IP Library › Granted Patent US 12,743,516
Granted Patent B2
US 12,743,516 · App. 18/955,459 · Granted Sep 22, 2026

Threat mitigation system and method

Inventors: Brian P. Murphy (Tampa, FL); Joe Partlow (Tampa, FL); Colin O'Connor (Tampa, FL); Jason Pfeiffer (Tampa, FL); Brian Philip Murphy (St. Petersburg, FL)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/566H04L63/1416H04L63/1441H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,516
App. No.
18/955,459
Granted
Sep 22, 2026
Kind
B2
Abstract

A computer-implemented method, computer program product and computing system for receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform; identifying two or more associated detection events included within the plurality of detection events; and grouping the two or more associated detection events to define a security incident.

Claims (142)

1 . A computer-implemented method, executed on a computing device, comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform;

identifying two or more associated detection events included within the plurality of detection events;

grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein the normalizing the plurality of detection events into a common ontology includes: translating a syntax of each of the plurality of detection events into a common syntax; and

translating the common syntax of a unified query to a syntax of each of plurality of subsystem-specific queries and each of the plurality of subsystem-specific queries has a specific structure and nomenclature;

distributing each of the plurality of subsystem-specific queries to the security relevant systems;

executing each of the plurality of subsystem-specific queries generates respective subsystem-specific result sets;

aggregating and combining, by a threat mitigation process, the respective subsystem-specific result sets to homogenize and produce a unified result set;

effectuating one or more remedial operations using the unified result set and based on an assigned threat level.

2 . The computer-implemented method of claim 1 wherein the plurality of security events includes one or more of:

Denial of Service (DoS) events;

Distributed Denial of Service DDoS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

3 . The computer-implemented method of claim 1 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

4 . The computer-implemented method of claim 1 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

5 . The computer-implemented method of claim 4 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

6 . The computer-implemented method of claim 4 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

7 . The computer-implemented method of claim 1 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

8 . The computer-implemented method of claim 1 wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem.

9 . A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform;

identifying two or more associated detection events included within the plurality of detection events; grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein normalizing the plurality of detection events into a common ontology includes: translating a syntax of each of the plurality of detection events into a common syntax; and

translating the common syntax of a unified query to a syntax of each of plurality of subsystem-specific queries and each of the plurality of subsystem-specific queries has a specific structure and nomenclature;

distributing each of the plurality of subsystem-specific queries to the security relevant systems;

executing each of the plurality of subsystem-specific queries generates respective subsystem-specific result sets;

aggregating and combining, by a threat mitigation process, the respective subsystem-specific result sets to homogenize and produce a unified result set;

effectuating one or more remedial operations using the unified result set and based on an assigned threat level.

10 . The computer program product of claim 9 wherein the plurality of security events includes one or more of:

Denial of Service (DoS) events;

Distributed Denial of Service DDoS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

11 . The computer program product of claim 9 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

12 . The computer program product of claim 9 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

13 . The computer program product of claim 12 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

14 . The computer program product of claim 12 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

15 . The computer program product of claim 9 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

16 . The computer program product of claim 9 wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem.

17 . A computing system including a processor and memory configured to perform operations comprising:

receiving a plurality of detection events concerning a plurality of security events occurring on a security-relevant subsystem within a computing platform;

identifying two or more associated detection events included within the plurality of detection events; grouping the two or more associated detection events to define a security incident;

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events;

normalizing the plurality of detection events into a common ontology, wherein normalizing the plurality of detection events into a common ontology includes: translating a syntax of each of the plurality of detection events into a common syntax; and

translating the common syntax of a unified query to a syntax of each of plurality of subsystem-specific queries and each of the plurality of subsystem-specific queries has a specific structure and nomenclature;

distributing each of the plurality of subsystem-specific queries to the security relevant systems;

executing each of the plurality of subsystem-specific queries generates respective subsystem-specific result sets;

aggregating and combining, by a threat mitigation process, the respective subsystem-specific result sets to homogenize and produce a unified result set;

effectuating one or more remedial operations using the unified result set and based on an assigned threat level.

18 . The computing system of claim 17 wherein the plurality of security events includes one or more of:

Denial of Service (DoS) events;

Distributed Denial of Service DDoS events;

Man-in-the-Middle (MitM) events;

phishing events;

Password Attack events;

SQL Injection events;

Cross-Site Scripting (XSS) events;

Insider Threat events;

spamming events;

malware events;

web attacks; and

exploitation events.

19 . The computing system of claim 17 wherein the security-relevant subsystem includes one or more of:

CDN (i.e., Content Delivery Network) systems;

DAM (i.e., Database Activity Monitoring) systems;

UBA (i.e., User Behavior Analytics) systems;

MDM (i.e., Mobile Device Management) systems;

IAM (i.e., Identity and Access Management) systems;

DNS (i.e., Domain Name Server) systems;

Antivirus systems;

operating systems;

data lakes;

data logs;

security-relevant software applications;

security-relevant hardware systems; and

resources external to the computing platform.

20 . The computing system of claim 17 wherein one or more artifacts/log entries are associated with each of the plurality of detection events.

21 . The computing system of claim 20 wherein identifying two or more associated detection events included within the plurality of detection events includes:

identifying two or more detection events included within the plurality of detection events that have common artifacts/log entries.

22 . The computing system of claim 20 wherein grouping the two or more associated detection events into a security incident includes:

grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.

23 . The computing system of claim 17 further comprising:

receiving one or more additional detection events concerning one or more additional security events occurring on the security-relevant subsystem within the computing platform; and

adding the one or more additional detection events to the security incident if the one or more additional detection events are related to the two or more associated detection events.

24 . The computing system of claim 17 wherein the plurality of security events are detected on the security-relevant subsystem using one or more detection rules executed on the security-relevant subsystem.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2025
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 069716/0579 →
Continuity (3)
Continuation 18130152 · Apr 3, 2023
Provisional Application 63326375 · Apr 1, 2022
Related Publication 20260127282A1 · May 7, 2026
References Cited (99)
US 7797419B2 · Bhattacharya · 2010 [cited by examiner]
US 8065722B2 · Barford · 2011 [cited by examiner]
US 9027120B1 · Tidwell · 2015 [cited by examiner]
US 9069954B2 · Anurag · 2015 [cited by examiner]
US 10003605B2 · Muddu et al. · 2018 [cited by applicant]
US 10313379B1 · Han · 2019 [cited by examiner]
US 10574700B1 · Dell'Amico · 2020 [cited by examiner]
US 10728263B1 · Neumann · 2020 [cited by applicant]
US 11258825B1 · Yang · 2022 [cited by examiner]
US 11316887B2 · Murphy et al. · 2022 [cited by applicant]
US 11483337B2 · Murphy et al. · 2022 [cited by applicant]
US 11636213B1 · Elgressy · 2023 [cited by examiner]
US 11652833B2 · Neuvirth · 2023 [cited by examiner]
US 20030188189A1 · Desai · 2003 [cited by examiner]
US 20030206099A1 · Richman · 2003 [cited by applicant]
US 20050254654A1 · Rockwell et al. · 2005 [cited by applicant]
US 20130332473A1 · Ryman · 2013 [cited by applicant]
US 20150156213A1 · Baker · 2015 [cited by examiner]
US 20160156664A1 · Nagaratnam · 2016 [cited by examiner]
US 20170063905A1 · Muddu · 2017 [cited by examiner]
US 20170134415A1 · Muddu et al. · 2017 [cited by applicant]
US 20170364694A1 · Jacob et al. · 2017 [cited by applicant]
US 20190158517A1 · Muddu et al. · 2019 [cited by applicant]
US 20190260785A1 · Jenkinson et al. · 2019 [cited by applicant]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20200057850A1 · Kraus · 2020 [cited by examiner]
US 20210126938A1 · Trost · 2021 [cited by examiner]
US 20210160274A1 · Murphy · 2021 [cited by examiner]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210250369A1 · Åvist · 2021 [cited by examiner]
US 20210273970A1 · Alshech · 2021 [cited by examiner]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220103575A1 · Fokker · 2022 [cited by examiner]
US 20220150268A1 · Herwono et al. · 2022 [cited by applicant]
US 20230164158A1 · Fellows et al. · 2023 [cited by applicant]
CA 2428192A1 · 2004 [cited by applicant]
WO 2017193036A1 · 2017 [cited by applicant]
WO 2023192677A1 · 2023 [cited by applicant]
WO 2023192680A1 · 2023 [cited by applicant]
WO 2023192682A1 · 2023 [cited by applicant]
WO 2023192683A1 · 2023 [cited by applicant]
WO 2023192684A1 · 2023 [cited by applicant]
WO 2023192685A1 · 2023 [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on May 23, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,271 on Aug. 6, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,271 on Nov. 13, 2025. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Sep. 18, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,271 on Aug. 27, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,271 on Sep. 9, 2025. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781928.9 on Feb. 6, 2026. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781930.5 on Feb. 11, 2026. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781932.1 on Feb. 6, 2026. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781933.9 on Feb. 11, 2026. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781934.7 on Feb. 6, 2026. [cited by applicant]
Extended European Search Report and Search Opinion issued in related Application Serial No. 23781935.4 on Feb. 11, 2026. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jan. 20, 2026. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Feb. 14, 2025. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Apr. 10, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Jan. 16, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Jan. 15, 2025. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jan. 13, 2025. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,167 on Jan. 24, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,182 on Mar. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jan. 8, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,218 on Oct. 30, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,231 on Apr. 29, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on Dec. 19, 2024. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/130,271 on Feb. 26, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017336 on Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017339 on Jun. 14, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017341 on Jun. 15, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017342 on Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017343 on Jun. 12, 2023. [cited by applicant]
International Search Report and Written Opinion issued in related Application Serial No. PCT/US2023/017344 on Jun. 15, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,152 on Jun. 13, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,167 on Jun. 27, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,182 on Jul. 14, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jul. 11, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on Jun. 29, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jul. 18, 2024. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,271 on Jun. 23, 2023. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,231 on Aug. 28, 2023. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Aug. 7, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Nov. 14, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,152 on Oct. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Dec. 11, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,167 on Oct. 16, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,182 on Sep. 9, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Aug. 8, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Dec. 6, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Jul. 29, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Nov. 1, 2024. [cited by applicant]
Notice of Allowance issued in related U.S. Appl. No. 18/130,231 on Sep. 18, 2024. [cited by applicant]
Liu et al., A Review of Rule Learning-Based Intrusion Detection Systems and Their Prospects in Smart Grids, IEEE Acess, Apr. 20, 2021, pp. 57542-57564) (Year: 2021). [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/130,218 on May 11, 2026. [cited by applicant]
Non-Final Office Action issued in related U.S. Appl. No. 18/956,148 on Apr. 23, 2026. [cited by applicant]
Final Office Action issued in related U.S. Appl. No. 18/956,148 on Aug. 10, 2026. [cited by applicant]