IP Library Granted Patent US 9,674,211
Granted Patent B2
US 9,674,211 · App. 14/618,322 · Granted Jun 6, 2017

Cloud service usage risk assessment using darknet intelligence

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,211
App. No.
14/618,322
Granted
Jun 6, 2017
Kind
B2
Abstract

A method of assessing a risk level of an enterprise using cloud-based services from one or more cloud service providers includes assessing provider risk scores associated with the one or more cloud service providers and in view of darknet intelligence data; assessing cloud service usage behavior and pattern of the enterprise; and generating a risk score for the enterprise based on the provider risk scores and on the cloud service usage behavior and pattern of the enterprise. The risk score is indicative of the risk of the enterprise relating to the use of the cloud-based services from the one or more cloud service providers.

Claims (77)

1. A method of assessing a risk level of an enterprise using cloud-based services from one or more cloud service providers, the method comprising:

receiving, by a hardware processor cloud service provider information characterized by a plurality of attributes, each attribute being associated with a plurality of attribute values, each attribute value being associated with a point value, wherein the plurality of attributes comprises a darknet intelligence attribute related to darknet intelligence data, the darknet intelligence attribute having attributes values of data compromised or data not compromised being associated with respective point values;

for each cloud service provider, assessing, by the hardware processor the attribute point value for each attribute based on the cloud service provider information;

aggregating, by the hardware processor, the attribute point values for all of the plurality of attributes associated with each cloud service provider;

generating, by the hardware processor a provider risk score for each cloud service provider based on the aggregated attribute point values associated with the cloud service provider;

receiving, by the hardware processor network event data from a data network associated with the enterprise, the network event data relating to network data traffic between the data network and the one or more cloud service providers;

correlating, by the hardware processor the network event data to the one or more cloud service providers;

generating, by the hardware processor, one or more cloud service usage analytics based on the network event data and the cloud service provider information associated with the cloud service providers correlated to the network event data;

generating, using the hardware processor, a risk score for the enterprise based on the provider risk scores for the cloud service providers correlated to the network event data and based on the cloud service usage analytics indicative of the cloud service usage behavior and pattern of the enterprise, the risk score being indicative of the risk of the enterprise relating to the use of the cloud-based services from the one or more cloud service providers; and

generating, by the hardware processor an output comprising a remediation means based on the risk score generated for the enterprise,

wherein generating a risk score for the enterprise comprises:

generating an enterprise risk score associated with a part of or all of the cloud service usage behavior and pattern belonging to the enterprise; and

generating a user risk score associated with the cloud service usage behavior and pattern belonging to one or more users of the enterprise and a darknet intelligence attribute associated with the one or more users.

2. The method of claim 1 , further comprising:

assigning, by the hardware processor, attribute weight values to each of the plurality of attributes, the attribute weight values being applied to adjust the relative contribution of an attribute to the provider risk score; and

for each cloud service provider, assessing, by the hardware processor, the attribute point value for each attribute based on the cloud service provider information, the attribute point value being adjusted by the respective attribute weight value.

3. The method of claim 1 , wherein receiving, by a hardware processor, cloud service provider information characterized by a plurality of attributes comprises:

receiving, by the hardware processor, cloud service provider information characterized by the plurality of attributes, the plurality of attributes belonging to one or more risk categories, the risk categories including one or more of a cloud service risk, a data risk, a user/device risk, and a business risk, the cloud service risk being related to the inherent risk of the cloud service provider, the data risk being related to handling of data at the cloud service provider, the user/device risk being related to users and devices accessing the cloud-based service of the cloud service providers, and the business risk being related to business practices of the cloud service providers.

4. The method of claim 1 , wherein assessing, by the hardware processor, cloud service usage behavior and pattern of the enterprise comprises:

receiving, by the hardware processor, network event data from a data network associated with the enterprise, the network event data relating to network data traffic between the data network and the one or more cloud service providers;

correlating, by the hardware processor, network event data to the one or more cloud service providers; and

generating, by the hardware processor, one or more cloud service usage analytics based on the network event data and the cloud service provider information.

5. The method of claim 1 , wherein generating a user risk score further comprises:

generating, by the hardware processor, the user risk score associated with the cloud service usage behavior and pattern belonging to one or more users of the enterprise and the darknet intelligence attribute associated with the one or more users, the darknet intelligence attribute comprising darknet intelligence data indicating whether user credentials associated with the one or more users have been compromised.

6. The method of claim 5 , further comprising:

determining, by the hardware processor, a user risk score for a first user exceeding a first threshold; and

generating, by the hardware processor, a recommendation to the enterprise to change the user credential of the first user.

7. The method of claim 1 , further comprising:

generating an N-day average enterprise risk score using the enterprise risk score;

comparing the enterprise risk score at a given time interval to the N-day average enterprise risk score;

detecting the enterprise risk score at a given time interval exceeding the N-day average enterprise risk score by a predetermined limit value; and

generating an alert for the enterprise in response to the detecting.

8. The method of claim 7 , further comprising:

generating an N-day average user risk score using the user risk score;

comparing the user risk score at a given time interval to the N-day average user risk score;

detecting the user risk score at a given time interval exceeding the N-day average user risk score by a predetermined limit value; and

generating an alert for the enterprise in response to the detecting.

9. The method of claim 7 , further comprising:

generating an N-day average enterprise risk score using the enterprise risk score;

comparing the user risk score at a given time interval to the N-day average enterprise risk score;

detecting the user risk score at a given time interval exceeding the N-day average enterprise risk score by a predetermined limit value; and

generating an alert for the enterprise in response to the detecting.

10. A system for assessing a risk level of an enterprise using cloud-based services from one or more cloud service providers, the system comprising:

a hardware processor configured to:

receive cloud service provider information characterized by a plurality of attributes, each attribute being associated with a plurality of attribute values, each attribute value being associated with a point value, wherein the plurality of attributes comprises a darknet intelligence attribute related to darknet intelligence data, the darknet intelligence attribute having attributes values of data compromised or data not compromised being associated with respective point values;

for each cloud service provider, assess the attribute point value for each attribute based on the cloud service provider information;

aggregate the attribute point values for all of the plurality of attributes associated with a cloud service provider;

generate a provider risk score for each cloud service provider based on the aggregated attribute point values associated with the cloud service provider;

receive network event data from a data network associated with the enterprise, the network event data relating to network data traffic between the data network and the one or more cloud service providers;

correlate the network event data to the one or more cloud service providers;

generate one or more cloud service usage analytics based on the network event data and the cloud service provider information associated with the cloud service providers correlated to the network event data;

generate a risk score for the enterprise based on the provider risk scores for the cloud service providers correlated to the network event data and based on the cloud service usage analytics indicative of the cloud service usage behavior and pattern of the enterprise, the risk score being indicative of the risk of the enterprise relating to the use of the cloud-based services from the one or more cloud service providers; and

generate an output comprising a remediation means based on the risk score generated for the enterprise,

wherein to generate a risk score for the enterprise comprises:

generate an enterprise risk score associated with a part of or all of the cloud service usage behavior and pattern belonging to the enterprise; and

generate a user risk score associated with the cloud service usage behavior and pattern belonging to one or more users of the enterprise and a darknet intelligence attribute associated with the one or more users; and

a memory coupled to the hardware processor and configured to provide the hardware processor with instructions.

11. The system of claim 10 , wherein the hardware processor is further configured to:

generate a user risk score associated with the cloud service usage behavior and pattern belonging to one or more users of the enterprise and a darknet intelligence attribute associated with the one or more users, the darknet intelligence attribute comprising darknet intelligence data indicating whether user credentials associated with the one or more users have been compromised.

12. The system of claim 11 , wherein the hardware processor is further configured to:

determine a user risk score for a first user exceeding a first threshold; and

generate a recommendation to the enterprise to change the user credential of the first user.

13. The system of claim 10 , wherein the hardware processor is further configured to:

generate an N-day average enterprise risk score using the enterprise risk score;

comparing the enterprise risk score at a given time interval to the N-day average enterprise risk score;

detect the enterprise risk score at a given time interval exceeding the N-day average enterprise risk score by a predetermined limit value; and

generate an alert for the enterprise in response to the detecting.

14. The system of claim 13 , wherein the hardware processor is further configured to:

generate an N-day average user risk score using the user risk score;

comparing the user risk score at a given time interval to the N-day average user risk score;

detect the user risk score at a given time interval exceeding the N-day average user risk score by a predetermined limit value; and

generate an alert for the enterprise in response to the detecting.

15. The system of claim 13 , wherein the hardware processor is further configured to:

generating an N-day average enterprise risk score using the enterprise risk score;

comparing the user risk score at a given time interval to the N-day average enterprise risk score;

detecting the user risk score at a given time interval exceeding the N-day average enterprise risk score by a predetermined limit value; and

generating an alert for the enterprise in response to the detecting.

Assignments (16)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 19, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047955/0432 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2015
From: CURCIC, DEJAN; GUPTA, RAJIV; NARAYAN, KAUSHIK; SOMASAMUDRAM, PRASAD RAGHAVENDRA; SARUKKAI, SEKHAR
To: SKYHIGH NETWORKS, INC.
Reel/Frame 035419/0170 →