IP Library Granted Patent US 11,550,921
Granted Patent B2
US 11,550,921 · App. 16/732,798 · Granted Jan 10, 2023

Threat response systems and methods

Inventors: Cody Cornell (Boulder, CO); Brian Kafenbaum (Anthem, AZ); Brant Wheeler (Cookeville, TN); Austin McDaniel (Boynton Beach, FL)
Assignee: Swimlane, Inc.
G06F21/577G06F21/554G06Q10/0633H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,921
App. No.
16/732,798
Granted
Jan 10, 2023
Kind
B2
Abstract

A security operations system may receive an alarm in response to a detected threat. The alarm may include characteristics of the threat. The system may then generate a record in response to the alarm and populate a form with the characteristics of the threat. The form may be associated with the record and selected in response to a type of the threat. The system may further generate a workflow including at least one but potentially multiple actions. The system also receives security contextual information in response to a request including the characteristics of the threat or associated indicators of the threat and then updates the form to include the security contextual information. The security operations system can evaluate contextual information and request additional information, as well as leverage workflow to take iterative changes to rulesets and configurations, to provide additional security protection or garner additional information on a threat.

Claims (64)

1. A method for incident response comprising:

generating, by a security operations system, a workflow, wherein the workflow:

prior to the security operations system receiving an alarm, is customizable via a form among a plurality of customizable forms by at least one of:

adding, removing, or modifying a rule for an action from the form; and

is configured to be automatically executed to address the alarm;

automatically executing, by the security operations system, a first action based on the workflow;

receiving, by the security operations system, security contextual data including a type of threat and characteristics of a threat;

automatically selecting, by the security operations system, the form from among the plurality of customizable forms based on the type of threat;

automatically populating the form from among the plurality of customizable forms with (1) at least a portion of the security contextual data and (2) threat intelligence data gathered from past threats;

automatically executing, by the security operations system, the workflow to generate a second action based on the form, as automatically populated; and

automatically executing, by the security operations system, the second action.

2. The method of claim 1 further comprising:

receiving, by the security operations system, the alarm in response to the threat detected on a monitored system, wherein the alarm includes the characteristics of the threat.

3. The method of claim 1 , wherein the type of threat includes at least one of data loss, denial of service (DoS), malware, virus, or a violation of a user policy.

4. The method of claim 1 further comprising:

generating, by the security operations system, a record in response to the alarm, wherein the record includes a severity level assigned to the record, wherein the severity level is automatically generated based on a threat level identified in the alarm.

5. The method of claim 1 , wherein the threat has a capability to impact confidentiality of data, availability of services or integrity of data.

6. The method of claim 1 further comprising:

updating the threat intelligence data with the at least the portion of the security contextual data; and

automatically populating a new form from among the plurality of customizable forms with the threat intelligence data, as updated.

7. The method of claim 1 , wherein the security operations system comprises a self-learning system.

8. A computer-based system, comprising:

a processor;

a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause a security operations system to perform operations comprising:

generating, by a security operations system, a workflow, wherein the workflow:

prior to the security operations system receiving an alarm, is customizable via a form among a plurality of customizable forms by at least one of:

adding, removing, or modifying a rule for an action from the form; and

is configured to be automatically executed to address the alarm;

automatically executing, by the security operations system, a first action based on the workflow;

receiving, by the security operations system, security contextual data including a type of threat and characteristics of a threat;

automatically selecting, by the security operations system, the form from among the plurality of customizable forms based on the type of threat;

automatically populating the form from among the plurality of customizable forms with (1) at least a portion of the security contextual data and (2) threat intelligence data gathered from past threats;

automatically executing, by the security operations system, the workflow to generate a second action based on the form, as automatically populated; and

automatically executing, by the security operations system, the second action.

9. The computer-based system of claim 8 , wherein the operations further comprise:

receiving, by the security operations system, the alarm in response to the threat detected on a monitored system, wherein the alarm includes the characteristics of the threat.

10. The computer-based system of claim 8 , wherein the operations further comprise:

generating, by the security operations system, a record in response to the alarm, wherein the record includes a severity level assigned to the record, wherein the severity level is automatically generated based on a threat level identified in the alarm.

11. The computer-based system of claim 8 , wherein the operations further comprise:

updating the threat intelligence data with the at least the portion of the security contextual data; and

automatically populating a new form from among the plurality of customizable forms with the threat intelligence data, as updated.

12. The computer-based system of claim 8 , wherein the security operations system comprises a self-learning system.

13. The computer-based system of claim 8 , wherein the type of threat includes at least one of data loss, denial of service (DoS), malware, virus, or a violation of a user policy.

14. An article of manufacture including a non-transitory, tangible computer readable storage medium having instructions stored thereon that, in response to execution by a security operations system, cause the security operations system to perform operations comprising:

generating, by a security operations system, a workflow, wherein the workflow:

prior to the security operations system receiving an alarm, is customizable via a form among a plurality of customizable forms by at least one of:

adding, removing, or modifying a rule for an action from the form; and

is configured to be automatically executed to address the alarm;

automatically executing, by the security operations system, a first action based on the workflow;

receiving, by the security operations system, security contextual data including a type of threat and characteristics of a threat;

automatically selecting, by the security operations system, the form from among the plurality of customizable forms based on the type of threat;

automatically populating the form from among the plurality of customizable forms with (1) at least a portion of the security contextual data and (2) threat intelligence data gathered from past threats;

automatically executing, by the security operations system, the workflow to generate a second action based on the form, as automatically populated; and

automatically executing, by the security operations system, the second action.

15. The article of claim 14 , wherein the operations further comprise:

receiving, by the security operations system, the alarm in response to the threat detected on a monitored system, wherein the alarm includes the characteristics of the threat.

16. The article of claim 14 , wherein the operations further comprise:

generating, by the security operations system, a record in response to the alarm, wherein the record includes a severity level assigned to the record, wherein the severity level is automatically generated based on a threat level identified in the alarm.

17. The article of claim 16 , wherein the form is associated with the record.

18. The article of claim 14 , wherein the operations further comprise:

updating the threat intelligence data with the at least the portion of the security contextual data; and

automatically populating a new form from among the plurality of customizable forms with the threat intelligence data, as updated.

19. The article of claim 14 , wherein the security operations system comprises a self-learning system.

20. The article of claim 14 , wherein the type of threat includes at least one of data loss, denial of service (DoS), malware, virus, or a violation of a user policy.

Assignments (4)
SECURITY INTEREST Recorded May 28, 2025
From: SWIMLANE, INC.
To: TRINITY CAPITAL INC., AS ADMINISTRATIVE AGENT
Reel/Frame 071235/0690 →
SECURITY INTEREST Recorded May 28, 2025
From: SWIMLANE, INC.
To: CUSTOMERS BANK
Reel/Frame 071242/0198 →
CHANGE OF NAME Recorded Jul 8, 2022
From: SWIMLANE LLC
To: SWIMLANE, INC.
Reel/Frame 060617/0811 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2020
From: CORNELL, CODY; KAFENBAUM, BRIAN; WHEELER, BRANT; MCDANIEL, AUSTIN
To: SWIMLANE LLC
Reel/Frame 051460/0490 →
Continuity (2)
Continuation 15047391 · Feb 18, 2016
Related Publication 20200143062A1 · May 7, 2020