IP Library Granted Patent US 12,694,146
Granted Patent B2
US 12,694,146 · App. 18/910,112 · Granted Jul 28, 2026

Multi-modal queries in a digital cybersecurity systems

Inventors: Timothy Jason Berger (Eastvale, CA); Marcus Andrew King (Louisville, KY); Thomas Francis Lyons (Irvine, CA); Brent Ryan Nash (Irvine, CA); James Robert Plush (Coto De Caza, CA)
Assignee: CrowdStrike, Inc.
G06F21/6218G06F16/2455
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,694,146
App. No.
18/910,112
Granted
Jul 28, 2026
Kind
B2
Abstract

Multi-modal query processing greatly improves computer functioning. A single cybersecurity sensory nodal server concurrently processes standing queries, agent point queries, and agent fleet queries. The single cybersecurity sensory nodal server is dedicated to locally storing electronic data associated with a cybersecurity sensory agent installed at a client device. Because the single cybersecurity sensory nodal server locally stores the single source of the electronic data, the single cybersecurity sensory nodal server answers the standing queries, agent point queries, and agent fleet queries using less hardware resources, less network resources, less electrical energy, and less time.

Claims (39)

1 . A computer-implemented method, comprising:

receiving, by a compute engine located in a security network and executing remotely from one or more client computing devices coupled in communication with the security network, an event stream comprising event data associated with an occurrence of one or more events on the one or more client computing devices;

generating, by the compute engine, new event data based on the event data in the event stream;

receiving, by a predictions engine located in the security network and executing remotely from the one or more client computing devices, the new event data;

selecting, by the predictions engine, one or more of a plurality of machine learning models to which to apply at least a portion of the received new event data, based on contextual information associated with, or content of, the received new event data;

applying, by the predictions engine, the at least the portion of the received new event data to the selected one or more of a plurality of machine learning models;

generating, by the selected one or more of the plurality of machine learning models, a prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents one or more target behaviors, responsive to the applying, by the predictions engine, of the at least the portion of the received new event data to the selected one or more of the plurality of machine learning models.

2 . The computer-implemented method of claim 1 , further comprising receiving, by the compute engine from a compiler of the security network, a configuration that includes a compiled set of executable instructions for processing the event data associated with occurrences of one or more events on or by the one or more client computing devices.

3 . The computer-implemented method of claim 1 , wherein generating, by the compute engine, the new event data based on the event data in the event stream comprises generating, by the compute engine, a context collection comprising the new event data associated with a context collection format based on the event data in the event stream.

4 . The computer-implemented method of claim 3 , wherein receiving, by the predictions engine located in the security network and executing remotely from the one or more client computing devices, the new event data comprises receiving, by the predictions engine located in the security network and executing remotely from the one or more client computing devices, the context collection comprising the new event data.

5 . The computer-implemented method of claim 4 , wherein

selecting, by the predictions engine, the one or more of a plurality of machine learning models to which to apply the at least the portion of the received new event data based on the contextual information associated with the received new event data, comprises selecting, by the predictions engine, the one or more of the plurality of machine learning models to which to apply the at least the portion of the received new event data based on the context collection comprising the received new event data.

6 . The computer-implemented method of claim 5 , wherein generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying, by the predictions engine, the at least the portion of the received new event data to the selected one or more of the plurality of machine learning models comprises generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying, by the predictions engine, the at least the portion of the received new event data in the received context collection to the selected one or more of the plurality of machine learning models.

7 . The computer-implemented method of claim 1 , wherein generating, by the compute engine, the new event data based on the event data in the event stream, comprises generating, by the compute engine using at least one of one or more query operations, one or more refinement operations, or one or more composition operations, the new event data based on the event data in the event stream.

8 . The computer-implemented method of claim 1 , wherein generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors comprises generating a confidence score associated with the prediction result.

9 . The computer-implemented method of claim 1 , further comprising transmitting, by the security network, the prediction result to the one or more client computing devices.

10 . The computer-implemented method of claim 9 , wherein transmitting, by the security network, the prediction result to one or more of the plurality of client computing devices comprises transmitting, by the security network, the prediction result to one or more of the plurality of client computing devices responsive to the prediction result indicating that the occurrence of the one or more events from which the new event data is generated represents the one or more target behaviors.

11 . The computer-implemented method of claim 1 , further comprising generating behavior detection logic, by the one or more client computing devices, for the one or more client computing devices to execute, responsive to receiving, from the security network, the prediction result.

12 . A computer system located in a security network, comprising:

one or more processors executing remotely from one or more client computing devices coupled in communication with the security network;

memory storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving an event stream comprising event data associated with an occurrence of one or more events on the one or more client computing devices;

generating new event data based on the event data in the event stream;

selecting one or more of a plurality of machine learning models to which to apply at least a portion of the new event data, based on contextual information associated with, or content of, the new event data;

applying the at least the portion of the new event data to the selected one or more of a plurality of machine learning models;

generating, by the selected one or more of the plurality of machine learning models of the security network, a prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents one or more target behaviors, responsive to the applying the at least the portion of the new event data to the selected one or more of the plurality of machine learning models.

13 . The computer system of claim 12 , wherein generating the new event data based on the event data in the event stream comprises generating a context collection comprising the new event data associated with a context collection format based on the event data in the event stream.

14 . The computer system of claim 13 , wherein selecting the one or more of a plurality of machine learning models to which to apply the at least the portion of the new event data based on the contextual information associated with the new event data, comprises selecting the one or more of the plurality of machine learning models to which to apply the at least the portion of the new event data based on the context collection comprising the new event data.

15 . The computer system of claim 14 , wherein generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying the at least the portion of the new event data to the selected one or more of the plurality of machine learning models comprises generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying the at least the portion of the new event data in the context collection to the selected one or more of the plurality of machine learning models.

16 . The computer system of claim 12 , wherein generating the new event data based on the event data in the event stream, comprises generating through at least one of one or more query operations, one or more refinement operations, or one or more composition operations, the new event data based on the event data in the event stream.

17 . One or more non-transitory computer-readable media storing computer-executable instructions for one or more computing elements located in a security network remotely from one or more client computing devices coupled in communication with the security network that, when executed by one or more processors of the one or more computing elements, cause the one or more computing elements to perform operations comprising:

receiving an event stream comprising event data associated with an occurrence of one or more events on one or more client computing devices;

generating new event data based on the event data in the event stream;

selecting one or more of a plurality of machine learning models to which to apply at least a portion of the new event data, based on contextual information associated with, or content of, the new event data;

applying the at least the portion of the new event data to the selected one or more of a plurality of machine learning models;

generating, by the selected one or more of the plurality of machine learning models, a prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents one or more target behaviors, responsive to the applying the at least the portion of the new event data to the selected one or more of the plurality of machine learning models.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein generating the new event data based on the event data in the event stream comprises generating a context collection comprising the new event data associated with a context collection format based on the event data in the event stream.

19 . The one or more non-transitory computer-readable media of claim 18 , wherein selecting the plurality of machine learning models to which to apply the at least the portion of the new event data based on the contextual information associated with the new event data, comprises selecting the one or more of the plurality of machine learning models to which to apply the at least the portion of the new event data based on the context collection comprising the new event data.

20 . The one or more non-transitory computer-readable media of claim 19 , wherein generating, by the selected one or more of the plurality of machine learning models of the security network, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying the at least the portion of the new event data to the selected one or more of the plurality of machine learning models, comprises generating, by the selected one or more of the plurality of machine learning models, the prediction result that indicates whether the occurrence of the one or more events from which the new event data was generated represents the one or more target behaviors, responsive to the applying the at least the portion of the new event data in the context collection to the selected one or more of the plurality of machine learning models.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: BERGER, TIMOTHY JASON; KING, MARCUS ANDREW; LYONS, THOMAS FRANCIS; NASH, BRENT RYAN; PLUSH, JAMES ROBERT
To: CROWDSTRIKE, INC.
Reel/Frame 068847/0909 →
Continuity (1)
Related Publication 20260099617A1 · Apr 9, 2026
References Cited (301)
US 7146352B2 · Brundage et al. · 2006 [cited by applicant]
US 7840501B1 · Sallam · 2010 [cited by applicant]
US 8779921B1 · Curtiss · 2014 [cited by applicant]
US 9043903B2 · Diehl et al. · 2015 [cited by applicant]
US 9069930B1 · Hart · 2015 [cited by applicant]
US 9202249B1 · Cohen et al. · 2015 [cited by applicant]
US 9386165B2 · Raleigh et al. · 2016 [cited by applicant]
US 9514159B2 · Barsness · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9661003B2 · Parker · 2017 [cited by applicant]
US 9697710B2 · Kuznetsov · 2017 [cited by applicant]
US 9825989B1 · Mehra et al. · 2017 [cited by applicant]
US 10162896B1 · Sumter et al. · 2018 [cited by applicant]
US 10200262B1 · Leverich et al. · 2019 [cited by applicant]
US 10248787B1 · Magar · 2019 [cited by applicant]
US 10320831B2 · Agarmore et al. · 2019 [cited by applicant]
US 10382454B2 · Avidan et al. · 2019 [cited by applicant]
US 10438164B1 · Xiong et al. · 2019 [cited by applicant]
US 10498744B2 · Hunt et al. · 2019 [cited by applicant]
US 10523540B2 · Joshi et al. · 2019 [cited by applicant]
US 10523914B1 · Phillips et al. · 2019 [cited by applicant]
US 10581886B1 · Sharifi Mehr · 2020 [cited by applicant]
US 10623433B1 · Veselov et al. · 2020 [cited by applicant]
US 10659432B2 · Meyer et al. · 2020 [cited by applicant]
US 10673880B1 · Pratt et al. · 2020 [cited by applicant]
US 10749557B1 · Griffin et al. · 2020 [cited by applicant]
US 10951606B1 · Shahidzadeh et al. · 2021 [cited by applicant]
US RE48656E · Goldner et al. · 2021 [cited by applicant]
US 11132461B2 · Swafford et al. · 2021 [cited by applicant]
US 11277416B2 · Ray et al. · 2022 [cited by applicant]
US 11303651B1 · Mouleeswaran et al. · 2022 [cited by applicant]
US 11336698B1 · Wu · 2022 [cited by applicant]
US 11343268B2 · Apostolopoulos · 2022 [cited by applicant]
US 11410420B1 · Roy et al. · 2022 [cited by applicant]
US 11563756B2 · Diehl · 2023 [cited by applicant]
US 11604777B1 · Fritz · 2023 [cited by applicant]
US 11616790B2 · Diehl · 2023 [cited by applicant]
US 11721137B2 · Fang · 2023 [cited by applicant]
US 11829371B1 · Buxton, Jr. · 2023 [cited by applicant]
US 11836137B2 · Nash et al. · 2023 [cited by applicant]
US 11962606B2 · Shulman et al. · 2024 [cited by applicant]
US 11995658B2 · Arcot Omkar · 2024 [cited by applicant]
US 12061714B2 · Das · 2024 [cited by applicant]
US 12314420B2 · Lance et al. · 2025 [cited by applicant]
US 12367667B2 · Ast · 2025 [cited by applicant]
US 12399768B1 · Saha · 2025 [cited by examiner]
US 20020055820A1 · Scannell · 2002 [cited by applicant]
US 20020078381A1 · Farley · 2002 [cited by applicant]
US 20020128897A1 · Nelson · 2002 [cited by applicant]
US 20020156879A1 · Delany · 2002 [cited by applicant]
US 20030200293A1 · Fearn et al. · 2003 [cited by applicant]
US 20040002961A1 · Dettinger et al. · 2004 [cited by applicant]
US 20040205397A1 · Rajiv et al. · 2004 [cited by applicant]
US 20040205398A1 · Osborn et al. · 2004 [cited by applicant]
US 20050086064A1 · Dively, II et al. · 2005 [cited by applicant]
US 20050198247A1 · Perry · 2005 [cited by applicant]
US 20050262233A1 · Alon · 2005 [cited by applicant]
US 20060031076A1 · Lei et al. · 2006 [cited by applicant]
US 20060064486A1 · Baron et al. · 2006 [cited by applicant]
US 20060294214A1 · Chou · 2006 [cited by applicant]
US 20070179709A1 · Doyle · 2007 [cited by applicant]
US 20070192080A1 · Carpenter et al. · 2007 [cited by applicant]
US 20070226796A1 · Gilbert et al. · 2007 [cited by applicant]
US 20080038708A1 · Slivka · 2008 [cited by applicant]
US 20080080384A1 · Atkins et al. · 2008 [cited by applicant]
US 20080126951A1 · Sood et al. · 2008 [cited by applicant]
US 20080162565A1 · Waguet · 2008 [cited by applicant]
US 20090064189A1 · Cutlip · 2009 [cited by applicant]
US 20090316675A1 · Malladi · 2009 [cited by applicant]
US 20100030896A1 · Chandramouli et al. · 2010 [cited by applicant]
US 20100094852A1 · Gupta · 2010 [cited by applicant]
US 20100185678A1 · Dettinger · 2010 [cited by applicant]
US 20100250111A1 · Gutierrez et al. · 2010 [cited by applicant]
US 20110022444A1 · Fridman et al. · 2011 [cited by applicant]
US 20110093491A1 · Zabback · 2011 [cited by applicant]
US 20110099632A1 · Beck et al. · 2011 [cited by applicant]
US 20110131588A1 · Allam · 2011 [cited by applicant]
US 20110181443A1 · Gutierrez et al. · 2011 [cited by applicant]
US 20110299597A1 · Freiburg et al. · 2011 [cited by applicant]
US 20120079092A1 · Woxblom · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120166688A1 · Schoning et al. · 2012 [cited by applicant]
US 20120256915A1 · Jenkins · 2012 [cited by applicant]
US 20130007151A1 · Chen et al. · 2013 [cited by applicant]
US 20130021933A1 · Kovvali et al. · 2013 [cited by applicant]
US 20130290110A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130290339A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130290905A1 · LuVogt et al. · 2013 [cited by applicant]
US 20130298244A1 · Kumar et al. · 2013 [cited by applicant]
US 20130332090A1 · Scolnicov et al. · 2013 [cited by applicant]
US 20130333040A1 · Diehl et al. · 2013 [cited by applicant]
US 20140007222A1 · Qureshi et al. · 2014 [cited by applicant]
US 20140032535A1 · Singla · 2014 [cited by applicant]
US 20140075004A1 · Van Dusen · 2014 [cited by applicant]
US 20140085107A1 · Gutierrez · 2014 [cited by applicant]
US 20140201836A1 · Amsler · 2014 [cited by applicant]
US 20140201838A1 · Varsanyi et al. · 2014 [cited by applicant]
US 20140283067A1 · Call · 2014 [cited by applicant]
US 20150227582A1 · Gu et al. · 2015 [cited by applicant]
US 20150358790A1 · Nasserbakht · 2015 [cited by applicant]
US 20160034576A1 · Jiang · 2016 [cited by applicant]
US 20160119365A1 · Barel · 2016 [cited by applicant]
US 20160163172A1 · Hosomi · 2016 [cited by applicant]
US 20160163186A1 · Davidson et al. · 2016 [cited by applicant]
US 20160179618A1 · Resch et al. · 2016 [cited by applicant]
US 20160191351A1 · Smith et al. · 2016 [cited by applicant]
US 20160210427A1 · Mynhier et al. · 2016 [cited by applicant]
US 20160246929A1 · Zenati et al. · 2016 [cited by applicant]
US 20160248803A1 · O'Connell et al. · 2016 [cited by applicant]
US 20160321574A1 · Peterson · 2016 [cited by applicant]
US 20160373588A1 · Raleigh et al. · 2016 [cited by applicant]
US 20170012854A1 · Balasubramanian · 2017 [cited by applicant]
US 20170039245A1 · Wholey, III · 2017 [cited by applicant]
US 20170078316A1 · Liang et al. · 2017 [cited by applicant]
US 20170109530A1 · Diehl et al. · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170235848A1 · Van Dusen et al. · 2017 [cited by applicant]
US 20170244762A1 · Kinder et al. · 2017 [cited by applicant]
US 20170264589A1 · Hunt et al. · 2017 [cited by applicant]
US 20180004817A1 · Nguyen · 2018 [cited by applicant]
US 20180004943A1 · Lukacs · 2018 [cited by applicant]
US 20180013768A1 · Hunt et al. · 2018 [cited by applicant]
US 20180020021A1 · Gilmore et al. · 2018 [cited by applicant]
US 20180024901A1 · Tankersley et al. · 2018 [cited by applicant]
US 20180060926A1 · Guadagno · 2018 [cited by applicant]
US 20180069875A1 · Ben Ezra et al. · 2018 [cited by applicant]
US 20180091559A1 · Luger · 2018 [cited by applicant]
US 20180173580A1 · Pavlas et al. · 2018 [cited by applicant]
US 20180183821A1 · Schneider · 2018 [cited by examiner]
US 20180234434A1 · Viljoen · 2018 [cited by applicant]
US 20180260251A1 · Beveridge et al. · 2018 [cited by applicant]
US 20180278647A1 · Gabaev et al. · 2018 [cited by applicant]
US 20180285873A1 · Espinoza et al. · 2018 [cited by applicant]
US 20180308112A1 · Prentice et al. · 2018 [cited by applicant]
US 20180314740A1 · Van Osten · 2018 [cited by applicant]
US 20180329958A1 · Choudhury · 2018 [cited by applicant]
US 20180367549A1 · Jang et al. · 2018 [cited by applicant]
US 20190014141A1 · Segal et al. · 2019 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20190098032A1 · Murphey · 2019 [cited by applicant]
US 20190108470A1 · Jain · 2019 [cited by applicant]
US 20190110241A1 · Jain · 2019 [cited by applicant]
US 20190121979A1 · Chari et al. · 2019 [cited by applicant]
US 20190130009A1 · McLean · 2019 [cited by applicant]
US 20190130512A1 · Kuhn · 2019 [cited by applicant]
US 20190164168A1 · Sundaramoorthy et al. · 2019 [cited by applicant]
US 20190166152A1 · Steele et al. · 2019 [cited by applicant]
US 20190182267A1 · Aher et al. · 2019 [cited by applicant]
US 20190182269A1 · Lee et al. · 2019 [cited by applicant]
US 20190190945A1 · Jang et al. · 2019 [cited by applicant]
US 20190190952A1 · Cherry · 2019 [cited by applicant]
US 20190222594A1 · Davis, III et al. · 2019 [cited by applicant]
US 20190229915A1 · Digiambattista et al. · 2019 [cited by applicant]
US 20190253431A1 · Atanda · 2019 [cited by applicant]
US 20190260879A1 · Raleigh et al. · 2019 [cited by applicant]
US 20190287004A1 · Bhoj et al. · 2019 [cited by applicant]
US 20190289025A1 · Kursun et al. · 2019 [cited by applicant]
US 20190319987A1 · Levy et al. · 2019 [cited by applicant]
US 20190340912A1 · Sellathamby et al. · 2019 [cited by applicant]
US 20190349204A1 · Enke et al. · 2019 [cited by applicant]
US 20190370146A1 · Babu et al. · 2019 [cited by applicant]
US 20200012239A1 · Yamamoto · 2020 [cited by applicant]
US 20200036603A1 · Nieves et al. · 2020 [cited by applicant]
US 20200057953A1 · Livny et al. · 2020 [cited by applicant]
US 20200067969A1 · Abbaszadeh et al. · 2020 [cited by applicant]
US 20200135311A1 · Mairs · 2020 [cited by applicant]
US 20200145449A1 · Segal et al. · 2020 [cited by applicant]
US 20200193018A1 · Van Dyke · 2020 [cited by applicant]
US 20200220754A1 · Hunter et al. · 2020 [cited by applicant]
US 20200244680A1 · Brandel et al. · 2020 [cited by applicant]
US 20200259852A1 · Wolff et al. · 2020 [cited by applicant]
US 20200274894A1 · Argoeti et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200296124A1 · Pratt et al. · 2020 [cited by applicant]
US 20200314117A1 · Nguyen et al. · 2020 [cited by applicant]
US 20200321122A1 · Neumann · 2020 [cited by applicant]
US 20200371512A1 · Srinivasamurthy et al. · 2020 [cited by applicant]
US 20210042408A1 · Van Dyke et al. · 2021 [cited by applicant]
US 20210042854A1 · Hazy et al. · 2021 [cited by applicant]
US 20210055927A1 · Sarukkai et al. · 2021 [cited by applicant]
US 20210075686A1 · Smith et al. · 2021 [cited by applicant]
US 20210081539A1 · Karin et al. · 2021 [cited by applicant]
US 20210083891A1 · Anchondo · 2021 [cited by applicant]
US 20210117251A1 · Cristofi et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210211438A1 · Trim et al. · 2021 [cited by applicant]
US 20210248443A1 · Shu et al. · 2021 [cited by applicant]
US 20210266333A1 · Wright et al. · 2021 [cited by applicant]
US 20210273957A1 · Boyer et al. · 2021 [cited by applicant]
US 20210288981A1 · Numainville et al. · 2021 [cited by applicant]
US 20210320944A1 · Ogle et al. · 2021 [cited by applicant]
US 20210326452A1 · Diehl et al. · 2021 [cited by applicant]
US 20210326453A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329012A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329013A1 · Diehl et al. · 2021 [cited by applicant]
US 20210329014A1 · Diehl et al. · 2021 [cited by applicant]
US 20210334369A1 · Keiter et al. · 2021 [cited by applicant]
US 20210352099A1 · Rogers · 2021 [cited by applicant]
US 20210406041A1 · Saraiya et al. · 2021 [cited by applicant]
US 20210406368A1 · Agranonik et al. · 2021 [cited by applicant]
US 20220012148A1 · Plum et al. · 2022 [cited by applicant]
US 20220067957A1 · Majumder · 2022 [cited by applicant]
US 20220136857A1 · Pompili et al. · 2022 [cited by applicant]
US 20220210185A1 · Boucadair et al. · 2022 [cited by applicant]
US 20220222686A1 · Mihara · 2022 [cited by applicant]
US 20220374434A1 · Nash et al. · 2022 [cited by applicant]
US 20230046839A1 · Raleigh et al. · 2023 [cited by applicant]
US 20230083443A1 · Saveliev · 2023 [cited by applicant]
US 20230114821A1 · Thomas · 2023 [cited by examiner]
US 20230164151A1 · Diehl et al. · 2023 [cited by applicant]
US 20230229717A1 · Diehl et al. · 2023 [cited by applicant]
US 20230421587A1 · Meyer et al. · 2023 [cited by applicant]
US 20240061844A1 · Nash et al. · 2024 [cited by applicant]
US 20240289481A1 · Lance et al. · 2024 [cited by applicant]
US 20240291835A1 · Sethi · 2024 [cited by examiner]
US 20240305654A1 · Diehl et al. · 2024 [cited by applicant]
CN 105550189A · 2016 [cited by applicant]
CN 107846418A · 2018 [cited by applicant]
EP 3896934A1 · 2021 [cited by applicant]
EP 4092554 · 2022 [cited by applicant]
EP 4296872A1 · 2023 [cited by applicant]
GB 2580467 · 2020 [cited by applicant]
JP WO2015004854A1 · 2015 [cited by applicant]
KR 20230097438 · 2023 [cited by applicant]
WO 2013184281A1 · 2013 [cited by applicant]
WO 2016049319A1 · 2016 [cited by applicant]
Apache Flink, https://flink.apache.org, accessed on or about Aug. 1, 2024. [cited by applicant]
Apache Flink, Introducing Gelly, https://flink.apache.org/2015/08/24/introducing-gelly-graph-processing-with-apache-flink/, accessed on or about Aug. 1, 2024. [cited by applicant]
Apache Flink, Flink Architecture, https://flink.apache.org/what-is-flink/flink-architecture/, accessed on or about Aug. 1, 2024. [cited by applicant]
Apache Flink, Structured Streaming, https://spark.apache.org/docs/latest/structured-streaming-programming-guide.html, accessed on or about Aug. 1, 2024. [cited by applicant]
Apache Flink, Graph X, https://spark.apache.org/graphx/, accessed on or about Aug. 1, 2024. [cited by applicant]
Apache Spark Unified, https://spark.apache.org, accessed on or about Aug. 1, 2024. [cited by applicant]
Zaman, Ahmed Uz, “Introduction to Spark Streaming: Real-Time Data Processing with Ease”, 12 pages, Apr. 30, 2023. [cited by applicant]
Snowflake, “Breaking the Streaming and Batch Silos,” https://www.snowflake.com/en/solutions/use-cases/snowflake-streaming-data-pipelines/, accessed on or about Aug. 1, 2024. [cited by applicant]
“Graph Analytics,” Relational AI, https://docs.relational.ai/preview/snowflake/graph-analytics, accessed on or about Aug. 1, 2024. [cited by applicant]
Snowflake Guides, “Best Practices for Building Database Applications,” https://www.snowflake.com/guides/best-practices-database-applications/#:˜:text=Data%20concurrency,clusters%2C%20eliminating%20slowdowns%20and%20disr… [cited by applicant]
Snowflake Documentation, “Warehouse considerations,” https://docs.snowflake.com/en/user-guide/warehouses-considerations, accessed on or about Aug. 1, 2024. [cited by applicant]
Snowflake Guides, “Real-time Analytics Realizes Data's Potential,” https://www.snowflake.com/guides/real-time-analytics-realizes-datas-potential/, accessed on or about Aug. 1, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/849,537 mailed Jan. 24, 2025, 43 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Jun. 14, 2023, 23 pages. [cited by applicant]
Applicant's Response to the Jun. 14, 2023 Office Action submitted Oct. 16, 2023 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” 17 pages. [cited by applicant]
Applicant's response to the Feb. 2, 2024 Notice of Non-Compliant Amendment submitted Feb. 7, 2024 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security Syste… [cited by applicant]
Final Office Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed May 20, 2024, 26 pages. [cited by applicant]
Applicant's Response to the May 20, 2024 Final Office Action submitted Aug. 14, 2024 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” 19 pages. [cited by applicant]
Advisory Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Sep. 5, 2024, 4 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Oct. 31, 2024, 25 pages. [cited by applicant]
Applicant's Response to the Oct. 31, 2024 Office Action submitted Mar. 27, 2025 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” 35 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Jun. 20, 2025, 29 pages ***********. [cited by applicant]
Applicant's Response to the Jun. 20, 2025 Final Office Action submitted Aug. 18, 2025 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” 18 pages. [cited by applicant]
Advisory Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Sep. 8, 2025, 3 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” mailed Aug. 2, 2024, 52 pages. [cited by applicant]
Applicant's Response to the Aug. 2, 2024 Office Action submitted Oct. 30, 2024 to U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” 17 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” mailed Jan. 24, 2025, 43 pages. [cited by applicant]
Applicant's Response to the Jan. 24, 2025 Final Office Action submitted Apr. 23, 2025 to U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” 18 pages. [cited by applicant]
Advisory Action for U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” mailed May 13, 2025, 4 pages. [cited by applicant]
Applicant's Response to the Jan. 24, 2025 Final Office Action submitted Jun. 20, 2025 to U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/849,537, Meyer, “Distributed Digital Security System for Predicting Malicious Behavior,” mailed Aug. 25, 2025, 56 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” mailed Dec. 12, 2024, 25 pages. [cited by applicant]
Applicant's Response to the Dec. 12, 2024 Office Action submitted Mar. 12, 2025 to U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” 17 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” mailed Jun. 27, 2025, 25 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/115,647, Lance, “Query Management in a Streaming System,” mailed Jan. 29, 2025, 13 pages. [cited by applicant]
Applicant's Response to the Jun. 7, 2022 Office Action submitted Sep. 7, 2022 to U.S. Appl. No. 17/325,097, Nash, “Real-Time Streaming Graph Queries,” 14 pages. [cited by applicant]
Applicant's Response to the Apr. 13, 2023 Final Office Action submitted Jun. 13, 2023 to U.S. Appl. No. 17/325,097, Nash, “Real-Time Streaming Graph Queries,” 18 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/334,260, Diehl, “Distributed Digital Security System,” mailed Aug. 4, 2025, 26 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/663,974, Diehl, “Distributed Digital Security System,” mailed Jul. 15, 2025, 14 pages. [cited by applicant]
Applicant's response to the Jun. 27, 2025 Final Office Action submitted Sep. 26, 2025 to U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” 20 pages. [cited by applicant]
Applicant's response to the Jun. 20, 2025 Final Office Action submitted Sep. 18, 2025 to U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” 23 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/576,734, Diehl, “Optimized Real-Time Streaming Graph Queries in a Distributed Digital Security System,” mailed Oct. 1, 2025, 31 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/663,974, mailed on Nov. 21, 2024, 15 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/849,537, mailed 20240802, 52 pages. [cited by applicant]
Coppolino, et al., “A framework for mastering heterogeneity in multi-layer security information and event correlation”, Journal of Systems Architecture, vol. 62, Dec. 2, 2015, pp. 78-88. [cited by applicant]
The Extended European Search Report mailed Aug. 19, 2021 for European Patent Application No. 21164747.4, 9 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 24, 2021 for European Patent Application No. 21164749.0, 9 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 27, 2021 for European Patent Application No. 21164750.8, 7 pages. [cited by applicant]
The Extended European Search Report mailed Aug. 31, 2021 for European Patent Application No. 21164751.6, 7 pages. [cited by applicant]
The Extended European Search Report mailed Sep. 6, 2021 for European Patent Application No. 21164753.2, 8 pages. [cited by applicant]
Extended European Search Report for EP Patent Application No. 23180786.8, mailed Oct. 23, 2023, 7 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 16/849,543, mailed Aug. 26, 2022, 33 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 16/849,579, mailed on Nov. 14, 2022, Diehl, “Distributed Digital Security System”, 23 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/325,097, mailed Apr. 13, 2023, 22 pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/849,543, mailed Feb. 16, 2022, 30 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/849,543, mailed Jan. 3, 2023, 8 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/325,097, mailed Jul. 26, 2023, 23 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,411, , mailed on Oct. 6, 2021, Diehl, “Distributed Digital Security System”, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,496, mailed on Sep. 30, 2022, Diehl, “Distributed Digital Security System”, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,496, mailed on Dec. 24, 2021, Diehl, “Distributed Digital Security System”, 8 pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,579, mailed Apr. 26, 2022, Diehl, “Distributed Digital Security System”, 20 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/325,097, mailed on Jun. 7, 2022, Nash, “Real-Time Streaming Graph Queries”, 20 pages. [cited by applicant]
Choudhury, Sutanay, et al “StreamWorks—A system for Dynamic Graph Search,” Proceedings of the 2013 ACM SIGMOD International Conference on Management of Data (Jun. 2013) pp. 1101-1104. [cited by applicant]
Pacaci, Anil, et al “Regular Path Query Evaluation on Streaming Graphs,” arXiv:2004.02012v1 [cs.DB] Apr. 4, 2020, 19 pages. [cited by applicant]
Song, Fuqi, et al “Extended Query Pattern Graph and Heuristics—based SPARQL Query Planning,” Procedia Computer Science vol. 60 (2015) pp. 302-311. [cited by applicant]
Extended European Search Report for EP Patent Application No. 22170149.3, mailed Oct. 13, 2022, 9 pages. [cited by applicant]
Amended Claims in EP Patent Application No. 22170149.3, filed May 2, 2023, 36 pages. [cited by applicant]
Intention to Grant for EP Patent Application No. 22170149.3, dated Aug. 26, 2024, 116 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/663,974, dated May 8, 2025, 12 Pages. [cited by applicant]
European Search Report for EP Application No. 22170149, 2 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/116,629, mailed on Sep. 14, 2023, Diehl, “Distributed Digital Security System,” 10 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,543, mailed on Feb. 16, 2022, Diehl, “Distributed Digital Security System,” 29 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 16/849,543, mailed on Aug. 26, 2022, Diehl, “Distributed Digital Security System,” 32 Pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” mailed Nov. 24, 2025, 22 pages. [cited by applicant]
Corrected Notice of Allowance for U.S. Appl. No. 18/496,684, Nash, “Real-Time Streaming Graph Queries,” mailed Dec. 5, 2025, 8 pages. [cited by applicant]