IP Library › Granted Patent US 11,457,024
Granted Patent B2
US 11,457,024 · App. 16/283,260 · Granted Sep 27, 2022

Systems and methods for monitoring security of an organization based on a normalized risk score

Inventors: Rishabh Bindal (San Jose, CA); Nastaran Baradaran (San Jose, CA)
Assignee: Citrix Systems, Inc.
H04L63/1416G06F17/18H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,457,024
App. No.
16/283,260
Filed
Feb 22, 2019
Granted
Sep 27, 2022
Kind
B2
Art Unit
2439
USPC
726/22
Abstract

Embodiments described include a computing device for generating risk scores of network entities. The computing device can include one or more processors configured to detect a plurality of risk indicators. Each of the risk indicators identify one of a plurality of activities of a network entity of an organization. The network entity includes a device, an application or a user in the organization's network. The one or more processors can generate a risk score of the network entity, by combining a risk value, an amplification factor and a dampening factor of each of the plurality of risk indicators, and adding an adjustment value for the plurality of risk indicators. The one or more processors can determine, using the generated risk score, a normalized risk score of the network entity. The one or more processors can initiate an action according to the normalized risk score.

Claims (68)

1. A computing device comprising:

a memory;

one or more processors operatively coupled to the memory, the one or more processors configured to:

detect a plurality of risk indicators, at least one of the risk indicators identifying one of a plurality of activities of a network entity of an organization, the network entity comprising a device, an application or a user in the organization's network;

generate an overall risk score of the network entity, by:

(a) generating respective risk scores, each respective risk score corresponding to a respective one of the plurality of risk indicators and generated according to: (i) a risk value of one or more of the activities of the network entity, (ii) an amplification factor and (iii) a dampening factor, of a respective one of the plurality of risk indicators,

(b) performing a summation of the respective risk scores; and

(c) adding an adjustment value to the summation of the respective risk scores;

determine, by scaling the overall risk score of the network entity with respect to a value, a normalized risk score of the network entity which indicates potential risk from the network entity to the organization; and

initiate an action according to the normalized risk score, to protect the organization from the potential risk indicated by the normalized risk score of the network entity.

2. The computing device of claim 1 , wherein the one or more processors are configured to:

receive respective risk scores of the network entity over a training period, each respective risk score having an estimated frequency of occurrences of the respective risk score over the training period; and

determine a probability of occurrence of at least one of the respective risk scores over the training period according to the estimated frequency of each of the respective risk scores over the training period.

3. The computing device of claim 2 , wherein the one or more processors are configured to:

identify a probability P of occurrence of the overall risk score, according to the probabilities determined over the training period; and

determine the normalized risk score as (1−P)×100.

4. The computing device of claim 1 , wherein the adjustment value includes an amplification value for the plurality of risk indicators, and a dampening value for the plurality of risk indicators.

5. The computing device of claim 1 , wherein the one or more processors are configured to:

determine whether the overall risk score is greater or less than a pre-defined threshold; and

based on the determination of whether the overall risk score is greater or less than a pre-defined threshold, adjust the overall risk score according to the pre-defined threshold to determine the normalized risk score of the network entity.

6. The computing device of claim 5 , wherein the one or more processors are configured to:

proportionally adjust at least one of the risk value, the amplification factor or the dampening factor of each of the plurality of risk indicators, and the adjustment value for the plurality of risk indicators, according to the pre-defined threshold.

7. The computing device of claim 1 , wherein the one or more processors are configured to:

determine the amplification factor of a first risk indicator of the plurality of risk indicators according to a frequency of the first risk indicator; and

determine the dampening factor of a second risk indicator of the plurality of risk indicators for a time period according to a probability of the second risk indicator in a previous time period.

8. A method comprising:

detecting, by a server, a plurality of risk indicators, at least one of the risk indicators identifying one of a plurality of activities of a network entity of an organization, the network entity comprising a device, an application or a user in the organization's network;

generating, by the server, an overall risk score of the network entity, by:

(a) generating respective risk scores, each respective risk score corresponding to a respective one of the plurality of risk indicators and generated according to: (i) a risk value of one or more of the activities of the network entity, (ii) an amplification factor and (iii) a dampening factor, of a respective one of the plurality of risk indicators,

(b) performing a summation of the respective risk scores; and

(c) adding an adjustment value to the summation of the respective risk scores;

determining, by the server by scaling the overall risk score of the network entity with respect to a value, a normalized risk score of the network entity which indicates potential risk from the network entity to the organization; and

initiating, by the server, an action according to the normalized risk score to protect the organization from the potential risk indicated by the normalized risk score of the network entity.

9. The method of claim 8 , further comprising:

receiving, by the server, respective risk scores of the network entity over a training period, each respective risk score having an estimated frequency of occurrences of the respective risk score over the training period; and

determining, by the server, a probability of occurrence of at least one of the respective risk scores over the training period according to the estimated frequency of each of the respective risk scores over the training period.

10. The method of claim 9 , further comprising:

identifying, by the server, a probability P of occurrence for the overall risk score, according to the probabilities determined over the training period; and

determining, by the server, the normalized risk score as (1−P)×100.

11. The method of claim 8 , wherein the adjustment value includes an amplification value for the plurality of risk indicators, and a dampening value for the plurality of risk indicators.

12. The method of claim 8 , further comprising:

determining whether the overall risk score is greater or less than a pre-defined threshold; and

based on the determination of whether the overall risk score is greater or less than a pre-defined threshold, adjusting the overall risk score according to the pre-defined threshold to determine the normalized risk score of the network entity.

13. The method of claim 12 , further comprising:

proportionally adjusting at least one of the risk value, the amplification factor or the dampening factor of each of the plurality of risk indicators, and the adjustment value for the plurality of risk indicators, according to the pre-defined threshold.

14. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

detect a plurality of risk indicators, at least one of the risk indicators identifying one of a plurality of activities of a network entity of an organization, the network entity comprising a device, an application or a user in the organization's network;

generate, an overall risk score of the network entity, by:

(a) generating respective risk scores, each respective risk score corresponding to a respective one of the plurality of risk indicators and generated according to: (i) a risk value of one or more of the activities of the network entity, (ii) an amplification factor and (iii) a dampening factor, of a respective one of the plurality of risk indicators,

(b) performing a summation of the respective risk scores; and

(c) adding an adjustment value to the summation of the respective risk scores;

determine, by scaling the overall risk score of the network entity with respect to a value, a normalized risk score of the network entity which indicates potential risk from the network entity to the organization; and

initiate an action according to the normalized risk score, to protect the organization from the potential risk indicated by the normalized risk score of the network entity.

15. The non-transitory computer readable medium of claim 14 , wherein the program instructions further cause the one or more processors to:

receive respective risk scores of the network entity over a training period, each respective risk score having an estimated frequency of occurrences of the respective risk score over the training period; and

determine a probability of occurrence of at least one of the respective risk scores over the training period according to the estimated frequency of each of the risk scores over the training period.

16. The non-transitory computer readable medium of claim 15 , wherein the program instructions further cause the one or more processors to:

identify a probability P of occurrence for the overall risk score, according to the probabilities determined over the training period; and

determine the normalized risk score as (1−P)×100.

17. The non-transitory computer readable medium of claim 14 , wherein the adjustment value includes an amplification value for the plurality of risk indicators, and a dampening value for the plurality of risk indicators.

18. The non-transitory computer readable medium of claim 14 , wherein the program instructions further cause the one or more processors to:

determine whether the overall risk score is greater or less than a pre-defined threshold; and

based on the determination of whether the overall risk score is greater or less than a pre-defined threshold, adjust the overall risk score according to the pre-defined threshold to determine the normalized risk score of the network entity.

19. The non-transitory computer readable medium of claim 18 , wherein the program instructions further cause the one or more processors to:

proportionally adjust at least one of the risk value, the amplification factor or the dampening factor of each of the plurality of risk indicators, and the adjustment value for the plurality of risk indicators, according to the pre-defined threshold.

20. The non-transitory computer readable medium of claim 14 , wherein the program instructions further cause the one or more processors to:

determine the amplification factor of a first risk indicator of the plurality of risk indicators according to a frequency of the first risk indicator; and

determine the dampening factor of a second risk indicator of the plurality of risk indicators for a time period, according to a probability of the second risk indicator in a previous time period.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2019
From: BINDAL, RISHABH; BARADARAN, NASTARAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 048416/0221 →
Continuity (2)
Provisional Application 62714377 · Aug 3, 2018
Related Publication 20200045064A1 · Feb 6, 2020
Cited By (1)
US 12,348,536