IP Library Granted Patent US 10,491,623
Granted Patent B2
US 10,491,623 · App. 15/401,691 · Granted Nov 26, 2019

Social network security monitoring

Inventors: James C. Foster (Baltimore, MD); Evan Blair (Baltimore, MD); Christopher B. Cullison (Westminster, MD); Robert Francis (Baltimore, MD)
Assignee: ZeroFOX, Inc.
H04L63/1433G06F21/316G06Q10/0635H04L63/102H04L63/1425G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,491,623
App. No.
15/401,691
Granted
Nov 26, 2019
Kind
B2
Abstract

A computer-implemented method includes security settings data associated with one or more profiles of a protected social entity on one or more social networks is scanned, and the security settings data associated with the one or more profiles of the protected social entity is assessed. A first security risk score for the protected social entity is determined based on the assessment of the security settings data, and the first security risk score is provided to the protected social entity.

Claims (73)

1. A computer-implemented method for providing risk assessment data comprising:

receiving, a security analysis module and from a user device of one or more employees of a company, authorization to access security data, wherein the security data is private data that controls access to one or more social network profiles of the one or more employees of the company;

accessing, by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of the company;

determining, by the security analysis module, using a scoring algorithm, a security risk score for the company based on evaluating the security data associated with the one or more social network profiles of one or more employees of a company;

providing the determined security risk score to a user device of an entity associated with the company;

monitoring, on a continuous basis by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of a company for changes to the security data that alter a level of security to access the one or more social network profiles of the one or more employees of the company;

updating, by the security analysis module, the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company;

comparing, by the security analysis module, the updated security risk score to a risk score threshold;

generating, by the security analysis module, an alert based on the security risk score exceeding the risk score threshold;

providing, by the security analysis module, the alert to the user device of the employee of the company associated with the changes to the security data;

storing, for each of the updated security risk scores, the updated security risk score, a timestamp, the risk score threshold, and a reason for generating the updated security risk score;

generating, by the security analysis module, a historical list of security risk scores based on the stored updated security risk scores; and

providing the company access to the historical list of security risk scores via a social protection tool platform.

2. The method of claim 1 , further comprising:

determining one or more changes to the security data that lowers the updated security risk score; and

providing, to a user device of the employee associated with the changes to the security data, one or more changes to the security data that lowers the updated security risk score.

3. The method of claim 1 , wherein updating the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company comprises, updating the security risk score for the company based on security policy changes made by a social network.

4. The method of claim 1 wherein updating the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company comprises, updating the security risk score for the company based on changes made by one or more of the employees.

5. The method of claim 1 wherein determining a security risk score for the company based on evaluating the security data associated with one or more social network profiles of one or more employees of a company using a scoring algorithm comprises;

determining a security risk score for each of the one or more employees of the company using a first scoring algorithm; and

determining the security risk score for the company based on a weighted average of the security risk scores for each of the one or more employees of the company.

6. The method of claim 1 further comprising:

receiving from the entity associated with the company, one or more profile attributes to monitor; and

monitoring the one or more profiles of the employees of the company for changes to the one or more profile attributes.

7. The method of claim 6 further comprising:

identifying a change to one or more of the profile attributes; and

based on identifying a change, generating an alert to the entity associated with the company.

8. A system comprising:

one or more processing devices; and

one or more non-transitory computer-readable media coupled to the one or more processing devices having instructions stored thereon which, when executed by the one or more processing devices, cause the one or more processing devices to perform operations comprising:

receiving, by a security analysis module and from a user device of one or more employees of a company, authorization to access security data, wherein the security data is private data that controls access to one or more social network profiles of the one or more employees of the company;

accessing, by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of the company;

determining, by the security analysis module, using a scoring algorithm, a security risk score for the company based on evaluating the security data associated with the one or more social network profiles of one or more employees of a company;

providing the determined security risk score to a user device of an entity associated with the company;

monitoring, on a continuous basis by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of a company for changes to the security data that alters a level of security to access the one or more social network profiles of the one or more employees of the company;

updating, by the security analysis module, the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company;

comparing, by the security analysis module, the updated security risk score to a risk score threshold;

generating, by the security analysis module, an alert based on the security risk score exceeding the risk score threshold;

providing, by the security analysis module, the alert to the user device of the employee of the company associated with the changes to the security data;

storing, for each of the updated security risk scores, the updated security risk score, a timestamp, the risk score threshold, and a reason for generating the updated security risk score;

generating, by the security analysis module, a historical list of security risk scores based on the stored updated security risk scores; and

providing the company access to the historical list of security risk scores via a social protection tool platform.

9. The system of claim 8 further comprising:

determining one or more changes to the security data that lowers the updated security risk score; and

providing, to a user device of the employee associated with the changes to the security data, one or more changes to the security data that lowers the security risk score.

10. The system of claim 8 wherein updating the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company comprises, updating the security risk score for the company based security policy on changes made by a social network.

11. The system of claim 8 wherein updating the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company comprises, updating the security risk score for the company based on changes made by one or more of the employees.

12. The system of claim 8 wherein determining a security risk score for the company based on evaluating the security data associated with one or more social network profiles of one or more employees of a company using a scoring algorithm comprises;

determining a security risk score for each of the one or more employees of the company using a first scoring algorithm; and

determining the security risk score for the company based on a weighted average of the security risk scores for each of the one or more employees of the company.

13. The system of claim 8 further comprising:

receiving from the entity associated with the company, one or more profile attributes to monitor; and

monitoring the one or more profiles of the employees of the company for changes to the one or more profile attributes.

14. The system of claim 13 further comprising:

identifying a change to one or more of the profile attributes; and

based on identifying a change, generating an alert to the entity associated with the company.

15. A non-transitory computer-readable storage medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

receiving, by a security analysis module and from a user device of one or more employees of a company, authorization to access security data, wherein the security data is private data that controls access to one or more social network profiles of the one or more employees of the company;

accessing, by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of the company;

determining, by the security analysis module, using a scoring algorithm, a security risk score for the company based on evaluating the security data associated with the one or more social network profiles of one or more employees of a company;

providing the determined security risk score to a user device of an entity associated with the company;

monitoring, on a continuous basis by the security analysis module, the security data associated with the one or more social network profiles of one or more employees of a company for changes to the security data that alter a level of security to access the one or more social network profiles of the one or more employees of the company;

updating, by the security analysis module, the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company;

comparing, by the security analysis module, the updated security risk score to a risk score threshold;

generating, by the security analysis module, an alert based on the security risk score exceeding the risk score threshold;

providing, by the security analysis module, the alert to the user device of the employee of the company associated with the changes to the security data;

storing, for each of the updated security risk scores, the updated security risk score, a timestamp, the risk score threshold, and a reason for generating the updated security risk score;

generating, by the security analysis module, a historical list of security risk scores based on the stored updated security risk scores; and

providing the company access to the historical list of security risk scores via a social protection tool platform.

16. The medium of claim 15 further comprising:

determining one or more changes to the security data that lowers the security risk score; and

providing, to a user device of the employee associated with the changes to the security data, one or more changes to the security data that lowers the updated security risk score.

17. The medium of claim 15 wherein updating the security risk score for the company based on identifying changes to the security data associated with the one or more social network profiles of the one or more employees of the company comprises, updating the security risk score for the company based on changes made by a social network.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: ZEROFOX, INC.
Reel/Frame 067429/0328 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: VIGILANTEATI, INC.
Reel/Frame 060821/0137 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: ZEROFOX, INC.
Reel/Frame 060821/0173 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR AND ASSIGNEE'S INFORMATION ON THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 054878 FRAME: 0117. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 6, 2022
From: HERCULES CAPITAL, INC.
To: ZEROFOX, INC.
Reel/Frame 058652/0754 →
SECURITY INTEREST Recorded Jan 28, 2021
From: ZEROFOX, INC.
To: STIFEL BANK
Reel/Frame 055066/0916 →
SECURITY INTEREST Recorded Jan 13, 2021
From: ZEROFOX, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 054906/0449 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2021
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 054878/0117 →
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2019
From: SILVER LAKE WATERMAN FUND II, L.P.
To: ZEROFOX, INC.
Reel/Frame 049607/0961 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 26, 2019
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 049602/0173 →
SECURITY INTEREST Recorded Jun 1, 2017
From: ZEROFOX, INC.
To: SILVER LAKE WATERMAN FUND II, L.P., AS AGENT
Reel/Frame 042568/0264 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2017
From: FOSTER, JAMES; BLAIR, EVAN; CULLISON, CHRISTOPHER B.; FRANCIS, ROBERT
To: ZEROFOX, INC.
Reel/Frame 040905/0057 →