Threat mitigation system and method

US11057419B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11057419-B2
Application numberUS-202017016108-A
CountryUS
Kind codeB2
Filing dateSep 9, 2020
Priority dateSep 9, 2019
Publication dateJul 6, 2021
Grant dateJul 6, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method, computer program product and computing system for: detecting one or more security events within a computing platform of a client; notifying the client of the one or more security events within the computing platform; determining how long it took the client to resolve the one or more security events within the computing platform; and providing a resolution report to the client that quantifies client resolution performance based, at least in part, upon how long it took the client to resolve the one or more security events within the computing platform.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, executed on a computing device, comprising: monitoring, by a Security Information and Event Management (SIEM) system, activity of one or more security-relevant subsystems; detecting, by the SIEM system, one or more security events within a computing platform of a client; notifying the client of the one or more security events within the computing platform; determining how long it took the client to resolve the one or more security events within the computing platform; and providing a resolution report to the client that quantifies client resolution performance based, at least in part, upon how long it took the client to resolve the one or more security events within the computing platform, wherein the resolution report defines a client resolution time with respect to how long it took the client to resolve the one or more security events within the computing platform and compares the client resolution time to a resolution time of third parties. 2. The computer-implemented method of claim 1 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client. 3. The computer-implemented method of claim 1 wherein the resolution report defines time-based resolution performance over a defined period of time. 4. The computer-implemented method of claim 3 wherein the time-based resolution performance includes time-based resolution performance for the client and for third parties. 5. The computer-implemented method of claim 4 wherein the time-based resolution performance for the client includes time-based resolution performance for the client sorted by severity of the one or more security events. 6. The computer-implemented method of claim 4 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client. 7. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising: monitoring, by a Security Information and Event Management (SIEM) system, activity of one or more security-relevant subsystems; detecting, by the SIEM system, one or more security events within a computing platform of a client; notifying the client of the one or more security events within the computing platform; determining how long it took the client to resolve the one or more security events within the computing platform; and providing a resolution report to the client that quantifies client resolution performance based, at least in part, upon how long it took the client to resolve the one or more security events within the computing platform, wherein the resolution report defines a client resolution time with respect to how long it took the client to resolve the one or more security events within the computing platform and compares the client resolution time to a resolution time of third parties. 8. The computer program product of claim 7 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client. 9. The computer program product of claim 7 wherein the resolution report defines time-based resolution performance over a defined period of time. 10. The computer program product of claim 9 wherein the time-based resolution performance includes time-based resolution performance for the client and for third parties. 11. The computer program product of claim 10 wherein the time-based resolution performance for the client includes time-based resolution performance for the client sorted by severity. 12. The computer program product of claim 10 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client. 13. A computing system including a processor and memory configured to perform operations comprising: monitoring, by a Security Information and Event Management (SIEM) system, activity of one or more security-relevant subsystems; detecting, by the SIEM system, one or more security events within a computing platform of a client; notifying the client of the one or more security events within the computing platform; determining how long it took the client to resolve the one or more security events within the computing platform; and providing a resolution report to the client that quantifies client resolution performance based, at least in part, upon how long it took the client to resolve the one or more security events within the computing platform, wherein the resolution report defines a client resolution time with respect to how long it took the client to resolve the one or more security events within the computing platform and compares the client resolution time to a resolution time of third parties. 14. The computing system of claim 13 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client. 15. The computing system of claim 13 wherein the resolution report defines time-based resolution performance over a defined period of time. 16. The computing system of claim 15 wherein the time-based resolution performance includes time-based resolution performance for the client and for third parties. 17. The computing system of claim 16 wherein the time-based resolution performance for the client includes time-based resolution performance for the client sorted by severity. 18. The computing system of claim 16 wherein the third-parties include one or more of: other clients regardless of industry; and other clients in the same industry as the client.

Assignees

Inventors

Classifications

  • Probabilistic graphical models, e.g. probabilistic networks · CPC title

  • Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources (admission control or resource allocation H04L47/70) · CPC title

  • Machine learning · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • for performance assessment · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11057419B2 cover?
A computer-implemented method, computer program product and computing system for: detecting one or more security events within a computing platform of a client; notifying the client of the one or more security events within the computing platform; determining how long it took the client to resolve the one or more security events within the computing platform; and providing a resolution report t…
Who is the assignee on this patent?
Reliaquest Holdings Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 06 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).