprising:

analyzing variants associated with the least one cyber-security process to determine a target variant, wherein the target variant defines an optimal execution of the process.

4. The method of claim 1 , wherein correlating the received events into the plurality of flows further comprises:

correlating the received events received from the plurality of data sources into the plurality of flows based on a flow identifier (ID) which is similar to the same identifier of each event in the respective flow; and

organizing the received event having the same flow ID in a sequence based on their respective timestamps.

5. The method of claim 1 , wherein each variant of the plurality of variants is of flow having a different identifier.

6. The method of claim 1 , wherein the data sources further include at least one non-cyber-security system.

7. The method of claim 6 , wherein the at least one non-cyber-security system is any one of: a ticking system, a development pipeline platform, a standards system, and a workflow system.

8. The method of claim 6 , wherein the at least one cyber-security system is any one of: an intrusion detection system (IDS), an intrusion prevention system (IPS), a data loss prevention (DLP) system, a network security tool, a vulnerability scanner, a cloud vulnerability scanner, a security information and event management (SIEM) system, and a web application firewall (WAF).

9. The method of claim 1 , wherein the cyber-security process includes a sequence of steps related to a cyber-security issue.

10. The method of claim 1 , further comprising:

generating insights related to the plurality of variants of a cyber-security process; and

comparing the generated insights to a set of key performance indicators (KPIs).

11. A non-transitory computer-readable medium storing a set of instructions for cyber-security processes mining, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

correlate events received from a plurality of data sources into a plurality of flows, wherein a flow of the plurality of flows is a sequence of events having a same identifier, and wherein at least one of the plurality of data sources is a cyber-security system;

correlate the plurality of flows into a plurality of variants, wherein a variant out of the plurality of variants includes one or more flows having the same repeatable pattern;

correlate flows having a repeatable pattern into a variant, wherein a repeatable pattern includes a same number of events of the same type;

associate the plurality of variants with at least one cyber-security process based on a predefined template defining the cyber-security process; and

cause a display of the least one cyber-security process and its plurality of variants.

12. A system for cyber-security processes mining comprising:

one or more processors configured to:

correlate events received from a plurality of data sources into a plurality of flows, wherein a flow of the plurality of flows is a sequence of events having a same identifier, and wherein at least one of the plurality of data sources is a cyber-security system;

correlate the plurality of flows into a plurality of variants, wherein a variant out of the plurality of variants includes one or more flows having the same repeatable pattern;

correlate flows having a repeatable pattern into a variant, wherein a repeatable pattern includes a same number of events of the same type;

associate the plurality of variants with at least one cyber-security process based on a predefined template defining the cyber-security process; and

cause a display of the least one cyber-security process and its plurality of variants.

13. The system of claim 12 , wherein the system is further configured to:

tag a variant of the plurality of variants with at least one of a cyber-security risk.

14. The system of claim 12 , wherein the system is further configured to:

analyze variants associated with the least one cyber-security process to determine a target variant, wherein the target variant defines an optimal execution of the process.

15. The system of claim 12 , wherein the system is further configured to:

correlate the received events received from the plurality of data sources into the plurality of flows based on a flow identifier (ID) which is similar to the same identifier of each event in the respective flow; and

organize the received event having the same flow ID in a sequence based on their respective timestamps.

16. The system of claim 12 , wherein each variant of the plurality of variants is of flow having a different identifier.

17. The system of claim 12 , wherein the data sources further include at least one non-cyber-security system.

18. The system of claim 17 , wherein the at least one non-cyber-security system is any one of:

a ticking system, a development pipeline platform, a standards system, and a workflow system.

19. The system of claim 17 , wherein the at least one cyber-security system is any one of: an intrusion detection system (IDS), an intrusion prevention system (IPS), a data loss prevention (DLP) system, a network security tool, a vulnerability scanner, a cloud vulnerability scanner, a security information and event management (SIEM) system, and a web application firewall (WAF).

20. The system of claim 12 , wherein the cyber-security process includes a sequence of steps related to a cyber-security issue.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2026
From: MINIMUS LTD
To: ECHO SOFTWARE LTD.
Reel/Frame 075796/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2026
From: BERNSTEIN, BEN; MORELLO, JOHN; STOPEL, DIMA
To: GUTSY.IO, LTD
Reel/Frame 073869/0037 →
CHANGE OF NAME Recorded Feb 23, 2026
From: GUTSY.IO LTD
To: MINIMUS LTD
Reel/Frame 074991/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2024
From: BERNSTEIN, BEN; MORELLO, JOHN; STOPEL, DIMA
To: GUTSY.IO, LTD
Reel/Frame 067951/0393 →
Continuity (3)
Provisional Application 63504737 · May 27, 2023
Provisional Application 63502830 · May 17, 2023
Related Publication 20240388596A1 · Nov 21, 2024
References Cited (30)
US 7447666B2 · Wang · 2008 [cited by applicant]
US 7788719B1 · Hernacki · 2010 [cited by examiner]
US 8291495B1 · Burns · 2012 [cited by examiner]
US 8595840B1 · Malibiran · 2013 [cited by examiner]
US 8682812B1 · Ranjan · 2014 [cited by examiner]
US 9137139B2 · Roosta · 2015 [cited by examiner]
US 20050132206A1 · Palliyil · 2005 [cited by examiner]
US 20080005782A1 · Aziz · 2008 [cited by examiner]
US 20100198636A1 · Choudhary · 2010 [cited by examiner]
US 20110093955A1 · Chen · 2011 [cited by examiner]
US 20120030761A1 · Baba · 2012 [cited by examiner]
US 20150135263A1 · Singla et al. · 2015 [cited by applicant]
US 20160241574A1 · Kumar · 2016 [cited by examiner]
US 20160241577A1 · Johnson · 2016 [cited by examiner]
US 20170063884A1 · Seigel · 2017 [cited by applicant]
US 20180176139A1 · Mortensen · 2018 [cited by examiner]
US 20200213343A1 · Bharrat · 2020 [cited by examiner]
US 20210029148A1 · Wee · 2021 [cited by examiner]
US 20210136076A1 · Barhudarian · 2021 [cited by examiner]
US 20220311794A1 · Maya · 2022 [cited by examiner]
US 20230095870A1 · Du · 2023 [cited by applicant]
US 20230111864A1 · Thomas · 2023 [cited by examiner]
US 20230199024A1 · Dods · 2023 [cited by examiner]
US 20240098099A1 · Dutta · 2024 [cited by examiner]
CA 2943271C · 2023 [cited by examiner]
CN 108040493B · 2021 [cited by examiner]
CN 117391214A · 2024 [cited by examiner]
EP 3528460A1 · 2019 [cited by applicant]
International Search Report for PCT/IB2024/054822 dated Aug. 29, 2024. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]
Written Opinion of the Searching Authority for PCT/IB2024/054822 dated Aug. 29, 2024. Searching Authority, Israel Patent Office, Jerusalem, Israel. [cited by applicant]