IP Library Granted Patent US 10,686,819
Granted Patent B2
US 10,686,819 · App. 14/060,498 · Granted Jun 16, 2020

Hierarchical risk assessment and remediation of threats in mobile networking environment

Inventors: Ramana M. Mylavarapu (San Jose, CA); Ajay Nigam (Milpitas, CA); Vipin Balkatta Hegde (San Jose, CA)
Assignee: PROOFPOINT, INC.
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,819
App. No.
14/060,498
Granted
Jun 16, 2020
Kind
B2
Abstract

Mobile device security techniques are described. For a specific computing device, for each of a plurality of distinct security categories, a risk score is determined. The determined risk scores are aggregated to obtain an overall risk score.

Claims (78)

1. A method, comprising:

collecting or detecting vulnerability data from distributed sources, the vulnerability data including:

a first vulnerability data set from aspects of a mobile device, the mobile device being a first source of the distributed sources,

a second vulnerability data set from communication between the mobile device and a server in a secure network, the server being a second source of the distributed sources, and

a third set vulnerability data set from communication between the mobile device and a network service, the network service being a third source of the distributed sources, the collecting or detecting performed by a facility having a processor, a non-transitory computer-readable medium, and stored instructions translatable by the processor, the facility configured for enhancing security of mobile devices in a mobile networking environment;

centrally processing the vulnerability data in order of threat priority associated therewith, the processing performed by the facility, the processing comprising:

for each vulnerability event in the vulnerability data:

determining, from a plurality of vulnerability policies, a matching vulnerability policy that matches a respective vulnerability event in the vulnerability data and that contains a risk score;

extracting the risk score from the matching vulnerability policy;

based at least on the risk score extracted from the matching vulnerability policy, determining a best matching risk remediation policy for the respective vulnerability event in the vulnerability data; and

performing a remediation for the mobile device per the best matching risk remediation policy to remediate the respective vulnerability event in the vulnerability data; and

reporting, through a user interface of the facility, vulnerability events in the vulnerability data and associated remediations for the mobile device in the order of the threat priority.

2. The method according to claim 1 , wherein the aspects of the mobile device comprise at least one of mobile cloud service (MCS) access, data integrity, malware, application integrity, or device integrity, wherein the server in the secure network comprises a virtual private network (VPN) server in a VPN, and wherein the network service relates to an environmental factor, MCS application access, security monitoring, application access, or active directory access.

3. The method according to claim 1 , wherein the processing further comprises:

responsive to a vulnerability event in the vulnerability data having no matching vulnerability policy or matching risk remediation policy, placing the vulnerability event in a review queue.

4. The method according to claim 1 , further comprising:

storing the vulnerability events in a historical data store.

5. The method according to claim 1 , further comprising:

adding the vulnerability events to a risk profile for the mobile device.

6. The method according to claim 1 , further comprising:

generating a remediation action event describing the remediation taken; and

communicating the remediation action event to the user interface.

7. The method according to claim 1 , wherein the user interface is configured for allowing a user to adjust a type, degree, or level of the remediation selected automatically by the facility and wherein the user interface comprises a dashboard, a mobile device user interface, or a security information and event management (SIEM) user interface.

8. The method according to claim 1 , wherein the threat priority comprises none, low, medium, or high.

9. The method according to claim 1 , wherein the remediation comprises a solution, a fix, a patch, a temporary fix, or a work around.

10. A system, comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for:

collecting or detecting vulnerability data from distributed sources, the vulnerability data including:

a first vulnerability data set from aspects of a mobile device, the mobile device being a first source of the distributed sources,

a second vulnerability data set from communication between the mobile device and a server in a secure network, the server being a second source of the distributed sources, and

a third set vulnerability data set from communication between the mobile device and a network service, the network service being a third source of the distributed sources;

centrally processing the vulnerability data in order of threat priority associated therewith, the processing comprising:

for each vulnerability event in the vulnerability data:

determining, from a plurality of vulnerability policies, a matching vulnerability policy that matches a respective vulnerability event in the vulnerability data and that contains a risk score;

extracting the risk score from the matching vulnerability policy;

based at least on the risk score extracted from the matching vulnerability policy, determining a best matching risk remediation policy for the respective vulnerability event in the vulnerability data; and

performing a remediation for the mobile device per the best matching risk remediation policy to remediate the respective vulnerability event in the vulnerability data; and

reporting, through a user interface, vulnerability events in the vulnerability data and associated remediations for the mobile device in the order of the threat priority.

11. The system of claim 10 , wherein the aspects of the mobile device comprise at least one of mobile cloud service (MCS) access, data integrity, malware, application integrity, or device integrity, wherein the server in the secure network comprises a virtual private network (VPN) server in a VPN, and wherein the network service relates to an environmental factor, MCS application access, security monitoring, application access, or active directory access.

12. The system of claim 10 , wherein the processing further comprises:

responsive to a vulnerability event in the vulnerability data having no matching vulnerability policy or matching risk remediation policy, placing the vulnerability event in a review queue.

13. The system of claim 10 , wherein the stored instructions are further translatable by the processor for:

storing the vulnerability events in a historical data store.

14. The system of claim 10 , wherein the stored instructions are further translatable by the processor for:

adding the vulnerability events to a risk profile for the mobile device.

15. The system of claim 10 , wherein the stored instructions are further translatable by the processor for:

generating a remediation action event describing the remediation taken; and

communicating the remediation action event to the user interface.

16. The system of claim 10 , wherein the user interface is configured for allowing a user to adjust a type or degree of the remediation selected automatically by the facility and wherein the user interface comprises a dashboard, a mobile device user interface, or a security information and event management (SIEM) user interface.

17. The system of claim 10 , wherein the threat priority comprises none, low, medium, or high.

18. The system of claim 10 , wherein the remediation comprises a solution, a fix, a patch, a temporary fix, or a work around.

19. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor to perform:

collecting or detecting vulnerability data from distributed sources, the vulnerability data including:

a first vulnerability data set from aspects of a mobile device, the mobile device being a first source of the distributed sources,

a second vulnerability data set from communication between the mobile device and a server in a secure network, the server being a second source of the distributed sources, and

a third set vulnerability data set from communication between the mobile device and a network service, the network service being a third source of the distributed sources;

centrally processing the vulnerability data in order of threat priority associated therewith, the processing comprising:

for each vulnerability event in the vulnerability data:

determining, from a plurality of vulnerability policies, a matching vulnerability policy that matches a respective vulnerability event in the vulnerability data and that contains a risk score;

extracting the risk score from the matching vulnerability policy;

based at least on the risk score extracted from the matching vulnerability policy, determining a best matching risk remediation policy for the respective vulnerability event in the vulnerability data; and

performing a remediation for the mobile device per the best matching risk remediation policy to remediate the respective vulnerability event in the vulnerability data; and

reporting, through a user interface, vulnerability events in the vulnerability data and associated remediations for the mobile device in the order of the threat priority.

20. The computer program product of claim 19 , wherein the aspects of the mobile device comprise at least one of mobile cloud service (MCS) access, data integrity, malware, application integrity, or device integrity, wherein the server in the secure network comprises a virtual private network (VPN) server in a VPN, and wherein the network service relates to an environmental factor, MCS application access, security monitoring, application access, or active directory access.

21. The computer program product of claim 19 , wherein the processing further comprises:

responsive to a vulnerability event in the vulnerability data having no matching vulnerability policy or matching risk remediation policy, placing the vulnerability event in a review queue.

22. The computer program product of claim 19 , wherein the instructions are further translatable by the processor for:

storing the vulnerability events in a historical data store.

23. The computer program product of claim 19 , wherein the instructions are further translatable by the processor for:

adding the vulnerability events to a risk profile for the mobile device.

24. The computer program product of claim 19 , wherein the instructions are further translatable by the processor for:

generating a remediation action event describing the remediation taken; and

communicating the remediation action event to the user interface.

25. The computer program product of claim 19 , wherein the user interface is configured for allowing a user to adjust a type or degree of the remediation selected automatically by the facility and wherein the user interface comprises a dashboard, a mobile device user interface, or a security information and event management (SIEM) user interface.

26. The computer program product of claim 19 , wherein the threat priority comprises none, low, medium, or high.

27. The computer program product of claim 19 , wherein the remediation comprises a solution, a fix, a patch, a temporary fix, or a work around.

Assignments (11)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
EMPLOYMENT AGREEMENT Recorded Sep 17, 2019
From: HEGDE, VIPIN BALKATTA
To: IRONKEY, INC.
Reel/Frame 050409/0085 →
CHANGE OF NAME Recorded Sep 17, 2019
From: MARBLE ACCESS, INC.
To: MARBLE CLOUD, INC.
Reel/Frame 050409/0143 →
CHANGE OF NAME Recorded Sep 17, 2019
From: MARBLE CLOUD, INC.
To: MARBLE SECURITY, INC.
Reel/Frame 050409/0169 →
AMENDMENT Recorded Sep 17, 2019
From: IRONKEY, INC.
To: MARBLE ACCESS, INC.
Reel/Frame 050411/0351 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: MOSCOW ACQUISITION CORP
To: PROOFPOINT, INC.
Reel/Frame 048759/0912 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: MARBLE SECURITY, INC.
To: MOSCOW ACQUISITION CORP
Reel/Frame 048759/0901 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: MYLAVARAPU, RAMANA M.; NIGAM, AJAY
To: MARBLE SECURITY, INC.
Reel/Frame 048759/0871 →
Cited By (1)
US 12,487,811