IP Library Granted Patent US 11,521,147
Granted Patent B2
US 11,521,147 · App. 16/938,633 · Granted Dec 6, 2022

Cloud service usage risk assessment

Inventors: Dejan Curcic (San Jose, CA); Rajiv Gupta (Los Altos, CA); Kaushik Narayan (San Jose, CA); Prasad Raghavendra Somasamudram (Bangalore, IN); Sekhar Sarukkai (Cupertino, CA)
Assignee: Skyhigh Security LLC
G06Q10/0635H04L41/50H04L41/5032H04L63/1433H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,521,147
App. No.
16/938,633
Granted
Dec 6, 2022
Kind
B2
Abstract

A method of assessing a risk level of an enterprise using cloud-based services from one or more cloud service providers includes assessing provider risk scores associated with the one or more cloud service providers; assessing cloud service usage behavior and pattern of the enterprise; and generating a risk score for the enterprise based on the provider risk scores and on the cloud service usage behavior and pattern of the enterprise. The risk score is indicative of the risk of the enterprise relating to the use of the cloud-based services from the one or more cloud service providers.

Claims (29)

1. A method of assessing a risk level of an enterprise using a cloud-based service from a cloud service provider, the method comprising:

generating, at a hardware processor, one or more cloud service usage analytics based on: data from a data network associated with the enterprise; and cloud service provider information associated with the cloud service provider and correlated to the data, the data relating to usage of the cloud service provider;

generating, using the hardware processor, a risk score for the enterprise based on the cloud service usage analytics and based on a cloud service provider risk score associated with the cloud service provider; and

generating, at the hardware processor, an output comprising a remediation suggestion based on the risk score generated.

2. The method of claim 1 , wherein the cloud service provider information is collected in one or more risk categories, and each of the one or more risk categories includes one or more attributes.

3. The method of claim 2 , wherein a weight value is assigned to each of the one or more risk categories.

4. The method of claim 1 , wherein the data reflects use of the cloud-based service by the enterprise.

5. The method of claim 1 , further comprising detecting an anomaly in the data.

6. The method of claim 1 , wherein the data is based on event logs.

7. A system of assessing a risk level of an enterprise using a cloud-based service from a cloud service provider, the system comprising:

memory; and

a hardware processor coupled to the memory and configured to:

generate one or more cloud service usage analytics based on: data from a data network associated with the enterprise; and cloud service provider information associated with the cloud service provider and correlated to the data, the data relating to usage of the cloud service provider;

generate a risk score for the enterprise based on the cloud service usage analytics and based on a cloud service provider risk score associated with the cloud service provider; and

generate an output comprising a remediation suggestion based on the risk score generated.

8. The system of claim 7 , wherein the cloud service provider information is collected in one or more risk categories, and each of the one or more risk categories includes one or more attributes.

9. The system of claim 8 , wherein a weight value is assigned to each of the one or more risk categories.

10. The system of claim 7 , wherein the data reflects use of the cloud-based service by the enterprise.

11. The system of claim 7 , wherein the hardware processor is further configured to detect an anomaly in the data.

12. The system of claim 7 , wherein the data is based on event logs.

13. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for assessing a risk level of an enterprise using a cloud-based service from a cloud service provider, the method comprising:

generating one or more cloud service usage analytics based on: data from a data network associated with the enterprise; and cloud service provider information associated with the cloud service provider and correlated to the data, the data relating to usage of the cloud service provider;

generating a risk score for the enterprise based on the cloud service usage analytics and based on a cloud service provider risk score associated with the cloud service provider; and

generating an output comprising a remediation suggestion based on the risk score generated.

14. The non-transitory computer-readable medium of claim 13 , wherein the cloud service provider information is collected in one or more risk categories, and each of the one or more risk categories includes one or more attributes.

15. The non-transitory computer-readable medium of claim 14 , wherein a weight value is assigned to each of the one or more risk categories.

16. The non-transitory computer-readable medium of claim 13 , wherein the data reflects use of the cloud-based service by the enterprise.

17. The non-transitory computer-readable medium of claim 13 , wherein the method further comprises detecting an anomaly in the data.

18. The non-transitory computer-readable medium of claim 13 , wherein the data is based on event logs.

Assignments (11)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
CHANGE OF NAME Recorded May 4, 2022
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 059855/0852 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: CURCIC, DEJAN; GUPTA, RAJIV; NARAYAN, KAUSHIK; SOMASAMUDRAM, PRASAD RAGHAVENDRA; SARUKKAI, SEKHAR
To: SKYHIGH NETWORKS, INC
Reel/Frame 059768/0537 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →