IP Library Granted Patent US 11,194,925
Granted Patent B1
US 11,194,925 · App. 16/224,358 · Granted Dec 7, 2021

User-based cyber risk communications using personalized notifications

Inventors: Johann Roturier (Maynooth, IE); Petros Efstathopoulos (Los Angeles, CA)
Assignee: NortonLifeLock inc.
G06F21/6245G06F9/542G06F16/955G06F16/958G06F21/554G06F21/556H04L51/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,194,925
App. No.
16/224,358
Granted
Dec 7, 2021
Kind
B1
Abstract

Methods and systems are provided for monitoring private information exposure. One example method generally includes detecting, at a computing device, a potentially exposing post on a publicly-accessible server and determining, by an exposure model operated by the computing device, an exposure chance for the potentially exposing post. The method further includes transmitting an initial notification of the potentially exposing post from the computing device to a client device based on the exposure chance from the exposure model and detecting an update event associated with the potentially exposing post. The method further includes updating the exposure model based on the update event and transmitting a personalized notification from the computing device to the client device based on the update event.

Claims (60)

1. A computer-implemented method for monitoring private information exposure, at least a portion of the method being performed by a computing device comprising one or more processors, the method comprising:

detecting, at the computing device, a potentially exposing post on a publicly-accessible server;

determining, by an exposure model operated by the computing device, an exposure chance for the potentially exposing post;

transmitting an initial notification of the potentially exposing post from the computing device to a client device based on the exposure chance from the exposure model;

detecting an update event associated with the potentially exposing post;

updating the exposure model based on the update event, the updating comprising:

determining a length of time between transmitting the initial notification and detecting a change in the potentially exposing post; and

modifying parameters of the exposure model based on the length of time; and

transmitting a personalized notification from the computing device to the client device based on the update event.

2. The computer-implemented method of claim 1 , further comprising taking a remedial action based on the potentially exposing post.

3. The computer-implemented method of claim 1 , wherein the personalized notification includes at least one of:

information of what information is shared by the potentially exposing post;

an explanation of why the information should not be shared; or

advice relating to preventing subsequent exposures of the information.

4. The computer-implemented method of claim 1 , wherein the initial notification includes a screenshot of the potentially exposing post.

5. The computer-implemented method of claim 1 , further comprising, after transmitting the initial notification, periodically accessing the potentially exposing post.

6. The computer-implemented method of claim 1 , wherein the update event includes one of:

a removal of the potentially exposing post from the publicly-accessible server; or

an alteration of the potentially exposing post to remove information from the potentially exposing post.

7. The computer-implemented method of claim 1 , wherein detecting the update event comprises:

determining, after a time limit for changes to the potentially exposing post has been exceeded, that a false positive was detected; and

updating the exposure model based on the false positive.

8. The computer-implemented method of claim 1 , wherein an identification of private information is not requested from the client device.

9. The computer-implemented method of claim 1 , wherein the potentially exposing post is associated with a uniform resource locator (URL), and wherein the method further comprises transmitting the personalized notification to one or more other computing devices subsequently accessing the URL.

10. A computing device comprising:

at least one processor; and

a memory having instructions stored thereon which, when executed by the processor, perform operations for monitoring private information exposure, the operations comprising:

detecting, at the computing device, a potentially exposing post on a publicly-accessible server;

determining, by an exposure model operated by the computing device, an exposure chance for the potentially exposing post;

transmitting an initial notification of the potentially exposing post from the computing device to a client device based on the exposure chance from the exposure model;

detecting an update event associated with the potentially exposing post, the detecting comprising determining, after a time limit for changes to the potentially exposing post has been exceeded, that a false positive was detected;

updating the exposure model based on the update event being a false positive; and

transmitting a personalized notification from the computing device to the client device based on the update event.

11. The computing device of claim 10 , the operations further comprising taking a remedial action based on the potentially exposing post.

12. The computing device of claim 10 , wherein the personalized notification includes at least one of:

information of what information is shared by the potentially exposing post; an explanation of why the information should not be shared; or

advice relating to preventing subsequent exposures of the information.

13. The computing device of claim 10 , wherein the initial notification includes a screenshot of the potentially exposing post.

14. The computing device of claim 10 , the operations further comprising, after transmitting the initial notification, periodically accessing the potentially exposing post.

15. The computing device of claim 10 , wherein the update event includes one of: a removal of the potentially exposing post from the publicly-accessible server;

or

an alteration of the potentially exposing post to remove information from the potentially exposing post.

16. The computing device of claim 10 , wherein updating the exposure model comprises:

determining a length of time between transmitting the initial notification and detecting a change in the potentially exposing post; and

modifying parameters of the exposure model based on the length of time.

17. The computing device of claim 10 , wherein the potentially exposing post is associated with a uniform resource locator (URL), and wherein the operations further comprise transmitting the personalized notification to one or more other computing devices subsequently accessing the URL.

18. A non-transitory computer-readable medium having instructions stored thereon which, when executed by at least one processor of a computing device, perform operations for monitoring private information exposure, the operations comprising:

detecting, at the computing device, a potentially exposing post on a publicly-accessible server;

determining, by an exposure model operated by the computing device, an exposure chance for the potentially exposing post;

transmitting an initial notification of the potentially exposing post from the computing device to a client device based on the exposure chance from the exposure model;

detecting an update event associated with the potentially exposing post;

updating the exposure model based on the update event, the updating comprising:

determining a length of time between transmitting the initial notification and detecting a change in the potentially exposing post; and

modifying parameters of the exposure model based on the length of time; and

transmitting a personalized notification from the computing device to the client device based on the update event.

19. The non-transitory computer-readable medium of claim 18 , wherein the operations further comprise taking a remedial action based on the potentially exposing post.

20. The non-transitory computer-readable medium of claim 18 , wherein the personalized notification includes at least one of:

information of what information is shared by the potentially exposing post;

an explanation of why the information should not be shared; or

advice relating to preventing subsequent exposures of the information.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 10, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052135/0745 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2018
From: ROTURIER, JOHANN; EFSTATHOPOULOS, PETROS
To: SYMANTEC CORPORATION
Reel/Frame 047810/0192 →