IP Library Patent Application 16749836
Patent Application
App. No. 16/749,836

AUTOMATED ORGANIZATIONAL SECURITY SCORING SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/749,836
Abstract

Computer security systems and methods are disclosed. In one general aspect, a computer security monitoring method is disclosed that includes continuously gathering machine-readable facts relating to a number of topics and continuously deriving and storing risk profiles for a plurality of monitored entities based on at least some of the facts. This method also includes providing an ontology that associates a different subset of the monitored entities to each of a plurality of organizational entities possessing digital assets, aggregating the risk scores for the scored entities for each of the organizational entities based on the associations in the ontology to derive an aggregated risk score, and electronically reporting the aggregated risk score to an end user.

Claims (32)

1 . A computer security monitoring method, including:

continuously gathering machine-readable facts relating to a number of topics,

continuously deriving and storing risk profiles for a plurality of monitored entities based on at least some of the facts,

providing an ontology that associates a different subset of the monitored entities to each of a plurality of organizational entities possessing digital assets,

aggregating the risk scores for the scored entities for each of the organizational entities based on the associations in the ontology to derive an aggregated risk score, and

electronically reporting the aggregated risk score to an end user.

2 . The method of claim 1 further including responding to user requests to explore the ontological relationships that led to the aggregated organizational risk score.

3 . The method of claim 1 further including the step of determining whether the aggregated organizational risk score meets a predetermined criteria, and wherein the step of electronically reporting includes electronically issuing an alert in response to the meeting of the predetermined criteria.

4 . The method of claim 1 wherein the step of electronically reporting includes issuing a report that includes the aggregated organizational entity risk score.

5 . The method of claim 4 wherein the step of issuing a report includes issuing a report that further includes a plurality of visual elements that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score.

6 . The method of claim 4 wherein the step of issuing a report includes issuing an interactive report that includes a plurality of controls that allow the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

7 . The method of claim 4 wherein the step of issuing a report includes issuing an interactive report that includes a plurality of visual elements that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score, and wherein the visual elements are responsive to user actuation to allow the user to explore the ontological relationships that lead to the aggregated organizational entity risk score.

8 . The method of claim 7 wherein the step of presenting visual elements presents the visual elements as a series of textual links that visually summarize the ontological relationships that lead to the aggregated organizational entity risk score, and wherein the links can be actuated to further explore the ontological relationships that lead to the aggregated organizational entity risk score.

9 . The method of claim 1 further including continuously updating the ontological relationships using an ongoing ontology maintenance process.

10 . The method of claim 1 wherein the ontological relationships include relationships between different organizational entities.

11 . The method of claim 10 wherein the ontological relationships include relationships between organizational entities and their subsidiaries.

12 . The method of claim 10 wherein the ontological relationships include relationships between organizational entities and their contractors.

13 . The method of claim 1 wherein the ontological relationships include relationships between organizational entities and network identifiers.

14 . The method of claim 1 wherein the ontological relationships include relationships between organizational entities and types of technology.

15 . The method of claim 1 wherein the ontological relationships can be expressed as a directed acyclic graph.

16 . A computer security monitoring system, including:

a fact monitoring interface operative to continuously gather machine-readable facts relating to a number of topics,

risk assessment logic responsive to the fact monitoring interface and operative to continuously derive and store risk profiles for a plurality of monitored entities based on at least some of the facts,

ontology storage operative to store an ontology that associates a different subset of the monitored entities to each of a plurality of organizational entities possessing digital assets,

aggregation logic operative to aggregate the risk scores for the scored entities for each of the organizational entities based on the associations in the ontology to derive an aggregated risk score, and

a reporting interface operative to electronically report the aggregated risk score to an end user.

17 . A computer security monitoring system, including:

means for continuously gathering machine-readable facts relating to a number of topics,

means for continuously deriving and storing risk profiles for a plurality of monitored entities based on at least some of the facts,

means for providing an ontology that associates a different subset of the monitored entities to each of a plurality of organizational entities possessing digital assets,

means for aggregating the risk scores for the scored entities for each of the organizational entities based on the associations in the ontology to derive an aggregated risk score, and

means for electronically reporting the aggregated risk score to an end user.

Assignments (2)
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2024
From: ALTER DOMUS (US) LLC
To: RECORDED FUTURE, INC; SECURITYTRAILS, LLC
Reel/Frame 069665/0398 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jun 28, 2024
From: RECORDED FUTURE, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 067964/0413 →