IP Library Granted Patent US 9,773,116
Granted Patent B2
US 9,773,116 · App. 14/165,357 · Granted Sep 26, 2017

Automated local exception rule generation system, method and computer program product

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,773,116
App. No.
14/165,357
Granted
Sep 26, 2017
Kind
B2
Abstract

A system, method and computer readable medium pertaining to evaluation of events from a computer system to assess security risks to that system. Events are evaluated according to the aspects of each event and the aspects are used to make a preliminary determination regarding violation of a security rule. In addition to a preliminary determination of a rule violation, exceptions to the rule may be identified.

Claims (41)

1. A method of reducing false positive security violation responses comprising:

receiving by a processor of a computer system a first information regarding a computer security event associated with an operation of a computer system;

identifying, by the processor, a security rule of a collection of security rules, the security rule corresponding to the computer security event;

determining, by the processor, whether automatic generation of exceptions to the security rule is allowed;

generating, by the processor, a security violation response to the computer security event responsive to a determination that the security rule does not allow automatic generation of exceptions;

creating, automatically by the processor, an exception to the security rule, responsive to a determination that the security rule allows automatic exception generation;

offering a user an opportunity to exclude the exception from a database of rule exceptions;

storing the exception as an entry in the database of rule exceptions; and

using the stored exception to avoid a security violation response to a future computer security event.

2. The method of claim 1 , wherein the collection of security rules resides in a database.

3. The method of claim 2 , wherein the database is remotely located from the processor and memory.

4. The method of claim 1 , wherein one or more rules from the collection of security rules comprises identification of a security related aspect and an indication regarding whether that aspect presents a security risk.

5. The method of claim 4 , wherein the identified security related aspect presents a security risk and the identified security related aspect corresponds with tag information, the tag information providing an indication of preconditions for the security risk.

6. A non-transitory computer-readable medium on which are stored instructions for reducing false positive computer security responses, comprising instructions that when executed program a computer system to:

receive a first information regarding a computer security event associated with an operation of the computer system;

identify a security rule of a collection of security rules, the security rule corresponding to the computer security event;

determine whether automatic generation of exceptions to the security rule is allowed;

generate a security violation response to the computer security event responsive to a determination that the security rule does not allow automatic generations of exceptions;

automatically create an exception to the security rule, responsive to a determination that the security rule allows automatic exception generation;

offer a user an opportunity to exclude the exception from a database of rule exceptions;

store the exception in the database of rule exceptions; and

use the stored exception to avoid a security violation response to a future computer security event.

7. The computer readable medium of claim 6 , wherein second information is a subset of first information.

8. The computer readable medium of claim 7 , wherein first information is received over a network.

9. The computer-readable medium of claim 6 , wherein one or more rules from the collection of rules comprises identification of a security related aspect and an indication regarding whether that aspect presents a security risk.

10. The computer readable medium of claim 6 , wherein the first information includes a user identifier, information regarding a program interface, a path, or registry information.

11. A computer system programmed to reduce false positive computer security responses, comprising:

a processor; and

a memory, coupled to the processor, on which are stored instructions, comprising instructions that when executed cause the processor to:

receive a first information regarding a computer security event associated with an operation of the computer system;

identify a security rule of a collection of security rules, the security rule corresponding to the computer security event;

determine whether automatic generation of exceptions to the security rule is allowed;

generate a security violation response to the computer security event responsive to a determination that the security rule does not allow automatic generation of exceptions;

automatically create an exception to the security rule responsive to a determination that the security rule allows automatic exception generation;

offer a user an opportunity to exclude the exception from a database of rule exceptions;

store the exception in the database of rule exceptions; and

use the stored exception to avoid a security violation response to a future computer security event.

12. The computer system of claim 11 , further comprising:

a database that stores the collection of security rules.

13. The computer system of claim 11 , wherein the instructions that when executed cause the processor to receive the first information comprise instructions that when executed cause the processor to receive the first information over a network connected to the computer system.

14. The computer system of claim 11 , where an exception rule of the collection of exception rules comprises at least one of a user identifier, a path, or a registry information.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →