IP Library Granted Patent US 11,477,227
Granted Patent B1
US 11,477,227 · App. 16/699,879 · Granted Oct 18, 2022

Enterprise security measures

Inventors: Douglas C. Rambo (Davidson, NC); Steven M. Trudeau (Advance, NC); Titanya Hughes (Charlotte, NC); Michael Colehouse (Shoreview, MN); Timothy J. Calabro (Brooklyn, NY); Vincent N. Nguyen (Minneapolis, MN); Ben D. Brenden (Eau Claire, WI)
Assignee: WELLS FARGO BANK, N.A.
H04L63/1433G06F8/65G06F16/24578G06F21/50G06F21/577H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,227
App. No.
16/699,879
Granted
Oct 18, 2022
Kind
B1
Abstract

A system for managing security within an enterprise includes a computing device that receives a vulnerability, generates a user score for each user within the enterprise and generates a threat score for the vulnerability. A user device score may also be generated for each device associated with a user. Based on the user score and the threat score, a composite score is generated. After acquiring a security measure, the security measure is implemented based on the composite score and, at times, the user score.

Claims (48)

1. An electronic computing device, comprising:

a processing unit; and

system memory, the system memory including instructions that, when executed by the processing unit, cause the electronic computing device to:

generate a user score for at least one of a plurality of users of computing devices, the user score being based upon behavioral data including behavioral patterns and access patterns of the at least one of the plurality of users;

determine a number of the computing devices affected by a vulnerability;

determine, based on the number of the computing devices and types of the computing devices affected by the vulnerability, a number of the plurality of users affected by the vulnerability;

based on the user score and the number of the plurality of users, determine a sequence of priority of distribution of remediation for the computing devices associated with the plurality of users; and

sequentially implement remediation for the computing devices, including to implement remediation for one of the computing devices after implementing remediation for another of the computing devices, based on the sequence of priority.

2. The electronic computing device of claim 1 , wherein the instructions, when executed by the processing unit, cause the electronic computing device to:

generate a user score for each of the plurality of users of the computing devices based upon behavioral data including behavioral patterns and access patterns of all of the plurality of users,

wherein the sequence of the priority of distribution of remediation is based on all of the user scores.

3. The electronic computing device of claim 1 , wherein the remediation includes publishing a security patch.

4. The electronic computing device of claim 3 , wherein the publishing the security patch includes sending a reminder to update after a predetermined period of time.

5. The electronic computing device of claim 1 , wherein the behavioral data includes at least one of: a type of a user device associated with the at least one of the plurality of users and a type of processes used by the user device associated with the at least one of the plurality of users.

6. The electronic computing device of claim 1 , wherein the behavioral data includes at least one of: a corporate rank of the at least one of the plurality of users and a system access level for the at least one of the plurality of users.

7. The electronic computing device of claim 1 ,

wherein the behavioral patterns include at least one of the following: a browsing history of the at least one of the plurality of users, a volume of junkmail, a previous computing device infection, a volume of phishing email; and

wherein the access patterns include at least one of the following: a quantity of unique devices used by the at least one of the plurality of users to access enterprise-related data, and an access pattern of the at least one of the plurality of users including time of day.

8. The electronic computing device of claim 1 , wherein the instructions, when executed by the processing unit, cause the electronic computing device to:

activate a security module to lock out a device capability of a computing device associated with the at least one of the plurality of users if the at least one of the plurality of users does not perform the remediation within a first predetermined time period.

9. The electronic computing device of claim 8 , wherein the instructions, when executed by the processing unit, cause the electronic computing device to:

deactivate access to data if the at least one of the plurality of users does not perform the remediation within a second predetermined time period.

10. The electronic computing device of claim 1 , wherein the instructions, when executed by the processing unit, cause the electronic computing device to:

determine compliance of the at least one of the plurality of users with the implemented remediation; and

implement, based on the compliance, an additional security measure.

11. A computer-implemented method, comprising:

generating a user score for at least one of a plurality of users of computing devices, the user score being based upon behavioral data including behavioral patterns and access patterns of the at least one of the plurality of users;

determining a number of the computing devices affected by a vulnerability;

determining, based on the number of the computing devices and types of the computing devices affected by the vulnerability, a number of the plurality of users affected by the vulnerability;

determining, based on the user score and the number of the plurality of users, a sequence of priority of distribution of remediation for the computing devices associated with the plurality of users; and

sequentially implementing remediation for the computing devices, including implementing remediation for one of the computing devices after implementing remediation for another of the computing devices, based on the sequence of priority.

12. The computer-implemented method of claim 11 , further comprising:

generating a user score for each of the plurality of users of the computing devices based upon behavioral data including behavioral patterns and access patterns of all of the plurality of users,

wherein the sequence of the priority of distribution of remediation is based on all of the user scores.

13. The computer-implemented method of claim 11 , wherein the remediation includes publishing a security patch.

14. The computer-implemented method of claim 13 , wherein the publishing the security patch includes sending a reminder to update after a predetermined period of time.

15. The computer-implemented method of claim 11 , wherein the behavioral data includes at least one of: a type of a user device associated with the at least one of the plurality of users and a type of processes used by the user device associated with the at least one of the plurality of users.

16. The computer-implemented method of claim 11 , wherein the behavioral data includes at least one of: a corporate rank of the at least one of the plurality of users and a system access level for the at least one of the plurality of users.

17. The computer-implemented method of claim 11 ,

wherein the behavioral patterns include at least one of the following: a browsing history of the at least one of the plurality of users, a volume of junkmail, a previous computing device infection, a volume of phishing email; and

wherein the access patterns include at least one of the following: a quantity of unique devices used by the at least one of the plurality of users to access enterprise-related data, and an access pattern of the at least one of the plurality of users including time of day.

18. The computer-implemented method of claim 11 , further comprising:

activating a security module to lock out a device capability of a computing device associated with the at least one of the plurality of users if the at least one of the plurality of users does not perform the remediation within a first predetermined time period.

19. The computer-implemented method of claim 18 , further comprising:

deactivating access to data if the at least one of the plurality of users does not perform the remediation within a second predetermined time period.

20. The computer-implemented method of claim 11 , further comprising:

determining compliance of the at least one of the plurality of users with the implemented remediation; and

implementing, based on the compliance, an additional security measure.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071657/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2019
From: RAMBO, DOUGLAS C; TRUDEAU, STEVEN M; HUGHES, TITANYA; COLEHOUSE, MICHAEL; CALABRO, TIMOTHY J; NGUYEN, VINCENT N; BRENDEN, BEN D
To: WELLS FARGO BANK, N.A.
Reel/Frame 051192/0451 →
Continuity (2)
Continuation 16107461 · Aug 21, 2018
Continuation 15148766 · May 6, 2016