IP Library Granted Patent US 10,721,263
Granted Patent B2
US 10,721,263 · App. 15/981,702 · Granted Jul 21, 2020

Systems for network risk assessment including processing of user access rights associated with a network of devices

Inventors: Miles Seiver (Los Altos Hills, CA); Stephen Cohen (Palo Alto, CA)
Assignee: Palantir Technologies Inc.
H04L63/1433G06F21/577H04L29/06585H04L41/0853H04L41/0866H04L41/12H04L43/0876H04L45/02H04L63/10H04L63/101H04L63/102H04L63/1416H04L63/1466H04W12/08H04W84/005H04L43/12H04L2012/5609H04L2012/5623
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,263
App. No.
15/981,702
Granted
Jul 21, 2020
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for network risk assessment. One of the methods includes obtaining information describing network traffic between a plurality of network devices within a network. A network topology of the network is determined based on the information describing network traffic, with the network topology including nodes connected by an edge to one or more other nodes, and with each node being associated with one or more network devices. Indications of user access rights of users are associated to respective nodes included in the network topology. User interface data associated with the network topology is generated.

Claims (42)

1. A computerized method comprising:

determining, by a system of one or more computers, respective compromise risks of network devices associated with a network;

causing presentation, via an interactive user interface, of visual representations of the network devices, each visual representation being visually adjusted according to one or more of the determined compromise risks,

wherein each visual representation is visually adjusted based on user specified thresholds associated with compromise risks; and

receiving, by the system, user selection of a visual representation, and updating the user interface to present detailed information describing the one or more compromise risks associated with the selected visual representation.

2. The computerized method of claim 1 , wherein each visual representation is associated with one or more network devices, and wherein the visual representation is visually adjusted based on the compromise risks of the network devices.

3. The computerized method of claim 2 , wherein a particular visual representation is visually adjusted based on a highest compromise risk of the one or more network devices associated with the particular visual representation.

4. The computerized method of claim 1 , wherein adjusting a visual representation according to one or more compromise risks comprises:

selecting a color of a plurality of colors based on the compromise risks; and

causing presentation, via the interactive user interface, of the visual representation presented according to the selected color.

5. The computerized method of claim 1 , wherein adjusting a visual representation according to one or more compromise risks comprises:

selecting a pattern of a plurality of patterns based on the compromise risks; and

causing presentation, via the interactive user interface, of the visual representation presented according to the selected pattern.

6. The computerized method of claim 1 , wherein each visual representation is visually adjusted based on user specified thresholds of values of compromise risks.

7. The computerized method of claim 1 , wherein determining the compromise risk for a particular network device is based on aggregated Common Vulnerability Scoring System (CVSS) values associated with the particular network device.

8. The computerized method of claim 1 , wherein each visual representation is associated with one or more network devices belonging to a same subnet.

9. A system comprising one or more computer systems and one or more computer storage media storing instructions that when executed by the computer systems cause the computer systems to perform operations comprising:

determining, by the system configured to be in communication with a network, respective compromise risks of network devices associated with the network;

causing presentation, via an interactive user interface, of visual representations of the network devices, each visual representation being visually adjusted according to one or more of the determined compromise risks,

wherein each visual representation is visually adjusted based on user specified thresholds associated with compromise risks; and

receiving, by the system, user selection of a visual representation, and updating the user interface to present detailed information describing the one or more compromise risks associated with the selected visual representation.

10. The system of claim 9 , wherein each visual representation is associated with one or more network devices, and wherein the visual representation is visually adjusted based on a highest compromise risk of the one or more network devices associated with the visual representation.

11. The system of claim 9 , wherein adjusting a visual representation according to one or more compromise risks comprises:

selecting a color of a plurality of colors based on the compromise risks; and

causing presentation, via the interactive user interface, of the visual representation presented according to the selected color.

12. The system of claim 9 , wherein adjusting a visual representation according to one or more compromise risks comprises:

selecting a pattern of a plurality of patterns based on the compromise risks; and

causing presentation, via the interactive user interface, of the visual representation presented according to the selected pattern.

13. The system of claim 9 , wherein each visual representation is visually adjusted based on user specified thresholds of values of compromise risks.

14. The system of claim 9 , wherein determining the compromise risk for a particular network device is based on aggregated Common Vulnerability Scoring System (CVSS) values associated with the particular network device.

15. The system of claim 9 , wherein each visual representation is associated with one or more network devices belonging to a same subnet.

16. Non-transitory computer storage media storing instruction that when executed by a system of one or more computers, cause the one or more computers to perform operations comprising:

determining, by the system configured to be in communication with a network, respective compromise risks of network devices associated with the network;

causing presentation, via an interactive user interface, of visual representations of the network devices, each visual representation being visually adjusted according to one or more of the determined compromise risks,

wherein each visual representation is visually adjusted based on user specified thresholds associated with compromise risks; and

receiving, by the system, user selection of a visual representation, and updating the user interface to present detailed information describing the one or more compromise risks associated with the selected visual representation.

17. The computer storage media of claim 16 , wherein adjusting a visual representation according to one or more compromise risks comprises:

selecting a color of a plurality of colors based on the compromise risks or selecting a pattern of a plurality of patterns based on the compromise risks; and

causing presentation, via the interactive user interface, of the visual representation presented according to the selected color or according to the selected pattern.

18. The computer storage media of claim 16 , wherein each visual representation is visually adjusted based on user specified thresholds of values of compromise risks.

19. The computer storage media of claim 16 , wherein determining the compromise risk for a particular network device is based on aggregated Common Vulnerability Scoring System (CVSS) values associated with the particular network device.

20. The computer storage media of claim 16 , wherein each visual representation is associated with one or more network devices belonging to a same subnet.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: SEIVER, MILES; COHEN, STEPHEN
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 064876/0726 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Cited By (1)
US 12,250,243