IP Library Granted Patent US 11,570,197
Granted Patent B2
US 11,570,197 · App. 16/863,803 · Granted Jan 31, 2023

Human-centric risk modeling framework

Inventors: Margaret Cunningham (Austin, TX); Clifford Charles Wright (Oxfordshire, GB); Dalwinderjeet Kular Grewal (Austin, TX)
Assignee: Forcepoint LLC
H04L63/1433G06F21/316G06F21/552G06F21/577H04L63/102H04L63/1425H04L63/1483H04L67/306H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,197
App. No.
16/863,803
Granted
Jan 31, 2023
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing a security risk modeling operation. The security risk modeling operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; deriving an observable based upon the monitoring of the electronically-observable data source; identifying a security related activity, the security related activity being based upon the observable from the electronic data source; analyzing the security related activity, the analyzing the security related activity using a human-centric risk modeling framework; and, performing a security operation in response to the analyzing the security related activity.

Claims (55)

1. A computer-implementable method for modeling security risk, comprising:

monitoring an entity, the monitoring observing an electronically-observable data source;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity, the security related activity being based upon the observable from the electronic data source;

analyzing the security related activity, the analyzing the security related activity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting a user entity behavior; and,

performing a security operation in response to the analyzing the security related activity.

2. The method of claim 1 , wherein:

the human-centric risk modeling framework is implemented as a reference model, the reference model being used to assess a risk associated with a user entity enacting the security related activity.

3. The method of claim 2 , wherein:

the risk is quantitatively expressed as a user entity risk score.

4. The method of claim 1 , wherein:

the human-centric risk modeling framework comprises at least one of a user entity behavior, a security risk use case, a kill chain phase, a security risk persona, a user entity predisposition, a security vulnerability scenario, a concerning behavior and a contextual modifier.

5. The method of claim 4 , wherein:

the concerning behavior comprises an associated concerning behavior score, the security risk persona comprises an associated persona baseline risk score, and the user entity behavior comprises the security related activity.

6. The method of claim 4 , wherein:

the contextual modifier comprises a stressor modifier, an organizational modifier and a motivation modifier.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring an entity, the monitoring observing an electronically-observable data source;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity, the security related activity being based upon the observable from the electronic data source;

analyzing the analyzing the security related activity, the analyzing the security related activity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting a user entity behavior; and,

performing a security operation in response to the analyzing the security related activity.

8. The system of claim 7 , wherein:

the human-centric risk modeling framework is implemented as a reference model, the reference model being used to assess a risk associated with a user entity enacting the security related activity.

9. The system of claim 8 , wherein:

the risk is quantitatively expressed as a user entity risk score.

10. The system of claim 7 , wherein:

the human-centric risk modeling framework comprises at least one of a user entity behavior, a security risk use case, a kill chain phase, a security risk persona, a user entity predisposition, a security vulnerability scenario, a concerning behavior and a contextual modifier.

11. The system of claim 10 , wherein:

the concerning behavior comprises an associated concerning behavior score, the security risk persona comprises an associated persona baseline risk score, and the user entity behavior comprises the security related activity.

12. The system of claim 10 , wherein:

the contextual modifier comprises a stressor modifier, an organizational modifier and a motivation modifier.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring an entity, the monitoring observing an electronically-observable data source;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity, the security related activity being based upon the observable from the electronic data source;

analyzing the security related activity, the analyzing the security related activity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting a user entity behavior; and,

performing a security operation in response to the analyzing the security related activity.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the human-centric risk modeling framework is implemented as a reference model, the reference model being used to assess a risk associated with a user entity enacting the security related activity.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the risk is quantitatively expressed as a user entity risk score.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the human-centric risk modeling framework comprises at least one of a user entity behavior, a security risk use case, a kill chain phase, a security risk persona, a user entity predisposition, a security vulnerability scenario, a concerning behavior and a contextual modifier.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein:

the concerning behavior comprises an associated concerning behavior score, the security risk persona comprises an associated persona baseline risk score, and the user entity behavior comprises the security related activity.

18. The non-transitory, computer-readable storage medium of claim 16 , wherein:

the contextual modifier comprises a stressor modifier, an organizational modifier and a motivation modifier.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2020
From: CUNNINGHAM, MARGARET; WRIGHT, CLIFFORD CHARLES; GREWAL, DALWINDERJEET KULAR
To: FORCEPOINT LLC
Reel/Frame 052776/0201 →
Continuity (3)
Provisional Application 63017400 · Apr 29, 2020
Provisional Application 62964372 · Jan 22, 2020
Related Publication 20210226983A1 · Jul 22, 2021
Cited By (1)
US 12,425,440