IP Library Granted Patent US 12,052,276
Granted Patent B2
US 12,052,276 · App. 16/278,016 · Granted Jul 30, 2024

People-centric threat scoring

Inventors: Bryan Robert Burns (Portland, OR); David Robert Knight (Los Altos, CA); Christopher Anthony Iezzoni (Santa Cruz, CA)
Assignee: Proofpoint, Inc.
H04L63/1433H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,276
App. No.
16/278,016
Granted
Jul 30, 2024
Kind
B2
Abstract

The subject disclosure relates to methods for assessing cyber-security risks, and in particular for calculating a risk-index for multiple users of a computer network. In some implementations, a process of the disclosed technology includes steps for determining a privileged index for each of a plurality of network users, determining a vulnerability index for each of the plurality of network users, calculating a threat score for one or more cyber-security attacks directed at each of the plurality of network users, and calculating a risk-index for at least one network user from among the plurality of network users, wherein the risk-index is based on the privileged index, the vulnerability index, and the threat score associated with each of the network users. Systems and machine-readable media are also provided.

Claims (71)

1. A computer-implemented method for assessing cyber-security risk:

determining a privileged index for each of a plurality of network users;

determining a vulnerability index for each of the plurality of network users;

calculating a threat score for one or more cyber-security attacks directed at each of the plurality of network users, wherein calculating the threat score further comprises:

determining a targetedness of the one or more cyber-security attacks,

and wherein the threat score calculated for each of the one or more cyber-security attacks is based on the determined targetedness associated with the corresponding cyber-security attack of the one or more cyber-security attacks,

identifying, based on a type of the one or more cyber-security attacks and an actor type corresponding to the one or more cyber-security attacks, a threat score range, wherein calculating the threat score comprises calculating:

at least a first threat score based on a first targetedness of a first cyber-security attack of the one or more cyber-security attacks, wherein the first threat score indicates a lower bound of the threat score range, and

at least a second threat score based on a second targetedness of a second cyber-security attack of the one or more cyber-security attacks, wherein

the second threat score indicates an upper bound of the threat score range, and

wherein the second targetedness is higher than the first targetedness;

wherein the threat score range is within an overall score range;

calculating a risk-index for at least one network user from among the plurality of network users, wherein the risk-index is based on the privileged index, the vulnerability index, and the threat score associated with each of the network users;

ranking, based on the risk-index, the at least one network user along with the plurality of network users to create a list of a subset of the plurality of network users upon which to focus security resources; and

displaying the ranked list.

2. The computer-implemented method of claim 1 , wherein the threat score calculated for each of the one or more cyber-security attacks is based on a threat type associated with the cyber-security attack.

3. The computer-implemented method of claim 1 , wherein the privileged index for each of the plurality of network users is based on a level of network access rights associated with the network user.

4. The computer-implemented method of claim 1 , wherein the privileged index for each of the plurality of network users is based on one or more of: an ability to transfer funds, an ability to access employee data, or an ability to access intellectual property.

5. The computer-implemented method of claim 1 , wherein the vulnerability index determined for each of the plurality of network users is based on the associated network user's performance on one or more security audits.

6. The computer-implemented method of claim 1 , wherein the vulnerability index determined for each of the plurality of network users is based on: a frequency of interaction with threat vectors, or detected vulnerabilities in user software.

7. A system for assessing a cyber-security risk, the system comprising:

one or more processors;

a network interface coupled to the one or more processors; and

a non-transitory computer-readable medium coupled to the one or more processors, wherein the medium comprises instructions stored therein, which when executed by the processors, cause the processors to perform operations comprising:

determining a privileged index for each of a plurality of network users;

determining a vulnerability index for each of the plurality of network users;

calculating a threat score for one or more cyber-security attacks directed at each of the plurality of network users, wherein calculating the threat score further comprises:

determining a targetedness of the one or more cyber-security attacks,

and wherein the threat score calculated for each of the one or more cyber-security attacks is based on the determined targetedness associated with the corresponding cyber-security attack of the one or more cyber-security attacks,

identifying, based on a type of the one or more cyber-security attacks and an actor type corresponding to the one or more cyber-security attacks, a threat score range, wherein calculating the threat score comprises calculating:

at least a first threat score based on a first targetedness of a first cyber-security attack of the one or more cyber-security attacks, wherein the first threat score indicates a lower bound of the threat score range, and

at least a second threat score based on a second targetedness of a second cyber-security attack of the one or more cyber-security attacks, wherein

the second threat score indicates an upper bound of the threat score range, and

wherein the second targetedness is higher than the first targetedness;

wherein the threat score range is within an overall score range;

calculating a risk-index for at least one network user from among the plurality of network users, wherein the risk-index is based on the privileged index, the vulnerability index, and the threat score associated with each of the network users;

ranking, based on the risk-index, the at least one network user along with the plurality of network users to create a list of a subset of the plurality of network users upon which to focus security resources; and

displaying the ranked list.

8. The system of claim 7 , wherein the threat score calculated for each of the one or more cyber-security attacks is based on a threat type associated with the cyber-security attack.

9. The system of claim 7 , wherein the privileged index for each of the plurality of network users is based on a level of network access rights associated with the network user.

10. The system of claim 7 , wherein the privileged index for each of the plurality of network users is based on one or more of: an ability to transfer funds, an ability to access employee data, or an ability to access intellectual property.

11. The system of claim 7 , wherein the vulnerability index determined for each of the plurality of network users is based on the associated network user's performance on one or more security audits.

12. The system of claim 7 , wherein the vulnerability index determined for each of the plurality of network users is based on: a frequency of interaction with threat vectors, or detected vulnerabilities in user software.

13. A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the processors to perform operations comprising:

determining a privileged index for each of a plurality of network users;

determining a vulnerability index for each of the plurality of network users;

calculating a threat score for one or more cyber-security attacks directed at each of the plurality of network users, wherein calculating the threat score further comprises:

determining a targetedness of the one or more cyber-security attacks,

and wherein the threat score calculated for each of the one or more cyber-security attacks is based on the determined targetedness associated with the corresponding cyber-security attack of the one or more cyber-security attacks,

identifying, based on a type of the one or more cyber-security attacks and an actor type corresponding to the one or more cyber-security attacks, a threat score range, wherein calculating the threat score comprises calculating:

at least a first threat score based on a first targetedness of a first cyber-security attack of the one or more cyber-security attacks, wherein the first threat score indicates a lower bound of the threat score range, and

at least a second threat score based on a second targetedness of a second cyber-security attack of the one or more cyber-security attacks, wherein

the second threat score indicates an upper bound of the threat score range, and

wherein the second targetedness is higher than the first targetedness;

wherein the threat score range is within an overall score range;

calculating a risk-index for at least one network user from among the plurality of network users, wherein the risk-index is based on the privileged index, the vulnerability index, and the threat score associated with each of the network users;

ranking, based on the risk-index, the at least one network user along with the plurality of network users to create a list of a subset of the plurality of network users upon which to focus security resources; and

displaying the ranked list.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the threat score calculated for each of the one or more cyber-security attacks is based on a threat type associated with the cyber-security attack.

15. The computer-implemented method of claim 1 , wherein the targetedness is based on geographic specificity.

16. The computer-implemented method of claim 1 , further comprising:

normalizing risk-indexes of the subset of the plurality of network users; and

performing, using the normalized risk-indexes, a quantitative risk comparison of a first organization, corresponding to the plurality of network users, to a second organization, wherein

the second organization is larger than the first organization.

17. The computer-implemented method of claim 1 , wherein displaying the ranked list comprises graphically displaying a time series of risk-indexes of the ranked list over a predetermined time period.

18. The computer-implemented method of claim 1 , wherein bounds of the overall score range are outside of the threat score range.

19. The computer-implemented method of claim 1 , wherein the threat score range is specific to a combination of:

the type of the one or more cyber-security attacks, and

the actor type corresponding to the one or more cyber-security attacks, and wherein a second threat score range is specific to a combination of:

a second type of cyber-security attack, and

a second actor type.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2019
From: BURNS, BRYAN ROBERT; KNIGHT, DAVID ROBERT; IEZZONI, CHRISTOPHER ANTHONY
To: PROOFPOINT, INC.
Reel/Frame 048535/0393 →
Cited By (1)
US 12,665,833