IP Library Granted Patent US 8,549,649
Granted Patent B2
US 8,549,649 · App. 12/761,751 · Granted Oct 1, 2013

Systems and methods for sensitive data remediation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,549,649
App. No.
12/761,751
Granted
Oct 1, 2013
Kind
B2
Abstract

Systems and methods for sensitive data remediation include calculating a Probability of Loss of data on a given computer based on measures of control, integrity, and potential avenues of exploitation of the given computer, determining an Impact of Loss of the data on the given computer based on a type, volume, and nature of the data, and correlating the Probability of Loss with the Impact of Loss to generate a risk score for the given computer that can be compared to other computers in the network. The computers with higher risk scores can then be subjected to data remediation activity.

Claims (32)

1. A computer network auditing method, comprising:

deploying agents on respective computers among a plurality of computers throughout a network;

using the agents to collect information about the volume and sensitivity of data stored on the respective computers and the programs running on the respective computers;

receiving the information from the agents at a central location;

for each computer for which the information has been received, calculating a risk score, where the risk score is based on the volume and sensitivity of data stored on said each computer and a security of said each computer;

comparing, at the central location, calculated risk scores of multiple computers and ranking the multiple computers in a risk score order; and

for a given one of the multiple computers in the risk score order, performing a remediation technique that has the effect of reducing the risk score for the given computer,

wherein calculating the risk score comprises separately taking account of (i) for a given one of the computers, data considered to be of a first sensitivity value stored on the given one of the computers, (ii) data considered to be of a second sensitivity value, different form the first sensitivity value, stored on the given one of the computers, (iii) an exposure level of the data stored on the given one of the computers, and (iv) an integrity assessment of the given one of the computers, and

wherein the risk score is based on a probability of loss that is itself based on the exposure level of the data stored on the given one of the computers and the integrity assessment of the given one of the computers, and an impact of loss metric that is itself based on the first and second sensitivity values.

2. The method of claim 1 , further comprising pushing the agents from a server to the respective computers.

3. The method of claim 1 , further comprising receiving the information from the agents via a secure encrypted tunnel.

4. The method of claim 1 , further comprising applying weights to variables associated with the type of data stored on respective computers and associated with metrics of security for the respective computer.

5. The method of claim 4 , wherein the variables or metrics include at least one of number of pieces of malware, number of rootkits, number of hidden files, days since last audit, running programs, network connections, potential network connections, confirmed signature-based vulnerabilities, confirmed mis-configurations, or network location/role of the computer.

6. The method of claim 1 , wherein the remediation technique comprises at least one of deleting, encrypting, or moving data on or from the given one of the multiple computers.

7. The method of claim 1 , wherein the remediation technique comprises changing a configuration, uninstalling an application, installing an application, executing an application, or disabling a running service on the given one of the multiple computers.

8. The method of claim 1 , further comprising notifying a user of the given one of the multiple computers that data has been removed from the computer.

9. The method of claim 1 , wherein data considered to be of the fist sensitivity value comprises at least one of social security numbers and credit cards numbers.

10. The method of claim 1 , wherein data considered to be of the second sensitivity value comprises telephone numbers.

11. A method of monitoring a network of computers, comprising;

receiving, from respective computers in the network, an indication of the volume and sensitivity of information stored thereon;

receiving, from the respective computers in the network, an indication of a level of security thereof;

receiving, from the respective computers in the network, an indication of configuration of the respective computer;

calculating a risk score for each respective computer based on the volume and sensitivity of information, security and configuration of each respective computer; and

ranking the computers based on their respective risk scores,

wherein calculating the risk score comprises separately taking account of (i) for a given one of the computers, data considered to be of a first sensitivity value stored on the given one of the computers, (ii) data considered to be of a second sensitivity value, different from the first sensitivity value, stored one the given one of the computers, (iii) an exposure level of the data stored on the given one of the computers, and (iv) an integrity assessment of the given one of the computers, and

wherein the risk score is based on a probability of loss that is itself based on the exposure level of the data stored on the given one of the computers and the integrity assessment of the given one of the computers, and an impact of loss metric that is itself based on the first and second sensitivity values.

12. The method of claim 11 , further comprising performing a remediation technique on a highest ranking computer of the computers subjected to ranking.

13. The method of claim 11 , wherein the remediation technique comprises at least one of deleting, encrypting, or moving data on the highest ranking computer.

14. The method of claim 11 , wherein the remediation technique comprises changing a configuration, uninstalling an application, installing an application, executing an application, or disabling a running service on the highest ranking computer.

15. The method of claim 11 , further comprising notifying a user of the highest ranking computer that data has been removed from the computer.

16. The method of claim 11 , wherein data considered to be of the first sensitivity value comprises at least one of social security numbers and credit cards numbers.

17. The method of claim 11 , wherein data considered to be of the second sensitivity value comprises telephone numbers.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
CHANGE OF NAME Recorded May 17, 2011
From: NETWITNESS HOLDING INC.
To: EMC CORPORATION
Reel/Frame 026292/0374 →
CHANGE OF NAME Recorded May 16, 2011
From: NETWITNESS LLC
To: NETWITNESS HOLDING INC.
Reel/Frame 026283/0986 →
MERGER Recorded May 4, 2011
From: NETWITNESS CORPORATION
To: NETWITNESS LLC
Reel/Frame 026221/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2010
From: GOLOMB, GARY J.; DOUGLAS, KEVIN T.; GIRARDI, BRIAN P.
To: NETWITNESS CORPORATION
Reel/Frame 024246/0433 →