IP Library Granted Patent US 11,743,252
Granted Patent B2
US 11,743,252 · App. 17/202,697 · Granted Aug 29, 2023

Security workflows to mitigate vulnerabilities in biometric devices

Inventors: Jared Frankston (Newton, MA); Barry Curran (Belfast, GB); Luke Milby (Bloomington, IL); Ashwin Anand (Acton, MA)
Assignee: Rapid7, Inc.
H04L63/0861H04L41/28H04L63/0853H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,252
App. No.
17/202,697
Granted
Aug 29, 2023
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for facilitating security orchestration, automation, and response (SOAR) in cybersecurity computing environments that use biometric data or implement biometric data gathering. An instruction is periodically transmitted to a protected computing device to perform a security scanning operation that captures biometric data generated from a biometric device associated with the protected computing device. The biometric data received from the protected computing device includes a biometric identity of a trusted user or an untrusted user. A security database is accessed to determine whether the biometric identity matches a stored biometric identity of the trusted user. A security workflow that includes orchestrated security operations configured to identify the untrusted user and to prevent the untrusted user from accessing the protected computing device if the biometric identity does not match the stored biometric identity is generated and transmitted to the protected computing device. A confirmation is received from the protected computing device that the orchestrated security operations have been performed.

Claims (50)

1. A computer-implemented method, comprising:

transmitting, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated by a plurality of biometric devices associated with the protected computing device;

receiving an indication from the protected computing device that the biometric data comprises multiplexed biometric data;

based on receiving the indication that the biometric data comprises the multiplexed biometric data, sending a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplexing the multiplexed biometric data into a plurality of demultiplexed parts constituting the biometric data, wherein

each demultiplexed part of the plurality of demultiplexed parts is generated by a different biometric device of the plurality of biometric devices;

accessing a security database to determine that at least one part of the plurality of demultiplexed parts does not match a stored biometric identity associated with the protected computing device; and

configuring a security workflow to comprise one or more offensive security operations or one or more defensive security operations based on a vulnerability level attached to a biometric device of the plurality of biometric device whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity.

2. The computer-implemented method of claim 1 , further comprising:

the security workflow comprises a plurality of orchestrated security operations that further comprise the one or more offensive security operations and the one or more defensive security operations.

3. The computer-implemented method of claim 2 , wherein

the vulnerability level attached to the biometric device of the plurality of biometric devices whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity triggers configuring the security workflow if the biometric device associated with the at least one part of the plurality of demultiplexed parts performs facial recognition within a scanning range.

4. The computer-implemented method of claim 3 , further comprising:

transmitting the security workflow to the protected computing device.

5. The computer-implemented method of claim 4 , wherein

the periodically transmitted instruction from the security server causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on the scanning range of the biometric device that performs the facial recognition.

6. A non-transitory computer readable storage medium comprising program instructions executable to:

transmit, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated by a plurality of biometric devices associated with the protected computing device;

receive an indication from the protected computing device that the biometric data comprises multiplexed biometric data;

based on receiving the indication that the biometric data comprises the multiplexed biometric data, send a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplex the multiplexed biometric data into a plurality of demultiplexed parts constituting the biometric data, wherein

each demultiplexed part of the plurality of demultiplexed parts is generated by a different biometric device of the plurality of biometric devices;

access a security database to determine that at least one part of the plurality of demultiplexed parts does not match a stored biometric identity associated with the protected computing device; and

configure a security workflow to comprise one or more offensive security operations or one or more defensive security operations based on a vulnerability level attached to a biometric device of the plurality of biometric device whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity.

7. The non-transitory computer readable storage medium of claim 6 , further comprising:

the security workflow comprises a plurality of orchestrated security operations that further comprise the one or more offensive security operations and the one or more defensive security operations.

8. The non-transitory computer readable storage medium of claim 7 , wherein

the vulnerability level attached to the biometric device of the plurality of biometric devices whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity triggers configuring the security workflow if the biometric device associated with the at least one part of the plurality of demultiplexed parts performs facial recognition within a scanning range.

9. The non-transitory computer readable storage medium of claim 8 , further comprising:

transmitting the security workflow to the protected computing device.

10. The non-transitory computer readable storage medium of claim 8 , wherein

the periodically transmitted instruction from the security server causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on the scanning range of the biometric device that performs the facial recognition.

11. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

transmit, from a security server, an instruction periodically to a protected computing device to perform a security scanning operation that captures biometric data generated by a plurality of biometric devices associated with the protected computing device;

receive an indication from the protected computing device that the biometric data comprises multiplexed biometric data;

based on receiving the indication that the biometric data comprises the multiplexed biometric data, send a request to the protected computing device for the biometric data;

upon receiving the biometric data, demultiplex the multiplexed biometric data into a plurality of demultiplexed parts constituting the biometric data, wherein

each demultiplexed part of the plurality of demultiplexed parts is generated by a different biometric device of the plurality of biometric devices;

access a security database to determine that at least one part of the plurality of demultiplexed parts does not match a stored biometric identity associated with the protected computing device; and

configure a security workflow to comprise one or more offensive security operations or one or more defensive security operations based on a vulnerability level attached to a biometric device of the plurality of biometric device whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity.

12. The system of claim 11 , further comprising:

the security workflow comprises a plurality of orchestrated security operations that further comprise the one or more offensive security operations and the one or more defensive security operations.

13. The system of claim 12 , wherein

the vulnerability level attached to the biometric device of the plurality of biometric devices whose demultiplexed portion of the biometric data comprises the at least one part of the plurality of demultiplexed parts that does not match the stored biometric identity triggers configuring the security workflow if the biometric device associated with the at least one part of the plurality of demultiplexed parts performs facial recognition within a scanning range.

14. The system of claim 13 , further comprising:

transmitting the security workflow to the protected computing device.

15. The system of claim 14 , wherein

the periodically transmitted instruction from the security server causes the protected computing device to perform the security scanning operation in a protected geospatial location that is proximate to the protected computing device based on the scanning range of the biometric device that performs the facial recognition.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2021
From: ANAND, ASHWIN; CURRAN, BARRY; FRANKSTON, JARED; MILBY, LUKE
To: RAPID7, INC.
Reel/Frame 055912/0208 →
Continuity (2)
Continuation 16416426 · May 20, 2019
Related Publication 20210226946A1 · Jul 22, 2021