Systems, methods, and graphical user interfaces for accelerating a construction of a data integration for a non-integrated technology data source

US12598199B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12598199-B2
Application numberUS-202519207677-A
CountryUS
Kind codeB2
Filing dateMay 14, 2025
Priority dateJun 20, 2023
Publication dateApr 7, 2026
Grant dateApr 7, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system, method, and computer-program product includes displaying, via a data integration building user interface, a plurality of integration-identifying user interface input elements configured to receive one or more strings of text for specifying a set of integration identification parameters that characterize an in-development security integration for a third-party security service, displaying, via the data integration building user interface, a signal-specific data mapping container based on receiving an input selecting a signal mapping addition control button of the data integration building user interface, displaying, via the data integration building user interface, a raw event simulation container based on receiving an input selecting a simulation addition control button of the data integration building user interface, and displaying, via the data integration building user interface, an integration deployment control element that, when operated, transitions the in-development security integration to a deployed security integration.

First claim

Opening claim text (preview).

We claim: 1 . A computer-program product comprising a non-transitory machine-readable storage medium storing computer instructions that, when executed by one or more processors, perform operations comprising: providing, via the one or more processors, a graphical user interface that includes: one or more input elements configured to receive one or more strings of text for specifying a set of parameters that characterize an in-development integration associated with a third-party service; a signal-specific data mapping container configured to receive inputs of characters to map technology-specific data attributes of the third-party service to technology source-agnostic data attributes required by a distinct technology source-agnostic event signal type of a plurality of predetermined technology source-agnostic event signal types, wherein the signal-specific data mapping container includes a signal type user interface element that, when selected, displays a drop-down menu element of the plurality of predetermined technology source-agnostic event signal types provided by a cybersecurity event detection and response service; a raw event simulation container configured to receive input of: (i) a distinct raw event generated by the third-party service, and (ii) an expected technology source-agnostic event signal type for validating that the in-development integration translates the distinct raw event to a respective technology-source agnostic event signal of the expected technology source-agnostic event signal type using mapping instructions specified by the signal-specific data mapping container; and an integration deployment control element configured to receive an input for transitioning the in-development integration to a deployed integration for the third-party service; receiving an unnormalized event from the third-party service; generating a technology-source agnostic event signal that corresponds to the unnormalized event using the deployed integration for the third-party security service; and executing a threat mitigation response that mitigates a security threat associated with the technology-source agnostic event signal corresponding to the unnormalized event. 2 . The computer-program product according to claim 1 , wherein: executing the threat mitigation response that mitigates the security threat associated with the technology-source agnostic event signal includes reporting the security threat in real-time to a threat reporting user interface accessible by a subscribing entity. 3 . The computer-program product according to claim 1 , wherein: executing the threat mitigation response that mitigates the security threat associated with the technology-source agnostic event signal includes surfacing the security threat via a threat reporting user interface. 4 . The computer-program product according to claim 1 , wherein: the deployed integration for the third-party service defines a data integration nexus between the third-party service and the event detection and response service. 5 . The computer-program product according to claim 1 , wherein the computer instructions, when executed by the one or more processors, perform operations further comprising: determining a threat severity of the technology-source agnostic event signal based on assessing the technology-source agnostic event signal against a set of automated detection decisioning workflows digitally mapped to a type of the technology-source agnostic event signal. 6 . The computer-program product according to claim 5 , wherein the computer instructions, when executed by the one or more processors, perform operations further comprising: routing the technology-source agnostic event signal to one of a plurality of event queues, wherein: the technology-source agnostic event signal is routed to an event escalation queue when the technology-source agnostic event signal satisfies escalation criteria of the set of automated detection decisioning workflows, and the technology-source agnostic event signal is routed to an event disposal queue when the technology-source agnostic event signal satisfies disposal criteria of the set of automated detection decisioning workflows. 7 . A computer-implemented method comprising: instantiating, via a data integration building user interface, a plurality of integration-identifying user interface input elements configured to receive one or more strings of text for specifying a set of integration identification parameters that characterize an in-development security integration for a third-party security service; instantiating, via the data integration building user interface, a signal-specific data mapping container based on receiving an input selecting a signal mapping addition control button of the data integration building user interface, wherein the signal-specific data mapping container is configured to receive inputs of characters to map technology-specific data attributes of the third-party security service to technology source-agnostic data attributes required by a target technology source-agnostic event signal type; instantiating, via the data integration building user interface, a raw event simulation container based on receiving an input selecting a simulation addition control button of the data integration building user interface, wherein the raw event simulation container is configured to receive input of: (i) a distinct raw event generated by the third-party security service, and (ii) an expected technology source-agnostic event signal type for validating that the in-development security integration accurately translates the distinct raw event to a technology source-agnostic event signal of the expected technology source-agnostic event signal type using mapping instructions specified by the signal-specific data mapping container; and displaying, via the data integration building user interface, an integration deployment control element that, when operated, transitions the in-development security integration to a deployed security integration, wherein the raw event simulation container executes, via one or more processing devices, a computer-based integration simulation that generates a simulation output indicating whether a reconfiguration of the in-development security integration is needed before the in-development security integration is deployed into production by assessing whether the mapping instructions specified by the signal-specific data mapping container translated the distinct raw event to the technology-source agnostic event signal of the expected technology source-agnostic event signal type. 8 . The computer-implemented method according to claim 7 , further comprising: at a cybersecurity event detection and response service: identifying that the third-party security service is in inoperable communication with the cybersecurity event detection and response service; and instantiating, via the one or more processing devices, the data integration building user interface based on identifying that the third-party security service is in inoperable communication with the cybersecurity event detection and response service, wherein the data integration building user interface is digitally accessible by a user of the cybersecurity event detection and response service. 9 . The computer-implemented method according to claim 7 , wherein: transitioning the in-development security integration to the deployed security integration includes: installing, via the one or more processing devices, the mapping instructions associated with the in-development security integration into a database or repository storing a plurality of previously deployed security data integrations.

Assignees

Inventors

Classifications

  • G06F8/34Primary

    Graphical or visual programming · CPC title

  • Vulnerability analysis · CPC title

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12598199B2 cover?
A system, method, and computer-program product includes displaying, via a data integration building user interface, a plurality of integration-identifying user interface input elements configured to receive one or more strings of text for specifying a set of integration identification parameters that characterize an in-development security integration for a third-party security service, display…
Who is the assignee on this patent?
Expel Inc
What technology area does this patent fall under?
Primary CPC classification G06F8/34. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 07 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).