IP Library Granted Patent US 12,248,602
Granted Patent B2
US 12,248,602 · App. 17/459,999 · Granted Mar 11, 2025

Methods and apparatus to orchestrate personal protection across digital assets

Inventors: Srikanth Nalluri (Bangalore, IN); Dattatraya Kulkarni (Bangalore, IN); Raghavendra Hebbalalu (Bangalore, IN); Sandeep Swastik (Bangalore, IN); Piyush Pramod Joshi (Aurangabad, IN); Samrat Chitta (Bangalore, IN); Partha Sarathi Barik (Bangalore, IN)
Assignee: MCAFEE, LLC
G06F21/6245H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,602
App. No.
17/459,999
Granted
Mar 11, 2025
Kind
B2
Abstract

Methods, apparatus, systems, and articles of manufacture for orchestrating personal protection across digital assets are disclosed. An example apparatus includes at least one memory, instructions in the apparatus, and processor circuitry to execute the instructions to monitor digital assets associated with a protection threat surface to detect a protection event, determine one or more protection vectors associated with the digital assets in response to detecting the protection event, the one or more protection vectors including one or more values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface, and determine protection remediation action for the digital assets based on the one or more protection vectors.

Claims (75)

1. An apparatus comprising:

at least one memory;

instructions in the apparatus; and

processor circuitry to execute the instructions to:

monitor digital assets associated with a protection threat surface to detect a protection event;

determine one or more protection vectors associated with the protection threat surface in response to detecting the protection event, a first protection vector of the one or more protection vectors mapped to a respective protection capability associated with at least one of the digital assets, the first protection vector including at least two separate values, one or more of the at least two separate values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface;

determine a protection remediation action for the protection threat surface based on the one or more protection vectors;

assign the protection remediation action to a group based on at least one of the digital assets associated with the protection remediation action or a first device utilized to access at least one of the digital assets associated with the protection remediation action; and

cause the determined protection remediation action to be dispatched to the first device or a second device associated with at least one of the digital assets.

2. The apparatus of claim 1 , wherein the processor circuitry is to determine a priority of the determined protection remediation action based on an impact of the determined protection remediation action on the overall protection posture.

3. The apparatus of claim 2 , wherein the processor circuitry is to:

update the one or more protection vectors to correspond to an implementation of the protection remediation action; and

determine an improvement to an overall protection efficacy score based on the one or more protection vectors to determine the impact of the determined protection remediation action.

4. The apparatus of claim 3 , wherein the processor circuitry is to cause the improvement to the overall protection efficacy score to be dispatched to one or more of the first device, the second device, or a third device in response to the protection remediation action not being executed.

5. The apparatus of claim 1 , wherein the protection remediation action is a first protection remediation action and the protection event is a first protection event, wherein the processor circuitry is to:

determine the one or more protection vectors based on at least one of the first protection event or a second protection event;

determine a second protection remediation action for the protection threat surface based on the one or more protection vectors; and

prioritize the first protection remediation action or the second protection remediation action based on impact weights associated with the one or more protection vectors and notional values associated with the digital assets.

6. The apparatus of claim 1 , wherein the processor circuitry is to utilize a rule- based model to determine the protection remediation action, the rule-based model to determine the protection remediation action based on the protection event and an impact of the protection event on the one or more protection vectors.

7. The apparatus of claim 1 , wherein the processor circuitry is to utilize a machine learning-based model to determine the protection remediation action, the machine learning-based model to process the protection event, an impact of the protection event on the one or more protection vectors, and user behaviors associated with the digital assets to determine the protection remediation action.

8. The apparatus of claim 1 , wherein the processor circuitry is to:

identify at least one of the digital assets of the protection threat surface associated with the protection remediation action;

determine a time that a user frequently utilizes the first device or the second device; and

cause the determined protection remediation action to be dispatched to the the first device or the second device at the time.

9. The apparatus of claim 1 , wherein the protection threat surface includes user devices associated with more than one user, the user devices including the first device and the second device.

10. A non-transitory machine readable medium comprising instructions which, when executed, cause one or more processors to:

monitor digital assets associated with a protection threat surface to detect a protection event;

determine one or more protection vectors associated with the protection threat surface in response to detecting the protection event, a first protection vector of the one or more protection vectors mapped to a respective protection capability associated with at least one of the digital assets, the first protection vector including at least two separate values, one or more of the at least two separate values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface;

determine a protection remediation action for the protection threat surface based on the one or more protection vectors;

assign the protection remediation action to a group based on at least one of the digital assets associated with the protection remediation action or a first device utilized to access at least one of the digital assets associated with the protection remediation action; and

cause the determined protection remediation action to be dispatched to the first device or a second device associated with at least one of the digital assets.

11. The non-transitory machine readable medium of claim 10 , wherein the instructions, when executed, cause the one or more processors to determine a priority of the determined protection remediation action based on an impact of the determined protection remediation action on the overall protection posture.

12. The non-transitory machine readable medium of claim 11 , wherein the instructions, when executed, cause the one or more processors to:

update the one or more protection vectors to correspond with an implementation of the protection remediation action; and

determine an improvement to an overall protection efficacy score based on the one or more protection vectors to determine the impact of the determined protection remediation action.

13. The non-transitory machine readable medium of claim 12 , wherein the instructions, when executed, cause the one or more processors to cause the improvement to the overall protection efficacy score to be dispatched to one or more of the first device, the second device, or a third device in response to the protection remediation action not being executed.

14. The non-transitory machine readable medium of claim 10 , wherein the protection remediation action is a first protection remediation action and the protection event is a first protection event, wherein the instructions, when executed, cause the one or more processors to:

determine the one or more protection vectors based on at least one of the first protection event or a second protection event;

determine a second protection remediation action for the protection threat surface based on the one or more protection vectors; and

prioritize the first protection remediation action or the second protection remediation action based on impact weights associated with the one or more protection vectors and notional values associated with the digital assets.

15. The non-transitory machine readable medium of claim 10 , wherein the instructions, when executed, cause the one or more processors to utilize a rule-based model to determine the protection remediation action, the rule-based model to determine the protection remediation action based on the protection event and an impact of the protection event on the one or more protection vectors.

16. The non-transitory machine readable medium of claim 10 , wherein the instructions, when executed, cause the one or more processors to utilize a machine learning- based model to determine the protection remediation action, the machine learning-based model to process the protection event, an impact of the protection event on the one or more protection vectors, and user behaviors associated with the digital assets to determine the protection remediation action.

17. The non-transitory machine readable medium of claim 10 , wherein at least one of the digital assets is associated with more than one user device.

18. An apparatus comprising:

means for monitoring digital assets associated with a protection threat surface to detect a protection event;

means for determining protection vectors associated with the protection threat surface in response to detecting the protection event, a first protection vector of the one or more protection vectors mapped to a respective protection capability associated with at least one of the digital assets, the first protection vector including at least two separate values, one or more of the at least two separate values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface;

means for determining a protection remediation action for the protection threat surface based on the one or more protection vectors;

means for classifying the protection remediation action based on at least one of the digital assets associated with the protection remediation action or a first device utilized to access at least one of the digital assets associated with the protection remediation action; and

means for causing the determined protection remediation action to be dispatched to the first device or a second device associated with at least one of the digital assets.

19. The apparatus of claim 18 , further including means for determining a priority of the determined protection remediation action based on an impact of the determined protection remediation action on the overall protection posture.

20. The apparatus of claim 19 , wherein the means for determining the protection remediation action is to:

update the one or more protection vectors to correspond with an implementation of the protection remediation action; and

determine an improvement to an overall protection efficacy score based on the one or more protection vectors to determine the impact of the determined protection remediation action.

21. The apparatus of claim 20 , further including means for causing the improvement to the overall protection efficacy score to be dispatched to one or more one or more of the first device, the second device, or a third device in response to the protection remediation action not being executed.

22. The apparatus of claim 18 , further including means for determining a priority of the determined protection remediation action based on one or more impact weights associated with corresponding ones of the one or more protection vectors and notional values associated with the digital assets.

23. The apparatus of claim 1 , wherein the at least two separate values of the first protection vector include two or more of (i) a first value indicative of an associated asset type, (ii) a second value indicative of a protection aspect that the respective protection capability provides, (iii) a third value indicative of a configuration of the respective protection capability, (iv) a fourth value indicative of a classification of the protection event, (v) a fifth value indicative of a user behavior associated with at least one of the digital assets, or (iv) a sixth value indicative of an impact of the first protection vector on the overall protection posture.

24. The apparatus of claim 1 , wherein the first protection vector is associated with a first digital asset of the digital assets, wherein the at least two separate values of the first protection vector include a first value and a second value, wherein the first value corresponds to a switch, wherein the second value is a weight factor, and wherein the switch activates the weight factor for consideration in the determination of the protection remediation action in response to the respective protection capability being utilized in association with the first digital asset.

25. A method comprising:

monitoring digital assets associated with a protection threat surface to detect a protection event;

determining one or more protection vectors associated with the protection threat surface in response to detecting the protection event, a first protection vector of the one or more protection vectors mapped to a respective protection capability associated with at least one of the digital assets, the first protection vector including at least two separate values, one or more of the at least two separate values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface;

determining a protection remediation action for the protection threat surface based on the one or more protection vectors;

assigning the protection remediation action to a group based on at least one of the digital assets associated with the protection remediation action or a first device utilized to access at least one of the digital assets associated with the protection remediation action; and

causing the determined protection remediation action to be dispatched to the first device or a second device associated with at least one of the digital assets.

26. The method of claim 25 , further including determining a priority of the determined protection remediation action based on an impact of the determined protection remediation action on the overall protection posture of the digital assets.

27. The method of claim 26 , further including:

updating the one or more protection vectors to correspond with an implementation of the protection remediation action; and

determining an improvement to an overall protection efficacy score based on the one or more protection vectors to determine the impact of the determined protection remediation action.

28. The method of claim 27 , further including causing the improvement to the overall protection efficacy score to be dispatched to one or more user devices in response to the protection remediation action not being executed.

29. An apparatus comprising:

asset analyzing circuitry to monitor digital assets associated with a protection threat surface to detect a protection event;

protection analyzing circuitry to determine one or more protection vectors associated with the protection threat surface in response to detection of the protection event, a first protection vector of the one or more protection vectors mapped to a respective protection capability associated with at least one of the digital assets, the first protection vector including at least two separate values, one or more of the at least two separate values corresponding to an impact of the protection event on an overall protection posture associated with the protection threat surface;

protection generating circuitry to determine a protection remediation action for the digital assets based on the one or more protection vectors;

protection selecting circuitry to group the protection remediation action based on at least one of the digital assets associated with the protection remediation action or a first device utilized to access at least one of the digital assets associated with the protection remediation action; and

protection dispatching circuitry to cause the determined protection remediation action to be dispatched to the first device or a second device associated with at least one of the digital assets.

30. The apparatus of claim 29 , further including protection selecting circuitry to determine a priority of the determined protection remediation action based on one or more impact weights associated with corresponding ones of the one or more protection vectors and notional values associated with the digital assets.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: NALLURI, SRIKANTH; KULKARNI, DATTATRAYA; HEBBALALU, RAGHAVENDRA; SWASTIK, SANDEEP; JOSHI, PIYUSH PRAMOD; CHITTA, SAMRAT; BARIK, PARTHA SARATHI
To: MCAFEE, LLC
Reel/Frame 057358/0399 →
Continuity (2)
Provisional Application 63151538 · Feb 19, 2021
Related Publication 20220269817A1 · Aug 25, 2022
References Cited (22)
US 8495745B1 · Schrecker et al. · 2013 [cited by applicant]
US 10111099B2 · Hunt et al. · 2018 [cited by applicant]
US 20130340084A1 · Schrecker et al. · 2013 [cited by applicant]
US 20170026401A1 · Polyakov · 2017 [cited by examiner]
US 20190281082A1 · Carmichael · 2019 [cited by examiner]
US 20200351294A1 · Davis · 2020 [cited by examiner]
US 20220070198A1 · Willis · 2022 [cited by examiner]
CN 111475804B · 2023 [cited by examiner]
WO 2021028060A1 · 2021 [cited by applicant]
Pavel Yermalovich ⋅ Mohamed Mejri; Information security risk assessment based on decomposition probability via Bayesian Network; 2020 International Symposium on Networks, Computers and Communications (ISNCC) (2020, pp. … [cited by examiner]
Asad Arfeen ⋅ Saad Ahmed ⋅ Muhammad Asim Khan ⋅ Syed Faraz Ali Jafri; Endpoint Detection & Response: A Malware Identification Solution; 2021 International Conference on Cyber Warfare and Security (ICCWS) (2021, pp. 1-8)… [cited by examiner]
Bashayer Alshehhi ⋅ Halim Khelalfa ⋅ Shafiz A Mohd Yusof; Scenario Intelligence: Modeling Insider Threats for Effective Anomaly Detection Using Real Life Scenarios; 2023 24th International Arab Conference on Information… [cited by examiner]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 17/459,979, mailed on Apr. 11, 2023, 23 pages. [cited by applicant]
International Searching Authority, “International Preliminary Report on Patentability,” issued in connection with International Patent Application No. PCT/US2022/015267, issued on Aug. 22, 2023, 8 pages. [cited by applicant]
International Searching Authority, “International Search Report”, issued in connection with International Application No. PCT/US2022/015267, dated May 12, 2022, 5 pages. [cited by applicant]
International Searching Authority, “Written Opinion”, issued in connection with International Application No. PCT/US2022/015267, dated May 12, 2022, 8 pages. [cited by applicant]
Nageab et al., “Cybersecurity in the Era of Artificial Intelligence: Risks and Solutions,” ASU International Conference in Emerging Technologies for Sustainability and Intelligent Systems (ICETSIS), 2024, 6 pages. [cited by applicant]
Cavalli et al., “Cybersecurity, Monitoring, Explainability and Resilience,” Fourteenth International Conference on Mobile Computing and Ubiquitous Network (ICMU), 2023, 7 pages. [cited by applicant]
Fakhouri et al., “AI-Driven Solutions for Social Engineering Attacks: Detection, Prevention, and Response,” 2nd International Conference on Cyber Resilience (ICCR), 2024, 8 pages. [cited by applicant]
United States Patent and Trademark Office, “Advisory Action,” issued in connection with U.S. Appl. No. 17/459,979, dated Dec. 18, 2023, 3 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 17/459,979, dated Jun. 13, 2024, 18 pages. [cited by applicant]
United States Patent and Trademark Office, “Final Office Action,” issued in connection with U.S. Appl. No. 17/459,979, dated Oct. 13, 2023, 30 Pages. [cited by applicant]