IP Library › Granted Patent US 12,393,684
Granted Patent B2
US 12,393,684 · App. 18/745,774 · Granted Aug 19, 2025

Method to prevent root level access attack and measurable SLA security and compliance platform

Inventors: Robert Pike (Woodinville, WA); Gary Zelanko (Snohomish, WA); Bryan Greene (Kenly, NC)
Assignee: Cyemptive Technologies, Inc.
G06F21/554G06F21/54H04L41/5019H04L43/065H04L43/16H04L63/1433H04L63/1491G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,684
App. No.
18/745,774
Granted
Aug 19, 2025
Kind
B2
Abstract

A compliance monitor measures metrics regarding one or more managed devices in a network. The compliance monitor generates a log based on the information detected by the measurement trackers and to transmit a report based on the generated log to a recipient. The compliance monitor also initiates one or more security actions based on the one or more measurement trackers indicating that a measured metric exceeds an associated threshold measurement value.

Claims (50)

1. A method comprising:

receiving, from a plurality of devices in a managed network, first logged information describing activity of the plurality of devices in the managed network;

computing a first value for a security compliance metric for the managed network based on the received first logged information;

comparing, at a first time, the first value for the security compliance metric to a threshold value corresponding to the metric;

identifying the security compliance metric as being out of compliance based on the comparing of the first value to the threshold value;

receiving second logged information from the plurality of devices;

computing, at a second time later than the first time, a second value for the security compliance metric based on the second logged information;

comparing the second value for the security compliance metric to the threshold value corresponding to the security compliance metric;

determining that the security compliance metric that is in compliance based on the comparing of the second value to the threshold value;

computing a time to compliance for the managed network based on the first time, the second time, the first logged information, and the second logged information;

comparing the time to compliance to a threshold value; and

initiating, responsive to the time to compliance exceeding the threshold value, a security action.

2. The method of claim 1 , wherein the security action includes rolling back a state of a managed device to an earlier known good state.

3. The method of claim 1 , wherein the security compliance metric includes a mean time to isolation metric representing a mean time to an isolation of each device of the plurality of devices when a change is detected at the device.

4. The method of claim 1 , wherein the security compliance metric includes a hacker investigation time metric that tracks a time spent by a malicious attacker at a device of the plurality of devices.

5. The method of claim 4 , wherein the device is a honeypot designed to provide dummy resources for a malicious attacker to access, the dummy resources being attractive to the malicious attacker.

6. The method of claim 1 , wherein the security compliance metric includes a mean time to repair metric that represents a mean time to repair a device of the plurality of devices after a change is detected at the device.

7. The method of claim 1 , wherein the security compliance metric includes a mean time to service metric that represents a mean time to restore a service provided by the plurality of devices in the network after a disruption of the service caused by a change detected at a device of the plurality of devices.

8. The method of claim 1 , further comprising:

selecting a security action of a plurality actions based on the identified security compliance metric; and

initiating, responsive to the time to compliance exceeding the threshold value, the selected security action.

9. The method of claim 1 , wherein computing the first value for the security compliance metric comprises:

computing the first value by a tracker corresponding to the security compliance metric.

10. The method of claim 1 , further comprising:

transmitting a notification of the initiated security action to a user.

11. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, from a plurality of devices in a managed network, first logged information describing activity of the plurality of devices in the managed network;

computing a first value for a security compliance metric for the managed network based on the received first logged information;

comparing, at a first time, the first value for the security compliance metric to a threshold value corresponding to the metric;

identifying the security compliance metric as being out of compliance based on the comparing of the first value to the threshold value;

receiving second logged information from the plurality of devices;

computing, at a second time later than the first time, a second value for the security compliance metric based on the second logged information;

comparing the second value for the security compliance metric to the threshold value corresponding to the security compliance metric;

determining that the security compliance metric that is in compliance based on the comparing of the second value to the threshold value;

computing a time to compliance for the managed network based on the first time, the second time, the first logged information, and the second logged information;

comparing the time to compliance to a threshold value; and

initiating, responsive to the time to compliance exceeding the threshold value, a security action.

12. The computer-readable medium of claim 11 , wherein the security action includes rolling back a state of a managed device to an earlier known good state.

13. The computer-readable medium of claim 11 , wherein the security compliance metric includes a mean time to isolation metric representing a mean time to an isolation of each device of the plurality of devices when a change is detected at the device.

14. The computer-readable medium of claim 11 , wherein the security compliance metric includes a hacker investigation time metric that tracks a time spent by a malicious attacker at a device of the plurality of devices.

15. The computer-readable medium of claim 14 , wherein the device is a honeypot designed to provide dummy resources for a malicious attacker to access, the dummy resources being attractive to the malicious attacker.

16. The computer-readable medium of claim 11 , wherein the security compliance metric includes a mean time to repair metric that represents a mean time to repair a device of the plurality of devices after a change is detected at the device.

17. The computer-readable medium of claim 11 , wherein the security compliance metric includes a mean time to service metric that represents a mean time to restore a service provided by the plurality of devices in the network after a disruption of the service caused by a change detected at a device of the plurality of devices.

18. The computer-readable medium of claim 11 , the operations further comprising:

selecting a security action of a plurality actions based on the identified security compliance metric; and

initiating, responsive to the time to compliance exceeding the threshold value, the selected security action.

19. The computer-readable medium of claim 11 , wherein computing the first value for the security compliance metric comprises:

computing the first value by a tracker corresponding to the security compliance metric.

20. The computer-readable medium of claim 11 , the operations further comprising:

transmitting a notification of the initiated security action to a user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2024
From: PIKE, ROBERT; ZELANKO, GARY; GREENE, BRYAN
To: CYEMPTIVE TECHNOLOGIES, INC.
Reel/Frame 067781/0086 →
Continuity (5)
Continuation 18308388 · Apr 27, 2023
Continuation 16907302 · Jun 21, 2020
Provisional Application 62865080 · Jun 21, 2019
Provisional Application 62865083 · Jun 21, 2019
Related Publication 20240338440A1 · Oct 10, 2024
References Cited (59)
US 7082463B1 · Bradley et al. · 2006 [cited by applicant]
US 9117069B2 · Oliphant et al. · 2015 [cited by applicant]
US 9892109B2 · Myslinski · 2018 [cited by applicant]
US 10404469B2 · Madhavan et al. · 2019 [cited by applicant]
US 10552796B1 · Delacourt et al. · 2020 [cited by applicant]
US 10754972B2 · Efendiyev et al. · 2020 [cited by applicant]
US 11093518B1 · Lu et al. · 2021 [cited by applicant]
US 11100232B1 · Juncker et al. · 2021 [cited by applicant]
US 12045345B2 · Pike · 2024 [cited by examiner]
US 20040010557A1 · Chapman et al. · 2004 [cited by applicant]
US 20050015624A1 · Ginter et al. · 2005 [cited by applicant]
US 20050086531A1 · Kenrich · 2005 [cited by applicant]
US 20050240756A1 · Mayer · 2005 [cited by applicant]
US 20060112311A1 · Cobb · 2006 [cited by applicant]
US 20070220068A1 · Thompson et al. · 2007 [cited by applicant]
US 20080059474A1 · Lim · 2008 [cited by applicant]
US 20120011573A1 · Menasce et al. · 2012 [cited by applicant]
US 20130031037A1 · Brandt et al. · 2013 [cited by applicant]
US 20130298244A1 · Kumar et al. · 2013 [cited by applicant]
US 20140317754A1 · Niemela et al. · 2014 [cited by applicant]
US 20150006897A1 · Rajakarunanayake et al. · 2015 [cited by applicant]
US 20150121532A1 · Barel · 2015 [cited by applicant]
US 20160330221A1 · Dulkin et al. · 2016 [cited by applicant]
US 20170061432A1 · Ekambaram et al. · 2017 [cited by applicant]
US 20170201545A1 · Nicodemus et al. · 2017 [cited by applicant]
US 20170250892A1 · Cooper et al. · 2017 [cited by applicant]
US 20180062786A1 · Hodge · 2018 [cited by applicant]
US 20180316577A1 · Freeman et al. · 2018 [cited by applicant]
US 20180324056A1 · Occhialini et al. · 2018 [cited by applicant]
US 20190102717A1 · Wu et al. · 2019 [cited by applicant]
US 20190116189A1 · Schlegel et al. · 2019 [cited by applicant]
US 20190324879A1 · Abraham et al. · 2019 [cited by applicant]
US 20200285752A1 · Wyatt et al. · 2020 [cited by applicant]
US 20200401692A1 · Pike et al. · 2020 [cited by applicant]
US 20200410448A1 · Gadge et al. · 2020 [cited by applicant]
US 20220391291A1 · Helland · 2022 [cited by applicant]
CA 2424144A1 · 2003 [cited by applicant]
CN 107078997A · 2017 [cited by applicant]
JP 2010117783A · 2010 [cited by applicant]
JP 2014229127A · 2014 [cited by applicant]
JP 2016184358A · 2016 [cited by applicant]
JP 2017010258A · 2017 [cited by applicant]
WO WO2016024876A1 · 2016 [cited by applicant]
Buecker, A. et al. “IBM Security Solutions Architecture for Network, Server, and Endpoint,” IBM Redbooks, Feb. 17, 2011. [cited by applicant]
Canadian Intellectual Property Administration, Office Action, Canadian Patent Application No. 3,144,465, Dec. 27, 2023, 6 pages. [cited by applicant]
Canadian Intellectual Property Office, Office Action, Canadian Patent Application No. 3,144,465, Jul. 28, 2022, 6 pages. [cited by applicant]
Extended European Search Report and Written Opinion, European Patent Application No. 20827633.7, Sep. 25, 2023, 13 pages. [cited by applicant]
Jacobs, S. “Securing Management and Managing Security,” Engineering Information Security: The Application of Systems Engineering Concepts to Achieve Information Assurance, 2016, pp. 607-659. [cited by applicant]
Japan Patent Office, Office Action with English Translation, Japanese Patent Application No. 2022-164051, May 21, 2024, 8 pages. [cited by applicant]
Muller, N. “Managing Service Level Agreements,” International Journal of Network Management, vol. 9, No. 3, May 1999, pp. 155-166. [cited by applicant]
PCT International Search Report and Written Opinion, PCT Application No. PCT/US2020/038837, Oct. 26, 2020, 17 pages. [cited by applicant]
Rios, E. “Service Level Agreement-Based GDPR Compliance and Security Assurance in (multi) Cloud-Based Systems.” IET Software, vol. 13, No. 3, Feb. 1, 2019, pp. 1-12. [cited by applicant]
The Japan Patent Office, Official Notice of Rejection, Japanese Patent Application No. 2021-576332, Jul. 12, 2022, 9 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/907,302, Jun. 27, 2022, 10 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/907,305, Sep. 21, 2021, 13 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/841,918, Dec. 22, 2022, 24 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/350,587, Feb. 29, 2024, 34 pages. [cited by applicant]
China National Intellectual Property Administration, Office Action, CN Patent Application No. 202080057744.0, Nov. 12, 2024, 13 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/350,587, filed Feb. 12, 2025, 12 pages. [cited by applicant]