IP Library Granted Patent US 12,425,438
Granted Patent B1
US 12,425,438 · App. 18/137,719 · Granted Sep 23, 2025

Threat activity statistical analysis driven adaptation of a control specification

Inventors: Bryan Cline (Frisco, TX); Jeremy Huval (Celina, TX); Andrew Russell (Plano, TX)
Assignee: HITRUST Services Corp.
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,438
App. No.
18/137,719
Granted
Sep 23, 2025
Kind
B1
Abstract

Threat activity statistical analysis driven adaptive control specification includes retrieving a data structure from over a computer communications network into memory of a computing device and parsing the data structure in the memory to extract a listing of different threat activities. Threat activity statistical analysis driven adaptive control specification also includes computing in the memory a statistical analysis of the different threat activities. Finally, threat activity statistical analysis driven adaptive control specification includes responding to the statistical analysis surpassing a threshold for an identified one of the different threat activities by determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address changes in the corresponding threat.

Claims (26)

1. A method for threat activity statistical analysis driven adaptive control specification comprising:

retrieving a data structure from over a computer communications network into memory of a computing device;

parsing the data structure in the memory to extract a listing of different threat activities;

computing in the memory a statistical analysis of the different threat activities; and,

responsive to the statistical analysis surpassing a threshold for an identified one of the different threat activities, determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address the corresponding threat, wherein the statistical analysis is an extrapolation of frequency at a future moment based upon a set of previously computed frequencies at previous moments, and the threshold is a threshold frequency of occurrence of the identified one of the different threat activities at the future moment.

2. The method of claim 1 , wherein the modification to the control specification is an addition of a new control.

3. The method of claim 1 , wherein the modification to the control specification is a removal of an existing control.

4. The method of claim 1 , wherein the modification to the control specification is a change to a parameter of an existing control.

5. A data processing system adapted for threat activity statistical analysis driven adaptive control specification, the system comprising:

a host computing platform comprising one or more computers, each with memory and one or more processing units including one or more processing cores; and,

a control specification module comprising computer program instructions enabled while executing in the memory of at least one of the processing units of the host computing platform to perform:

retrieving a data structure from over a computer communications network into the memory of the host computing platform;

parsing the data structure in the memory to extract a listing of different threat activities;

computing in the memory by the one or more processing units a statistical analysis of the different threat activities; and,

responsive to the statistical analysis surpassing a threshold for an identified one of the different threat activities, determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address the corresponding threat, wherein the statistical analysis is an extrapolation of frequency at a future moment based upon a set of previously computed frequencies at previous moments, and the threshold is a threshold frequency of occurrence of the identified one of the different threat activities at the future moment.

6. The system of claim 5 , wherein the modification to the control specification is an addition of a new control.

7. The system of claim 5 , wherein the modification to the control specification is a removal of an existing control.

8. The system of claim 5 , wherein the modification to the control specification is a change to a parameter of an existing control.

9. A computing device comprising a non-transitory computer readable storage medium having program instructions stored therein, the instructions being executable by at least one processing core of a processing unit to cause the processing unit to perform a method for threat activity statistical analysis driven adaptive control specification, the method including:

retrieving a data structure from over a computer communications network into memory of a computing device;

parsing the data structure in the memory to extract a listing of different threat activities;

computing in the memory a statistical analysis of the different threat activities; and,

responsive to the statistical analysis surpassing a threshold for an identified one of the different threat activities, determining a corresponding threat incorporating the identified one of the different threat activities in an associated kill chain, retrieving a control specification addressing the corresponding threat, and modifying the control specification to address the corresponding threat, wherein the statistical analysis is an extrapolation of frequency at a future moment based upon a set of previously computed frequencies at previous moments, and the threshold is a threshold frequency of occurrence of the identified one of the different threat activities at the future moment.

10. The device of claim 9 , wherein the modification to the control specification is an addition of a new control.

11. The device of claim 9 , wherein the modification to the control specification is a removal of an existing control.

12. The device of claim 9 , wherein the modification to the control specification is a change to a parameter of an existing control.

Assignments (3)
SECURITY INTEREST Recorded Mar 17, 2025
From: HITRUST SERVICES LLC
To: AB PRIVATE CREDIT INVESTORS LLC
Reel/Frame 070527/0008 →
ENTITY CONVERSION Recorded Mar 14, 2025
From: HITRUST SERVICES CORP.
To: HITRUST SERVICES LLC
Reel/Frame 070519/0219 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2023
From: CLINE, BRYAN; HUVAL, JEREMY; RUSSELL, ANDREW
To: HITRUST SERVICES CORP.
Reel/Frame 063403/0383 →
References Cited (25)
US 10778703B2 · Muddu · 2020 [cited by examiner]
US 20080115221A1 · Yun · 2008 [cited by examiner]
US 20150180891A1 · Seward · 2015 [cited by examiner]
US 20170091462A1 · Kurauchi · 2017 [cited by examiner]
US 20180039922A1 · King-Wilson · 2018 [cited by examiner]
US 20200314141A1 · Vajipayajula · 2020 [cited by examiner]
US 20210224385A1 · Ross · 2021 [cited by examiner]
US 20210360015A1 · Mammadli · 2021 [cited by examiner]
US 20220006818A1 · Cunningham · 2022 [cited by examiner]
US 20230344860A1 · Agranonik · 2023 [cited by examiner]
US 20240223596A1 · Sellars · 2024 [cited by examiner]
CN 111131285A · 2020 [cited by examiner]
CN 112543201A · 2021 [cited by examiner]
CN 116155548A · 2023 [cited by examiner]
CN 117938698A · 2024 [cited by examiner]
CN 118264481A · 2024 [cited by examiner]
CN 118573594A · 2024 [cited by examiner]
CN 118972163A · 2024 [cited by examiner]
CN 119172110A · 2024 [cited by examiner]
CN 119232497A · 2024 [cited by examiner]
GB 2628924A · 2024 [cited by examiner]
KR 100942456B1 · 2010 [cited by examiner]
WO WO2010136787A1 · 2010 [cited by examiner]
WO WO2020249572A1 · 2020 [cited by examiner]
WO WO2022023671A1 · 2022 [cited by examiner]