IP Library Granted Patent US 11,698,977
Granted Patent B1
US 11,698,977 · App. 17/098,074 · Granted Jul 11, 2023

Predicting and quantifying weaponization of software weaknesses

Inventors: Benjamin Anthony Mixon-Baca (Albuquerque, NM); Srinivas Mukkamala (Albuquerque, NM)
Assignee: Ivanti, Inc.
G06F21/577G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,698,977
App. No.
17/098,074
Granted
Jul 11, 2023
Kind
B1
Abstract

A method and/or computer software for estimating the probability that a software weakness will be used in an exploit and/or malware and the probability that the developed exploit and/or malware will result in a compromise.

Claims (48)

1. A method for providing a likelihood that a software weakness will be used in a future compromise, the method comprising:

generating one or more covariates by performing a first preprocessing transformation on modeling data;

inputting training group data into a first prediction program to create a model that predicts whether a software weakness will be integrated into one or both of an exploit and malware;

applying a second preprocessing transformation program to the output of the first prediction program, the modeling data, and a simulated compromise covariate;

performing a second statistical sampling function to an output of the second preprocessing transformation program; and

applying a second predictive program to an output of the second statistical sampling function to, wherein an output of the second predictive program provides indicia of a probability that a software weakness will be used in a future compromise.

2. The method of claim 1 , wherein:

the modeling data comprises an aggregation of two or more items of data selected from software weakness data, exploit data, malware data, and compromise data;

the software weakness comprises code that causes local code execution, remote code execution, denial of service, unauthorized reading of data; unintentional reading of data; or unauthorized modification of data; and

the exploit or the malware comprises code that uses the software weakness and that causes one or more or a combination of denial of service, unauthorized read of a program running code with the software weakness, unauthorized write of a program running code with the software weakness, and performance of an operation desired by an entity using the exploit or the malware.

3. The method of claim 1 , further comprising splitting the modeling data into at least three groups of data, wherein the at least three groups of data comprise the training group data, a testing group data, and a validation group data.

4. The method of claim 3 , further comprising:

inputting the training group data into the first prediction program to create one or more preliminary models that are able to predict whether a software weakness is integrated in the exploit or the malware;

testing prediction accuracy metrics of the preliminary models using the testing group data, the prediction accuracy metrics including false positive, true negative, false negative, and true positive rates; and

selecting one of the preliminary models as the model based on prediction accuracy metrics.

5. The method of claim 4 , further comprising repeating the testing a predetermined number of times, wherein the predetermined number of times is based on a classification accuracy of the preliminary models, a running time of the preliminary models, or a scalability of the preliminary models.

6. The method of claim 1 , further comprising performing a first statistical sampling function on the one or more covariates.

7. The method of claim 6 , wherein the first statistical sampling function includes one or more or a combination of:

splitting the modeling data apart,

reordering entries of the modeling data, and

randomly shuffle the modeling data.

8. The method of claim 6 , wherein the first statistical sampling function performs one or both of an upsampling technique and a downsampling technique.

9. A non-transitory computer-readable medium comprising computer software for providing a likelihood that a software weakness will be used in a future compromise comprising:

code for generating one or more covariates by performing a first preprocessing transformation on modeling data;

code for inputting training group data into a first prediction program to create a model that predicts whether a software weakness will be integrated into one or both of an exploit and malware;

code for applying a second preprocessing transformation program to the output of the first prediction program, the modeling data, and a simulated compromise covariate;

code for performing a second statistical sampling function to an output of the second preprocessing transformation program; and

code for applying a second predictive program to an output of the second statistical sampling function, wherein an output of the second predictive program provides indicia of a probability that a software weakness will be used in a future compromise.

10. The method of claim 1 , wherein the simulated compromise covariate includes a number of a particular hardware or a software platform running on an organization's computing resource that were successfully abused by a cyber weapon.

11. The method of claim 1 , wherein:

the output of the second predictive program is used with risk and prioritization metrics to specify a policy having an action to be taken when a specific software weakness is present in a computing environment of an organization; and

the action includes a prioritize patching of the software weakness or prioritizing a firewall fix to block access to specific computing resources.

12. The non-transitory computer-readable medium of claim 9 , further comprising code for splitting the modeling data into at least three groups of data, wherein the at least three groups of data comprise the training group data, a testing group data, and a validation group data.

13. The non-transitory computer-readable medium of claim 12 , further comprising:

code for inputting the training group data into the first prediction program to create one or more preliminary models that are able to predict whether a software weakness is integrated in the exploit or the malware;

code for testing prediction accuracy metrics of the preliminary models using the testing group data, the prediction accuracy metrics including false positive, true negative, false negative, and true positive rates; and

code for selecting one of the preliminary models as the model based on prediction accuracy metrics.

14. The non-transitory computer-readable medium of claim 13 , further comprising code for repeating the testing a predetermined number of times, wherein the predetermined number of times is based on a classification accuracy of the preliminary models, a running time of the preliminary models, or a scalability of the preliminary models.

15. The non-transitory computer-readable medium of claim 9 , further comprising code for performing a first statistical sampling function on the one or more covariates.

16. The non-transitory computer-readable medium of claim 15 , wherein the code for the first statistical sampling function comprises code that is configured to perform one or more or a combination of:

splitting the modeling data apart,

reordering entries of the modeling data, and

randomly shuffle the modeling data.

17. The non-transitory computer-readable medium of claim 15 , wherein the code for the first statistical sampling function comprises code for performing one or both of an upsampling technique and a downsampling technique.

18. The non-transitory computer-readable medium of claim 9 , wherein the simulated compromise covariate includes a number of a particular hardware or a software platform running on an organization's computing resource that were successfully abused by a cyber weapon.

19. The non-transitory computer-readable medium of claim 9 , wherein:

the output of the second predictive program is used with risk and prioritization metrics to specify a policy having an action to be taken when a specific software weakness is present in a computing environment of an organization; and

the action includes a prioritize patching of the software weakness or prioritizing a firewall fix to block access to specific computing resources.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 058029/0029 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0609 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 067457/0497 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071124/0331 →
SECOND LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 067457/0497 →
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded May 19, 2024
From: IVANTI, INC.; PULSE SECURE, LLC; MOBILEIRON, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 067457/0472 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: RISKSENSE, INC.
To: IVANTI, INC.
Reel/Frame 060903/0683 →
SECURITY INTEREST Recorded Nov 5, 2021
From: RISKSENSE, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 058028/0873 →
SECURITY INTEREST Recorded Nov 5, 2021
From: RISKSENSE, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 058029/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2021
From: MIXON-BACA, BENJAMIN ANTHONY; MUKKAMALA, SRINIVAS
To: RISKSENSE, INC.
Reel/Frame 056025/0549 →
Continuity (1)
Provisional Application 62934978 · Nov 13, 2019
Cited By (2)
US 12,299,133 US 12,333,056