Threat mitigation system and method

US12406068B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12406068-B2
Application numberUS-201916432751-A
CountryUS
Kind codeB2
Filing dateJun 5, 2019
Priority dateJun 6, 2018
Publication dateSep 2, 2025
Grant dateSep 2, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving a unified query from a third-party concerning the plurality of security-relevant subsystems; distributing at least a portion of the unified query to the plurality of security-relevant subsystems; and effectuating the at least a portion of the unified query on each of the plurality of security-relevant subsystems to generate a plurality of result sets.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, executed on a computing device, comprising: detecting a security event within a computing platform; gathering artifacts concerning the security event from log files maintained by a plurality of security-relevant subsystems, including obtaining artifact information concerning one or more artifacts from one or more investigation resources; assigning a threat level to the security event using artificial intelligence/machine learning; executing a remedial action plan based upon, at least in part, the assigned threat level; generating a security event report based upon, at least in part, the gathered artifacts; obtaining consolidated platform information concerning the computing platform; processing the consolidated platform information to identify one or more non-deployed security-relevant subsystems; ranking the one or more non-deployed security-relevant subsystems based on anticipated use within the computing platform, wherein ranking the one or more non-deployed security-relevant subsystems is based on: one or more of a functionality and an effectiveness of the non-deployed security relevant subsystems; and an anticipated manner in which the implementation of the one or more nondeployed security relevant subsystems will impact a functionality/security of the computing platform; searching the artifacts concerning the security event within log files maintained by the plurality of security-relevant subsystems including: establishing connectivity with the plurality of security-relevant subsystems within the computing platform including utilizing a respective application program interface to access each of the plurality of security-relevant subsystems, wherein each security-relevant subsystem of the plurality of security-relevant subsystems is configured to monitor and log their activity with respect to the computing platform; receiving a unified query concerning logged files of the plurality of security-relevant subsystems with respect to the computing platform; distributing at least a portion of the unified query to the plurality of security-relevant subsystems, including: parsing the unified query to form a plurality of queries, wherein a specific query is defined for each of the plurality of security-relevant subsystems; and providing the specific query defined for each of the plurality of security-relevant subsystems to the respective security-relevant subsystems; effectuating the at least a portion of the unified query on each of the plurality of security-relevant subsystems to generate a plurality of result sets; receiving the plurality of result sets from the plurality of security-relevant subsystems; and processing one or more results sets of the plurality of result sets so that the results sets all have at least one of a common format, a common nomenclature, and a common structure, and rendering the results set as security-relevant information within an interactive report. 2. The computer-implemented method of claim 1 further comprising: combining the plurality of result sets to form a unified query result. 3. The computer-implemented method of claim 2 wherein combining the plurality of result sets to form a unified query result includes: homogenizing the plurality of result sets to form the unified query result. 4. The computer-implemented method of claim 2 further comprising: providing the unified query result to a third-party. 5. The computer-implemented method of claim 1 wherein the plurality of security-relevant subsystems includes one or more of: a data lake; a data log; a security-relevant software application; a security-relevant hardware system; and a resource external to the computing platform. 6. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising: detecting a security event within a computing platform; gathering artifacts concerning the security event from log files maintained by a plurality of security-relevant subsystems, including obtaining artifact information concerning one or more artifacts from one or more investigation resources; assigning a threat level to the security event using artificial intelligence/machine learning; executing a remedial action plan based upon, at least in part, the assigned threat level; generating a security event report based upon, at least in part, the gathered artifacts; obtaining consolidated platform information concerning the computing platform; processing the consolidated platform information to identify one or more non-deployed security-relevant subsystems; ranking the one or more non-deployed security-relevant subsystems based on anticipated use within the computing platform, wherein ranking the one or more non-deployed security-relevant subsystems is based on: one or more of a functionality and an effectiveness of the non-deployed security relevant subsystems; and an anticipated manner in which the implementation of the one or more non-deployed security relevant subsystems will impact a functionality/security of the computing platform; searching the artifacts concerning the security event within log files maintained by the plurality of security-relevant subsystems including: establishing connectivity with the plurality of security-relevant subsystems within the computing platform including utilizing a respective application program interface to access each of the plurality of security-relevant subsystems, wherein each security-relevant subsystem of the plurality of security-relevant subsystems is configured to monitor and log their activity with respect to the computing platform; receiving a unified query concerning logged files of the plurality of security-relevant subsystems with respect to the computing platform; distributing at least a portion of the unified query to the plurality of security-relevant subsystems, including: parsing the unified query to form a plurality of queries, wherein a specific query is defined for each of the plurality of security-relevant subsystems; and providing the specific query defined for each of the plurality of security-relevant subsystems to the respective security-relevant subsystems; effectuating the at least a portion of the unified query on each of the plurality of security-relevant subsystems to generate a plurality of result sets; receiving the plurality of result sets from the plurality of security-relevant subsystems; and processing one or more results sets of the plurality of result sets so that the results sets all have at least one of a common format, a common nomenclature, and a common structure, and rendering the results set as security-relevant information within an interactive report. 7. The computer program product of claim 6 further comprising: combining the plurality of result sets to form a unified query result. 8. The computer program product of claim 7 wherein combining the plurality of result sets to form a unified query result includes: homogenizing the plurality of result sets to form the unified query result. 9. The computer program product of claim 7 further comprising: providing the unified query result to a third-party. 10. The computer program product of claim 6 wherein the plurality of security-relevant subsystems includes one or more of: a data lake; a data log; a security-relevant software application; a security-relevant hardware system; and a resource external to the computing platform. 11. A computing system including a processor and memory configured to

Assignees

Inventors

Classifications

  • Analysing · CPC title

  • Generating training patterns; Bootstrap methods, e.g. bagging or boosting · CPC title

  • Rule management · CPC title

  • eliminating virus, restoring damaged files · CPC title

  • Design optimisation, verification or simulation (optimisation, verification or simulation of circuit designs G06F30/30) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12406068B2 cover?
A computer-implemented method, computer program product and computing system for: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; receiving a unified query from a third-party concerning the plurality of security-relevant subsystems; distributing at least a portion of the unified query to the plurality of security-relevant subsystems; and e…
Who is the assignee on this patent?
Reliaquest Holdings Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Sep 02 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).