IP Library Granted Patent US 10,735,454
Granted Patent B2
US 10,735,454 · App. 16/394,351 · Granted Aug 4, 2020

Automated asset criticality assessment

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); Sven Schrecker (San Marcos, CA)
Assignee: McAfee, LLC
H04L63/1433G06F21/568G06F21/577H04L63/1408H04L63/1416G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,735,454
App. No.
16/394,351
Granted
Aug 4, 2020
Kind
B2
Abstract

A set of attributes of a particular asset of a computing environment is identified that are determined from data collected by one or more utilities in the computing environment. A criticality rating is automatically determined for the particular asset based at least in part on the set of attributes. A security activity is caused to be performed relating to the particular asset based on the automatically determined criticality rating of the particular asset.

Claims (36)

1. A method, comprising:

identifying a set of attributes of an asset of a computing environment, wherein the set of attributes identifies one or more users or a context of use of the asset by the one or more users, and the set of attributes identifies an access control deployed in connection with the asset;

determining, using at least one processor device, a criticality rating value for the asset based at least in part on (i) the one or more users or the context of use and (ii) the access control, wherein the criticality rating value is determined in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset;

calculating a risk measure for the asset from the criticality rating value; and

causing a security activity to be performed based at least in part on the risk measure for the asset.

2. The method of claim 1 , wherein the set of attributes identifies the one or more users and the context of use of the asset by the one or more users.

3. The method of claim 1 , wherein the risk measure is based on a magnitude of the impact and a probability that an event will cause the impact.

4. The method of claim 1 , wherein the risk measure is calculated from vulnerability detection data identifying vulnerabilities of the asset and countermeasure detection data identifying countermeasures deployed on the asset.

5. The method of claim 1 , wherein the causing the security activity to be performed includes determining a priority for the security activity based on the criticality rating value.

6. The method of claim 1 , wherein the criticality rating value indicates an impact of damage to or loss of the asset.

7. The method of claim 1 , further comprising:

determining that the criticality rating value does not exist for the asset based on an event involving the asset, wherein the set of attributes is determined from data collected by one or more utilities in the computing environment.

8. At least one non-transitory storage medium having instructions stored thereon, wherein the instructions, when executed on a machine, cause the machine to perform a method comprising:

identifying a set of attributes of an asset of a computing environment, wherein the set of attributes identifies one or more users or a context of use of the asset by the one or more users, and the set of attributes identifies an access control deployed in connection with the asset;

determining a criticality rating value for the asset based at least in part on (i) the one or more users or the context of use and (ii) the access control, wherein the criticality rating value is determined in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset;

calculating a risk measure for the asset from the criticality rating value; and

causing a security activity to be performed based at least in part on the risk measure for the asset.

9. The medium of claim 8 , wherein the set of attributes identifies the one or more users and the context of use of the asset by the one or more users.

10. The medium of claim 8 , wherein the risk measure is based on a magnitude of the impact and a probability that an event will cause the impact.

11. The medium of claim 8 , wherein the risk measure is calculated from vulnerability detection data identifying vulnerabilities of the asset and countermeasure detection data identifying countermeasures deployed on the asset.

12. The medium of claim 8 , wherein the causing the security activity to be performed includes determining a priority for the security activity based on the criticality rating value.

13. The medium of claim 8 , wherein the criticality rating value indicates an impact of damage to or loss of the asset.

14. The medium of claim 8 , the method further comprising:

determining that the criticality rating value does not exist for the asset based on an event involving the asset, wherein the set of attributes is determined from data collected by one or more utilities in the computing environment.

15. A system, comprising:

at least one memory element that stores instructions; and

at least one processor device that executes the instructions to

identify a set of attributes of an asset of a computing environment, wherein the set of attributes identifies one or more users or a context of use of the asset by the one or more users, and the set of attributes identifies an access control deployed in connection with the asset;

determine a criticality rating value for the asset based at least in part on (i) the one or more users or the context of use and (ii) the access control, wherein the criticality rating value is determined in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset;

calculate a risk measure for the asset from the criticality rating value; and

cause a security activity to be performed based at least in part on the risk measure for the asset.

16. The system of claim 15 , wherein the set of attributes identifies the one or more users and the context of use of the asset by the one or more users.

17. The system of claim 15 , wherein the risk measure is based on a magnitude of the impact and a probability that an event will cause the impact.

18. The system of claim 15 , wherein the risk measure is calculated from vulnerability detection data identifying vulnerabilities of the asset and countermeasure detection data identifying countermeasures deployed on the asset.

19. The system of claim 15 , wherein the security activity includes a determination of a priority for the security activity based on the criticality rating value.

20. The system of claim 15 , wherein the criticality rating value indicates an impact of damage to or loss of the asset.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (3)
Continuation 15959946 · Apr 23, 2018
Continuation 13718970 · Dec 18, 2012
Related Publication 20190253450A1 · Aug 15, 2019
Cited By (1)
US 12,229,277