IP Library › Granted Patent US 12,189,791
Granted Patent B2
US 12,189,791 · App. 18/133,884 · Granted Jan 7, 2025

Distributed digital security system

Inventors: David F. Diehl (Minneapolis, MN); James Robert Plush (Lake Forest, CA); Timothy Jason Berger (Eastvale, CA)
Assignee: CrowdStrike, Inc.
G06F21/60G06F9/542H04L63/0892H04L63/105H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,791
App. No.
18/133,884
Granted
Jan 7, 2025
Kind
B2
Abstract

A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.

Claims (121)

1. A computer-implemented method comprising:

receiving, by a network storage engine of a security network, and from one or more security agents executing at one or more client devices remote from the network storage engine, first event data associated with one or more events that have occurred at the one or more client devices;

providing, by the network storage engine, a first copy of the first event data to a network compute engine of the security network;

receiving, by the network storage engine at a first time, and from the network compute engine, a claim check for second event data, wherein:

the second event data is related to the first event data, and

the second event data has, at the first time, not been received by the network storage engine or the network compute engine;

receiving, by the network storage engine at a second time, the second event data associated with the claim check;

determining, by the network storage engine, that the claim check has been satisfied based on receipt of the first event data and the second event data; and

providing, by the network storage engine in response to determining that the claim check has been satisfied, the second event data and a second copy of the first event data to the network compute engine.

2. The computer-implemented method of claim 1 , wherein the network compute engine is configured to provide the claim check to the network storage engine in response to the network compute engine receiving the first copy of the first event data.

3. The computer-implemented method of claim 1 , wherein the network compute engine:

is configured to determine whether a stream of event data provided by the one or more security agents to the network storage engine includes event data corresponding to a behavior pattern associated with the first event data and the second event data, and

sends the claim check to the network storage engine in response to determining that:

the first copy of the first event data associated with the behavior pattern has been received by the network compute engine from the network storage engine; and

the second event data associated with the behavior pattern has not yet been received by the network compute engine from the network storage engine.

4. The computer-implemented method of claim 1 , wherein:

the first event data is associated with a child process executed on a client device of the one or more client devices, and

the second event data is associated with a parent process, executed on the client device, that spawned the child process on the client device.

5. The computer-implemented method of claim 1 , wherein the network compute engine is configured to:

disregard the first copy of the first event data after providing the claim check to the network storage engine, and

process the second copy of the first event data along with the second event data provided by the network storage engine in response to determining that the claim check has been satisfied.

6. The computer-implemented method of claim 1 , further comprising:

receiving, by the network storage engine, third event data;

providing, by the network storage engine, the third event data to the network compute engine;

receiving, by the network storage engine at a third time, and from the network compute engine, a second claim check for fourth event data, wherein:

the fourth event data is related to the third event data, and

the fourth event data has, at the third time, not been received by the network storage engine or the network compute engine;

determining, by the network storage engine at a fourth time, that the second claim check has expired based on the fourth event data not having arrived by the fourth time; and

re-sending, by the network storage engine, the third event data to the network compute engine in response to determining that the second claim check has expired.

7. The computer-implemented method of claim 1 , further comprising:

receiving, by the network storage engine at a third time, and from the network compute engine, a second claim check for third event data, wherein:

the third event data is related to the first event data,

the third event data has, at the third time, not been received by the network storage engine or the network compute engine, and

the second claim check is related to the claim check associated with the first event data and the second event data;

receiving, by the network storage engine at a fourth time, the third event data associated with the second claim check;

determining, by the network storage engine, that the second claim check has been satisfied based on receipt of the first event data and the third event data; and

providing, by the network storage engine, the second event data, the third event data, and the second copy of the first event data to the network compute engine in response to determining that:

the claim check has been satisfied, and

the second claim check has been satisfied.

8. The computer-implemented method of claim 7 , wherein:

the first event data is associated with a child process executed on a client device of the one or more client devices,

the second event data is associated with a parent process, executed on the client device, that spawned the child process on the client device, and

the third event data is associated with a grandparent process, executed on the client device, that spawned the parent process on the client device.

9. The computer-implemented method of claim 1 , wherein the claim check is part of a group of related claim checks, and the computer-implemented method further comprises:

generating, by the network storage engine, a dependency graph indicating dependencies between claim checks in the group of related claim checks;

receiving, by the network storage engine, an instance of event data; and

identifying, by the network storage engine, one or more claim checks in the group of related claim checks that are associated with the instance of event data, based on traversing the dependency graph in response to receipt of the instance of event data.

10. A computing system comprising:

one or more processors; and

memory storing computer-executable instructions associated with a network storage engine of a security network that, when executed by the one or more processors, cause the computing system to perform operations comprising:

receiving, from one or more security agents executing at one or more client devices remote from the network storage engine, first event data associated with one or more events that have occurred at the one or more client devices;

providing a first copy of the first event data to a network compute engine of the security network;

receiving, at a first time, and from the network compute engine, a claim check for second event data, wherein:

the second event data is related to the first event data, and

the second event data has, at the first time, not been received by the network storage engine or the network compute engine;

receiving, at a second time, the second event data associated with the claim check;

determining that the claim check has been satisfied based on receipt of the first event data and the second event data; and

providing, in response to determining that the claim check has been satisfied, the second event data and a second copy of the first event data to the network compute engine.

11. The computing system of claim 10 , wherein:

the first event data is associated with a child process executed on a client device of the one or more client devices, and

the second event data is associated with a parent process, executed on the client device, that spawned the child process on the client device.

12. The computing system of claim 10 , wherein the operations further comprise:

receiving third event data;

providing the third event data to the network compute engine;

receiving, at a third time, and from the network compute engine, a second claim check for fourth event data, wherein:

the fourth event data is related to the third event data, and

the fourth event data has, at the third time, not been received by the network storage engine or the network compute engine;

determining, at a fourth time, that the second claim check has expired based on the fourth event data not having arrived by the fourth time; and

re-sending the third event data to the network compute engine in response to determining that the second claim check has expired.

13. The computing system of claim 10 , wherein the operations further comprise:

receiving, at a third time, and from the network compute engine, a second claim check for third event data, wherein:

the third event data is related to the first event data,

the third event data has, at the third time, not been received by the network storage engine or the network compute engine, and

the second claim check is related to the claim check associated with the first event data and the second event data;

receiving, at a fourth time, the third event data associated with the second claim check;

determining that the second claim check has been satisfied based on receipt of the first event data and the third event data; and

providing the second event data, the third event data, and the second copy of the first event data to the network compute engine in response to determining that:

the claim check has been satisfied, and

the second claim check has been satisfied.

14. The computing system of claim 13 , wherein:

the first event data is associated with a child process executed on a client device of the one or more client devices,

the second event data is associated with a parent process, executed on the client device, that spawned the child process on the client device, and

the third event data is associated with a grandparent process, executed on the client device, that spawned the parent process on the client device.

15. The computing system of claim 10 , wherein the claim check is part of a group of related claim checks, and the operations further comprise:

generating a dependency graph indicating dependencies between claim checks in the group of related claim checks;

receiving an instance of event data; and

identifying one or more claim checks in the group of related claim checks that are associated with the instance of event data, based on traversing the dependency graph in response to receipt of the instance of event data.

16. One or more non-transitory computer-readable media storing computer-executable instructions associated with a network storage engine of a security network that, when executed by one or more processors, cause the network storage engine to:

receive, from one or more security agents executing at one or more client devices remote from the network storage engine, first event data associated with one or more events that have occurred at the one or more client devices;

provide a first copy of the first event data to a network compute engine of the security network;

receive, at a first time, and from the network compute engine, a claim check for second event data, wherein:

the second event data is related to the first event data, and

the second event data has, at the first time, not been received by the network storage engine or the network compute engine;

receive, at a second time, the second event data associated with the claim check;

determine that the claim check has been satisfied based on receipt of the first event data and the second event data; and

provide, in response to determining that the claim check has been satisfied, the second event data and a second copy of the first event data to the network compute engine.

17. The one or more non-transitory computer-readable media of claim 16 , wherein:

the first event data is associated with a child process executed on a client device of the one or more client devices, and

the second event data is associated with a parent process, executed on the client device, that spawned the child process on the client device.

18. The one or more non-transitory computer-readable media of claim 16 , wherein the computer-executable instructions further cause the network storage engine to:

receive third event data;

provide the third event data to the network compute engine;

receive, at a third time, and from the network compute engine, a second claim check for fourth event data, wherein:

the fourth event data is related to the third event data, and

the fourth event data has, at the third time, not been received by the network storage engine or the network compute engine;

determine, at a fourth time, that the second claim check has expired based on the fourth event data not having arrived by the fourth time; and

re-send the third event data to the network compute engine in response to determining that the second claim check has expired.

19. The one or more non-transitory computer-readable media of claim 16 , wherein the computer-executable instructions further cause the network storage engine to:

receive, at a third time, and from the network compute engine, a second claim check for third event data, wherein:

the third event data is related to the first event data,

the third event data has, at the third time, not been received by the network storage engine or the network compute engine, and

the second claim check is related to the claim check associated with the first event data and the second event data;

receive, at a fourth time, the third event data associated with the second claim check;

determine that the second claim check has been satisfied based on receipt of the first event data and the third event data; and

provide the second event data, the third event data, and the second copy of the first event data to the network compute engine in response to determining that:

the claim check has been satisfied, and

the second claim check has been satisfied.

20. The one or more non-transitory computer-readable media of claim 16 , wherein the claim check is part of a group of related claim checks, and the computer-executable instructions further cause the network storage engine to:

generate a dependency graph indicating dependencies between claim checks in the group of related claim checks;

receive an instance of event data; and

identify one or more claim checks in the group of related claim checks that are associated with the instance of event data, based on traversing the dependency graph in response to receipt of the instance of event data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: DIEHL, DAVID F.; PLUSH, JAMES ROBERT; BERGER, TIMOTHY JASON
To: CROWDSTRIKE, INC.
Reel/Frame 063333/0343 →
Continuity (2)
Continuation 16849543 · Apr 15, 2020
Related Publication 20230297690A1 · Sep 21, 2023
References Cited (194)
US 6850974B2 · Schweitzer · 2005 [cited by applicant]
US 6934749B1 · Black · 2005 [cited by applicant]
US 7020696B1 · Perry · 2006 [cited by applicant]
US 7143153B1 · Black · 2006 [cited by applicant]
US 7349960B1 · Pothier · 2008 [cited by applicant]
US 7523191B1 · Thomas · 2009 [cited by applicant]
US 7840501B1 · Sallam · 2010 [cited by applicant]
US 8122122B1 · Clingenpeel · 2012 [cited by applicant]
US 8407337B2 · Debettencourt · 2013 [cited by applicant]
US 8779921B1 · Curtiss · 2014 [cited by applicant]
US 8850321B2 · Seeger · 2014 [cited by applicant]
US 8909761B2 · Reynolds · 2014 [cited by applicant]
US 9043903B2 · Diehl et al. · 2015 [cited by applicant]
US 9069930B1 · Hart · 2015 [cited by examiner]
US 9202249B1 · Cohen · 2015 [cited by examiner]
US 9386165B2 · Raleigh · 2016 [cited by examiner]
US 9661003B2 · Parker · 2017 [cited by applicant]
US 9906549B2 · Fan · 2018 [cited by applicant]
US 10200262B1 · Leverich et al. · 2019 [cited by applicant]
US 10320831B2 · Agarmore et al. · 2019 [cited by applicant]
US 10382454B2 · Avidan · 2019 [cited by examiner]
US 10498744B2 · Hunt · 2019 [cited by applicant]
US 10523540B2 · Joshi · 2019 [cited by applicant]
US 10523914B1 · Phillips et al. · 2019 [cited by applicant]
US 10659432B2 · Meyer et al. · 2020 [cited by applicant]
US 10673880B1 · Pratt et al. · 2020 [cited by applicant]
US 10749557B1 · Griffin et al. · 2020 [cited by applicant]
US 10951606B1 · Shahidzadeh et al. · 2021 [cited by applicant]
US RE48656E · Goldner et al. · 2021 [cited by applicant]
US 11132461B2 · Swafford · 2021 [cited by applicant]
US 11277416B2 · Ray et al. · 2022 [cited by applicant]
US 11303651B1 · Mouleeswaran et al. · 2022 [cited by applicant]
US 11336698B1 · Wu · 2022 [cited by applicant]
US 11410420B1 · Roy et al. · 2022 [cited by applicant]
US 11563756B2 · Diehl · 2023 [cited by applicant]
US 11721137B2 · Fang · 2023 [cited by applicant]
US 11829371B1 · Buxton, Jr. · 2023 [cited by applicant]
US 20020055820A1 · Scannell · 2002 [cited by applicant]
US 20020078381A1 · Farley · 2002 [cited by applicant]
US 20020156879A1 · Delany · 2002 [cited by applicant]
US 20030200293A1 · Fearn et al. · 2003 [cited by applicant]
US 20040002961A1 · Dettinger et al. · 2004 [cited by applicant]
US 20040205397A1 · Rajiv et al. · 2004 [cited by applicant]
US 20040205398A1 · Osborn et al. · 2004 [cited by applicant]
US 20050086064A1 · Dively, II et al. · 2005 [cited by applicant]
US 20050198247A1 · Perry · 2005 [cited by applicant]
US 20050262233A1 · Alon · 2005 [cited by applicant]
US 20060031076A1 · Lei et al. · 2006 [cited by applicant]
US 20060064486A1 · Baron et al. · 2006 [cited by applicant]
US 20060294214A1 · Chou · 2006 [cited by applicant]
US 20070179709A1 · Doyle · 2007 [cited by applicant]
US 20070192080A1 · Carpenter · 2007 [cited by examiner]
US 20070226796A1 · Gilbert et al. · 2007 [cited by applicant]
US 20080080384A1 · Atkins et al. · 2008 [cited by applicant]
US 20080126951A1 · Sood et al. · 2008 [cited by applicant]
US 20080162565A1 · Waguet · 2008 [cited by examiner]
US 20090064189A1 · Cutlip · 2009 [cited by examiner]
US 20100030896A1 · Chandramouli et al. · 2010 [cited by applicant]
US 20100250111A1 · Gutierrez et al. · 2010 [cited by applicant]
US 20110022444A1 · Fridman et al. · 2011 [cited by applicant]
US 20110099632A1 · Beck et al. · 2011 [cited by applicant]
US 20110181443A1 · Gutierrez et al. · 2011 [cited by applicant]
US 20110299597A1 · Freiburg et al. · 2011 [cited by applicant]
US 20120079092A1 · Woxblom · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120166688A1 · Schoning · 2012 [cited by examiner]
US 20130021933A1 · Kovvali et al. · 2013 [cited by applicant]
US 20130290110A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130290339A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130290905A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130333040A1 · Diehl et al. · 2013 [cited by applicant]
US 20140075004A1 · Van Dusen · 2014 [cited by applicant]
US 20140085107A1 · Gutierrez · 2014 [cited by applicant]
US 20140201836A1 · Amsler · 2014 [cited by applicant]
US 20140283067A1 · Call · 2014 [cited by applicant]
US 20150227582A1 · Gu et al. · 2015 [cited by applicant]
US 20150358790A1 · Nasserbakht · 2015 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160163172A1 · Hosomi · 2016 [cited by examiner]
US 20160163186A1 · Davidson et al. · 2016 [cited by applicant]
US 20160179618A1 · Resch et al. · 2016 [cited by applicant]
US 20160191351A1 · Smith et al. · 2016 [cited by applicant]
US 20160210427A1 · Mynhier et al. · 2016 [cited by applicant]
US 20160246929A1 · Zenati et al. · 2016 [cited by applicant]
US 20160321574A1 · Peterson · 2016 [cited by applicant]
US 20160373588A1 · Raleigh et al. · 2016 [cited by applicant]
US 20170012854A1 · Balasubramanian · 2017 [cited by applicant]
US 20170078316A1 · Liang et al. · 2017 [cited by applicant]
US 20170109530A1 · Diehl · 2017 [cited by examiner]
US 20170155683A1 · Singla · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170230410A1 · Hassanzadeh · 2017 [cited by applicant]
US 20170235848A1 · Van Dusen et al. · 2017 [cited by applicant]
US 20170264589A1 · Hunt et al. · 2017 [cited by applicant]
US 20180004943A1 · Lukacs · 2018 [cited by applicant]
US 20180013768A1 · Hunt et al. · 2018 [cited by applicant]
US 20180024901A1 · Tankersley et al. · 2018 [cited by applicant]
US 20180060926A1 · Guadagno · 2018 [cited by applicant]
US 20180069875A1 · Ben Ezra et al. · 2018 [cited by applicant]
US 20180091559A1 · Luger · 2018 [cited by applicant]
US 20180173580A1 · Pavlas et al. · 2018 [cited by applicant]
US 20180234434A1 · Viljoen · 2018 [cited by applicant]
US 20180260251A1 · Beveridge et al. · 2018 [cited by applicant]
US 20180278647A1 · Gabaev et al. · 2018 [cited by applicant]
US 20180285873A1 · Espinoza et al. · 2018 [cited by applicant]
US 20180308112A1 · Prentice et al. · 2018 [cited by applicant]
US 20180329958A1 · Choudhury et al. · 2018 [cited by applicant]
US 20180332063A1 · Ford · 2018 [cited by applicant]
US 20180367549A1 · Jang et al. · 2018 [cited by applicant]
US 20190014141A1 · Segal et al. · 2019 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20190108470A1 · Jain · 2019 [cited by applicant]
US 20190110241A1 · Jain · 2019 [cited by applicant]
US 20190121979A1 · Chari et al. · 2019 [cited by applicant]
US 20190130512A1 · Kuhn · 2019 [cited by applicant]
US 20190158513A1 · Shtar · 2019 [cited by applicant]
US 20190164168A1 · Sundaramoorthy et al. · 2019 [cited by applicant]
US 20190166152A1 · Steele et al. · 2019 [cited by applicant]
US 20190182269A1 · Lee et al. · 2019 [cited by applicant]
US 20190190945A1 · Jang et al. · 2019 [cited by applicant]
US 20190190952A1 · Cherry · 2019 [cited by applicant]
US 20190222594A1 · Davis, III et al. · 2019 [cited by applicant]
US 20190229915A1 · Digiambattista et al. · 2019 [cited by applicant]
US 20190253431A1 · Atanda · 2019 [cited by applicant]
US 20190260879A1 · Raleigh et al. · 2019 [cited by applicant]
US 20190287004A1 · Bhoj et al. · 2019 [cited by applicant]
US 20190340912A1 · Sellathamby et al. · 2019 [cited by applicant]
US 20190349204A1 · Enke et al. · 2019 [cited by applicant]
US 20190370146A1 · Babu et al. · 2019 [cited by applicant]
US 20200012239A1 · Yamamoto · 2020 [cited by applicant]
US 20200036603A1 · Nieves · 2020 [cited by applicant]
US 20200057953A1 · Livny et al. · 2020 [cited by applicant]
US 20200135311A1 · Mairs · 2020 [cited by applicant]
US 20200145449A1 · Segal et al. · 2020 [cited by applicant]
US 20200193018A1 · Van Dyke · 2020 [cited by applicant]
US 20200220754A1 · Hunter et al. · 2020 [cited by applicant]
US 20200244680A1 · Brandel et al. · 2020 [cited by applicant]
US 20200259852A1 · Wolff et al. · 2020 [cited by applicant]
US 20200274894A1 · Argoeti et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200296124A1 · Pratt et al. · 2020 [cited by applicant]
US 20200321122A1 · Neumann · 2020 [cited by applicant]
US 20200371512A1 · Srinivasamurthy et al. · 2020 [cited by applicant]
US 20210042408A1 · Van Dyke et al. · 2021 [cited by applicant]
US 20210042854A1 · Hazy et al. · 2021 [cited by applicant]
US 20210055927A1 · Sarukkai et al. · 2021 [cited by applicant]
US 20210075686A1 · Smith et al. · 2021 [cited by applicant]
US 20210081539A1 · Karin et al. · 2021 [cited by applicant]
US 20210083891A1 · Anchondo · 2021 [cited by applicant]
US 20210117251A1 · Cristofi et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210211438A1 · Trim et al. · 2021 [cited by applicant]
US 20210248443A1 · Shu et al. · 2021 [cited by applicant]
US 20210266333A1 · Wright et al. · 2021 [cited by applicant]
US 20210288981A1 · Numainville et al. · 2021 [cited by applicant]
US 20210326452A1 · Diehl et al. · 2021 [cited by applicant]
US 20210326453A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329012A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329013A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329014A1 · Diehl et al. · 2021 [cited by applicant]
US 20210334369A1 · Keiter et al. · 2021 [cited by applicant]
US 20210352099A1 · Rogers · 2021 [cited by applicant]
US 20210406041A1 · Saraiya et al. · 2021 [cited by applicant]
US 20220012148A1 · Plum et al. · 2022 [cited by applicant]
US 20220067957A1 · Majumder · 2022 [cited by applicant]
US 20220136857A1 · Pompili et al. · 2022 [cited by applicant]
US 20220197306A1 · Cella · 2022 [cited by applicant]
US 20220222686A1 · Mihara · 2022 [cited by applicant]
US 20220224723A1 · Crabtree · 2022 [cited by applicant]
US 20220374434A1 · Nash · 2022 [cited by applicant]
US 20230046839A1 · Raleigh · 2023 [cited by applicant]
US 20230164151A1 · Diehl · 2023 [cited by applicant]
US 20230328076A1 · Diehl · 2023 [cited by applicant]
US 20230328082A1 · Diehl · 2023 [cited by applicant]
CN 105550189A · 2016 [cited by applicant]
EP 3896934 · 2021 [cited by applicant]
WO WO2013184281A1 · 2013 [cited by applicant]
WO WO2016049319A1 · 2016 [cited by applicant]
Office Action for U.S. Appl. No. 18/116,629, mailed on Sep. 14, 2023, Diehl, “Distributed Digital Security System” 10 pages. [cited by applicant]
Coppolino, et al, “A framework for mastering heterogeneity in multi-layer security information and event correlation”, Journal of Systems Architecture, vol. 62, Dec. 2, 2015, pp. 78-88. [cited by applicant]
The Extended European Search Report mailed Aug. 19, 2021 for European Patent Application No. 21164747.4, 9 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 24, 2021 for European Patent Application No. 21164749.0, 9 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 27, 2021 for European Patent Application No. 21164750.8, 8 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 31, 2021 for European Patent Application No. 21164751.6, 8 pages. [cited by applicant]
Extended European Search Report mailed Sep. 6, 2021 for European Patent Application No. 21164753.2, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,496, mailed on Sep. 30, 2022, Diehl, “Distributed Digital Security System”, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,411, mailed on Oct. 6, 2021, Diehl, “Distributed Digital Security System”, 9 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,579, mailed on Nov. 14, 2022, Diehl, “Distributed Digital Security System”, 23 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,496, mailed on Dec. 24, 2021, Diehl, “Distributed Digital Security System”, 8 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,543, mailed on Feb. 16, 2022, Diehl, “Distributed Digital Security System”, 29 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,579, mailed Apr. 26, 2022, Diehl, “Distributed Digital Security System”, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/325,097, mailed on Jun. 7, 2022, Nash, “Real-Time Streaming Graph Queries”, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,543, mailed on Aug. 26, 2022, Diehl, “Distributed Digital Security System”, 32 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/094,303, mailed on Dec. 7, 2023, Diehl, “Distributed Digital Security System”, 7 Pages. [cited by applicant]