IP Library Granted Patent US 10,496,826
Granted Patent B2
US 10,496,826 · App. 15/438,199 · Granted Dec 3, 2019

Device based automated threat detection and response

Inventors: Abhinav Sejpal (Bengaluru, IN); Vijayakrishna Bs (Bangalore, IN)
Assignee: Accenture Global Solutions Limited
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,496,826
App. No.
15/438,199
Filed
Feb 21, 2017
Granted
Dec 3, 2019
Kind
B2
Examiner
DINH, MINH
Art Unit
2432
USPC
726/25
Abstract

A device may include one or more processors. The device may communicate with a set of user devices operating a set of mobile applications to obtain data regarding a set of malicious attacks associated with the set of user devices. The device may store the data regarding the set of malicious attacks via a data structure for analysis. The device may process the stored data to identify one or more vulnerabilities associated with the set of user devices or the set of mobile applications. The device may generate a security tool user interface that includes information identifying the one or more vulnerabilities associated with the set of user devices or the set of mobile applications. The device may cause the security tool user interface to be provided for display via a client device based on generating the security tool user interface.

Claims (94)

1. A device, comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, to:

communicate with a set of user devices operating a set of mobile applications to obtain data regarding a set of malicious attacks associated with the set of user devices;

store the data regarding the set of malicious attacks via a data structure for analysis;

process the stored data to identify one or more vulnerabilities associated with the set of user devices or the set of mobile applications;

generate a security tool user interface that includes information identifying the one or more vulnerabilities associated with the set of user devices or the set of mobile applications,

the security tool user interface including information identifying a risk assessment score relating to the one or more vulnerabilities,

the security tool user interface including information associated with performing one or more response actions to improve the risk assessment score;

cause the security tool user interface to be provided for display via a client device based on generating the security tool user interface;

generate a recommendation relating to improving the risk assessment score based on processing the stored data,

the recommendation relating to a modification to the set of mobile applications;

communicate with one or more other devices to create an updated version of the set of mobile applications by modifying program code of the set of mobile applications; and

communicate with the set of user devices to provide the updated version of the set of mobile applications.

2. The device of claim 1 , where the one or more processors are further to:

classify a malicious attack, of the set of malicious attacks, based on a channel of the malicious attack, an attack signature of the malicious attack, a pattern of the malicious attack, or a source of the malicious attack; and

include, in the security tool user interface, information identifying the malicious attack based on classifying the malicious attack.

3. The device of claim 1 , where the one or more processors are further to:

include, in the security tool user interface, the recommendation relating to improving the risk assessment score.

4. The device of claim 1 , where the recommendation relates to implementation of an incident response plan; and

where the one or more processors, when communicating with the one or more other devices, are to:

communicate with the one or more other devices to identify the incident response plan; and

communicate with the one or more other devices as a response to detecting a trigger relating to the incident response plan to provide a notification relating to the trigger.

5. The device of claim 1 , where the one or more processors, when processing the stored data to identify the one or more vulnerabilities, are to:

determine that a user device, of the set of user devices, is associated with at least one of:

a root based vulnerability,

a jailbreak based vulnerability,

a data security based vulnerability,

a network connection based vulnerability,

an operating system based vulnerability, or

a mobile application based vulnerability.

6. The device of claim 1 , where the one or more processors are further to:

cause, based on a user interaction with a user interface element of the security tool user interface, a software development kit (SDK) to be downloaded to a mobile application of the set of mobile applications.

7. The device of claim 6 , where the one or more processors are further to:

cause, based on the user interaction with the user interface element of the security tool user interface, the SDK to be loaded into an integrated development environment (IDE) associated with the mobile application.

8. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

configure monitoring of a set of user devices using a mobile application;

communicate with the set of user devices using the mobile application to obtain data regarding a set of malicious attacks associated with the set of user devices;

store the data regarding the set of malicious attacks via a data structure for analysis;

process the stored data to identify one or more vulnerabilities associated with the set of user devices or the mobile application;

generate a security tool user interface that includes information identifying the one or more vulnerabilities associated with the set of user devices or the mobile application,

the security tool user interface including information identifying a risk assessment score relating to the one or more vulnerabilities,

the security tool user interface including information associated with performing one or more response actions to improve the risk assessment score;

cause the security tool user interface to be provided for display via a client device based on generating the security tool user interface;

generate a recommendation relating to improving the risk assessment score based on processing the stored data,

the recommendation relating to a modification to the mobile application;

communicate with one or more other devices to create an updated version of the mobile application by modifying program code of the mobile applications; and

communicate with the set of user devices to provide the updated version of the mobile application.

9. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

classify a malicious attack, of the set of malicious attacks, based on a channel of the malicious attack, a pattern of the malicious attack, or a source of the malicious attack; and

include, in the security tool user interface, information identifying the malicious attack based on classifying the malicious attack.

10. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, cause the one or more processors to:

include, in the security tool user interface, the recommendation relating to reducing the risk assessment score.

11. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, cause the one or more processors to:

provide a configuration user interface for display via the client device to configure the monitoring of the set of user devices.

12. The non-transitory computer-readable medium of claim 8 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

cause, based on a user interaction with a user interface element of the security tool user interface, a software development kit (SDK) to be downloaded to the mobile application; and

cause, based on the user interaction with the user interface element of the security tool user interface, the SDK to be loaded into an integrated development environment (IDE) associated with the mobile application.

13. A method, comprising:

communicating, by a device, with a set of user devices operating a set of mobile applications to obtain data regarding a set of malicious attacks associated with the set of user devices;

storing, by the device, the data regarding the set of malicious attacks via a data structure for analysis;

processing, by the device, the stored data to identify one or more vulnerabilities associated with the set of user devices or the set of mobile applications;

generating, by the device, a security tool user interface that includes information identifying the one or more vulnerabilities associated with the set of user devices or the set of mobile applications,

the security tool user interface including information identifying a risk assessment score relating to the one or more vulnerabilities, and

the security tool user interface including information associated with performing one or more response actions to improve the risk assessment score;

causing, by the device, the security tool user interface to be provided for display via a client device based on generating the security tool user interface;

generating, by the device, a recommendation relating to improving the risk assessment score based on processing the stored data,

the recommendation relating to a modification to the set of mobile applications;

communicating, by the device, with one or more other devices to create an updated version of the set of mobile applications by modifying program code of the set of mobile applications; and

communicating, by the device, with the set of user devices to provide the updated version of the set of mobile applications.

14. The method of claim 13 , further comprising:

classifying a malicious attack, of the set of malicious attacks, based on a channel of the malicious attack, an attack signature of the malicious attack, a pattern of the malicious attack, or a source of the malicious attack; and

including, in the security tool user interface, information identifying the malicious attack based on classifying the malicious attack.

15. The method of claim 13 , further comprising:

including, in the security tool user interface, the recommendation relating to improving the risk assessment score.

16. The method of claim 13 , where the recommendation relates to implementation of an incident response plan; and

where communicating with the one or more other devices comprises:

communicating with the one or more other devices to identify the incident response plan; and

communicating with the one or more other devices as a response to detecting a trigger relating to the incident response plan to provide a notification relating to the trigger.

17. The method of claim 13 , where processing the stored data to identify the one or more vulnerabilities comprises:

determining that a user device, of the set of user devices, is associated with at least one of:

a root based vulnerability,

a jailbreak based vulnerability,

a data security based vulnerability,

a network connection based vulnerability,

an operating system based vulnerability, or

a mobile application based vulnerability.

18. The method of claim 13 , further comprising:

providing a configuration user interface for display via the client device to configure monitoring of the set of user devices.

19. The method of claim 13 , further comprising:

causing, based on user interaction with a user interface element of the security tool user interface, a software development kit (SDK) to be downloaded to a mobile application of the set of mobile applications.

20. The method of claim 19 , further comprising:

causing, based on the user interaction with the user interface element of the security tool user interface, the SDK to be loaded into an integrated development environment (IDE) associated with the mobile application.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA TO CORRECTLY READ ACCENTURE GLOBAL SOLUTIONS LIMITED PREVIOUSLY RECORDED ON REEL 041321 FRAME 0011. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 22, 2020
From: SEJPAL, ABHINAV; BS, VIJAYAKRISHNA
To: ACCENTURE GLOBAL SOLUTIONS LIMITED
Reel/Frame 051668/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2017
From: SEJPAL, ABHINAV; BS, VIJAYAKRISHNA
To: ACCENTURE GLOBAL SOLUTION LIMITED
Reel/Frame 041321/0011 →
Priority Claims (1)
IN 201641005995 · Feb 22, 2016 · national
Continuity (1)
Related Publication 20170243009A1 · Aug 24, 2017