IP Library Granted Patent US 12,299,619
Granted Patent B2
US 12,299,619 · App. 16/894,627 · Granted May 13, 2025

Adaptive enterprise risk evaluation

Inventors: Mark Joseph Risoldi (Princeton, NJ); Sethuraman Balasubramanian (Monmouth Junction, NJ)
Assignee: Merck Sharp & Dohme LLC
G06Q10/0635G06F3/0482G06F21/577G06F30/20G06Q10/06375G06F2111/10G06F2221/033G06F2221/034H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,619
App. No.
16/894,627
Filed
Jun 5, 2020
Granted
May 13, 2025
Kind
B2
Art Unit
3623
USPC
705/7.28
Abstract

An adaptive risk management application retrieves data corresponding to an asset. The asset is a computing device or software application of an enterprise system. The adaptive risk management system identifies a set of vulnerabilities of the asset. For each vulnerability in the set of vulnerabilities, the adaptive risk management application generates a recommendation for mitigating the vulnerability. The adaptive risk management application generates a user interface for the asset. The user interface comprises a list of the recommendations. The adaptive risk management system provides the user interface for display.

Claims (49)

1. A method, comprising:

retrieving data corresponding to an asset, wherein the asset is a computing device or software application of an enterprise system;

identifying a set of vulnerabilities of the asset;

for each vulnerability in the set of vulnerabilities, determining whether a respective measure of effectiveness of a respective security control has breached a respective threshold measure of effectiveness of the respective security control;

for each vulnerability in a subset of the set of vulnerabilities, responsive to determining that the respective measure of effectiveness of the respective security control has breached the respective threshold measure of effectiveness of the respective security control, generating a targeted recommendation to implement a new security control on the asset for mitigating the vulnerability;

generating a user interface for the asset comprising a list including each targeted recommendation;

providing the user interface for display;

receiving user selection of a particular targeted recommendation in the list, the particular targeted recommendation mitigating a particular vulnerability of the subset of vulnerabilities; and

applying the security control identified by the particular targeted recommendation to the asset to mitigate the particular vulnerability.

2. The method of claim 1 , wherein the user interface comprises a risk factors and mitigations panel that lists tactics for mitigating risk for the asset.

3. The method of claim 1 , wherein the user interface comprises an installed applications panel listing software applications installed upon the asset.

4. The method of claim 1 , further comprising:

receiving a user interaction at a portion of a second user interface corresponding to the asset;

wherein the user interface for the asset is generated responsive to receiving the user interaction.

5. The method of claim 1 , wherein the user interface comprises a risk score for the asset.

6. The method of claim 5 , wherein the user interface comprises an indicator of a potential change in risk score if recommendations are implemented.

7. A non-transitory computer-readable storage medium comprising stored computer program instructions that, when executed by a computing device, cause the computing device to:

retrieve data corresponding to an asset, wherein the asset is a computing device or software application of an enterprise system;

identify a set of vulnerabilities of the asset;

for each vulnerability in the set of vulnerabilities, determine whether a respective measure of effectiveness of a respective security control has breached a respective threshold measure of effectiveness of the respective security control;

for each vulnerability in a subset of the set of vulnerabilities, responsive to determining that the respective measure of effectiveness of the respective security control has breached the respective threshold measure of effectiveness of the respective security control, generate a targeted recommendation to implement a new security control on the asset for mitigating the vulnerability;

generate a user interface for the asset comprising a list including each targeted recommendation;

provide the user interface for display;

receive user selection of a particular targeted recommendation in the list, the particular targeted recommendation mitigating a particular vulnerability of the subset of vulnerabilities; and

apply the security control identified by the particular targeted recommendation to the asset to mitigate the particular vulnerability.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the user interface comprises a risk factors and mitigations panel that lists tactics for mitigating risk for the asset.

9. The non-transitory computer-readable storage medium of claim 7 , wherein the user interface comprises an installed applications panel listing software applications installed upon the asset.

10. The non-transitory computer-readable storage medium of claim 7 , wherein the computer program instructions further cause the computing device to:

receive a user interaction at a portion of a second user interface corresponding to the asset;

wherein the user interface for the asset is generated responsive to the user interaction.

11. The non-transitory computer-readable storage medium of claim 7 , wherein the user interface comprises a risk score for the asset.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the user interface comprises an indicator of a potential change in risk score if recommendations are implemented.

13. A system, comprising:

a processor; and

a non-transitory computer-readable storage medium comprising stored computer program instructions that, when executed by the processor, cause the processor to:

retrieve data corresponding to an asset, wherein the asset is a computing device or software application of an enterprise system;

identify a set of vulnerabilities of the asset;

for each vulnerability in the set of vulnerabilities, determine whether a respective measure of effectiveness of a respective security control has breached a respective threshold measure of effectiveness of the respective security control;

for each vulnerability in a subset of the set of vulnerabilities, responsive to determining that the respective measure of effectiveness of the respective security control has breached the respective threshold measure of effectiveness of the respective security control, generate a targeted recommendation to implement a new security control on the asset for mitigating the vulnerability;

generate a user interface for the asset comprising a list including each targeted recommendation;

provide the user interface for display;

receive user selection of a particular targeted recommendation in the list, the particular targeted recommendation mitigating a particular vulnerability of the subset of vulnerabilities; and

apply the security control identified by the particular targeted recommendation to the asset to mitigate the particular vulnerability.

14. The system of claim 13 , wherein the user interface comprises a risk factors and mitigations panel that lists tactics for mitigating risk for the asset.

15. The system of claim 13 , wherein the computer program instructions further comprise:

receive a user interaction at a portion of a second user interface corresponding to the asset;

wherein the user interface for the asset is generated responsive to the user interaction.

16. The system of claim 13 , wherein the user interface comprises a risk score for the asset.

17. The system of claim 16 , wherein the user interface comprises an indicator of a potential change in risk score if recommendations are implemented.

Assignments (2)
MERGER Recorded Jul 6, 2023
From: MERCK SHARP & DOHME CORP.
To: MERCK SHARP & DOHME LLC
Reel/Frame 064162/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2020
From: RISOLDI, MARK JOSEPH; BALASUBRAMANIAN, SETHURAMAN
To: MERCK SHARP & DOHME CORP.
Reel/Frame 053388/0379 →
Continuity (3)
Continuation In Part 16688732 · Nov 19, 2019
Provisional Application 62772608 · Nov 28, 2018
Related Publication 20200311630A1 · Oct 1, 2020
References Cited (61)
US 8256004B1 · Hill · 2012 [cited by examiner]
US 9292695B1 · Bassett · 2016 [cited by applicant]
US 10749891B2 · King-Wilson · 2020 [cited by applicant]
US 10817604B1 · Kimball et al. · 2020 [cited by applicant]
US 10848515B1 · Pokhrel et al. · 2020 [cited by applicant]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 11070582B1 · Berger · 2021 [cited by examiner]
US 20120180133A1 · Al-Harbi · 2012 [cited by examiner]
US 20140337971A1 · Casassa Mont et al. · 2014 [cited by applicant]
US 20160119373A1 · Fausto et al. · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by applicant]
US 20160234229A1 · Carpenter · 2016 [cited by examiner]
US 20160234239A1 · Knapp · 2016 [cited by examiner]
US 20160239665A1 · Hamby · 2016 [cited by examiner]
US 20170034023A1 · Nickolov et al. · 2017 [cited by applicant]
US 20170366572A1 · Dereszynski et al. · 2017 [cited by applicant]
US 20170346846A1 · Findlay · 2017 [cited by examiner]
US 20180020021A1 · Gilmore · 2018 [cited by examiner]
US 20180041533A1 · Chesla · 2018 [cited by examiner]
US 20180322584A1 · Fellows · 2018 [cited by applicant]
US 20180351987A1 · Patel · 2018 [cited by examiner]
US 20190020686A1 · Cohen · 2019 [cited by examiner]
US 20190222597A1 · Crabtree · 2019 [cited by examiner]
US 20190236661A1 · Hogg · 2019 [cited by examiner]
US 20200050986A1 · Vescio · 2020 [cited by examiner]
US 20200252423A1 · Hogg · 2020 [cited by examiner]
US 20200265145A1 · Slabyak · 2020 [cited by examiner]
US 20200274894A1 · Argoeti · 2020 [cited by examiner]
US 20200314134A1 · Izrael · 2020 [cited by examiner]
US 20200356678A1 · Gourisetti · 2020 [cited by examiner]
US 20200396254A1 · Crabtree · 2020 [cited by examiner]
US 20200404013A1 · Waplington · 2020 [cited by examiner]
US 20200410001A1 · Sarkissian · 2020 [cited by examiner]
US 20200412758A1 · Trivellato · 2020 [cited by examiner]
US 20210021644A1 · Crabtree · 2021 [cited by examiner]
US 20210037038A1 · Alsharif · 2021 [cited by examiner]
US 20210084057A1 · Chhabra · 2021 [cited by examiner]
US 20210089647A1 · Suwad · 2021 [cited by examiner]
US 20210110319A1 · Gourisetti · 2021 [cited by examiner]
US 20210152588A1 · Cruz · 2021 [cited by examiner]
US 20210168175A1 · Crabtree · 2021 [cited by examiner]
US 20210200870A1 · Yavo · 2021 [cited by examiner]
US 20210211450A1 · Aleidan · 2021 [cited by examiner]
US 20210211452A1 · Patel · 2021 [cited by examiner]
US 20210234885A1 · Campbell · 2021 [cited by examiner]
US 20210264034A1 · Jones · 2021 [cited by examiner]
US 20210273957A1 · Boyer · 2021 [cited by examiner]
US 20210273968A1 · Shaieb · 2021 [cited by examiner]
US 20210273978A1 · Hadar · 2021 [cited by examiner]
Shahriar, Hossain, and Mohammad Zulkernine. “Mitigating program security vulnerabilities: Approaches and challenges.” ACM Computing Surveys (CSUR) 44.3 (2012): 1-46. (Year: 2012). [cited by examiner]
Upadhyay, Darshana, and Srinivas Sampalli. “SCADA (Supervisory Control and Data Acquisition) systems: Vulnerability assessment and security recommendations.” Computers & Security 89 (2020): 101666. (Year: 2020). [cited by examiner]
Feng, Nan, Harry Jiannan Wang, and Minqiang Li. “A security risk analysis model for information systems: Causal relationships of risk factors and vulnerability propagation analysis.” Information sciences 256 (2014): 57-… [cited by examiner]
Hilson, D. et al., “Practical Project Risk Management: The ATOM Methodology,” Management Concepts Press, 2012, 11 pages, Second Edition (with cover page and table of contents). [cited by applicant]
Joint Task Force Transformation Initiative, “Managing Information Security Risk: Organization, Mission, and Information System View,” NIST Special Publication SP 800-39, Mar. 2011, 88 pages. [cited by applicant]
Perkins, T., “Managing Financial Trouble,” Morgan Stanley Journal of Applied Corporate Finance, Fall 2007, three pages, vol. 19, No. 4 (with table of contents). [cited by applicant]
Rausand, M., “Chapter 1: Introduction, Risk Assessment: Theory, Methods, and Applications,” John Wiley & Sons, Inc., 2011, 26 pages, First Edition. [cited by applicant]
Securityscorecard, “Understand and reduce risk with the world's most expansive & scalable cybersecurity ratings platform,” undated, 10 pages, [Online] [Retrieved on Mar. 11, 2020], Retrieved from the Internet <URL: http… [cited by applicant]
Noel, S. et al. “Measuring Security Risk of Networks Using Attack Graphs.” International Journal of Next-Generation Computing, vol. 1, No. 1, Jul. 2010, pp. 135-147. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/688,732, filed Dec. 17, 2021, 22 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/688,732, filed Mar. 31, 2022, 31 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/688,732, filed Aug. 25, 2022, 35 pages. [cited by applicant]