Systems and methods for intelligent cyber security threat detection and intelligent verification-informed handling of cyber security events through automated verification workflows

US11550907B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11550907-B2
Application numberUS-202217671881-A
CountryUS
Kind codeB2
Filing dateFeb 15, 2022
Priority dateMar 11, 2021
Publication dateJan 10, 2023
Grant dateJan 10, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for automated verification of a cybersecurity event includes identifying a cybersecurity event of a subscriber; automatically constructing a response-enabled verification communication based on one or more features of the cybersecurity event satisfying verification-initiating criteria of an automated verification-initiation workflow, and transmitting the response-enabled verification communication to the subscriber associated with the cybersecurity event, wherein the response-enabled verification communication includes: one or more pieces of event-descriptive content; a first selectable interface object that, when selected by the subscriber, automatically increases a threat severity level of the cybersecurity event; and a second selectable interface object that, when selected by the subscriber, automatically de-escalates the threat severity level of the cybersecurity event causing a disposal of the cybersecurity event; and automatically routing the cybersecurity event to one of a cybersecurity threat escalation route and a cybersecurity threat de-escalation route based on subscriber input.

First claim

Opening claim text (preview).

We claim: 1. A method for automated verification-informed handling of cybersecurity activity, the method comprising: at a cybersecurity event detection and response service: identifying a cybersecurity event based on event data or activity data associated with one or more computing or digital assets of a subscriber to the cybersecurity event detection and response service; automatically constructing, by one or more computers, a response-enabled verification communication for the cybersecurity event based on (1) one or more features of the cybersecurity event satisfying verification-initiating criteria and (2) receiving, during a cybersecurity investigation, a verification-triggering input selecting a first selectable object displayed on a graphical user interface of the cybersecurity event detection and response service, wherein the first selectable object, when selected, causes an execution of an automated verification-initiation workflow that includes the automatically constructing of the response-enabled verification communication, transmitting the response-enabled verification communication to the subscriber associated with the cybersecurity event, wherein the response-enabled verification communication includes: (a) one or more pieces of event-descriptive content that include event-specific characteristics of the cybersecurity event; (b) a second selectable interface object that, when selected by the subscriber, automatically increases a threat severity level of the cybersecurity event; (c) a third selectable interface object that, when selected by the subscriber, automatically de-escalates the threat severity level of the cybersecurity event for an accelerated disposal of the cybersecurity event; and (d) a text box data field that is configured to receive, as input, one or more text strings of cybersecurity event handling instructions from the subscriber; identifying, by the one or more computers, a subscriber input selecting the second selectable interface object or the third selectable interface object of the response-enabled verification communication that confirms the cybersecurity event as either an authorized cybersecurity event or a non-authorized cybersecurity event and the one or more text strings of cybersecurity event handling instructions from the subscriber; designating, based on the subscriber input, the cybersecurity event as one of: (i) a cybersecurity incident if the subscriber input corresponds to the subscriber selecting the second selectable interface object of the response-enabled verification communication, wherein the designating the cybersecurity event as the cybersecurity incident includes converting the threat severity level of the cybersecurity event to a cybersecurity incident threat severity level; and (ii) a disposable cybersecurity event if the subscriber input corresponds to the subscriber selecting the third selectable interface object of the response-enabled verification communication, wherein the designating the cybersecurity event as the disposable cybersecurity event includes converting the threat severity level of the cybersecurity event to a cybersecurity disposal threat severity level; and automatically routing, based on the designation of the cybersecurity event, the cybersecurity event to one of (1) a cybersecurity threat escalation route of the cybersecurity event detection and response service if the cybersecurity event corresponds to the cybersecurity incident threat severity level and (2) a cybersecurity threat de-escalation route of the cybersecurity event detection and response service if the cybersecurity event corresponds to the cybersecurity disposal threat severity level. 2. The method according to claim 1 , further comprising: automatically constructing an illustrative cybersecurity event graphic based on likely security critical event data associated with the cybersecurity event, wherein automatically constructing the response-enabled verification communication further includes installing the illustrative cybersecurity event graphic as one of the one or more pieces of event-descriptive content of the response-enabled verification communication. 3. The method according to claim 1 , further comprising: automatically deriving text-based content that includes one or more text strings that textually communicate the event-specific characteristics based on likely security critical event data associated with the cybersecurity event, wherein automatically constructing the response-enabled verification communication includes installing the text-based content as one of the one or more pieces of event-descriptive content of the response-enabled verification communication. 4. The method according to claim 1 , wherein in response to automatically constructing the response-enabled verification communication: electronically transmitting the response-enabled verification communication to a digital verification queue of the cybersecurity event detection and response service; displaying, via a web-based user interface of the cybersecurity event detection and response service, a representation of the digital verification queue that includes the response-enabled verification communication; and displaying, via the web-based user interface of the cybersecurity event detection and response service, the response-enabled verification communication. 5. The method according to claim 4 , further comprising: while displaying the response-enabled verification communication: receiving the subscriber input directed to the second selectable interface object of the response-enabled verification communication. 6. The method according to claim 4 , further comprising: while displaying the response-enabled verification communication: receiving the subscriber input directed to the third selectable interface object of the response-enabled verification communication. 7. The method according to claim 1 , wherein the transmitting the response-enabled verification communication to the subscriber includes electronically sending the response-enabled verification communication to the subscriber during the cybersecurity investigation of the cybersecurity event. 8. The method according to claim 1 , wherein the transmitting of the response-enabled verification communication includes electronically sending the response-enabled verification communication to an impartial administrator of the subscriber for selecting a response to the response-enabled verification communication. 9. The method according to claim 1 , wherein in response to automatically constructing the response-enabled verification communication: electronically transmitting the response-enabled verification communication to the subscriber via a bi-directional third-party messaging channel; and at the bi-directional third-party messaging channel identifying the subscriber input comprising a selection of the second selectable interface object or selection of the third selectable interface object. 10. The method according to claim 1 , further comprising: mitigating, via executing one or more cybersecurity threat mitigation actions, a cybersecurity threat associated with the cybersecurity event based on identifying the subscriber input directed to the second selectable interface object of the response-enabled verification communication. 11. The method according to claim 1 , wherein in response to automatically constructing the response-enabled verification communication: selectively identifying a communication transmission destination from a plurality of distinct communication transmission destinations based on a subscriber-defined cybersecurity policy; and transmitting the response

Assignees

Inventors

Classifications

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • Test or assess a computer or a system · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11550907B2 cover?
A system and method for automated verification of a cybersecurity event includes identifying a cybersecurity event of a subscriber; automatically constructing a response-enabled verification communication based on one or more features of the cybersecurity event satisfying verification-initiating criteria of an automated verification-initiation workflow, and transmitting the response-enabled ver…
Who is the assignee on this patent?
Expel Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 10 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).