IP Library Granted Patent US 10,262,137
Granted Patent B1
US 10,262,137 · App. 15/197,995 · Granted Apr 16, 2019

Security recommendations based on incidents of malware

Inventors: Michael Hart (Farmington, CT); Kevin Alejandro Roundy (El Segundo, CA); Shang-Tse Chen (Atlanta, GA); Christopher Gates (Venice, CA)
Assignee: Symantec Corporation
G06F21/566H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,262,137
App. No.
15/197,995
Granted
Apr 16, 2019
Kind
B1
Abstract

A method for providing security recommendations is described. In one embodiment, the method may include identifying a set of monitored customers. In some cases, each monitored customer may include one or more computing devices. The method may include identifying a first computing device of a monitored customer for evaluation, selecting a potential security product to install on the first computing device, and quantifying the ability of the monitored customer to detect or prevent malware incidents based at least in part on the selected potential security product.

Claims (52)

1. A method for providing security recommendations of computer system security products in relation to previously installed security products across monitored machines, comprising:

identifying a set of monitored customers, each monitored customer comprising one or more computing devices;

identifying a first computing device of a first monitored customer for evaluation, the first monitored customer being one of the set of monitored customers;

selecting a first security product to potentially install on the first computing device; and

quantifying the ability of the first monitored customer to detect or prevent malware incidents based at least in part on the selected first security product and a second security product previously installed on the first computing device, wherein the second security product is independent from the selected first security product.

2. The method of claim 1 , comprising:

identifying one or more computing device that are similar in at least one aspect to the first computing device.

3. The method of claim 2 , comprising:

selecting a second computing device from the identified one or more computing devices based on the second computing device including a software application not installed on the first computing device, the software application identified as detecting malware incidents the first computing device fails to detect.

4. The method of claim 3 , comprising:

determining a number of malware incidents the software application of the second computing device detects that the first computing device fails to detect.

5. The method of claim 3 , comprising:

identifying a customer response rate associated with the malware incidents detected by the software application of the second computing device.

6. The method of claim 5 , comprising:

estimating, based at least in part on the identified customer response associated with the malware incidents detected by the software application of the second computing device, a likelihood adding the software application of the second computing device to the first computing device results in an increased customer response by the monitored customer of the first computing device.

7. The method of claim 1 , comprising:

generating a list of software applications installed on the computing devices of the monitored customers.

8. The method of claim 7 , comprising:

ranking a performance of each software application on the list of software applications in relation to each software application performing security actions on the one or more computing device; and

recommending a software application from the list of software applications to one or more monitored customers based on the rank of the recommended software application.

9. The method of claim 1 , comprising:

categorizing each monitored customer by at least one of industry, number of computing devices, computing device type, computing device operating system, operating system version, firmware, firmware version, software applications installed, and rate of malware incidents.

10. The method of claim 9 , the computing device type including at least one of a mobile computing device, a laptop, a tablet, a desktop, and a server.

11. A computing device configured for providing security recommendations of computer system security products in relation to previously installed security products across monitored machines, comprising:

a processor;

memory in electronic communication with the processor, wherein the memory stores computer executable instructions that when executed by the processor cause the processor to perform the steps of:

identifying a set of monitored customers, each monitored customer comprising one or more computing devices;

identifying a first computing device of a first monitored customer for evaluation, the first monitored customer being one of the set of monitored customers;

selecting a first security product to potentially install on the first computing device; and

quantifying the ability of the first monitored customer to detect or prevent malware incidents based at least in part on the selected first security product and a second security product previously installed on the first computing device, wherein the second security product is independent from the selected first security product.

12. The computing device of claim 11 , wherein the instructions executed by the processor cause the processor to perform the steps of:

identifying one or more computing device that are similar in at least one aspect to the first computing device.

13. The computing device of claim 12 , wherein the instructions executed by the processor cause the processor to perform the steps of:

selecting a second computing device from the identified one or more computing devices based on the second computing device including a software application not installed on the first computing device, the software application identified as detecting malware incidents the first computing device fails to detect.

14. The computing device of claim 13 , wherein the instructions executed by the processor cause the processor to perform the steps of:

determining a number of malware incidents the software application of the second computing device detects that the first computing device fails to detect.

15. The computing device of claim 13 , wherein the instructions executed by the processor cause the processor to perform the steps of:

identifying a customer response rate associated with the malware incidents detected by the software application of the second computing device.

16. The computing device of claim 15 , wherein the instructions executed by the processor cause the processor to perform the steps of:

estimating, based at least in part on the identified customer response associated with the malware incidents detected by the software application of the second computing device, a likelihood adding the software application of the second computing device to the first computing device results in an increased customer response by the monitored customer of the first computing device.

17. The computing device of claim 11 , wherein the instructions executed by the processor cause the processor to perform the steps of:

generating a list of software applications installed on the computing devices of the monitored customers.

18. The computing device of claim 11 , wherein the instructions executed by the processor cause the processor to perform the steps of:

ranking a performance of each software application on the list of software applications in relation to each software application performing security actions on the one or more computing device; and

recommending a software application from the list of software applications to one or more monitored customers based on the rank of the recommended software application.

19. A non-transitory computer-readable storage medium storing computer executable instructions for providing security recommendations of computer system security products in relation to previously installed security products across monitored machines, that when executed by a processor cause the processor to perform the steps of:

identifying a set of monitored customers, each monitored customer comprising one or more computing devices;

identifying a first computing device of a first monitored customer for evaluation, the first monitored customer being one of the set of monitored customers;

selecting a first security product to potentially install on the first computing device; and

quantifying the ability of the first monitored customer to detect or prevent malware incidents based at least in part on the selected first security product and a second security product previously installed on the first computing device, wherein the second security product is independent from the selected first security product.

20. The computer-program product of claim 19 , wherein the instructions executed by the processor cause the processor to perform the steps of:

identifying one or more computing device that are similar in at least one aspect to the first computing device.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2016
From: HART, MICHAEL; ROUNDY, KEVIN ALEJANDRO; CHEN, SHANG-TSE; GATES, CHRISTOPHER
To: SYMANTEC CORPORATION
Reel/Frame 039053/0535 →
Cited By (1)
US 12,284,202