IP Library Patent Application 15990739
Patent Application
App. No. 15/990,739

SYSTEMS AND METHODS FOR DETERMINING THE EFFICACY OF COMPUTER SYSTEM SECURITY POLICIES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/990,739
Abstract

Systems and methods for determining the efficacy of security measures taken for a computer system are disclosed. Exemplary implementations may: determine a set of risk parameters of the computing system; collect sets of values of the security parameters at various times and determine the efficacy adjustments based on a comparison of the sets of values and an elapsed time between collection of the sets of values.

Claims (52)

1 . A system configured for determining the efficacy of a security policy, the security policy defining procedures to be taken by an organization for managing risk of a computing environment and a desired state of the computing environment resulting from the procedures, the system comprising:

one or more hardware processors configured by machine-readable instructions to:

determine a set of risk management parameters which indicate a state of the computing environment, wherein the computing environment includes multiple computing systems and wherein the set of risk management parameters is determined based on at least one of the procedures;

collect a first set of values of the risk management parameters of the computing environment at a first time t 1 ;

determine, based on the first set of values of the risk management parameters that at least one of the procedures has not resulted in the desired state of the computing environment defined in the security policy and thus there is a cyber risk management problem relating to the computing environment;

adjust at least one of the procedures of the security policy to create an adjusted security policy and apply the adjusted security policy to the computing environment to address the cyber risk management problem;

collect a second set of values of the risk management parameters of the computing environment at a second time t 2 ;

collect a third set of values of the risk management parameters of the computing environment at a third time t 3 ;

collect a fourth set of values of the risk management parameters of the computing environment at a fourth time t 4 ; and

determine the efficacy of the adjusted security policy based on an algorithm applied to two of the sets of values of the risk management parameters and an elapsed time between collection of two of the sets of values of the risk management parameters.

2 . The system of claim 1 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the first set of values and the second set of values.

3 . The system of claim 1 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the second set of values and one of the third set of values and the fourth set of values.

4 . The system of claim 1 , wherein the time period between successive times is constant.

5 . The system of claim 1 , wherein the time period between successive times varies.

6 . The system of claim 1 , wherein the set of risk management parameters includes parameters related to asset existence, asset value, control conditions, network traffic volume, and/or threat landscape.

7 . The system of claim 1 , wherein the set of risk management parameters includes parameters collected by antivirus technologies, netrecon, netcat technologies, dlp solutions, cmdb technologies, and/or vulnerability scanning technologies.

8 . The system of claim 1 , wherein the algorithm applied to the determine the efficacy of the adjustment varies based on the elapsed time.

9 . A method for determining the efficacy of a security policy, the security policy defining procedures to be taken by an organization for managing risk of a computing environment and a desired state of the computing environment resulting from the procedures, the method comprising:

determining a set of risk management parameters which indicate a state of the computing environment, wherein the computing environment includes multiple computing systems and wherein the set of risk manage management parameters is determined based on at least one of the procedures;

collecting a first set of values of the risk management parameters of the computing environment at a first time t 1 ;

determining, based on the first set of values of the risk management parameters that at least one of the procedures has not resulted in the desired state of the computing environment defined in the security policy and thus there is a cyber risk management problem relating to the computing environment;

adjusting at least one of the procedures of the security policy to create an adjusted security policy and apply the adjusted security policy to the computing environment to address the cyber risk management problem;

collecting a second set of values of the risk management parameters of the computing environment at a second time t 2 ;

collecting a third set of values of the risk management parameters of the computing environment at a third time t 3 ;

collecting a fourth set of values of the risk management parameters of the computing environment at a fourth time t 4 ; and

determining the efficacy of the adjusted security policy based on an algorithm applied to two of the sets of values of the risk management parameters and an elapsed time between collection of two of the sets of values of the risk management parameters.

10 . The method of claim 9 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the first set of values and the second set of values.

11 . The method of claim 9 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the second set of values and one of the third set of values and the fourth set of values.

12 . The method of claim 9 , wherein the time period between successive times is constant.

13 . The method of claim 9 , wherein the time period between successive times varies.

14 . The method of claim 9 , wherein the set of risk management parameters includes parameters related to asset existence, asset value, control conditions, network traffic volume, and/or threat landscape.

15 . The method of claim 9 , wherein the set of risk management parameters includes parameters collected by antivirus technologies, netrecon, netcat technologies, dlp solutions, cmdb technologies, and/or vulnerability scanning technologies.

16 . The method of claim 9 , wherein the algorithm applied to the determine the efficacy of the adjustment varies based on the elapsed time.

17 . A non-transient computer-readable storage medium having instructions embodied thereon, the instructions being executable by one or more processors to perform a method for determining the efficacy of a security policy, the security policy defining procedures to be taken by organization for a computing environment, the method comprising:

determining a set of risk management parameters which indicate a state of the computing environment, wherein the computing environment includes multiple computing systems and wherein the set of risk management parameters is determined based at least one of the procedures;

collecting a first set of values of the risk management parameters of the computing environment at a first time t 1 ;

determining, based on the first set of values of the risk management parameters that at least one of the procedures has not resulted in the desired state of the computing environment defined in the security policy and thus there is a cyber risk management problem relating to the computing environment;

adjusting at least one of the procedures of the security policy to create an adjusted security policy and apply the adjusted security policy to operating the computing environment to address the cyber risk management problem;

collecting a second set of values of the risk management parameters of the computing environment at a second time t 2 ;

collecting a third set of values of the risk management parameters of the computing environment at a third time t 3 ;

collecting a fourth set of values of the risk management parameters of the computing environment at a fourth time t 4 ; and

determining the efficacy of the adjusted security policy based on an algorithm applied to two of the sets of values of the risk management parameters and an elapsed time between collection of two of the sets of values of the risk management parameters.

18 . The computer-readable storage medium of claim 17 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the first set of values and the second set of values.

19 . The computer-readable storage medium of claim 17 , wherein t 1 is a time that is before the adjustment is made and t 2 is a time after the adjustment is made, t 3 is a time after t 2 and t 4 is after t 3 and wherein the two sets of values are the second set of values and one of the third set of values and the fourth set of values.

20 . The computer-readable storage medium of claim 17 , wherein the time period between successive times is constant.

21 . The computer-readable storage medium of claim 17 , wherein the time period between successive times varies.

22 . The computer-readable storage medium of claim 17 , wherein the set of risk management parameters includes parameters related to asset existence, asset value, control conditions, network traffic volume, and/or threat landscape.

23 . The computer-readable storage medium of claim 17 , wherein the set of risk management parameters includes parameters collected by antivirus technologies, netrecon, netcat technologies, dlp solutions, cmdb technologies, and/or vulnerability scanning technologies.

24 . The computer-readable storage medium of claim 17 , wherein the algorithm applied to the determine the efficacy of the adjustment varies based on the elapsed time.

25 . The system of claim 1 , wherein the risk management problem includes patching compliance levels, security education and awareness levels, malware infections, detected attacks, lost devices, number of open “high risk” audit findings, and/or on-time remediation of audit findings.

26 . The method of claim 9 , wherein the risk management problem includes patching compliance levels, security education and awareness levels, malware infections, detected attacks, lost devices, number of open “high risk” audit findings, and/or on-time remediation of audit findings

27 . The computer-readable storage medium of claim 17 , wherein the risk management problem includes patching compliance levels, security education and awareness levels, malware infections, detected attacks, lost devices, number of open “high risk” audit findings, and/or on-time remediation of audit findings

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 17, 2023
From: RCF3, LLC
To: RISKLENS, INC.
Reel/Frame 064285/0528 →
RELEASE OF SECURITY INTEREST Recorded Jul 13, 2023
From: PACIFIC WESTERN BANK
To: RISKLENS, INC.
Reel/Frame 064247/0485 →
SECURITY INTEREST Recorded May 8, 2023
From: RISKLENS, INC.
To: RCF3, LLC
Reel/Frame 063568/0561 →
SECURITY INTEREST Recorded Jul 13, 2018
From: RISKLENS, INC.
To: PACIFIC WESTERN BANK
Reel/Frame 046345/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2018
From: JONES, JACK
To: RISKLENS, INC.
Reel/Frame 045941/0976 →