Systems and methods for intelligent cyber security threat detection and mitigation through an extensible automated investigations and threat mitigation platform

US12101348B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12101348-B2
Application numberUS-202318133285-A
CountryUS
Kind codeB2
Filing dateApr 11, 2023
Priority dateOct 14, 2020
Publication dateSep 24, 2024
Grant dateSep 24, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A cybersecurity system and method for handling a cybersecurity event includes identifying a cybersecurity alert; selectively initializing automated threat intelligence workflows based on computing a cybersecurity alert type, wherein the automated threat intelligence workflows include a plurality of automated investigative tasks that, when executed by one or more computers, derive cybersecurity alert intelligence data; and executing the plurality of automated investigative tasks includes automatically sourcing a corpus of investigative data; deriving the cybersecurity alert intelligence data based on extracting selective pieces of data from the corpus of investigative data, wherein the cybersecurity alert intelligence data informs an inference of a cybersecurity alert severity of the cybersecurity alert; and automatically routing the cybersecurity alert to one of a plurality of distinct threat mitigation or threat disposal routes based on the cybersecurity alert severity of the cybersecurity alert.

First claim

Opening claim text (preview).

We claim: 1. A method for accelerating a remediation or disposal of a cybersecurity event, the method comprising: producing a plurality of automated investigation tasks based on detecting a cybersecurity event, wherein producing each of the plurality of automated investigation tasks includes: (i) identifying a set of application programming interface (API) call parameters associated with a target external data source, and (ii) configuring one or more API calls based on the set of API call parameters of the target external data source; generating a corpus of investigation findings data associated with the cybersecurity event based on executing the plurality of automated investigation tasks; configuring a cybersecurity investigation findings artifact based on one or more pieces of cybersecurity threat-informative data included in the corpus of investigation findings data, wherein the cybersecurity investigation findings artifact includes one or more pieces of threat intelligence collateral that informs one or more threat mitigation responses to the cybersecurity event or informs a de-escalation response to the cybersecurity event; and executing one or more cybersecurity event handling actions or one or more cybersecurity event disposal actions that resolve or mitigate a threat of the cybersecurity event based on an assessment of the cybersecurity investigation findings artifact. 2. The method according to claim 1 , wherein: configuring the cybersecurity investigation findings artifact includes: automatically interleaving a selected subset of the one or more pieces of cybersecurity threat-informative data into one or more sections of the cybersecurity investigation findings artifact. 3. The method according to claim 1 , wherein: configuring the cybersecurity investigation findings artifact includes: automatically creating one or more illustrative threat graphics of the cybersecurity event based on a select subset of the one or more pieces of cybersecurity threat-informative data, and installing the one or more illustrative threat graphics into a target region of the cybersecurity investigation findings artifact. 4. The method according to claim 1 , wherein: at least one of the plurality of automated investigation tasks corresponds to a target investigative query; and a subset of the one or more pieces of cybersecurity threat-informative data satisfies the target investigative query. 5. The method according to claim 4 , wherein: a distinct section of the cybersecurity investigation findings artifact includes: the target investigative query; and the subset of the one or more pieces of cybersecurity threat-informative data; and the target investigative query is positioned ahead of each piece of cybersecurity threat-informative data of the subset within the distinct section. 6. The method according to claim 4 , wherein: a distinct section of the cybersecurity investigation findings artifact includes: the target investigative query; and the subset of the one or more pieces of cybersecurity threat-informative data; and each piece of cybersecurity threat-informative data of the subset is positioned below the target investigative query within the distinct section. 7. The method according to claim 1 , wherein: at least one of the plurality of automated investigation tasks corresponds to a target investigative question; a subset of the one or more pieces of cybersecurity threat-informative data of the corpus of investigation findings data satisfies the target investigative question; a target section of the cybersecurity investigation findings artifact includes: the target investigative question; and the subset of the one or more pieces of cybersecurity threat-informative data, wherein each piece of cybersecurity threat-informative data of the subset is positioned below the target investigative question within the target section. 8. A computer-implemented method comprising: initializing an ensemble of automated investigation tasks based on detecting cybersecurity activity, wherein the ensemble of automated investigation tasks is electronically linked to a likely cybersecurity activity type associated with the cybersecurity activity; obtaining a corpus of investigation findings data based on executing the ensemble of automated investigation tasks; configuring threat response collateral based on one or more pieces of cybersecurity threat-informative data included in the corpus of investigation findings data, wherein the threat response collateral informs one or more threat mitigation responses to the cybersecurity activity or informs a de-escalation response to the cybersecurity activity; and routing the cybersecurity activity to one of a plurality of distinct threat mitigation or threat disposal routes based on an assessment of the threat response collateral. 9. The computer-implemented method according to claim 8 , wherein: the cybersecurity activity includes one of a cybersecurity alert or a cybersecurity event. 10. The computer-implemented method according to claim 8 , wherein: the assessment includes: computing a probable cybersecurity threat severity value associated with the cybersecurity activity based on extracting selective pieces of data from the one or more pieces of cybersecurity threat-informative data; and the probable cybersecurity threat severity value informs the routing of the cybersecurity activity to the one of the plurality of distinct threat mitigation or threat disposal routes. 11. The computer-implemented method according to claim 10 , wherein: the probable cybersecurity threat severity value relates to a likelihood or an estimation that the cybersecurity activity includes one or more of a malicious attack, a compromise of one or more computing systems of a subscriber, and a violation of computer security policy of the subscriber. 12. The computer-implemented method according to claim 8 , wherein: initializing the ensemble of automated investigation tasks includes: identifying a reference mapping between each of a plurality of distinct likely cybersecurity activity types and a plurality of distinct automated investigation tasks; and identifying the ensemble of automated investigation tasks for the cybersecurity activity based on evaluating the likely cybersecurity activity type against the reference mapping. 13. The computer-implemented method according to claim 8 , wherein: initializing the ensemble of automated investigation tasks includes: identifying a reference mapping between each of a plurality of distinct cybersecurity activities and one or more distinct automated investigation tasks; and identifying the ensemble of automated investigation tasks for the cybersecurity activity based on performing a search of the reference mapping using the likely cybersecurity activity type associated with the cybersecurity activity. 14. The computer-implemented method according to claim 8 , wherein: configuring the threat response collateral includes composing an investigation intelligence artifact by: automatically interleaving a subset of the one or more pieces of cybersecurity threat-informative data into one or more distinct parts of the investigation intelligence artifact. 15. The method according to claim 8 , wherein: configuring the threat response collateral further includes composing an investigation intelligence artifact by: automatically creating one or more illustrative graphics of the cybersecurity activity based on a subset of the one or more pieces of cybersecurity threat-informative data, and installing the one or more

Assignees

Inventors

Classifications

  • Knowledge engineering; Knowledge acquisition · CPC title

  • Inference or reasoning models · CPC title

  • Remote procedure calls [RPC]; Web services · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12101348B2 cover?
A cybersecurity system and method for handling a cybersecurity event includes identifying a cybersecurity alert; selectively initializing automated threat intelligence workflows based on computing a cybersecurity alert type, wherein the automated threat intelligence workflows include a plurality of automated investigative tasks that, when executed by one or more computers, derive cybersecurity …
Who is the assignee on this patent?
Expel Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1441. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 24 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).