IP Library Granted Patent US 8,677,497
Granted Patent B2
US 8,677,497 · App. 13/339,221 · Granted Mar 18, 2014

Mobile risk assessment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,677,497
App. No.
13/339,221
Granted
Mar 18, 2014
Kind
B2
Abstract

A query is received from a particular endpoint device identifying a particular wireless access point encountered by the particular endpoint device. Pre-existing risk assessment data is identified for the identified particular wireless access point and query result data is sent to the particular endpoint device characterizing pre-assessed risk associated with the particular wireless access point. In some instances, the query result data is generated based on the pre-existing risk assessment data. In some instances, pre-existing risk assessment data can be the result of an earlier risk assessment carried-out at least in part by an endpoint device interfacing with and testing the particular wireless access point.

Claims (43)

1. A method comprising:

receiving a query from a particular endpoint device identifying a particular wireless access point encountered by the particular endpoint device;

determining whether pre-existing risk assessment data exists for the identified particular wireless access point; and

participating in a risk assessment of the particular wireless access point with the particular endpoint device, wherein the risk assessment includes:

the particular endpoint device attempting to communicate with a trusted endpoint over the particular wireless access point; and

monitoring the attempted communication with the trusted endpoint over the particular wireless access point to assess risk associated with the particular wireless access point.

2. The method of claim 1 , further comprising receiving risk assessment feedback data from the endpoint device in connection with at least one assessment task performed by the particular endpoint device.

3. The method of claim 2 , further comprising using the received risk assessment feedback data to determine a risk profile for the particular wireless access point.

4. The method of claim 3 , wherein the pre-assessed risk associated with the particular wireless access point is considered in the determination of the risk profile.

5. The method of claim 2 , wherein the feedback data includes at least one of a service set identifier (SSID), data describing encryption used by the wireless access point, splash page information, and wireless access point password information.

6. The method of claim 1 , wherein attempting to communicate with the trusted endpoint includes attempting to establish a secured connection between the particular endpoint device and the trusted endpoint, and establishing the secured connection includes receiving expected trust verification data from the trusted endpoint;

wherein receipt of data other than the expected trust verification data is presumed to indicate that the particular wireless access point is untrustworthy suggesting higher risk associated with the particular wireless access point.

7. The method of claim 6 , wherein participating in the risk assessment of the particular wireless access point includes facilitating communication of the expected trust verification data to the particular endpoint device in advance of the particular endpoint device attempting to communicate with the trusted endpoint over the particular wireless access point.

8. The method of claim 1 , wherein participating in the risk assessment of the particular wireless access point includes identifying, to the particular endpoint device, the trusted endpoint device from a plurality of available trusted endpoint devices in advance of the particular endpoint device attempting to communicate with the trusted endpoint over the particular wireless access point.

9. The method of claim 1 , wherein pre-existing risk assessment data for the identified particular wireless access point was generated in connection with at least one previous encounter with the particular wireless access point by an endpoint device.

10. The method of claim 9 , wherein the previous encounter with the particular wireless access point was made by an endpoint device other than the particular endpoint device.

11. The method of claim 1 , wherein the pre-existing risk assessment data for the identified particular wireless access point is identified from risk assessment records including pre-existing risk assessment data for a plurality of wireless access points identified by wireless-enabled endpoint devices.

12. The method of claim 1 , wherein the query includes geo-positional data indicating a location of at least one of the particular endpoint device and the particular wireless access point.

13. The method of claim 12 , further comprising:

generating query result data based at least in part on pre-existing risk assessment data for the identified particular wireless access point and the location identified in the geo-positional data.

14. The method of claim 1 , further comprising calculating a risk profile for the particular endpoint device based on a set of device attributes including risk associated with wireless access points accessed by the particular endpoint device.

15. The method of claim 1 , further comprising causing a graphical indicator of risk associated with the particular wireless access point to be presented at the particular endpoint device.

16. The method of claim 1 , wherein the query is sent over a secure connection other than a wireless network associated with the particular wireless access point.

17. The method of claim 16 , wherein the secure connection is implemented over at least one of a wireless mobile broadband connection and a VLAN tunnel.

18. The method of claim 1 , further comprising sending query result data to the particular endpoint device characterizing risk associated with the particular wireless access point.

19. The method of claim 18 , wherein pre-existing risk assessment data is determined to exist for the identified particular wireless access point and the query result data is based at least in part on the pre-existing risk assessment data.

20. The method of claim 18 , wherein the query result data is based at least in part on results of the risk assessment.

21. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

receive a query from a particular endpoint device identifying a particular wireless access point encountered by the particular endpoint device;

determine whether pre-existing risk assessment data exists for the identified particular wireless access point; and

participate in a risk assessment of the particular wireless access point with the particular endpoint device, wherein the risk assessment includes:

the particular endpoint device attempting to communicate with a trusted endpoint over the particular wireless access point; and

monitoring the attempted communication with the trusted endpoint over the particular wireless access point to assess risk associated with the particular wireless access point.

22. A system comprising:

at least one processor device;

at least one memory element; and

a wireless access point risk assessor, adapted when executed by the at least one processor device to:

receive a query from a particular endpoint device identifying a particular wireless access point encountered by the particular endpoint device;

determine whether pre-existing risk assessment data exists for the identified particular wireless access point pre-existing risk assessment data for the identified particular wireless access point; and

participate in a risk assessment of the particular wireless access point with the particular endpoint device, wherein the risk assessment includes:

the particular endpoint device attempting to communicate with a trusted endpoint over the particular wireless access point; and

monitoring the attempted communication with the trusted endpoint over the particular wireless access point to assess risk associated with the particular wireless access point.

23. The system of claim 22 , further comprising a device risk assessment tool adapted to calculate a risk profile for the particular endpoint device based on a set of device attributes including risk associated with wireless access points accessed by the particular endpoint device.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →