IP Library › Granted Patent US 11,288,364
Granted Patent B1
US 11,288,364 · App. 16/394,221 · Granted Mar 29, 2022

Data protection based on cybersecurity feeds

Inventors: Amihai Savir (Sansana, IL); Assaf Natanzon (Tel Aviv, IL); Avitan Gefen (Tel Aviv, IL)
Assignee: EMC IP Holding Company LLC
G06F21/554G06F11/1461G06F21/53G06F21/552G06F21/577G06F40/216G06F2201/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,288,364
App. No.
16/394,221
Filed
Apr 25, 2019
Granted
Mar 29, 2022
Kind
B1
Art Unit
2435
USPC
726/1
Abstract

Data protection based on cybersecurity feeds is described. A system receives cybersecurity feed content from a cybersecurity feed. If the cybersecurity feed content is relevant to data associated with an organization, the system evaluates a cybersecurity threat based on the cybersecurity feed content. The system selects at least one data protection policy, from multiple data protection policies, which corresponds to the evaluated cybersecurity threat. The system implements the selected at least one data protection policy.

Claims (34)

1. A system comprising:

one or more processors; and

a non-transitory computer readable medium storing a plurality of instructions, which when executed, cause the one or more processors to:

determine, in response to receiving cybersecurity feed content from a cybersecurity feed, whether the cybersecurity feed content is relevant to data associated with an organization;

evaluate, in response to a determination that the cybersecurity feed content is relevant to the data associated with the organization, a cybersecurity threat based on the cybersecurity feed content, by determining a ranking score for the cybersecurity feed content, the ranking score representing a risk of the cybersecurity threat on the data associated with the organization;

select at least one data protection policy, from a plurality of data protection policies, which corresponds to the evaluated cybersecurity threat based on the ranking score for the cybersecurity feed content; and

implement the selected at least one data protection policy.

2. The system of claim 1 , wherein the cybersecurity feed comprises a Real Simple Syndication (RSS) feed.

3. The system of claim 1 , wherein determining whether the cybersecurity feed content is relevant to the data associated with the organization comprises using natural language processing to analyze the cybersecurity feed content, and determining whether the cybersecurity feed content comprises new content relative to historical cybersecurity feed content.

4. The system of claim 1 , wherein evaluating the cybersecurity threat based on the cybersecurity feed content comprises using natural language processing to analyze the cybersecurity feed content, and identifying a corresponding data protection policy.

5. The system of claim 1 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to complete backup of critical data and stop backup of non-critical data.

6. The system of claim 1 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to lock data in retention mode.

7. The system of claim 1 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to isolate a data protection storage system.

8. A method comprising:

determine, in response to receiving cybersecurity feed content from a cybersecurity feed, whether the cybersecurity feed content is relevant to data associated with an organization;

evaluate, in response to a determination that the cybersecurity feed content is relevant to the data associated with the organization, a cybersecurity threat based on the cybersecurity feed content, by determining a ranking score for the cybersecurity feed content, the ranking score representing a risk of the cybersecurity threat on the data associated with the organization;

select at least one data protection policy, from a plurality of data protection policies, which corresponds to the evaluated cybersecurity threat based on the ranking score for the cybersecurity feed content; and

implement the selected at least one data protection policy.

9. The method of claim 8 , wherein the cybersecurity feed comprises a Real Simple Syndication (RSS) feed.

10. The method of claim 8 , wherein determining whether the cybersecurity feed content is relevant to the data associated with the organization comprises using natural language processing to analyze the cybersecurity feed content, and determining whether the cybersecurity feed content comprises new content relative to historical cybersecurity feed content.

11. The method of claim 8 , wherein evaluating the cybersecurity threat based on the cybersecurity feed content comprises using natural language processing to analyze the cybersecurity feed content, and identifying a corresponding data protection policy.

12. The method of claim 8 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to complete backup of critical data and stop backup of non-critical data.

13. The method of claim 8 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to lock data in retention mode.

14. The method of claim 8 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to isolate a data protection storage system.

15. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein to be executed by one or more processors, the program code including instructions to:

determine, in response to receiving cybersecurity feed content from a cybersecurity feed, whether the cybersecurity feed content is relevant to data associated with an organization;

evaluate, in response to a determination that the cybersecurity feed content is relevant to the data associated with the organization, a cybersecurity threat based on the cybersecurity feed content, by determining a ranking score for the cybersecurity feed content, the ranking score representing a risk of the cybersecurity threat on the data associated with the organization;

select at least one data protection policy, from a plurality of data protection policies, which corresponds to the evaluated cybersecurity threat based on the ranking score for the cybersecurity feed content; and

implement the selected at least one data protection policy.

16. The computer program product of claim 15 , wherein the cybersecurity feed comprises a Real Simple Syndication (RSS) feed.

17. The computer program product of claim 15 , wherein determining whether the cybersecurity feed content is relevant to the data associated with the organization comprises using natural language processing to analyze the cybersecurity feed content, and determining whether the cybersecurity feed content comprises new content relative to historical cybersecurity feed content, and evaluating the cybersecurity threat based on the cybersecurity feed content comprises using natural language processing to analyze the cybersecurity feed content, and identifying a corresponding data protection policy.

18. The computer program product of claim 15 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to complete backup of critical data and stop backup of non-critical data.

19. The computer program product of claim 15 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to lock data in retention mode.

20. The computer program product of claim 15 , wherein the at least one data protection policy which corresponds to the identified cybersecurity threat comprises a policy to isolate a data protection storage system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2019
From: SAVIR, AMIHAI; NATANZON, ASSAF; GEFEN, AVITAN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048994/0479 →
Cited By (2)
US 12,499,240 US 12,542,795