IP Library Granted Patent US 10,581,896
Granted Patent B2
US 10,581,896 · App. 15/452,861 · Granted Mar 3, 2020

Remedial actions based on user risk assessments

Inventors: Carey Stover Nachenberg (Manhattan Beach, CA); Maxime Lamothe-Brassard (Mountain View, CA); Svetla Yankova Yankova (Mountain View, CA)
Assignee: Chronicle LLC
H04L63/1441G06F21/316G06F21/50G06F21/554G06N20/00H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,581,896
App. No.
15/452,861
Granted
Mar 3, 2020
Kind
B2
Abstract

In some implementations, a method includes receiving, for each of multiple users, user activity data describing actions taken by the user by use of a user device over a period of time, determining, for each user and based on the actions taken by the user over the period of time and user responsibility data that describe responsibilities of the user, a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device, and determining, by the data processing apparatus, for each user and based on the risk assessment determined for the user, whether to implement a user-specific remedial action directed to risk mitigation.

Claims (45)

1. A method comprising:

receiving, at a data processing apparatus and for each of a plurality of users within an organization: (i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein:

the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and

the plurality of users within the organization comprises users having access to data associated with different security risks;

processing, by the data processing apparatus and for each user: (i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; and

determining, by the data processing apparatus, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user.

2. The method of claim 1 , wherein the risk assessment comprises one or more security hygiene scores.

3. The method of claim 1 , wherein the risk assessment comprises one or more security hygiene scores, and determining for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation comprises determining, based on a user action taken by a user by use of the user device, and the one or more security hygiene scores, whether to implement the user-specific remedial action.

4. The method of claim 1 , wherein the risk model comprises a machine learning model, a rule set, or both.

5. The method of claim 1 , wherein the user-specific remedial action includes presenting a message to the user, prompting the user not to take a current user device action.

6. The method of claim 1 , wherein the user-specific remedial action includes presenting a message to the user, informing the user that a current user device action being attempted by the user will not be executed.

7. The method of claim 1 , wherein the user-specific remedial action includes blocking one of: a current user device action being attempted by the user, an activity related to the current user device action, or an activity related to the user's risk assessment.

8. The method of claim 1 , wherein the user-specific remedial action includes presenting a report including the user's risk assessment to the user.

9. The method of claim 1 , further comprising:

for a particular user:

comparing, by the data processing apparatus, the user's risk assessment to risk assessments of other users within the organization;

determining, by the data processing apparatus and based on the comparing, a rank of the user among the users within the organization; and

providing, by the data processing apparatus and to the user, a message including the rank of the user.

10. The method of claim 1 , wherein the user-specific remedial action comprises restricting the user's access to a set of resources.

11. The method of claim 1 , wherein the user-specific remedial action includes presenting a message including a prescriptive recommendation to the user.

12. The method of claim 11 , wherein the prescriptive recommendation includes a suggested next user device action for the user to take.

13. The method of claim 1 , further comprising:

receiving, at the data processing apparatus and for each of the plurality of users within the organization, historical risk assessment data comprising one or more historical risk assessments for the user, wherein each historical risk assessment was generated using the risk model at a respective previous time point;

wherein for each of the plurality of users, using the risk model to generate the risk assessment representative of the security risk resulting from the actions taken by the user by use of the user device comprises:

processing the historical risk assessment data for the user using the risk model to generate the risk assessment for the user.

14. The method of claim 1 , wherein the message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user comprises:

a message requesting that the user provide an explanation for the current user device action being attempted by the user.

15. The method of claim 1 , wherein the message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user comprises:

a message requesting that the user provide confirmation that the current user device action being attempted by the user should be executed.

16. A system comprising:

one or more user devices; and

a remote server, comprising one or more computing devices and connected to the one or more user devices over a network, that performs operations comprising:

receiving, at the remote server and for each of a plurality of users within an organization from the one or more user devices: (i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein:

the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and

the user responsibility data describes different responsibilities for different users within the organization;

processing, by the remote server and for each user: (i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; and

determining, by the remote server, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user.

17. The system of claim 16 , wherein the risk assessment comprises one or more security hygiene scores.

18. A non-transitory computer readable medium storing instructions that when executed by one or more computing devices, cause the one or more computing devices to perform operations comprising:

receiving, at the one or more computing devices and for each of a plurality of users within an organization: (i) user activity data describing a plurality of actions taken by the user by use of a user device over a period of time and risks associated with the actions, and (ii) user responsibility data describing responsibilities of the user within the organization, wherein:

the user responsibility data comprises sensitivity assessment data characterizing a security risk associated with data to which the user has access; and

the user responsibility data describes different responsibilities for different users within the organization;

processing, by the one or more computing devices and for each user: (i) the user activity data describing the actions taken by the user by use of the user device over the period of time and the risks associated with the actions, and (ii) the user responsibility data describing the responsibilities of the user within the organization, using a risk model to generate a risk assessment representative of a security risk resulting from the actions taken by the user by use of the user device; and

determining, by the one or more computing devices, for each user and based on the risk assessment generated for the user, whether to implement a user-specific remedial action directed to risk mitigation, wherein the user-specific remedial action includes presenting a message to the user requesting that the user provide additional input before executing a current user device action being attempted by the user.

19. The non-transitory computer readable medium of claim 18 , wherein the risk assessment comprises one or more security hygiene scores.

Assignments (3)
CHANGE OF NAME Recorded May 22, 2018
From: MAYFIELD PARTNERS LLC
To: CHRONICLE LLC
Reel/Frame 046204/0313 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2018
From: X DEVELOPMENT LLC
To: MAYFIELD PARTNERS LLC
Reel/Frame 045192/0336 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2017
From: NACHENBERG, CAREY STOVER; LAMOTHE-BRASSARD, MAXIME; YANKOVA, SVETLA YANKOVA
To: X DEVELOPMENT LLC
Reel/Frame 041508/0909 →
Continuity (2)
Provisional Application 62440612 · Dec 30, 2016
Related Publication 20180191770A1 · Jul 5, 2018
Cited By (59)
US 12,186,623 US 12,191,018 US 12,191,021 US 12,220,201 US 12,220,202 US 12,224,052 US 12,226,670 US 12,226,671 US 12,230,381 US 12,230,382 US 12,230,383 US 12,246,222 US 12,249,410 US 12,283,356 US 12,285,654 US 12,301,663 US 12,324,961 US 12,327,623 US 12,340,884 US 12,343,180 US 12,347,543 US 12,347,558 US 12,357,195 US 12,367,959 US 12,367,960 US 12,380,984 US 12,380,985 US 12,390,689 US 12,402,804 US 12,402,805 US 12,420,143 US 12,420,145 US 12,424,319 US 12,427,376 US 12,469,587 US 12,478,837 US 12,495,987 US 12,515,104 US 12,537,088 US 12,539,446 US 12,548,656 US 12,555,667 US 12,558,593 US 12,558,594 US 12,562,243 US 12,562,271 US 12,589,279 US 12,592,308 US 12,605,613 US 12,614,622 US 12,616,529 US 12,640,272 US 12,658,301 US 12,658,302 US 12,661,554 US 12,670,978 US 12,708,814 US 12,718,923 US 12,718,927