IP Library Granted Patent US 9,779,253
Granted Patent B2
US 9,779,253 · App. 15/393,089 · Granted Oct 3, 2017

Methods and systems for sharing risk responses to improve the functioning of mobile communications devices

Inventors: Kevin Patrick Mahaffey (San Francisco, CA); Brian James Buck (Livermore, CA); William Robinson (Sunnyvale, CA); John G. Hering (San Francisco, CA); James David Burgess (San Francisco, CA); Timothy Micheal Wyatt (Toronto, CA); David Golombek (Washington, DC); David Luke Richardson (San Francisco, CA); Anthony McKay Lineberry (Oakland, CA); Kyle Barton (San Francisco, CA); Daniel Lee Evans (San Francisco, CA); Ariel Salomon (San Francisco, CA); Jonathan Pantera Grubb (Los Angeles, CA); Bruce Wootton (Alameda, CA); Timothy Strazzere (Oakland, CA); Yogesh Swami (San Francisco, CA)
Assignee: LOOKOUT, INC.
G06F21/577G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,779,253
App. No.
15/393,089
Granted
Oct 3, 2017
Kind
B2
Abstract

Methods and systems are provided for sharing security risk information between collections of computing devices, such as mobile communications devices, to improve the functioning of devices associated with the collections. The methods and systems disclosed may share security risk information by identifying a security risk response by a first collection and then providing the security risk response to a second collection when a relationship database profile for the first collection indicates the security response may be shared with the second collection. Methods and systems are also provided for determining whether to allow a request from an originating device where the request may have been initiated by a remote device.

Claims (88)

1. A method for sharing security risk responses between a plurality of collections to improve the functioning of mobile communications devices associated with at least one collection based on the shared security risk responses, the method comprising:

accessing, by a server security component, a security database including a plurality of security risk responses, each security risk response associated with at least one of the plurality of collections;

identifying, by the server security component, a first security risk response in the security database, wherein the first security risk response was implemented by at least one of the plurality of collections;

determining, by the server security component from the security database, a first collection associated with the first security risk response;

accessing, by the server security component, a relationship database, the relationship database including collection profiles related to the sharing of information between the plurality of collections, the collection profiles including collection attributes;

identifying, by the server security component from information related to the first security risk response in the security database, a set of response attributes of the first security risk response;

identifying, for a second collection, a set of collection attributes that are similar to response attributes in set of response attributes;

receiving, by the server security component, a response attribute value for each response attribute in the set of response attributes;

assigning, by the server security component, a collection attribute value to each of the attributes in the set of collection attributes, wherein the collection attribute values are assigned to a collection attribute based on the response attribute value of the similar corresponding response attribute in the set of response attributes;

summing, by the server security component, the assigned collection attribute values; and,

providing, by the server security component, the first security risk response to the second collection:

(i) when a first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; and

(ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value.

2. The method of claim 1 , wherein the first security response was initiated from a first administrator device associated with a first administrator of the first collection and wherein the providing the first security risk response to the second collection includes providing the first security risk response to a second administrator device associated with a second administrator of the second collection.

3. The method of claim 1 , wherein the first security risk response was implemented in response to a first security risk type and wherein information related to the first security risk response includes information related to the first security risk type, the method further including:

determining, by the server security component from the security database information, a third collection, the third collection having implemented a second security risk response in response to the first security risk type;

accessing, by the server security component, the relationship database; and,

providing, by the server security component, the second security risk response to the second collection when a third collection profile indicates that the third collection permits information related to the second security risk response to be provided to the second collection.

4. The method of claim 3 , further including providing, by the server security component, information related to the first security risk type to the second collection, the information related to the first security risk type including statistical information relating to the prevalence or propagation of the risk type, the statistical information derived from the security database.

5. The method of claim 1 , wherein the security database includes risk information acquired in part from device security components on mobile communications devices, wherein the mobile communications devices are associated with at least one collection of the plurality of collections, wherein the device security components send risk information related to security risk responses to the server security component, and wherein the server security component is associated with a platform, the platform associated with an entity separate from any of the plurality of collections.

6. The method of claim 1 further comprising:

determining, for the set of collection attributes, the number of collection attributes in the set collection attributes,

wherein the providing, by the server security component, the first security risk response to the second collection includes providing, by the server security component, the first security risk response to the second collection:

(i) when the first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection;

(ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value; and

(iii) when the determined number of collection attributes in the set of collection attributes equals or exceeds a threshold number.

7. The method of claim 6 , wherein the response attributes include attributes related to at least one of a risk, a mobile communications device, a collection, or a software, and wherein the collection attributes include attributes related to at least one of a collection of the plurality, the mobile communications devices of a collection, or a software of the collection.

8. The method of claim 1 ,

wherein the relationship database further includes relationship information related to the sharing of levels of information between the plurality of collections,

wherein the first security risk response includes information of a first level and information of a second level, and

wherein providing, by the server security component, the first security risk response to the second collection includes:

providing, by the server security component, the first level information to the second collection and not providing the second level information to the second collection:

(i) when the first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection;

(ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value; and

(iii) when the first collection profile indicates that the first collection permits the first level information to be provided to the second collection and does not permit the second level information to be provide to the second collection.

9. The method of claim 1 , wherein the identified first security risk response includes a response to a detected security risk event, and wherein the detected security risk event was detected by a device security component on a mobile communications device associated with the first collection.

10. The method of claim 1 , wherein the identified first security risk response includes a response to a detected security risk event, and wherein the detected security risk event was detected by the server security component based on an analysis of the security database information.

11. The method of claim 1 , wherein the second collection automatically implements the first security risk response.

12. A method for sharing security risk responses between a plurality of collections to improve the functioning of computing devices associated with at least one collection based on the shared security risk responses, the method comprising:

accessing, by a server security component, a security database including information useful for detecting security risk events associated with mobile communications devices;

detecting, by the server security component based on the security database information, a security risk event associated with at least one mobile communications device, wherein the at least one mobile communications device is associated with a first collection;

notifying, by the server security component, the first collection of the detected security risk event;

determining, by the server security component, a first security risk response of the first collection to the detected security risk event;

accessing, by the server security component, a relationship database, the relationship database including collection profiles related to the sharing of information between the plurality of collections, the collection profiles include collection attributes;

identifying, by the server security component from information related to the first security risk response in the security database, a set of response attributes of the first security risk response;

identifying, for a second collection, a set of collection attributes that are similar to response attributes in the set of response attributes;

receiving, by the server security component, a response attribute value for each response attribute in the set of response attributes;

assigning, by the server security component, a collection attribute value to each of the attributes in the set of collection attributes, wherein the collection attribute values are assigned to a collection attribute based on the response attribute value of the similar corresponding response attribute in the set of response attributes;

summing, by the server security component, the assigned collection attribute values; and,

providing, by the server security component, the first security risk response to the second collection:

(i) when a first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; and

(ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value.

13. The method of claim 12 , wherein the notifying step includes the server security component providing a notification to a first administrator device associated with a first administrator of the first collection, and wherein the first security risk response was initiated by the first administrator, and wherein the providing step includes the server security component providing the first security risk response to a second administrator device associated with a second administrator of the second collection.

14. The method of claim 12 , wherein the step of determining a first security risk response includes determining, by the server security component, the first security risk response of the first collection to the detected security risk event based on the server security component receiving a notice of the first security risk response.

15. The method of claim 12 , wherein the step of determining a first security risk response includes determining, by the server security component, the first security risk response of the first collection to the detected security risk event based on an analysis of information in the security database.

16. A method for sharing security risk responses between a plurality of collections to improve the functioning of mobile communications devices associated with at least one collection based on the shared security risk responses, the method comprising:

accessing, by a server security component, a security database including information useful for detecting security risk events associated with mobile communications devices;

determining, by the server security component from the security database information, a security risk event detected by a device security component on a first mobile communications device;

determining, by the server security component from the security database information, a first collection associated with the first mobile communications device;

accessing, by the server security component, a relationship database, the relationship database including collection profiles related to the sharing of information between the plurality of collections, the collection profiles including collection attributes;

determining, by the server security component from a first collection profile, that the first collection permits information related to the detected security risk event to be provided to a first set of at least one collection of the plurality;

providing, by the server security component, information related to the detected security risk event to the first set of at least one collection;

determining, by the server security component, a first security risk response to the detected security risk event from a second collection of the first set of at least one collection;

accessing, by the server security component, the relationship database;

identifying, by the server security component from information related to the first security risk response in the security database, a set of response attributes of the first security risk response;

identifying, for a second set of at least one collection, a set of collection attributes that are similar to response attributes in set of response attributes;

receiving, by the server security component, a response attribute value for each response attribute in the set of response attributes;

assigning, by the server security component, a collection attribute value to each of the attributes in the set of collection attributes, wherein the collection attribute values are assigned to a collection attribute based on the response attribute value of the similar corresponding response attribute in the set of response attributes;

summing, by the server security component, the assigned collection attribute values; and

providing, by the server security component, information related to the first security risk response to the second set of at least one collection:

(i) when the server security component determines from the second collection profile that the second collection permits information related to the first security risk response to be provided to the second set of at least one collection; and

(ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value.

17. The method of claim 16 , wherein providing information related to the detected security risk event to the first set includes providing, for each collection of the first set, information related to the detected security risk event to a computing device associated with an administrator of the collection, and wherein providing information related to the first security risk response to a second set includes providing, for each collection of the second set, information related to the first security risk response to an administrator of the collection.

18. The method of claim 16 , wherein the step of determining a first security risk response to the detected security risk event includes determining, by the server security component, the first security risk response of the second collection to the detected security risk event based on an analysis of information in the security database.

19. The method of claim 16 , wherein the determined first security risk response was provided from the second collection to a set of available risk responses, the set of available risk responses being stored in the security database, and wherein the step of determining a first security risk response includes accessing the set of available risk responses.

20. A method for sharing security risk responses between a plurality of collections to improve the functioning of mobile communications devices associated with at least one collection based on the shared security risk responses, the method comprising:

accessing, by a server security component, a security database including a plurality of security risk responses, each security risk response associated with at least one of the plurality of collections;

identifying, by the server security component, a first security risk response in the security database, wherein the first security risk response was implemented by at least one of the plurality of collections;

determining, by the server security component from the security database, a first collection associated with the first security risk response;

accessing, by the server security component, a relationship database, the relationship database including collection profiles related to the sharing of information between the plurality of collections, the collection profiles including collection attributes;

identifying, by the server security component from information related to the first security risk response in the security database, a set of response attributes of the first security risk response;

identifying, for a second collection, a set of collection attributes that are similar to response attributes in set of response attributes;

receiving, by the server security component, a response attribute value for each response attribute in the set of response attributes;

assigning, by the server security component, a collection attribute value to each of the attributes in the set of collection attributes, wherein the collection attribute values are assigned to a collection attribute based on the response attribute value of the similar corresponding response attribute in the set of response attributes;

evaluating, by the server security component, the assigned collection attribute values to determine whether the first security risk response is relevant to the second collection; and,

providing, by the server security component, the first security risk response to the second collection:

(i) when a first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; and

(ii) when the evaluation of the assigned collection attribute values indicates the first security risk response is relevant to the second collection.

Assignments (10)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: MAHAFFEY, KEVIN PATRICK; BUCK, BRIAN JAMES; ROBINSON, WILLIAM; HERING, JOHN G.; BURGESS, JAMES DAVID; WYATT, TIMOTHY MICHEAL; GOLOMBEK, DAVID; RICHARDSON, DAVID LUKE; LINEBERRY, ANTHONY MCKAY; BARTON, KYLE; EVANS, DANIEL LEE; SALOMON, ARIEL; GRUBB, JONATHAN PANTERA; WOOTTON, BRUCE; STRAZZERE, TIMOTHY; SWAMI, YOGESH
To: LOOKOUT, INC.
Reel/Frame 064875/0481 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
Continuity (37)
Continuation 14973636 · Dec 17, 2015
Continuation In Part 14473917 · Aug 29, 2014
Continuation 13790402 · Mar 8, 2013
Continuation 13267731 · Oct 6, 2011
Continuation 12255635 · Oct 21, 2008
Continuation In Part 14634115 · Feb 27, 2015
Continuation 14034320 · Sep 23, 2013
Continuation 13742110 · Jan 15, 2013
Continuation 13314032 · Dec 7, 2011
Continuation 12255632 · Oct 21, 2008
Continuation In Part 14455787 · Aug 8, 2014
Continuation 13741988 · Jan 15, 2013
Continuation 13333654 · Dec 21, 2011
Continuation 12255621 · Oct 21, 2008
Continuation In Part 14318450 · Jun 27, 2014
Continuation 13689588 · Nov 29, 2012
Continuation 12868669 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 14688292 · Apr 16, 2015
Continuation 13958434 · Aug 2, 2013
Continuation 12868672 · Aug 25, 2010
Continuation 12255621 · Oct 21, 2008
Continuation In Part 13896852 · May 17, 2013
Continuation 12868676 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 14611063 · Jan 30, 2015
Continuation 13033025 · Feb 23, 2011
Continuation In Part 12868669 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 13335779 · Dec 22, 2011
Continuation In Part 12868676 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Continuation In Part 14692669 · Apr 21, 2015
Division 13484132 · May 30, 2012
Continuation In Part 12868672 · Aug 25, 2010
Continuation In Part 12255621 · Oct 21, 2008
Related Publication 20170103215A1 · Apr 13, 2017