IP Library Granted Patent US 11,363,051
Granted Patent B2
US 11,363,051 · App. 16/371,794 · Granted Jun 14, 2022

System and method for mitigating cyber security threats by devices using risk factors

Inventors: Nadir Izrael (Mountain View, CA); Shiri Ladelsky Lellouch (Menlo Park, CA); Misha Seltzer (Toronto, CA)
Assignee: Armis Security Ltd.
H04L63/1433G06F21/552G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,363,051
App. No.
16/371,794
Granted
Jun 14, 2022
Kind
B2
Abstract

A system and method for mitigating cyber security threats by devices using risk factors. The method includes determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device; determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and performing at least one mitigation action based on the risk score.

Claims (43)

1. A method for mitigating cyber security threats by devices using risk factors, comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device;

determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors, wherein the plurality of weights includes at least one negative weight, wherein each negative weight is applied to a corresponding risk factor when the information of the device indicates a mitigating circumstance related to risk posed by the device; and

performing at least one mitigation action based on the risk score;

wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device.

2. The method of claim 1 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

3. The method of claim 1 , wherein the plurality of risk behaviors includes observed risk behaviors, wherein determining the plurality of risk factors further comprises:

determining the observed risk behaviors based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device.

4. The method of claim 1 , wherein the plurality of risk behaviors includes observed risk behaviors, wherein determining the plurality of risk factors further comprises:

determining the assumed risk behaviors based on at least one of: manufacturer reputation information, device model reputation information, known software vulnerabilities, and known operating system vulnerabilities.

5. The method of claim 1 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, further comprising:

updating the risk score based on the monitored network activity; and

performing at least one subsequent mitigation action based on the updated risk score.

6. The method of claim 1 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on the quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

7. The method of claim 1 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

8. The method of claim 1 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

9. The method of claim 1 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

10. The method of claim 1 , wherein the plurality of risk factors is determined based further on a plurality of risk behaviors of at least one other device.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device;

determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors, wherein the plurality of weights includes at least one negative weight, wherein each negative weight is applied to a corresponding risk factor when the information of the device indicates a mitigating circumstance related to risk posed by the device; and

performing at least one mitigation action based on the risk score;

wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device.

12. A system for mitigating cyber security threats by devices using risk factors, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

determine a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device;

determine a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors, wherein the plurality of weights includes at least one negative weight, wherein each negative weight is applied to a corresponding risk factor when the information of the device indicates a mitigating circumstance related to risk posed by the device; and

perform at least one mitigation action based on the risk score;

wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device.

13. The system of claim 12 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

14. The system of claim 12 , wherein the plurality of risk behaviors includes observed risk behaviors, wherein the system is further configured to:

determine the observed risk behaviors based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device.

15. The system of claim 12 , wherein the plurality of risk behaviors includes observed risk behaviors, wherein the system is further configured to:

determine the assumed risk behaviors based on at least one of: manufacturer reputation information, device model reputation information, known software vulnerabilities, and known operating system vulnerabilities.

16. The system of claim 12 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, f wherein the system is further configured to:

update the risk score based on the monitored network activity; and

perform at least one subsequent mitigation action based on the updated risk score.

17. The system of claim 12 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on the quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

18. The system of claim 12 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

19. The system of claim 12 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

20. The system of claim 12 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

21. The system of claim 12 , wherein the plurality of risk factors is determined based further on a plurality of risk behaviors of at least one other device.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2019
From: IZRAEL, NADIR; LADELSKY LELLOUCH, SHIRI; SELTZER, MISHA
To: ARMIS SECURITY LTD.
Reel/Frame 048757/0942 →
Continuity (1)
Related Publication 20200314134A1 · Oct 1, 2020
Cited By (5)
US 12,452,289 US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752