IP Library Granted Patent US 12,739,276
Granted Patent B1
US 12,739,276 · App. 18/804,176 · Granted Sep 15, 2026

Security alert customization using local compute environment characteristics

Inventor: Jeffrey Bruins (Reston, VA)
Assignee: Rapid7, Inc.
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,276
App. No.
18/804,176
Granted
Sep 15, 2026
Kind
B1
Abstract

Various embodiments include systems and methods pertaining to a security service platform that detects security threats based on results from multiple security systems. The multiple security systems may each generate and store respective security alerts within a priority object. The priority object may be used to define rules that are based on results from the multiple security systems, including determining groups of security alerts or determining security alert prioritization based on local compute environment characteristics. The security service platform may use the grouping and prioritization information to provide remediation for an alert that indicates a detected cyberattack.

Claims (60)

1 . A method comprising:

determining, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;

determining, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;

determining, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;

determining, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;

determining, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;

initiating, based on determining the third security alert data, one or more remediation operations;

determining, based on third telemetry data associated with the first compute environment, a fourth security alert; and

determining a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:

determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and

determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.

2 . The method of claim 1 , further comprising:

determining, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and

determining, based on the type of remediation operation, the one or more remediation options.

3 . The method of claim 1 , wherein

the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.

4 . The method of claim 3 , wherein

at least one of the first one or more detection rules is different from at least one of the second one or more detection rules.

5 . The method of claim 1 , wherein

the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.

6 . A system comprising:

a memory storing executable instructions; and

one or more processors that execute the executable instructions to:

determine, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;

determine, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;

determine, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;

determine, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;

determine, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;

initiate, based on determining the third security alert data, one or more remediation operations;

determine, based on third telemetry data associated with the first compute environment, a fourth security alert; and

determine a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:

determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and

determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.

7 . The system of claim 6 , wherein the one or more processors further execute the executable instructions to:

determine, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and

determine, based on the type of remediation operation, the one or more remediation options.

8 . The system of claim 6 , wherein

the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.

9 . The system of claim 8 , wherein

at least one of the first one or more detection rules is different from at least one of the second one or more detection rules.

10 . The system of claim 6 , wherein

the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.

11 . One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause one or more computer systems to:

determine, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;

determine, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;

determine, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;

determine, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;

determine, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;

initiate, based on determining the third security alert data, one or more remediation operations;

determine, based on third telemetry data associated with the first compute environment, a fourth security alert; and

determine a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:

determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and

determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.

12 . The one or more non-transitory computer-accessible storage media of claim 11 , wherein the one or more processors, further cause one or more computer systems to:

determine, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and

determine, based on the type of remediation operation, the one or more remediation options.

13 . The one or more non-transitory computer-accessible storage media of claim 11 , wherein

the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.

14 . The one or more non-transitory computer-accessible storage media of claim 13 , wherein

the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2024
From: BRUINS, JEFFREY
To: RAPID7, INC.
Reel/Frame 068341/0211 →
References Cited (65)
US 8468599B2 · McCusker et al. · 2013 [cited by applicant]
US 9646228B2 · Appel et al. · 2017 [cited by applicant]
US 9876815B2 · Sultan et al. · 2018 [cited by applicant]
US 10027711B2 · Gill et al. · 2018 [cited by applicant]
US 10178109B1 · Miskovic · 2019 [cited by examiner]
US 10250619B1 · Park et al. · 2019 [cited by applicant]
US 10805326B1 · Wang et al. · 2020 [cited by applicant]
US 10862914B1 · Mezic et al. · 2020 [cited by applicant]
US 10873596B1 · Bourget · 2020 [cited by examiner]
US 11411966B2 · Muddu et al. · 2022 [cited by applicant]
US 11876809B2 · Merza · 2024 [cited by applicant]
US 11902120B2 · Prasad et al. · 2024 [cited by applicant]
US 11956253B1 · Lin · 2024 [cited by examiner]
US 11962622B2 · Kung et al. · 2024 [cited by applicant]
US 12301614B1 · Payne · 2025 [cited by examiner]
US 12341797B1 · Adamson · 2025 [cited by examiner]
US 20030172167A1 · Judge · 2003 [cited by examiner]
US 20080189788A1 · Bahl · 2008 [cited by examiner]
US 20090254970A1 · Agarwal · 2009 [cited by examiner]
US 20110078497A1 · Lyne · 2011 [cited by examiner]
US 20120216243A1 · Gill · 2012 [cited by examiner]
US 20140090056A1 · Manadhata · 2014 [cited by examiner]
US 20140325643A1 · Bart · 2014 [cited by examiner]
US 20150271201A1 · Ruvio · 2015 [cited by examiner]
US 20160173513A1 · Rohde · 2016 [cited by examiner]
US 20160301704A1 · Hassanzadeh · 2016 [cited by examiner]
US 20170230410A1 · Hassanzadeh · 2017 [cited by examiner]
US 20180152471A1 · Jakobsson · 2018 [cited by examiner]
US 20180227322A1 · Luo · 2018 [cited by examiner]
US 20180247483A1 · Lindsay · 2018 [cited by applicant]
US 20190306011A1 · Fenoglio · 2019 [cited by examiner]
US 20190379683A1 · Overby · 2019 [cited by examiner]
US 20190379700A1 · Canzanese, Jr. · 2019 [cited by examiner]
US 20200105123A1 · Davies et al. · 2020 [cited by applicant]
US 20200236122A1 · Ott · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20200336506A1 · Levin · 2020 [cited by examiner]
US 20210067442A1 · Sundararajan · 2021 [cited by examiner]
US 20210126938A1 · Trost · 2021 [cited by examiner]
US 20210203673A1 · dos Santos · 2021 [cited by examiner]
US 20210211452A1 · Patel · 2021 [cited by examiner]
US 20210349994A1 · Ravindra · 2021 [cited by examiner]
US 20220222350A1 · Franzen · 2022 [cited by examiner]
US 20220318625A1 · O'Toole · 2022 [cited by examiner]
US 20220342988A1 · Brunza · 2022 [cited by examiner]
US 20230064153A1 · Kulandaivel · 2023 [cited by examiner]
US 20230216869A1 · Howard · 2023 [cited by examiner]
US 20230275912A1 · Shahul · 2023 [cited by examiner]
US 20230336586A1 · Sopan · 2023 [cited by examiner]
US 20230362184A1 · Gelman · 2023 [cited by examiner]
US 20230396638A1 · Hebbagodi · 2023 [cited by examiner]
US 20240056462A1 · Hathaway · 2024 [cited by examiner]
US 20240297904A1 · Bertiger · 2024 [cited by examiner]
US 20240356943A1 · Kopp · 2024 [cited by examiner]
US 20240362461A1 · Jain · 2024 [cited by examiner]
US 20240430285A1 · Almadi · 2024 [cited by examiner]
US 20250047693A1 · Kolosnjaji · 2025 [cited by examiner]
US 20250088517A1 · Davraev · 2025 [cited by examiner]
US 20250097253A1 · Huang · 2025 [cited by examiner]
US 20250131084A1 · Mo · 2025 [cited by examiner]
US 20250133093A1 · Oliver · 2025 [cited by examiner]
US 20250141896A1 · Thomas · 2025 [cited by examiner]
US 20250173434A1 · Yaron · 2025 [cited by examiner]
US 20250254208A1 · Rose · 2025 [cited by examiner]
US 20250280067A1 · Phatak · 2025 [cited by examiner]