Patent · US Active

Automated quantified assessment, recommendations and mitigation actions for enterprise level security operations

US12107869B1 · kind B1 · utility

10Cited by
3References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 20, 2021
Grant dateOct 1, 2024
Priority date
Expiry dateMay 9, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A dynamic threat landscape to which computer resources of a specific enterprise are subject is tracked. Data feeds maintained by a security system of the enterprise are assessed. The effectiveness of data feed utilization by the security system is quantified, relative to the threat landscape. Threat detection rules deployed by the security system are assessed, and the effectiveness thereof by the security system is quantified. Processing capability of alerts generated by threat detection rules and threat response capability may also be assessed and quantified. The effectiveness of the security system as a whole is automatically quantified, based on the tracked threat landscape, the quantifications of the effectiveness of data feed utilization, threat detection rule utilization, processing capability of alerts generated by threat detection rules and/or threat response capability. Recommendations concerning more effectively protecting the enterprise against specific threats are output. Actions are automatically taken to mitigate specific threats.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.