IP Library Granted Patent US 11,301,568
Granted Patent B1
US 11,301,568 · App. 16/116,490 · Granted Apr 12, 2022

Systems and methods for computing a risk score for stored information

Inventors: Shailesh Dargude (San Jose, CA); Satish Grandhi (Santa Clara, CA); Anand Athavale (San Jose, CA); Rohit Nath (Pune, IN)
Assignee: Veritas Technologies LLC
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,301,568
App. No.
16/116,490
Granted
Apr 12, 2022
Kind
B1
Abstract

The disclosed computer-implemented method for computing a risk score for stored information may include (1) extracting factor-specific information from metadata describing characteristics of files stored on multiple storage devices, (2) assigning at least one respective factor score to at least one respective factor based at least in part on the factor-specific information, and (3) calculating the risk score from the at least one factor score. Various other methods, systems, and computer-readable media are also disclosed.

Claims (74)

1. A computer-implemented method for computing a risk score for stored information, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

extracting, automatically by an extracting module of the computing device, factor-specific information from file metadata, wherein the file metadata describes characteristics of respective files stored on multiple storage devices;

assigning at least one respective factor score to at least one respective factor based at least in part on the factor-specific information, wherein the at least one respective factor comprises a factor indicating permission distance between multiple categories of users who are permitted to access a respective file in the respective files;

calculating the risk score from the at least one factor score; and

automatically limiting access to a sensitive file having a high risk score and that is in the files stored on the multiple storage devices.

2. The computer-implemented method of claim 1 , wherein the file metadata associated with at least one of the files indicates at least one of:

a file identifier;

a file access attempt history;

a file location;

a file size; and

a presence of sensitive information in the file.

3. The computer-implemented method of claim 1 , wherein the at least one respective factor further comprises a factor indicating sensitivity of information in the respective file.

4. The computer-implemented method of claim 1 , wherein the at least one respective factor further comprises:

a factor indicating a percentage of total information, in a respective file, having at least a minimum level of sensitivity;

a factor indicating a percentage of total users who are permitted to access the respective file;

a factor indicating a percentage of total users who are permitted to access sensitive files;

a factor indicating a percentage of unique tags associated with the respective file;

a factor indicating a percentage of highly sensitive files in a plurality of sensitive files;

a factor indicating an average number of instances of patterns per sensitive file;

a factor indicating a location of the respective file;

a factor indicating characteristics of a control point;

a factor indicating a type of data source associated with the respective file; and

a factor indicating a level of security for the storage device storing the respective file.

5. The computer-implemented method of claim 1 , wherein calculating further comprises adding respective factor scores for different factors.

6. The computer-implemented method of claim 1 , wherein calculating further comprises weighting the at least one factor score with a respective weight.

7. The computer-implemented method of claim 6 , further comprising receiving the respective weight from a user interface.

8. The computer-implemented method of claim 1 , wherein the at least one respective factor is in a plurality of factors having respective factor scores and calculating further comprises:

weighting the respective factor scores with respective weights to form respective weighted factor scores;

adding the respective weighted factor scores; and

dividing the sum of the respective weighted factor scores by a total number of factors in the plurality of factors.

9. The computer-implemented method of claim 1 , wherein calculating the risk score comprises calculating the risk score for at least one of a file, a directory, and a storage device.

10. The computer-implemented method of claim 1 , further comprising performing an action on an additional file in response to a value of the risk score.

11. The computer-implemented method of claim 10 , wherein the action comprises modifying a permission to access the additional file.

12. The computer-implemented method of claim 1 , further comprising displaying, on a user display, the risk score.

13. The computer-implemented method of claim 1 , further comprising sending information describing the risk score via a network interface.

14. A system for computing a risk score for stored information, the system comprising:

an extracting module, stored in a memory device, that is configured to cause at least one physical processor to automatically extract factor-specific information from file metadata, wherein the file metadata describes characteristics of respective files stored on multiple storage devices;

an assigning module, stored in the memory device, that assigns at least one respective factor score to at least one respective factor based at least in part on the factor-specific information, wherein the at least one respective factor comprises a factor indicating permission distance between multiple categories of users who are permitted to access a respective file in the respective files;

a calculating module, stored in the memory device, that calculates the risk score from the at least one factor score and automatically limits access to a sensitive file having a high risk score and that is in the files stored on the multiple storage devices; and

the at least one physical processor that executes the extracting module, the assigning module, and the calculating module.

15. The system of claim 14 , wherein the at least one respective factor further comprises a factor indicating sensitivity of information in the respective file.

16. The system of claim 14 , wherein the at least one respective factor further comprises:

a factor indicating a percentage of total information, in a respective file, having at least a minimum level of sensitivity;

a factor indicating a percentage of total users who are permitted to access the respective file;

a factor indicating a percentage of total users who are permitted to access sensitive files;

a factor indicating a percentage of unique tags associated with the respective file;

a factor indicating a percentage of highly sensitive files in a plurality of sensitive files;

a factor indicating an average number of instances of patterns per sensitive file;

a factor indicating a location of the respective file;

a factor indicating characteristics of a control point;

a factor indicating a type of data source associated with the respective file; and

a factor indicating a level of security for the storage device storing the respective file.

17. The system of claim 14 , wherein the at least one respective factor is in a plurality of factors having respective factor scores and calculating the risk score further comprises:

weighting the respective factor scores with respective weights to form respective weighted factor scores;

adding the respective weighted factor scores; and

dividing the sum of the respective weighted factor scores by a total number of factors in the plurality of factors.

18. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

extract factor-specific information from file metadata, wherein the file metadata describes characteristics of respective files stored on multiple storage devices;

assign at least one respective factor score to at least one respective factor based at least in part on the factor-specific information, wherein the at least one respective factor comprises a factor indicating permission distance between multiple categories of users who are permitted to access a respective file in the respective files;

calculate a risk score from the at least one factor score; and

automatically limit access to a sensitive file having a high risk score and that is in the files stored on the multiple storage devices.

19. The non-transitory computer-readable medium of claim 18 , wherein the at least one respective factor further comprises a factor indicating sensitivity of information in the respective file.

20. The non-transitory computer-readable medium of claim 18 , wherein the at least one respective factor further comprises:

a factor indicating a percentage of total information, in a respective file, having at least a minimum level of sensitivity;

a factor indicating a percentage of total users who are permitted to access the respective file;

a factor indicating a percentage of total users who are permitted to access sensitive files;

a factor indicating a percentage of unique tags associated with the respective file;

a factor indicating a percentage of highly sensitive files in a plurality of sensitive files;

a factor indicating an average number of instances of patterns per sensitive file;

a factor indicating a location of the respective file;

a factor indicating characteristics of a control point;

a factor indicating a type of data source associated with the respective file; and

a factor indicating a level of security for the storage device storing the respective file.

21. The computer-implemented method of claim 1 , wherein the categories of users in the multiple categories are organization subdivisions.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2026
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 075377/0130 →
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069697/0238 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 18, 2020
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 052189/0311 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2018
From: DARGUDE, SHAILESH; GRANDHI, SATISH; ATHAVALE, ANAND; NATH, ROHIT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 046743/0752 →
Continuity (1)
Provisional Application 62653541 · Apr 5, 2018
Cited By (10)
US 12,229,032 US 12,231,457 US 12,231,467 US 12,284,204 US 12,309,239 US 12,316,486 US 12,556,617 US 12,556,623 US 12,632,357 US 12,719,916