IP Library Granted Patent US 11,863,590
Granted Patent B2
US 11,863,590 · App. 17/477,294 · Granted Jan 2, 2024

Inferential analysis using feedback for extracting and combining cyber risk information

Inventors: George Y. Ng (San Mateo, CA); Brian Wu (San Francisco, CA); Ming Yang (San Mateo, CA); Paul Yang (San Mateo, CA); Fernando Tancioco, Jr. (San Ramon, CA)
Assignee: Guidewire Software, Inc.
H04L63/20G06N20/00G06Q30/012G06Q40/06G06Q40/08H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,863,590
App. No.
17/477,294
Granted
Jan 2, 2024
Kind
B2
Abstract

Inferential analysis includes: assessing risk of a cyber security failure in a computer network of an entity, using a computer agent configured to collect information from at least one accessible Internet elements, automatically determining, based on the assessed risk, a change or a setting to at least one element of policy criteria of a cyber security policy; and automatically recommending, based on the assessed risk, a computer network change to reduce the assessed risk.

Claims (49)

1. A method, comprising:

assessing risk of a cyber security failure in a computer network of an entity, using a computer agent configured to collect information from at least one accessible Internet elements, wherein the assessing of the risk comprises:

determining circumstantial or indirect information that is indicative of the entity based on the collected information; and

determining a relative strength of the circumstantial or indirect information;

automatically determining, based on the assessed risk, a change or a setting to at least one element of policy criteria of a cyber security policy;

automatically recommending, based on the assessed risk, a computer network change to reduce the assessed risk;

reassessing the risk of the cyber security failure in the computer network of the entity; and

based on the reassessed risk of the cyber security failure in the computer network of the entity, predicting, at least in part by utilizing machine learning, an action of the entity.

2. The method of claim 1 , wherein the cyber security failure comprises a privacy incident involving sensitive information.

3. The method of claim 1 , wherein the computer agent is further configured to perform: collecting information from the computer network of the entity, analyzing information from the computer network of the entity, or both.

4. The method of claim 1 , further comprising:

determining that the entity has enacted at least a portion of the recommended computer network change; and

initiating a change or a setting to the at least one element of policy criteria of the cyber security policy.

5. The method of claim 4 , further comprising estimating at least one impact to the entity for the cyber security failure, the estimating being dynamically calculated based at least in part on the determination that the entity has enacted at least a portion of the recommended computer network change.

6. The method of claim 1 , wherein the recommended computer network change is implemented automatically without intervention of the entity.

7. The method of claim 1 , wherein the cyber security policy includes:

a cyber security policy from another entity;

a product warranty for first and/or third party costs that the entity purchases from at least one of a networking, security product, and services provider; or

both.

8. A system, comprising:

a memory; and

one or more hardware processors coupled to the memory and configured to:

assess risk of a cyber security failure in a computer network of an entity, using a computer agent configured to collect information from at least one accessible Internet elements, wherein the assessing of the risk comprises:

determine circumstantial or indirect information that is indicative of the entity based on the collected information; and

determine a relative strength of the circumstantial or indirect information;

automatically determine, based on the assessed risk, a change or a setting to at least one element of policy criteria of a cyber security policy;

automatically recommend, based on the assessed risk, a computer network change to reduce the assessed risk;

reassess the risk of the cyber security failure in the computer network of the entity; and

based on the reassessed risk of the cyber security failure in the computer network of the entity, predict, at least in part by utilizing machine learning, an action of the entity.

9. The system of claim 8 , wherein the cyber security failure comprises a privacy incident involving sensitive information.

10. The system of claim 8 , wherein the computer agent is further configured to: collect information from the computer network of the entity, analyze information from the computer network of the entity, or both.

11. The system of claim 8 , wherein the one or more hardware processors are further configured to:

determine that the entity has enacted at least a portion of the recommended computer network change; and

initiate a change or a setting to the at least one element of policy criteria of the cyber security policy.

12. The system of claim 11 , wherein the one or more hardware processors are further configured to:

estimate at least one impact to the entity for the cyber security failure, the estimation being dynamically made based at least in part on the determination that the entity has enacted at least a portion of the recommended computer network change.

13. The system of claim 8 , wherein the recommended computer network change is implemented automatically without intervention of the entity.

14. The system of claim 8 , wherein the cyber security policy includes:

a cyber security policy from another entity;

a product warranty for first and/or third party costs that the entity purchases from at least one of a networking, security product, and services provider; or

both.

15. A computer program product embodied in a tangible, non-transitory computer readable storage medium and comprising computer instructions for:

assessing risk of a cyber security failure in a computer network of an entity, using a computer agent configured to collect information from at least one accessible Internet elements, wherein the assessing of the risk comprises:

determining circumstantial or indirect information that is indicative of the entity based on the collected information; and

determining a relative strength of the circumstantial or indirect information;

automatically determining, based on the assessed risk, a change or a setting to at least one element of policy criteria of a cyber security policy;

automatically recommending, based on the assessed risk, a computer network change to reduce the assessed risk;

reassessing the risk of the cyber security failure in the computer network of the entity; and

based on the reassessed risk of the cyber security failure in the computer network of the entity, predicting, at least in part by utilizing machine learning, an action of the entity.

Assignments (1)
PATENT SECURITY AGREEMENT Recorded Dec 3, 2024
From: GUIDEWIRE SOFTWARE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 069476/0488 →
Continuity (10)
Continuation 16662936 · Oct 24, 2019
Continuation 15971946 · May 4, 2018
Continuation 15371047 · Dec 6, 2016
Continuation In Part 15141779 · Apr 28, 2016
Continuation In Part PCTUS2015067968 · Dec 29, 2015
Continuation In Part 14931510 · Nov 3, 2015
Continuation 14614897 · Feb 5, 2015
Continuation In Part 14585051 · Dec 29, 2014
Provisional Application 62098238 · Dec 30, 2014
Related Publication 20220006840A1 · Jan 6, 2022