Threat mitigation system and method

US11297092B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11297092-B2
Application numberUS-202017016031-A
CountryUS
Kind codeB2
Filing dateSep 9, 2020
Priority dateSep 9, 2019
Publication dateApr 5, 2022
Grant dateApr 5, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method, computer program product and computing system for: obtaining consolidated platform information to identify current security-relevant capabilities for a computing platform; determining possible security-relevant capabilities for the computing platform; and rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, executed on a computing device, comprising: obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the SIEM system, activity of a plurality of security-relevant subsystems of the computing platform; determining possible security-relevant capabilities for the computing platform; rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform; identifying coverage gaps in the current security-relevant capabilities, wherein identifying the coverage gaps in the current security-relevant capabilities includes identifying a plurality of inefficiencies in one or more portions of the computing platform; and providing one or more recommendations for mitigating the identified coverage gaps, wherein providing the one or more recommendations for mitigating the identified coverage gaps includes: in response to identifying the plurality of inefficiencies in the one or more portions of the computing platform, determining an efficiency increase for each of the one or more portions of the computing platform that would result from mitigating the identified coverage gaps. 2. The computer-implemented method of claim 1 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using the currently-deployed security-relevant subsystems. 3. The computer-implemented method of claim 1 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems. 4. The computer-implemented method of claim 1 wherein the graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform includes: multi-axial comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform. 5. The computer-implemented method of claim 1 wherein the consolidated platform information is obtained from an independent information source. 6. The computer-implemented method of claim 1 wherein the consolidated platform information is obtained from a client information source. 7. The computer-implemented method of claim 1 , wherein providing the one or more recommendations for mitigating the identified coverage gaps includes: identifying a plurality of undeployed rules that are deployable in the computing platform, and ranking the plurality of undeployed rules that are deployable in the computing platform. 8. The computer-implemented method of claim 7 , wherein each of the plurality of undeployed rules are associated with one or more of: a kill chain phase; a severity level; and a performance score based, at least in part, on a probability of detecting one or more false positives. 9. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising: obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the SIEM system, activity of a plurality of security-relevant subsystems of the computing platform; determining possible security-relevant capabilities for the computing platform; rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform; identifying coverage gaps in the current security-relevant capabilities, wherein identifying the coverage gaps in the current security-relevant capabilities includes identifying a plurality of inefficiencies in one or more portions of the computing platform; and providing one or more recommendations for mitigating the identified coverage gaps, wherein providing the one or more recommendations for mitigating the identified coverage gaps includes: in response to identifying the plurality of inefficiencies in the one or more portions of the computing platform, determining an efficiency increase for each of the one or more portions of the computing platform that would result from mitigating the identified coverage gaps. 10. The computer program product of claim 9 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using the currently-deployed security-relevant subsystems. 11. The computer program product of claim 9 wherein the possible security-relevant capabilities concern the possible security-relevant capabilities of the computing platform using one or more supplemental security-relevant subsystems. 12. The computer program product of claim 9 wherein the graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform includes: multi-axial comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform. 13. The computer program product of claim 9 wherein the consolidated platform information is obtained from an independent information source. 14. The computer program product of claim 9 wherein the consolidated platform information is obtained from a client information source. 15. A computing system including a processor and memory configured to perform operations comprising: obtaining, by a Security Information and Event Management (SIEM) system, consolidated platform information to identify current security-relevant capabilities for a computing platform, including monitoring, by the STEM system, activity of a plurality of security-relevant subsystems of the computing platform; determining possible security-relevant capabilities for the computing platform; rendering graphical comparison information that illustrates a difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform including level-of-confidence comparison information that illustrates the difference between the current security-relevant capabilities of the computing platform and the possible security-relevant capabilities of the computing platform; identifying coverage gaps in the current security-relevant capabilities, wherein identify

Assignees

Inventors

Classifications

  • Probabilistic graphical models, e.g. probabilistic networks · CPC title

  • Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources (admission control or resource allocation H04L47/70) · CPC title

  • for performance assessment · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11297092B2 cover?
A computer-implemented method, computer program product and computing system for: obtaining consolidated platform information to identify current security-relevant capabilities for a computing platform; determining possible security-relevant capabilities for the computing platform; and rendering graphical comparison information that illustrates a difference between the current security-relevant…
Who is the assignee on this patent?
Reliaquest Holdings Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 05 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).