IP Library Granted Patent US 10,003,609
Granted Patent B2
US 10,003,609 · App. 15/373,298 · Granted Jun 19, 2018

Inferential analysis using feedback for extracting and combining cyber risk information including proxy connection analyses

Inventors: George Y. Ng (San Mateo, CA); Don Ma (Millbrae, CA); Yuen Tsing Ooi (Foster City, CA); Feiyin Zhang (Burlingame, CA); Fernando Tancioco, Jr. (San Ramon, CA)
Assignee: Guidewire Software, Inc.
H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,003,609
App. No.
15/373,298
Granted
Jun 19, 2018
Kind
B2
Abstract

Various embodiments of the present technology include methods of assessing risk of a cyber security failure in one or more computer networks for an entity. Various embodiments include establishing a plurality of proxy connections with entity resources, evaluating performance of the proxy connections, and scoring the proxy connections based on performance. Various embodiments may further include automatically determining, based on the proxy score, a change or setting regarding the proxy connections. Various embodiments may also include automatically recommending, based on the assessed risk, computer network changes for the one or more computer networks to reduce the assessed risk. Some embodiments may include providing recommended computer network and/or policy changes to reduce the assessed risk, determining the entity has enacted some recommended network changes, and in response, automatically reassessing the risk of a cyber security failure based on the enacted recommended computer network changes.

Claims (54)

1. A method, comprising:

assessing cyber risk in one or more computer networks for an entity, by collecting information from at least one accessible network element by:

establishing a plurality of proxy connections with entity resources of an entity, the plurality of proxy connections being established with one or more computer networks for the entity;

evaluating performance of the plurality of proxy connections; and

scoring the proxy connections based on their performance to determine a proxy score associated with the proxy connections;

automatically determining, based on the proxy score, a change or a setting regarding the proxy connections; and

automatically recommending, based on the assessed cyber risk, computer network changes for the one or more computer networks to reduce the assessed cyber risk.

2. The method according to claim 1 , wherein establishing the plurality of proxy connections with entity resources of the entity further comprises establishing the proxy connections with the entity resources in a randomized manner, wherein the proxy connections are established at different times of a day and different days in a week.

3. The method according to claim 2 , further comprising evaluating the plurality of proxy connections for connection quality.

4. The method according to claim 3 , wherein the proxy connections are established between the entity resources and a proxy endpoint, wherein the proxy endpoint is located in various locations.

5. The method according to claim 4 , wherein the proxy connections are randomly established and terminated to create ephemeral proxy data that is indicative of performance of the proxy connections.

6. The method according to claim 5 , further comprising randomly rotating through the plurality of proxy connections.

7. The method according to claim 1 , wherein the performance of the proxy connections comprise proxy connection availability and proxy connection reliability.

8. The method according to claim 1 , wherein each of the plurality of proxy connections comprises unique characteristics that allow for testing proxy capabilities of a resource and its response to proxy connections of varying characteristics.

9. The method of claim 1 , further comprising:

evaluating the collected information to obtain circumstantial or indirect information that is indicative of the entity;

cross referencing data in the collected information to confirm or infer that the entity is referenced in the circumstantial or indirect information that is indicative of the entity being referenced in the circumstantial or indirect information;

automatically determining a change or a setting to at least one element of policy criteria of a cyber security policy;

providing one or more of the recommended computer network changes to reduce the assessed cyber risk, enactment by the entity of at least one of the one or more of the recommended computer network changes to reduce the assessed cyber risk to the entity;

determining that the entity has enacted at least a portion of the recommended computer network changes, and in response, automatically reassessing the cyber risk in the computer network of the entity based on the enacted recommended computer network changes; and

dynamically re-determining, based on the reassessed cyber risk in the computer network of the entity, the change or the setting to the at least one element of policy criteria of the cyber security policy.

10. The method of claim 1 , wherein the cyber risk comprises a cyber attack.

11. The method of claim 1 , wherein the cyber risk comprises a privacy incident involving sensitive information.

12. The method of claim 9 , wherein the cyber risk is assessed using a computer agent configured to collect information from the at least one accessible network element, the computer agent being further configured to perform at least one of collecting information from the computer network of the entity, and analyzing information from the computer network of the entity.

13. The method of claim 9 , further comprising:

based on the assessing of the cyber risk, plotting one or more features of the entity and other members of a peer group of the entity, the plotting being configured to visually illustrate the cyber risk in the computer network of the entity; and

the automatically recommending of computer network changes being based on the plotting.

14. The method of claim 13 , further comprising:

in response to the determining that the entity has enacted at least a portion of the recommended computer network changes, initiating the change or the setting to the at least one element of policy criteria of the cyber security policy.

15. The method of claim 13 , wherein the assessing of the cyber risk further comprises assessing, using a plurality of sophistication elements for the entity, a sophistication for the entity with respect to preventing the cyber risk, the sophistication being one of a plurality of features of the entity.

16. The method of claim 1 , wherein the assessing of the cyber risk further comprises assessing, using a plurality of motivation elements regarding the entity, a motivation of an actor to initiate the cyber risk, the motivation being one of a plurality of features of the entity.

17. The method of claim 1 , wherein the assessing of the cyber risk further comprises:

assessing, using a plurality of sophistication elements for the entity, a sophistication for the entity with respect to preventing the cyber risk, the sophistication being one of a plurality of features of the entity; and

assessing, using a plurality of motivation elements regarding the entity, a motivation of an actor to initiate the cyber risk, the motivation being another one of the plurality of features of the entity.

18. The method of claim 17 , further comprising calculating a composite score from a motivation score and a sophistication score, the motivation score representing the plurality of motivation elements, the sophistication score representing the plurality of sophistication elements.

19. The method of claim 18 , further comprising:

creating an aggregate risk score of a portfolio of entities based on a plurality of motivation scores including the motivation score and a plurality of sophistication scores including the sophistication score; and

benchmarking over time at least one of the sophistication score, the motivation score, the composite score, and the aggregate risk score.

20. The method of claim 9 , further comprising at least one of increasing and decreasing the assessed cyber risk if the circumstantial or indirect information is negative or positive.

21. A method, comprising:

assessing cyber risk in one or more computer networks for an entity, using a computer agent configured to collect information from at least one accessible network element, wherein the assessing of the cyber risk comprises:

evaluating the collected information to obtain circumstantial or indirect information that is indicative of the entity;

cross referencing data in the collected information to confirm or infer that the entity is referenced in the circumstantial or indirect information that is indicative of the entity being referenced in the circumstantial or indirect information;

establishing a plurality of proxy connections with entity resources of the entity;

evaluating performance of the plurality of proxy connections;

scoring the proxy connections based on their performance; and

automatically determining proxy connection changes based on the scoring;

automatically determining, based on the assessed cyber risk, a change or a setting to at least one element of policy criteria of a cyber security policy; and

automatically recommending, based on the assessed cyber risk, computer network changes to reduce the assessed cyber risk.

22. The method of claim 21 , further comprising

providing one or more recommended computer network changes to reduce the assessed cyber risk, enactment by the entity of at least one of the one or more of the recommended computer network changes to reduce the assessed cyber risk to the entity;

determining that the entity has enacted at least a portion of the recommended computer network changes, and in response, automatically reassessing the cyber risk in the computer network of the entity based on the enacted recommended computer network changes; and

dynamically re-determining, based on the reassessed cyber risk in the computer network of the entity, the change or the setting to the at least one element of policy criteria of the cyber security policy.

23. The method of claim 21 , wherein the assessing of cyber risk further comprises at least one of increasing and decreasing the assessed cyber risk if the circumstantial or indirect information is negative or positive.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNMENT EXECUTION DATE FROM 10/05/2017 TO 04/01/2018 PREVIOUSLY RECORDED ON REEL 45716 FRAME 282. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 23, 2025
From: CYENCE LLC
To: GUIDEWIRE SOFTWARE, INC.
Reel/Frame 071370/0481 →
PATENT SECURITY AGREEMENT Recorded Dec 3, 2024
From: GUIDEWIRE SOFTWARE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 069476/0488 →
MERGER Recorded May 4, 2018
From: CYENCE INC.
To: CAESAR ACQUISITION SUB II, LLC
Reel/Frame 045716/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2018
From: CYENCE LLC
To: GUIDEWIRE SOFTWARE, INC.
Reel/Frame 045716/0282 →
CHANGE OF NAME Recorded May 4, 2018
From: CAESAR ACQUISITION SUB II, LLC
To: CYENCE LLC
Reel/Frame 046080/0138 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2018
From: NG, GEORGE Y.; MA, DON; OOI, YUEN-TSING; ZHANG, FEIYIN; TANCIOCO, FERNANDO, JR.
To: CYENCE INC.
Reel/Frame 045468/0256 →
Continuity (7)
Continuation In Part 15141779 · Apr 28, 2016
Continuation In Part 14931510 · Nov 3, 2015
Continuation In Part 14585051 · Dec 29, 2014
Continuation In Part PCTUS2015067968 · Dec 29, 2015
Continuation 14614897 · Feb 5, 2015
Provisional Application 62098238 · Dec 30, 2014
Related Publication 20170093904A1 · Mar 30, 2017