IP Library Granted Patent US 11,652,834
Granted Patent B2
US 11,652,834 · App. 17/025,930 · Granted May 16, 2023

Methods for using organizational behavior for risk ratings

Inventors: Philip John Steuart Gladstone (Carlisle, MA); Alan Joseph Kirby (Hollis, NH); John Matthew Truelove (Cambridge, MA); David Feinzeig (Stoneham, MA); Nagarjuna Venna (Waltham, MA); Stephen Boyer (Waltham, MA)
Assignee: BitSight Technologies, Inc.
H04L63/1425G06F3/0484G06Q30/0277G06Q50/01H04L61/4511H04L63/1416H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,834
App. No.
17/025,930
Granted
May 16, 2023
Kind
B2
Abstract

Among other things, traces are received of activities of an online user who is associated with an entity. By analysis of the traces a security state of the entity is inferred. Also, a map is generated between (a) technical assets that contribute to security characteristics of respective entities and (b) the identities of the entities that are associated with the respective technical assets At least part of the generating of the map is done automatically. A user can he engaged to assist in the generating of the map by presenting to the user through a user interface (a) data about the technical assets of entities and (b) an interactive tool for associating the technical assets with the identities of the entities.

Claims (53)

1. A computer-implemented method for mapping Internet Protocol (IP) addresses to an entity, the method comprising:

receiving a first domain name for the entity;

sending, to a domain name system (DNS) server, a first passive DNS query to identify first name servers for the first domain name;

receiving, from the DNS server, a list of the first name servers for the first domain name;

sending, for each of the first name servers, a second passive DNS query to identify second domain names for which the first name server is authoritative;

receiving, for each of the first name servers, a list of the second domain names for which the first name server is authoritative;

sending, for each of the second domain names, a third passive DNS query to identify host names for the hosts of the second domain name and IP addresses for the host names;

receiving a list of the host names and the IP addresses for the host names; and

mapping each IP address to an attribute for the entity.

2. The method of claim 1 , wherein the first domain name is received from a user interface.

3. The method of claim 1 , wherein the list of the host names comprises names of at least a subset of the first name servers.

4. The method of claim 1 , wherein the attribute is a Classless Inter-Domain Routing block.

5. The method of claim 1 , wherein receiving the first domain name for the entity comprises:

determining the first domain name for a website of the entity.

6. The method of claim 1 , wherein the method is executed at least two separate instances to track a change over time in the IP addresses for the host names.

7. The method of claim 6 , further comprising:

automatically updating the mapping of IP addresses upon identifying the change in the IP addresses.

8. The method of claim 1 , further comprising:

identifying a shared hosting service based on the mapped IP addresses.

9. The method of claim 1 , further comprising:

determining a security rating for the entity based on the mapped IP address.

10. The method of claim 1 , wherein the entity is a first entity, and wherein mapping each IP address to the attribute for the entity comprises:

determining that the IP address is mapped to attributes for the first entity and a second entity.

11. The method of claim 10 , further comprising:

determining a first security rating for the first entity and a second security rating for the second entity, the first security rating and the second security rating being related.

12. A computer-implemented system for mapping Internet Protocol (IP) addresses to an entity, the system comprising:

at least one memory storing computer-executable instructions; and

at least one processor for executing the instructions stored on the memory, wherein execution of the instructions programs the at least one processor to perform operations comprising:

receiving a first domain name for the entity;

sending, to a domain name system (DNS) server, a first passive DNS query to identify first name servers for the first domain name;

receiving, from the DNS server, a list of the first name servers for the first domain name;

sending, for each of the first name servers, a second passive DNS query to identify second domain names for which the first name server is authoritative;

receiving, for each of the first name servers, a list of the second domain names for which the first name server is authoritative;

sending, for each of the second domain names, a third passive DNS query to identify host names for the hosts of the second domain name and IP addresses for the host names;

receiving a list of the host names and the IP addresses for the host names; and

mapping each IP address to an attribute for the entity.

13. The system of claim 12 , further comprising:

a user interface coupled to the processor, wherein the processor is configured to receive the first domain name for the entity from the user interface.

14. The system of claim 12 , wherein the list of the host names comprises names of at least a subset of the first name servers.

15. The system of claim 12 , wherein the attribute is a Classless Inter-Domain Routing block.

16. The system of claim 12 , wherein receiving the first domain name for the entity comprises:

determining the first domain name for a website of the entity.

17. The system of claim 12 , wherein the operations are executed at least two separate instances to track a change over time in the IP addresses for the host names.

18. The system of claim 17 , wherein the operations further comprise:

automatically updating the mapping of IP addresses upon identifying the change in the IP addresses.

19. The system of claim 12 , wherein the operations further comprise:

identifying a shared hosting service based on the mapped IP addresses.

20. The system of claim 12 , wherein the operations further comprise:

determining a security rating for the entity based on the mapped IP address.

21. The system of claim 12 , wherein the entity is a first entity, and wherein mapping each IP address to the attribute for the entity comprises:

determining that the IP address is mapped to attributes for the first entity and a second entity.

22. The system of claim 21 , wherein the operations further comprise:

determining a first security rating for the first entity and a second security rating for the second entity, the first security rating and the second security rating being related.

Assignments (3)
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 054481/0727 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 054481/0739 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2020
From: GLADSTONE, PHILIP JOHN STEUART; KIRBY, ALAN JOSEPH; TRUELOVE, JOHN MATTHEW; FEINZEIG, DAVID; VENNA, NAGARJUNA; BOYER, STEPHEN
To: BITSIGHT TECHNOLOGIES, INC.
Reel/Frame 054299/0356 →
Continuity (4)
Continuation 16405121 · May 7, 2019
Continuation 15216955 · Jul 22, 2016
Continuation 14021585 · Sep 9, 2013
Related Publication 20210006581A1 · Jan 7, 2021
Cited By (8)
US 12,223,060 US 12,273,367 US 12,282,564 US 12,335,297 US 12,348,485 US 12,353,563 US 12,425,437 US 12,587,555