IP Library Granted Patent US 11,282,017
Granted Patent B2
US 11,282,017 · App. 16/278,652 · Granted Mar 22, 2022

Systems and methods for monitoring information security effectiveness

Inventors: Kelly Thomas White (Park City, UT); Michael Vance Fowkes (Salt Lake City, UT); Jesse Duane Card (American Fork, UT); Andrew James Menzel (Tallahassee, FL)
Assignee: RiskRecon Inc.
G06Q10/0635G06F21/552G06F21/6245G06N20/00H04L63/1433H04L63/205G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,282,017
App. No.
16/278,652
Granted
Mar 22, 2022
Kind
B2
Abstract

Systems and methods for automatically assessing and monitoring information security effectiveness using collected indicia of sensitive content and indicia of security measure information for a plurality of networked organizational assets/systems to provide respective asset/system value at risk ratings. Elements of the system include automated asset discovery, automated hosting provider and location discovery, collection of information harvested from public sources and, optionally non-public sources, analysis of the collected information against public, non-public, and proprietary sources, and/or mathematical models used to infer broader security program conclusions and to rank asset/system values at risk. Estimates of values at risk are used to prioritize allocation of security measures.

Claims (141)

1. A method comprising:

connecting to a network accessible computer asset using a network identifier;

communicating with the network accessible computer asset using respective network protocols;

collecting data returned from the network accessible computer asset;

analyzing the collected data using one or more of machine learning models, regular expressions, text string matching, natural language understanding, image processing, and text analysis;

identifying, without accessing sensitive data, characteristics of the collected data indicating one or more of the following: mechanisms for accessing the sensitive data, mechanisms for collecting the sensitive data, storage of the sensitive data, presentation of the sensitive data, sensitive data input mechanisms, sensitive data subjects, sensitive functionality subjects, security mechanisms, indicia of security mechanisms, and sensitive functionality;

identifying one or more security features of the network accessible computer asset based on the identified characteristics;

determining an asset subject of the network accessible computer asset based on the identified characteristics;

determining an asset purpose of the network accessible computer asset based on the identified characteristics;

using the asset subject, the asset purpose, and the identified security features of the network accessible computer asset, to establish an intrinsic organizational value at risk rating for the network accessible computer asset based in part on network proximity of the network accessible computer asset to one or more other network-accessible computer assets with a higher intrinsic organizational value at risk rating; and

based on the intrinsic organizational value at risk rating of the network accessible computer asset, prioritizing allocation of one or more information technology security controls and resources to the network accessible computer asset relative to the one or more other network accessible computer assets.

2. The method of claim 1 , wherein establishing the intrinsic organizational value at risk rating of the network accessible computer asset includes assigning a weight to each identified characteristic and combining each weight into an overall intrinsic organizational value at risk rating.

3. The method of claim 1 , wherein the collected data comprises one or more of the following:

network communications,

HTTP headers,

Network communication protocol headers,

HTTP cookies,

URLs,

HTML,

text,

images,

computer code,

videos,

files,

data files,

data,

executable files,

JavaScript, and

configurations.

4. The method of claim 1 , wherein indicators of one or more of types of sensitive data directly accessible through the network accessible computer asset include one or more of the following:

name,

personal identification number (PIN),

account number,

birth date,

physical address,

email address,

computer asset identifier,

telephone number,

social media identifier,

user identifier,

password,

authentication credential,

personal characteristics,

identification numbers of personally owned assets,

employment information,

education information,

medical information,

transaction history,

free form text,

email messages,

social media messages, and

call recordings.

5. The method of claim 1 , wherein the collected data comprises identified indicators of one or more of types of sensitive data collected by the network accessible computer asset, including one or more of the following:

name,

personal identification number (PIN),

account number,

birth date,

physical address,

email address,

computer asset identifier,

telephone number,

social media identifier,

user identifier,

password,

authentication credential,

personal characteristics,

identification numbers of personally owned assets,

employment information,

education information,

medical information,

transaction history,

free form text,

email messages,

social media messages, and

call recordings.

6. The method of claim 1 , wherein the security mechanisms associated with the network accessible computer asset include one or more of the following:

data encryption mechanism,

communications encryption mechanism,

authentication mechanism,

user id input field,

password input field,

second-factor authentication input field,

captcha,

security question,

secure cookies,

fraud monitoring code,

malware detection code,

reference to offers of security features,

claim of security certification or security testing, and

use of HTTP security headers.

7. The method of claim 1 , wherein the identified characteristics include indicators of types of sensitive computer asset functionality provided, including one or more of the following:

file transfer,

email communications,

chat communications,

remote access,

remote control,

money transfer,

file system,

file storage,

database,

data storage,

system administration,

mobile access gateway,

system configuration,

content editing,

E-commerce,

querying data,

accessing data,

information access,

media streaming (e.g., video, sound), and

read-only configuration.

8. The method of claim 1 , wherein the identified characteristics include indicators of the asset subject including one or more of the following:

consumer banking,

commercial banking,

stock trading,

financial account data,

personally-identifiable data,

personal health record data,

internal corporate data,

automobiles,

prescription drugs,

real estate,

retail,

E-commerce,

natural resources,

customer support,

email,

animals,

investments, and

health care.

9. One or more non-transitory computer-readable storage media having computer-executable instructions embodied thereon, wherein when executed by at least one processor, the computer-executable instructions cause the processor to:

connect to a network accessible computer asset using a network identifier;

communicate with the network accessible computer asset using respective network protocols;

collect data returned from the network accessible computer asset;

analyze the collected data using one or more of machine learning models, regular expressions, text string matching, natural language understanding, image processing, and text analysis;

identify, without accessing sensitive data, characteristics of the collected data indicating one or more of the following: mechanisms for accessing the sensitive data, mechanisms for collecting the sensitive data, storage of the sensitive data, presentation of the sensitive data, sensitive data input mechanisms, sensitive data subjects, sensitive functionality subjects, and sensitive functionality;

identify one or more security features of the network accessible computer asset;

determine an asset subject of the network accessible computer asset based on the identified characteristics;

determine an asset purpose of the network accessible computer asset based on the identified characteristics;

use the asset subject, the asset purpose, and the identified security features of the network accessible computer asset, to establish an intrinsic organizational value at risk rating for the network accessible computer asset based in part on network proximity of the network accessible computer asset to one or more other network-accessible computer assets with a higher intrinsic organizational value at risk rating; and

based on the intrinsic organizational value at risk rating of the network accessible computer asset, prioritize allocation of one or more information technology security controls and resources to the network accessible computer asset relative to the one or more other network accessible computer assets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2019
From: WHITE, KELLY THOMAS; FOWKES, MICHAEL VANCE; CARD, JESSE DUANE; MENZEL, ANDREW JAMES
To: RISKRECON INC.
Reel/Frame 048969/0528 →
Continuity (3)
Continuation In Part 15207395 · Jul 11, 2016
Provisional Application 62191362 · Jul 11, 2015
Related Publication 20190182289A1 · Jun 13, 2019