Security application and methods for becoming and staying cyber resilient
View Patent ↗Methods can be provided for reducing risks of being a target of cyber attacks, or a data breach of personal data, or impersonation or theft of a digital identity, etc. Such methods may be implemented, for example, via a security application.
1 . A method performed by a security application executing on a mobile user terminal connected to a local wireless network, the method performed by the security application executing on the mobile user terminal comprising:
(a) scanning the local wireless network, to obtain, for each particular device amongst devices connected to the wireless network, connected device information specific to the particular device, the connected device information including address information associated with the particular device;
(b) performing by the security application a vulnerability scan of said each particular device among the devices connected to the wireless network, to obtain by the security application vulnerability scan results, said vulnerability scan including identifying suspect open ports through which a prospective hacker can infiltrate the user terminal from the particular device;
(b1) using the address information of the particular device, to obtain additional device-associated information from a data source or external database which is external to the wireless LAN, the additional device-associated information including a device specification and device vulnerability information associated with at least one specific device among the devices; and
(c) providing, in a user-comprehensible manner and by the security application, the connected device information, the vulnerability scan results and device vulnerability information, including the suspect open ports identified in (b), and providing guidance as to user action on the user terminal as to the suspect open ports.
2 . The method of claim 1 , further comprising:
(a2) performing one or more additional scans, to determine the connected device information for each connected device amongst the devices connected to the wireless network, the connected device information including, in addition to the address information associated with the connected device, a device name of the connected device;
(a3) maintaining a device scan database; and
(a4) saving in the device scan database a result of the additional scans performed in (a2), including the connected device information determined in (a2) for the each connected device,
the additional device-associated information being obtained in (b1) from the device scan database or another data source or external database, and
the additional device-associated information including one or more of a device type, a device manufacturer and a device model of the connected device.
3 . The method of claim 2 , further comprising:
(a6) displaying on the user terminal, for the each connected device, the connected device information associated with the connected device, the displayed connected device information including at least the device type and the device name of the connected device;
(a7) permitting, by the security application, the displayed connected device information to be modified from the user terminal; and
(a8) when the displayed connected device information is modified from the user terminal in (a7), updating the device scan database to conform to the modified information.
4 . The method of claim 3 , wherein in (a7), the security application permits the displayed connected device information to be deleted entirely, from the user terminal.
5 . The method of claim 1 , wherein
for each device among the devices connected to the wireless network, the additional device-associated information obtained in (b1) additionally includes a firmware version of the device, determined based on the address information associated with the device, and
the device vulnerability information for the device is obtained in (b1) from the data source or external database by look-up with reference to the device specification and firmware of the device.
6 . The method of claim 1 , further comprising:
maintaining, by the security application, a vulnerability scan database; and
registering, by the security application, in the vulnerability scan database, the device vulnerability information in association with the connected device information, for the corresponding device.
7 . The method of claim 6 , wherein
the vulnerability scan performed in (b) also includes, for each connected device, using the address information associated with the connected device, to look-up in the vulnerability scan database with reference to the address information associated with the connected device, and
when the look-up in the vulnerability scan database includes matches of the address information associated with the connected device to registered device vulnerability information, a notification based on the registered device vulnerability information which is matched to the address information is provided.