Threat mitigation system and method

US11637847B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11637847-B2
Application numberUS-202117337132-A
CountryUS
Kind codeB2
Filing dateJun 2, 2021
Priority dateJun 6, 2018
Publication dateApr 25, 2023
Grant dateApr 25, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method, computer program product and computing system for: obtaining system-defined consolidated platform information for a computing platform from an independent information source; obtaining client-defined consolidated platform information for the computing platform from a client information source; and comparing the system-defined consolidated platform information to the client-defined consolidated platform information to define differential consolidated platform information for the computing platform.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, executed on a computing device, comprising: obtaining consolidated platform information for a computing platform; analyzing the consolidated platform information to evaluate one or more current security relevant capabilities for the computer platform; identifying one or more security assets which are available but not utilized by the computing platform including one or more of: features of the one or more security assets that are available but not utilized, features of the one or more security assets that are available but disabled, and expanded features of the one or more security assets; determining possible security-relevant capabilities for the computing platform, wherein the possible security-relevant capabilities accounts for the one or more security assets which are available but not utilized by the computing platform; generating comparison information that compares the current security-relevant capabilities of the computing platform to the possible security-relevant capabilities of the computing platform to identify security-relevant deficiencies; and generating a list of at least a portion of the one or more security assets that are available but not utilized by the computing platform to address at least a portion of the security-relevant deficiencies. 2. The computer-implemented method of claim 1 , wherein generating the list of the at least a portion of the one or more security assets includes: generating a list of ranked and recommended security assets that ranks the one or more available but not utilized security assets. 3. The computer-implemented method of claim 2 wherein generating the list of ranked and recommended security assets that ranks the one or more available but not utilized security assets includes: ranking the one or more security assets based upon the anticipated use of the one or more security assets. 4. The computer-implemented method of claim 1 , further comprising providing the ability/option to implement one or more security assets which are available but not utilized by the computing platform. 5. The computer-implemented method of claim 1 , wherein identifying the one or more security assets which are available but not utilized includes: utilizing artificial intelligence/machine learning to process the consolidated platform information to identify the one or more security assets which are available but not utilized. 6. The computer-implemented method of claim 1 , wherein the consolidated platform information includes client-defined consolidated platform information. 7. The computer-implemented method of claim 1 , wherein the consolidated platform information is received from a client, the client including one or more of a user, an owner, and an operator of the computing platform. 8. The computer-implemented method of claim 1 , wherein one or more of the current security-relevant capabilities and the possible security-relevant capabilities are provided by one or more of Content Delivery Network (CDN) systems; Database Activity Monitoring (DAM) systems; User Behavior Analytics (UBA) systems; Mobile Device Management (MDM) systems; Identity and Access Management (IAM) systems; Domain Name Server (DNS) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform. 9. The computer-implemented method of claim 1 , further including: determining comparative platform information that identifies security-relevant capabilities for a comparative platform, wherein the comparative platform concerns one or more vendor customers. 10. The computer-implemented method of claim 9 , further including: providing a score for the computing platform based upon, at least in part, the current security-relevant capabilities; and providing a score based upon, at least in part, the security-relevant capabilities for the comparative platform. 11. The computer-implemented method of claim 10 , wherein the comparative platform information concerns vendor customers in a specific industry. 12. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon, which, when executed by a processor, cause the processor to perform operations comprising: obtaining consolidated platform information for a computing platform; analyzing the consolidated platform information to evaluate one or more current security relevant capabilities for the computer platform; identifying one or more security assets which are available but not utilized by the computing platform including one or more of: features of the one or more security assets that are available but not utilized, features of the one or more security assets that are available but disabled, and expanded features of the one or more security assets; determining possible security-relevant capabilities for the computing platform, wherein the possible security-relevant capabilities accounts for the one or more security assets which are available but not utilized by the computing platform; generating comparison information that compares the current security-relevant capabilities of the computing platform to the possible security-relevant capabilities of the computing platform to identify security-relevant deficiencies; and generating a list of at least a portion of the one or more security assets that are available but not utilized by the computing platform to address at least a portion of the security-relevant deficiencies. 13. The computer program product of claim 12 , wherein generating the list of the at least a portion of the one or more security assets includes: generating a list of ranked and recommended security assets that ranks the one or more available but not utilized security assets. 14. The computer program product of claim 13 wherein generating the list of ranked and recommended security assets that ranks the one or more available but not utilized security assets includes: ranking the one or more security assets based upon the anticipated use of the one or more security assets. 15. The computer program product of claim 12 , further comprising instructions for providing the ability/option to implement one or more security assets which are available but not utilized by the computing platform. 16. The computer program product of claim 12 , wherein identifying the one or more security assets which are available but not utilized includes: utilizing artificial intelligence/machine learning to process the consolidated platform information to identify the one or more security assets which are available but not utilized. 17. The computer program product of claim 12 , wherein the consolidated platform information includes client-defined consolidated platform information. 18. The computer program product of claim 12 , wherein the consolidated platform information is received from a client, the client including one or more of a user, an owner, and an operator of the computing platform. 19. The computer program product of claim 12 , wherein one or more of the current security-relevant capabilities and the possible security-relevant capabilities are provided by one or more of Content Delivery Network (CDN) systems; Database Activity Monitoring (DAM) systems; User Behavior Analytics (UBA) systems; Mobile Device Management (MDM) systems; Identity and Access Management (IAM) systems; Domain Name Server (DNS) systems, antivirus s

Assignees

Inventors

Classifications

  • Generating training patterns; Bootstrap methods, e.g. bagging or boosting · CPC title

  • Updates (security arrangements therefor G06F21/57) · CPC title

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Detecting local intrusion or implementing counter-measures · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11637847B2 cover?
A computer-implemented method, computer program product and computing system for: obtaining system-defined consolidated platform information for a computing platform from an independent information source; obtaining client-defined consolidated platform information for the computing platform from a client information source; and comparing the system-defined consolidated platform information to t…
Who is the assignee on this patent?
Reliaquest Holdings Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 25 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).