IP Library Granted Patent US 10,986,090
Granted Patent B1
US 10,986,090 · App. 16/416,426 · Granted Apr 20, 2021

Security orchestration and automation using biometric data

Inventors: Jared Frankston (Newton, MA); Barry Curran (Belfast, GB); Luke Milby (Bloomington, IL); Ashwin Anand (Acton, MA)
Assignee: Rapid7, Inc.
H04L63/0861H04L41/28H04L63/0853H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,090
App. No.
16/416,426
Granted
Apr 20, 2021
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes for facilitating security orchestration, automation, and response (SOAR) in cybersecurity computing environments that use biometric data or implement biometric data gathering. An instruction is periodically transmitted to a protected computing device to perform a security scanning operation that captures biometric data generated from a biometric device associated with the protected computing device. The biometric data received from the protected computing device includes a biometric identity of a trusted user or an untrusted user. A security database is accessed to determine whether the biometric identity matches a stored biometric identity of the trusted user. A security workflow that includes orchestrated security operations configured to identify the untrusted user and to prevent the untrusted user from accessing the protected computing device if the biometric identity does not match the stored biometric identity is generated and transmitted to the protected computing device. A confirmation is received from the protected computing device that the orchestrated security operations have been performed.

Claims (67)

1. A computer-implemented method, comprising:

transmitting, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a biometric device associated with the protected computing device;

receiving an indication from the protected computing device if the biometric data comprises bifurcated biometric data or multiplexed biometric data;

sending a request to the protected computing device to determine whether a first part of a biometric identity comprised in the bifurcated biometric data is stored locally in a cache or a storage device associated with the protected computing device;

requesting the protected computing device to only transmit a second part of the biometric identity comprised in the bifurcated biometric data if the first part of the biometric identity is stored in the cache or the local storage device;

accessing a security database to determine whether the second part of the biometric identity matches a second part of the stored biometric identity;

receiving, at the security server, the bifurcated biometric data from the protected computing device that comprises the second part of the biometric identity of a trusted user or an untrusted user;

accessing the security database to determine whether the second part of the biometric identity matches a stored biometric identity of the trusted user;

generating a security workflow comprising a plurality of orchestrated security operations configured to prevent the untrusted user from accessing the protected computing device if the second part of the biometric identity does not match the stored biometric identity;

transmitting the security workflow to the protected computing device; and

receiving confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

2. The computer-implemented method of claim 1 , wherein

the periodic instruction causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on a scanning range of the biometric device.

3. The computer-implemented method of claim 1 , further comprising:

based on receiving the indication that the biometric data comprises the multiplexed biometric data, sending a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplexing the multiplexed biometric data into a plurality of demultiplexed parts of the biometric data, each generated from one or more biometric sensors in addition to the biometric device; and

configuring the security workflow to comprise one or more offensive security operations and one or more defensive security operations as part of the plurality of orchestrated security operations based on a vulnerability level attached to each biometric sensor of the one or more biometric sensors.

4. The computer-implemented method of claim 1 , wherein:

a first orchestrated security operation of the plurality of orchestrated security operations prevents file system access, and

a second orchestrated security operation of the plurality of orchestrated security operations prevents kernel access.

5. The computer-implemented method of claim 4 , further comprising:

transmitting another instruction to the protected computing system to modify the security workflow to cause inhibition of performance of the second orchestrated security operation upon determining that the biometric identity matches the stored biometric identity of the trusted user after initiation but prior to completion of the first orchestrated security operation.

6. A non-transitory computer readable storage medium comprising program instructions executable to:

transmit, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a biometric device associated with the protected computing device;

receive an indication from the protected computing device if the biometric data comprises bifurcated biometric data or multiplexed biometric data;

send a request to the protected computing device to determine whether a first part of a biometric identity comprised in the bifurcated biometric data is stored locally in a cache or a storage device associated with the protected computing device;

request the protected computing device to only transmit a second part of the biometric identity comprised in the bifurcated biometric data if the first part of the biometric identity is stored in the cache or the local storage device;

access a security database to determine whether the second part of the biometric identity matches a second part of the stored biometric identity;

receive, at the security server, the bifurcated biometric data from the protected computing device that comprises the second part of the biometric identity of a trusted user or an untrusted user;

access the security database to determine whether the second part of the biometric identity matches a stored biometric identity of the trusted user;

generate a security workflow comprising a plurality of orchestrated security operations configured to prevent the untrusted user from accessing the protected computing device if the second part of the biometric identity does not match the stored biometric identity;

transmit the security workflow to the protected computing device; and

receive confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

7. The non-transitory computer readable medium of claim 6 , wherein

the periodic instruction causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on a scanning range of the biometric device.

8. The non-transitory computer readable medium of claim 6 , further comprising:

based on receiving the indication that the biometric data comprises the multiplexed biometric data, sending a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplexing the multiplexed biometric data into a plurality of demultiplexed parts of the biometric data, each generated from one or more biometric sensors in addition to the biometric device; and

configuring the security workflow to comprise one or more offensive security operations and one or more defensive security operations as part of the plurality of orchestrated security operations based on a vulnerability level attached to each biometric sensor of the one or more biometric sensors.

9. The non-transitory computer readable medium of claim 6 , wherein:

a first orchestrated security operation of the plurality of orchestrated security operations prevents file system access, and

a second orchestrated security operation of the plurality of orchestrated security operations prevents kernel access.

10. The non-transitory computer readable medium of claim 9 , further comprising:

transmitting another instruction to the protected computing system to modify the security workflow to cause inhibition of performance of the second orchestrated security operation upon determining that the biometric identity matches the stored biometric identity of the trusted user after initiation but prior to completion of the first orchestrated security operation.

11. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

transmit, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a biometric device associated with the protected computing device;

receive an indication from the protected computing device if the biometric data comprises bifurcated biometric data or multiplexed biometric data;

send a request to the protected computing device to determine whether a first part of a biometric identity comprised in the bifurcated biometric data is stored locally in a cache or a storage device associated with the protected computing device;

request the protected computing device to only transmit a second part of the biometric identity comprised in the bifurcated biometric data if the first part of the biometric identity is stored in the cache or the local storage device;

access a security database to determine whether the second part of the biometric identity matches a second part of the stored biometric identity;

receive, at the security server, the bifurcated biometric data from the protected computing device that comprises the second part of the biometric identity of a trusted user or an untrusted user;

access the security database to determine whether the second part of the biometric identity matches a stored biometric identity of the trusted user;

generate a security workflow comprising a plurality of orchestrated security operations configured to prevent the untrusted user from accessing the protected computing device if the second part of the biometric identity does not match the stored biometric identity;

transmit the security workflow to the protected computing device; and

receive confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

12. The system of claim 11 , wherein

the periodic instruction causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on a scanning range of the biometric device.

13. The system of claim 11 , further comprising:

based on receiving the indication that the biometric data comprises the multiplexed biometric data, sending a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplexing the multiplexed biometric data into a plurality of demultiplexed parts of the biometric data, each generated from one or more biometric sensors in addition to the biometric device; and

configuring the security workflow to comprise one or more offensive security operations and one or more defensive security operations as part of the plurality of orchestrated security operations based on a vulnerability level attached to each biometric sensor of the one or more biometric sensors.

14. The system of claim 11 , wherein:

a first orchestrated security operation of the plurality of orchestrated security operations prevents file system access,

a second orchestrated security operation of the plurality of orchestrated security operations prevents kernel access, and

another instruction transmitted to the protected computing system to modify the security workflow causes inhibition of performance of the second orchestrated security operation if the biometric identity matches the stored biometric identity of the trusted user after initiation but prior to completion of the first orchestrated security operation.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2019
From: ANAND, ASHWIN; CURRAN, BARRY; FRANKSTON, JARED; MILBY, LUKE
To: RAPID7, INC.
Reel/Frame 049482/0259 →