IP Library › Granted Patent US 12,518,042
Granted Patent B2
US 12,518,042 · App. 18/641,329 · Granted Jan 6, 2026

Data breach detection and mitigation

Inventors: Alan James Sharp-Paul (Los Altos, CA); Christopher Robert Vickery (Santa Rosa, CA); Jonathan David Hendren (Mountain View, CA); Gregory Ford Pollock (San Jose, CA); Daniel Bradbury (Sydney, AU); Christian Alan Kiely (Sydney, AU); Gavin Richard Turner (Holgate, AU); Michael Franz Baukes (Hobart, AU)
Assignee: UpGuard, Inc.
G06F21/6218G06F16/22G06F16/24578G06F21/604H04L63/0823H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,042
App. No.
18/641,329
Granted
Jan 6, 2026
Kind
B2
Abstract

A breach detection engine detects and mitigates the effects of breaches across one or more data sources. An index is generated based on one or more data sources and the index is queried using keywords indicative of potential breaches. A database of potential breaches is populated based on the query of the index. The potential breach database is queried using keywords associated with a system identity (e.g., a third party). A likelihood of a candidate breach is identified based on a set of breach criteria weights. A network node associated with a candidate breach determined to be an actual breach is identified for isolation or for the performance of one or more additional security actions.

Claims (44)

1 . A method comprising:

querying, by a computer, one or more data sources using keywords indicative of potential breaches to produce query results;

identifying, by the computer, a candidate breach based at least in part on query results associated with characteristics of a system;

computing, by the computer, a likelihood that the candidate breach is an actual breach based on the query results and one or more security factors including one or more of a sensitivity level associated data, a classification of associated data, a presence of source code, one or more certificate authority keys, one or more API keys, and system credentials; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for mitigation.

2 . The method of claim 1 , wherein each security factor is associated with a query result and corresponds to a correlation between the query result and a breach.

3 . The method of claim 1 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

computing, for each query result of the query results, a breach score;

weighting, for each breach score, the breach score with an associated security factor to produce a weighted breach score; and

summing the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

4 . The method of claim 1 , further comprising:

automatically revoking, by the computer, a password associated with the candidate breach and initiating a process of resetting the password.

5 . The method of claim 1 , further comprising:

automatically identifying, by the computer, a port associated with the candidate breach and blocking the port.

6 . The method of claim 1 , further comprising:

automatically generating, by the computer, a message indicating the computed likelihood and recommending a corresponding corrective action to take and providing the generated message to a client device associated with the system identity.

7 . The method of claim 1 , further comprising:

automatically computing, by the computer, a liability score associated with the system identity based on the computed likelihood and providing the liability score to a client device associated with the system identity.

8 . A non-transitory computer-readable storage medium storing instructions for detecting security breaches, the instructions when executed by a processor cause the processor to perform steps including:

querying, by a computer, one or more data sources using keywords indicative of potential breaches to produce query results;

identifying, by the computer, a candidate breach based at least in part on query results associated with characteristics of a system;

computing, by the computer, a likelihood that the candidate breach is an actual breach based on the query results and one or more security factors including one or more of a sensitivity level associated data, a classification of associated data, a presence of source code, one or more certificate authority keys, one or more API keys, and system credentials; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for mitigation.

9 . The non-transitory computer-readable storage medium of claim 8 , wherein each security factor is associated with a query result of the query results and corresponds to a correlation between the query result and a breach.

10 . The non-transitory computer-readable storage medium of claim 8 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

compute, for each query result of the query results, a breach score;

weight, for each breach score, the breach score with an associated security factor to produce a weighted breach score; and

sum the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

11 . The non-transitory computer-readable storage medium of claim 9 , wherein the instructions when executed further cause the processor to perform steps including:

automatically revoking, by the computer, a password associated with the candidate breach and initiating a process of resetting the password.

12 . A computing system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions for detecting security breaches, the instructions when executed by the processor cause the processor to perform steps including:

querying, by the computing system, one or more data sources using keywords indicative of potential breaches to produce query results;

identifying, by the computing system, a candidate breach based at least in part on query results associated with characteristics of a system;

computing, by the computing system, a likelihood that the candidate breach is an actual breach based on the query results and one or more security factors including one or more of a sensitivity level associated data, a classification of associated data, a presence of source code, one or more certificate authority keys, one or more API keys, and system credentials; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for mitigation.

13 . The computing system of claim 12 , wherein each security factor is associated with a query result of the query results and corresponds to a correlation between the query result and a breach.

14 . The computing system of claim 12 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

compute, for each query result of the query results, a breach score;

weight, for each breach score, the breach score with an associated security factor to produce a weighted breach score; and

sum the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

15 . The computing system of claim 12 , wherein the instructions when executed further cause the processor to perform steps including:

automatically revoking, by the computer, a password associated with the candidate breach and initiating a process of resetting the password.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: SHARP-PAUL, ALAN JAMES; VICKERY, CHRISTOPHER ROBERT; HENDREN, JONATHAN DAVID; POLLOCK, GREGORY FORD; BRADBURY, DANIEL; KIELY, CHRISTIAN ALAN; TURNER, GAVIN RICHARD; BAUKES, MICHAEL FRANZ
To: UPGUARD, INC.
Reel/Frame 068848/0894 →
Continuity (4)
Continuation 18179376 · Mar 7, 2023
Continuation 17231819 · Apr 15, 2021
Continuation 16254605 · Jan 23, 2019
Related Publication 20240273228A1 · Aug 15, 2024
References Cited (15)
US 9032531B1 · Scorvo et al. · 2015 [cited by applicant]
US 10218721B1 · Khanna et al. · 2019 [cited by applicant]
US 10346623B1 · Brandwine · 2019 [cited by examiner]
US 10846431B2 · Mascaro · 2020 [cited by applicant]
US 11023610B2 · Sharp-Paul · 2021 [cited by examiner]
US 11630911B2 · Sharp-Paul · 2023 [cited by examiner]
US 11995206B2 · Sharp-Paul · 2024 [cited by examiner]
US 20150073981A1 · Adjaoute · 2015 [cited by applicant]
US 20150269268A1 · Zhang · 2015 [cited by applicant]
US 20180268135A1 · Nachenberg et al. · 2018 [cited by applicant]
US 20190156030A1 · Coroiu et al. · 2019 [cited by applicant]
US 20190347660A1 · Wilkinson et al. · 2019 [cited by applicant]
US 20200143500A1 · DeBeaune et al. · 2020 [cited by applicant]
United States Office Action, U.S. Appl. No. 17/231,819, filed Oct. 26, 2022, 8 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/179,376, filed Jan. 19, 2024, seven pages. [cited by applicant]