IP Library Granted Patent US 11,023,585
Granted Patent B1
US 11,023,585 · App. 16/884,607 · Granted Jun 1, 2021

Systems and methods for managing cybersecurity alerts

Inventors: Marc Noel Light (Somerville, MA); Tianyi Cai (Brookline, MA); Thomas Erhardt Montroy (Cambridge, MA)
Assignee: BitSight Technologies, Inc.
G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,023,585
App. No.
16/884,607
Granted
Jun 1, 2021
Kind
B1
Abstract

A system and method for setting alert thresholds related to cybersecurity ratings of one or more affiliate entities. An example method includes: obtaining entity data including cybersecurity event data for an affiliate entity; calculating a time-series cybersecurity rating for the affiliate entity based on the entity data; associating an alert reporting threshold with the time-series cybersecurity rating, wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the affiliate entity; applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the affiliate entity; and updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.

Claims (39)

1. A computer-implemented method of setting alert thresholds related to cybersecurity ratings of one or more affiliate entities, the method comprising:

obtaining entity data comprising a plurality of entity data sets, each entity data set associated with a respective affiliate entity from a plurality of affiliate entities and comprising cybersecurity event data associated with each respective affiliate entity;

calculating a time-series cybersecurity rating for one or more of the affiliate entities based on the respective entity data set;

associating an alert reporting threshold with the time-series cybersecurity rating,

wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the one or more affiliate entities;

applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the one or more affiliate entities; and

updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.

2. The method of claim 1 , wherein the plurality of affiliate entities comprises affiliates of an intended recipient of the alerts.

3. The method of claim 1 , wherein the time-series cybersecurity rating comprises a history of cybersecurity ratings during a previous time period.

4. The method of claim 1 , wherein the alert reporting threshold comprises a threshold cybersecurity rating.

5. The method of claim 1 , wherein the alert reporting threshold comprises a threshold rate of change in the time-series cybersecurity rating.

6. The method of claim 1 , wherein alerts are generated periodically while the time-series cybersecurity rating is either above or below the alert reporting threshold.

7. The method of claim 1 , wherein applying an alternative alert reporting threshold comprises iterating on the alert reporting threshold to achieve a desired number of alerts reported for the one or more affiliate entities during a previous time period.

8. The method of claim 7 , wherein iterating on the alert reporting threshold comprises receiving a user-specified desired number of alerts.

9. The method of claim 1 , wherein applying an alternative alert reporting threshold comprises iterating on the alert reporting threshold until a desired number of affiliate entities from the one or more affiliate entities trigger alerts during a previous time period.

10. The method of claim 1 , further comprising sending alerts to an intended recipient during a future time period using the updated alert reporting threshold.

11. A system comprising:

one or more computer systems programmed to perform operations comprising:

obtaining entity data comprising a plurality of entity data sets, each entity data set associated with a respective affiliate entity from a plurality of affiliate entities and comprising cybersecurity event data associated with each respective affiliate entity;

calculating a time-series cybersecurity rating for one or more of the affiliate entities based on the respective entity data set;

associating an alert reporting threshold with the time-series cybersecurity rating,

wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the one or more affiliate entities;

applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the one or more affiliate entities; and

updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.

12. The system of claim 11 , wherein the plurality of affiliate entities comprises affiliates of an intended recipient of the alerts.

13. The system of claim 11 , wherein the alert reporting threshold comprises a threshold cybersecurity rating.

14. The system of claim 11 , wherein the alert reporting threshold comprises a threshold rate of change in the time-series cybersecurity rating.

15. The system of claim 11 , wherein alerts are generated periodically while the time-series cybersecurity rating is either above or below the alert reporting threshold.

16. The system of claim 11 , wherein applying an alternative alert reporting threshold comprises iterating on the alert reporting threshold to achieve a desired number of alerts reported for the one or more affiliate entities during a previous time period.

17. The system of claim 16 , wherein iterating on the alert reporting threshold comprises receiving a user-specified desired number of alerts.

18. The system of claim 11 , wherein applying an alternative alert reporting threshold comprises iterating on the alert reporting threshold until a desired number of affiliate entities from the one or more affiliate entities trigger alerts during a previous time period.

19. The system of claim 11 , the operations comprising sending alerts to an intended recipient during a future time period using the updated alert reporting threshold.

20. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more computer processors, cause the one or more computer processors to perform operations comprising:

obtaining entity data comprising a plurality of entity data sets, each entity data set associated with a respective affiliate entity from a plurality of affiliate entities and comprising cybersecurity event data associated with each respective affiliate entity;

calculating a time-series cybersecurity rating for one or more of the affiliate entities based on the respective entity data set;

associating an alert reporting threshold with the time-series cybersecurity rating,

wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the one or more affiliate entities;

applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the one or more affiliate entities; and

updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2021
From: LIGHT, MARC NOEL; CAI, TIANYI; MONTROY, THOMAS ERHARDT
To: BITSIGHT TECHNOLOGIES, INC.
Reel/Frame 055410/0244 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 054481/0727 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 054481/0739 →
Cited By (16)
US 12,189,787 US 12,192,351 US 12,206,688 US 12,231,460 US 12,236,491 US 12,244,703 US 12,333,612 US 12,335,282 US 12,348,485 US 12,353,563 US 12,363,156 US 12,395,505 US 12,425,437 US 12,513,167 US 12,587,555 US 12,694,104