IP Library Granted Patent US 12,273,388
Granted Patent B2
US 12,273,388 · App. 17/586,538 · Granted Apr 8, 2025

Cyber risk analysis and remediation using network monitored sensors and methods of use

Inventors: Arvind Parthasarathi (Los Altos, CA); George Y. Ng (San Mateo, CA); Matthew Honea (San Mateo, CA)
Assignee: Guidewire Software, Inc.
H04L63/20H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,388
App. No.
17/586,538
Filed
Jan 27, 2022
Granted
Apr 8, 2025
Kind
B2
Art Unit
2494
USPC
726/1
Abstract

Systems and methods for cyber risk analysis and remediation using network monitored sensors are provided herein. An example system includes one or more data collecting devices deployed within a network that collect entity information and monitor network traffic of the network that is related to security information. The network includes computing systems that are subject to a cyber risk policy having breach parameters defining one or more events that are indicative of a cyber security breach. A cyber security risk assessment and management system is used to automatically detect occurrence of one or more of the events that are indicative of a cyber security breach, automatically determine the breach parameters that apply for the one or more events that occurred, and generates a remediation of cyber security parameters for the network.

Claims (40)

1. A system, comprising:

a processor configured to:

automatically detect occurrence of one or more of events that are indicative of a cyber security breach based on network traffic;

automatically determine one or more breach parameters that apply for the one or more events that occurred;

generate a remediation of cyber security parameters for a network based on the one or more determined breach parameters and an associated remediation provision, wherein the remediation of cyber security parameters at least includes modifying a password requirement associated with one or more computer systems;

cause the remediation to be performed, wherein the remediation causes one or more network changes that increase a sophistication score of an entity, wherein the remediation comprises a change to a hosting infrastructure, network or website topology, vulnerability scanning, content distribution networks, shared hosting, cloud services, patching, updating, default passwords, and any combinations thereof;

evaluate a plurality of networks to generate a plurality of sophistication scores and a plurality of motivation scores, the plurality of networks including a network associated with the system, wherein one motivation score of the plurality of motivation scores relates to a desire level of a malicious actor to cause a cyber security risk for the entity; and

plot the plurality of sophistication scores and the plurality of motivation scores graphically as a peer group; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system according to claim 1 , wherein the network traffic comprises data collected regarding employees using the one or more computing systems or a network associated with the system.

3. The system according to claim 1 , wherein the network traffic comprises data collected regarding websites visited by employees using a network associated with the system and the one or more computing systems.

4. The system according to claim 1 , wherein the processor is configured to evaluate the network traffic on one or more network layers.

5. The system according to claim 4 , wherein the network traffic is evaluated for any of dynamic host protocol (DHCP) information, classless inter-domain routing (CIDR) blocks, and domain name system (DNS) information included in the network traffic.

6. The system according to claim 5 , wherein the processor is further configured to:

create a fingerprint of the network traffic from the DHCP information; and

store the fingerprint in a database.

7. The system according to claim 1 , further comprising a first set of sensors that operate on a data link layer of a network associated with the system.

8. The system according to claim 7 , further comprising a second set of sensors that operate on an Internet Protocol Address layer of the network to evaluate address resolution (ARP) protocol information from the network traffic.

9. The system according to claim 8 , wherein the second set of sensors are configured to transmit the ARP protocol information to the first set of sensors for storage in a database along with DNS information.

10. The system according to claim 1 , wherein the remediation comprises recommendations for improvement for the entity based on a nature of the one or more events that occurred.

11. The system according to claim 1 , wherein the processor is further configured to perform at least one of query the entity or a network associated with the system for information; scrape available online sources; retrieve corporate filings; or query news sources and public record databases.

12. The system of claim 1 , wherein the sophistication score is indicative of a cyber security sophistication of the entity.

13. The system according to claim 1 , wherein information associated with the entity and the network traffic are evaluated for any of visibility, value, hacker sentiment, employee sentiment, company sentiment, customer sentiment, and combinations thereof.

14. The system according to claim 1 , wherein information associated with the entity and the network traffic are evaluated for any of traffic, usage, in-links, page views, duration, traffic volume, links, page rank, market value, stock trade volume, exporting/importing information, and combinations thereof.

15. A method, comprising:

automatically detecting occurrence of one or more of events that are indicative of a cyber security breach based on network traffic;

automatically determining one or more breach parameters that apply for the one or more events that occurred;

generating a remediation of cyber security parameters for a network based on the one or more determined breach parameters and an associated remediation provision, wherein the remediation at least includes modifying a password requirement associated with one or more computer systems;

causing the remediation to be performed, wherein the remediation causes one or more network changes that increase a sophistication score of an entity, wherein the remediation comprises a change to a hosting infrastructure, network or website topology, vulnerability scanning, content distribution networks, shared hosting, cloud services, patching, updating, default passwords, and any combinations thereof;

evaluating a plurality of networks to generate a plurality of sophistication scores and a plurality of motivation scores, the plurality of networks including a network associated with the system, wherein one motivation score of the plurality of motivation scores relates to a desire level of a malicious actor to cause a cyber security risk for the entity; and

plotting the plurality of sophistication scores and the plurality of motivation scores graphically as a peer group.

16. The method according to claim 15 , further comprising providing recommendations for improvement for the entity based on a nature of the one or more events that occurred.

17. The method according to claim 16 , further comprising tying at least one of sophistication scores and changes in sophistication scores to remediation adjustments.

18. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising instructions for:

automatically detecting occurrence of one or more events that are indicative of a cyber security breach based on network traffic;

automatically determining one or more breach parameters that apply for the one or more events that occurred;

generating a remediation of cyber security parameters for a network based on the one or more determined breach parameters and an associated remediation provision, wherein the remediation of the cyber security parameters at least includes modifying a password requirement associated with one or more computing systems;

causing the remediation to be performed, wherein the remediation causes one or more network changes that increase a sophistication score of an entity, wherein the remediation comprises a change to a hosting infrastructure, network or website topology, vulnerability scanning, content distribution networks, shared hosting, cloud services, patching, updating, default passwords, and any combinations thereof;

evaluating a plurality of networks to generate a plurality of sophistication scores and a plurality of motivation scores, the plurality of networks including a network associated with the system, wherein one motivation score of the plurality of motivation scores relates to a desire level of a malicious actor to cause a cyber security risk for the entity; and

plotting the plurality of sophistication scores and the plurality of motivation scores graphically as a peer group.

Assignments (1)
PATENT SECURITY AGREEMENT Recorded Dec 3, 2024
From: GUIDEWIRE SOFTWARE, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 069476/0488 →
Continuity (4)
Continuation 16513186 · Jul 16, 2019
Continuation 15082890 · Mar 28, 2016
Provisional Application 62141114 · Mar 31, 2015
Related Publication 20220255965A1 · Aug 11, 2022
References Cited (213)
US 5535383A · Gower · 1996 [cited by applicant]
US 5920861A · Hall · 1999 [cited by applicant]
US 5949876A · Ginter · 1999 [cited by applicant]
US 5987440A · O'Neil · 1999 [cited by applicant]
US 6269349B1 · Aieta · 2001 [cited by applicant]
US 6374358B1 · Townsend · 2002 [cited by applicant]
US 6839689B2 · Aieta · 2005 [cited by applicant]
US 6980927B2 · Tracy · 2005 [cited by applicant]
US 7047419B2 · Black · 2006 [cited by applicant]
US 7324952B2 · Hisano · 2008 [cited by applicant]
US 7680659B2 · Gao · 2010 [cited by applicant]
US 7711646B2 · Cianciarulo · 2010 [cited by applicant]
US 8332242B1 · Medina, III · 2012 [cited by applicant]
US 8448245B2 · Banerjee · 2013 [cited by applicant]
US 8468599B2 · McCusker · 2013 [cited by applicant]
US 8484066B2 · Miller · 2013 [cited by applicant]
US 8494955B2 · Quarterman · 2013 [cited by applicant]
US 8577775B1 · Gerber · 2013 [cited by applicant]
US 8601587B1 · Powell · 2013 [cited by applicant]
US 8699767B1 · Khosla · 2014 [cited by applicant]
US 8744894B2 · Christiansen · 2014 [cited by applicant]
US 8973088B1 · Leung · 2015 [cited by applicant]
US 9027125B2 · Kumar · 2015 [cited by applicant]
US 9031951B1 · Baluja · 2015 [cited by applicant]
US 9043905B1 · Allen · 2015 [cited by applicant]
US 9100430B1 · Seiver · 2015 [cited by applicant]
US 9241008B2 · Powell · 2016 [cited by applicant]
US 9253203B1 · Ng · 2016 [cited by applicant]
US 9292881B2 · Alperovitch · 2016 [cited by applicant]
US 9367694B2 · Eck · 2016 [cited by applicant]
US 9373144B1 · Ng · 2016 [cited by applicant]
US 9471777B1 · Juels · 2016 [cited by applicant]
US 9521160B2 · Ng · 2016 [cited by applicant]
US 9613442B2 · Pan · 2017 [cited by applicant]
US 9646428B1 · Konrardy · 2017 [cited by applicant]
US 9699209B2 · Ng · 2017 [cited by applicant]
US 9715711B1 · Konrardy · 2017 [cited by applicant]
US 9893970B2 · Gauvin · 2018 [cited by applicant]
US 9894036B2 · Weinberger · 2018 [cited by applicant]
US 10050990B2 · Ng · 2018 [cited by applicant]
US 10099297B2 · Lemmer · 2018 [cited by applicant]
US 10102589B1 · Tofte · 2018 [cited by applicant]
US 10230764B2 · Ng · 2019 [cited by applicant]
US 10326786B2 · Gladstone · 2019 [cited by applicant]
US 10404737B1 · Sweeney · 2019 [cited by applicant]
US 10404748B2 · Parthasarathi · 2019 [cited by applicant]
US 10498757B2 · Pickles · 2019 [cited by applicant]
US 10574539B2 · Brown · 2020 [cited by applicant]
US 10656993B2 · Thatcher · 2020 [cited by applicant]
US 20020026335A1 · Honda · 2002 [cited by applicant]
US 20020091551A1 · Parisi · 2002 [cited by applicant]
US 20030014342A1 · Vande Pol · 2003 [cited by applicant]
US 20030014344A1 · Chacko · 2003 [cited by applicant]
US 20030028803A1 · Bunker · 2003 [cited by applicant]
US 20030040942A1 · Hooten · 2003 [cited by applicant]
US 20030084349A1 · Friedrichs · 2003 [cited by applicant]
US 20030126049A1 · Nagan · 2003 [cited by applicant]
US 20030135758A1 · Turner · 2003 [cited by applicant]
US 20030154393A1 · Young · 2003 [cited by applicant]
US 20030236990A1 · Hrastar · 2003 [cited by applicant]
US 20040006532A1 · Lawrence · 2004 [cited by applicant]
US 20040010709A1 · Baudoin · 2004 [cited by applicant]
US 20040024693A1 · Lawrence · 2004 [cited by applicant]
US 20040049698A1 · Ott · 2004 [cited by applicant]
US 20040064726A1 · Girouard · 2004 [cited by applicant]
US 20040167793A1 · Masuoka · 2004 [cited by applicant]
US 20040260945A1 · Raikar · 2004 [cited by applicant]
US 20050015624A1 · Ginter · 2005 [cited by applicant]
US 20050044418A1 · Miliefsky · 2005 [cited by applicant]
US 20050096944A1 · Ryan · 2005 [cited by applicant]
US 20050097320A1 · Golan · 2005 [cited by applicant]
US 20050131828A1 · Gearhart · 2005 [cited by applicant]
US 20050132225A1 · Gearhart · 2005 [cited by applicant]
US 20050261943A1 · Quarterman · 2005 [cited by applicant]
US 20050278786A1 · Tippett · 2005 [cited by applicant]
US 20060020814A1 · Lieblich · 2006 [cited by applicant]
US 20060184473A1 · Eder · 2006 [cited by applicant]
US 20060265746A1 · Farley · 2006 [cited by applicant]
US 20070180490A1 · Renzi · 2007 [cited by examiner]
US 20070192867A1 · Miliefsky · 2007 [cited by applicant]
US 20070294118A1 · Tait · 2007 [cited by applicant]
US 20070298720A1 · Wolman · 2007 [cited by examiner]
US 20080016563A1 · McConnell · 2008 [cited by applicant]
US 20080047016A1 · Spoonamore · 2008 [cited by applicant]
US 20080162377A1 · Pinkas · 2008 [cited by applicant]
US 20080167920A1 · Schmidt · 2008 [cited by applicant]
US 20080250064A1 · Duchon · 2008 [cited by applicant]
US 20080280637A1 · Shaffer · 2008 [cited by applicant]
US 20090024663A1 · McGovern · 2009 [cited by applicant]
US 20090037323A1 · Feinstein · 2009 [cited by applicant]
US 20090063365A1 · Pinkas · 2009 [cited by applicant]
US 20090126018A1 · Keohane · 2009 [cited by applicant]
US 20090271863A1 · Govindavajhala · 2009 [cited by applicant]
US 20090319342A1 · Shilman · 2009 [cited by applicant]
US 20100046553A1 · Daigle · 2010 [cited by applicant]
US 20100114634A1 · Christiansen · 2010 [cited by applicant]
US 20100153156A1 · Guinta · 2010 [cited by applicant]
US 20100205014A1 · Sholer · 2010 [cited by applicant]
US 20100229187A1 · Marwah · 2010 [cited by applicant]
US 20110078073A1 · Annappindi · 2011 [cited by applicant]
US 20110154497A1 · Bailey, Jr. · 2011 [cited by applicant]
US 20110161116A1 · Peak · 2011 [cited by applicant]
US 20110239267A1 · Lyne · 2011 [cited by applicant]
US 20110244798A1 · Daigle · 2011 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by applicant]
US 20110289597A1 · Hinds · 2011 [cited by applicant]
US 20110295722A1 · Reisman · 2011 [cited by applicant]
US 20110313930A1 · Bailey, Jr. · 2011 [cited by applicant]
US 20120011077A1 · Bhagat · 2012 [cited by applicant]
US 20120041790A1 · Koziol · 2012 [cited by applicant]
US 20120046989A1 · Baikalov · 2012 [cited by examiner]
US 20120059779A1 · Syed · 2012 [cited by applicant]
US 20120079598A1 · Brock · 2012 [cited by applicant]
US 20120089617A1 · Frey · 2012 [cited by applicant]
US 20120096558A1 · Evrard · 2012 [cited by applicant]
US 20120159624A1 · König · 2012 [cited by applicant]
US 20120215575A1 · Deb · 2012 [cited by applicant]
US 20120239438A1 · Hemmings · 2012 [cited by applicant]
US 20120284158A1 · Kovac · 2012 [cited by applicant]
US 20120300975A1 · Chalamala · 2012 [cited by applicant]
US 20130055404A1 · Khalili · 2013 [cited by applicant]
US 20130073473A1 · Heath · 2013 [cited by applicant]
US 20130104236A1 · Ray · 2013 [cited by applicant]
US 20130188475A1 · Lim · 2013 [cited by applicant]
US 20130191829A1 · Shimokawa · 2013 [cited by applicant]
US 20130218670A1 · Spears · 2013 [cited by applicant]
US 20130239167A1 · Sreenivas · 2013 [cited by applicant]
US 20130239168A1 · Sreenivas · 2013 [cited by applicant]
US 20130239177A1 · Sigurdson · 2013 [cited by applicant]
US 20130283336A1 · Macy · 2013 [cited by applicant]
US 20130346328A1 · Agle · 2013 [cited by applicant]
US 20130347060A1 · Hazzani · 2013 [cited by applicant]
US 20140007190A1 · Alperovitch · 2014 [cited by applicant]
US 20140019171A1 · Koziol · 2014 [cited by applicant]
US 20140067713A1 · Gerber · 2014 [cited by applicant]
US 20140067716A1 · Gerber · 2014 [cited by applicant]
US 20140137257A1 · Martinez · 2014 [cited by applicant]
US 20140142988A1 · Grosso · 2014 [cited by applicant]
US 20140181982A1 · Guo · 2014 [cited by applicant]
US 20140200930A1 · Zizzamia · 2014 [cited by applicant]
US 20140215621A1 · Xaypanya · 2014 [cited by applicant]
US 20140257917A1 · Spencer · 2014 [cited by applicant]
US 20140257918A1 · Spencer · 2014 [cited by applicant]
US 20140328179A1 · Kabakura · 2014 [cited by applicant]
US 20140379708A1 · Fox · 2014 [cited by applicant]
US 20150088595A1 · Chillar · 2015 [cited by applicant]
US 20150095206A1 · Van Heerden · 2015 [cited by applicant]
US 20150100442A1 · Van Heerden · 2015 [cited by applicant]
US 20150100443A1 · Van Heerden · 2015 [cited by applicant]
US 20150106260A1 · Andrews · 2015 [cited by applicant]
US 20150188949A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150269383A1 · Lang · 2015 [cited by applicant]
US 20150271142A1 · Oliphant · 2015 [cited by examiner]
US 20150324559A1 · Boss · 2015 [cited by examiner]
US 20150331932A1 · Georges · 2015 [cited by applicant]
US 20150341389A1 · Kurakami · 2015 [cited by applicant]
US 20150373043A1 · Wang · 2015 [cited by applicant]
US 20150379488A1 · Ruff · 2015 [cited by applicant]
US 20150381662A1 · Nair · 2015 [cited by applicant]
US 20160099963A1 · Mahaffey · 2016 [cited by applicant]
US 20160148332A1 · Stibel · 2016 [cited by applicant]
US 20160162924A1 · Rathod · 2016 [cited by applicant]
US 20160189301A1 · Ng · 2016 [cited by applicant]
US 20160197953A1 · King-Wilson · 2016 [cited by examiner]
US 20160205138A1 · Krishnaprasad · 2016 [cited by applicant]
US 20160212169A1 · Knjazihhin · 2016 [cited by applicant]
US 20160234247A1 · Ng · 2016 [cited by applicant]
US 20160248799A1 · Ng · 2016 [cited by applicant]
US 20160248800A1 · Ng · 2016 [cited by applicant]
US 20160294854A1 · Parthasarathi · 2016 [cited by applicant]
US 20160306979A1 · Kotler · 2016 [cited by examiner]
US 20170085595A1 · Ng · 2017 [cited by applicant]
US 20170093904A1 · Ng · 2017 [cited by applicant]
US 20170093905A1 · Ng · 2017 [cited by applicant]
US 20170116552A1 · Deodhar · 2017 [cited by applicant]
US 20170142140A1 · Muddu · 2017 [cited by applicant]
US 20170187745A1 · Ng · 2017 [cited by applicant]
US 20180025157A1 · Titonis · 2018 [cited by applicant]
US 20180359276A1 · Ng · 2018 [cited by applicant]
US 20190035027A1 · Ng · 2019 [cited by applicant]
US 20210358046A1 · Roll · 2021 [cited by applicant]
US 20220245727A1 · Roll · 2022 [cited by applicant]
EP 3675455 · 2021 [cited by applicant]
TW 201636937 · 2016 [cited by applicant]
WO 2014036396 · 2014 [cited by applicant]
WO 2016109162 · 2016 [cited by applicant]
WO 2016109608 · 2016 [cited by applicant]
WO 2017078986 · 2017 [cited by applicant]
Santos et al., Method of Automated Cyber Risk Assessment, Insurance Underwriting, and Remediation, Cisco Systems, Inc. 2017. [cited by applicant]
Bohme et al., “Models and Measures for Correlation in Cyber-Insurance,” Workshop on the Economics of Information Security (WEIS), Jun. 2006, Retrieved from <http://www.econinfosec.org/archive/weis2006/docs/16.pdf>. [cited by applicant]
Intemational Search Report & Written Opinion dated Feb. 10, 2016 in Patent Cooperation Treaty Application No. PCT/US2015/065365, filed Dec. 11, 2015. [cited by applicant]
Intemational Search Report & Written Opinion dated Feb. 26, 2016 in Patent Cooperation Treaty Application No. PCT/US2015/067968, filed Dec. 29, 2015. [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority, Patent Cooperation Treaty Application No. PCT/US2016/058711, Dec. 8, 2016, 9 pages. [cited by applicant]
Martin Salois, “Password Complexity Recommendations”, Defense Research and Development Canada, Oct. 2014, pp. 1-34. [cited by applicant]
Mathew et al., “Intruders and Password Management,” International Journal of Science Technology & Engineering, Oct. 2015, pp. 312-315. [cited by applicant]
Notice of Allowance mailed Aug. 24, 2017 for U.S. Appl. No. 15/099,297, filed Apr. 14, 2016. [cited by applicant]
Notice of Allowance mailed Jan. 3, 2017 for U.S. Appl. No. 15/142,997, filed Apr. 29, 2016. [cited by applicant]
Notice of Allowance mailed Jul. 29, 2016 in U.S. Appl. No. 15/141,779, filed Apr. 28, 2016. [cited by applicant]
Notice of Allowance mailed Mar. 15, 2016 for U.S. Appl. No. 14/931,510, filed Nov. 3, 2015. [cited by applicant]
Notice of Allowance mailed Sep. 25, 2015 for U.S. Appl. No. 14/585,051, filed Dec. 29, 2014. [cited by applicant]
Office Action mailed Apr. 1, 2015 for U.S. Appl. No. 14/585,051, filed Dec. 29, 2014. [cited by applicant]
Office Action mailed Apr. 20, 2015 in U.S. Appl. No. 14/614,897, filed Feb. 5, 2015. [cited by applicant]
Office Action mailed Aug. 23, 2017 in U.S. Appl. No. 15/371,047, filed Dec. 6, 2016. [cited by applicant]
Office Action mailed Jul. 29, 2016 in U.S. Appl. No. 15/142,997, filed Apr. 29, 2016. [cited by applicant]
Office Action mailed Mar. 14, 2017 in U.S. Appl. No. 15/099,297, filed Apr. 14, 2016. [cited by applicant]
Office Action mailed May 23, 2017 in U.S. Appl. No. 15/457,921, filed Mar. 13, 2017. [cited by applicant]
Office Action mailed Oct. 16, 2015 in U.S. Appl. No. 14/614,897, filed Feb. 5, 2015. [cited by applicant]
Office Action mailed Sep. 7, 2016 for U.S. Appl. No. 15/099,297, filed Apr. 14, 2016. [cited by applicant]
Office Action mailed Sep. 7, 2017 in U.S. Appl. No. 15/373,298, filed Dec. 8, 2016. [cited by applicant]
Office Action mailed Sep. 7, 2017 in U.S. Appl. No. 15/374,212, filed Dec. 9, 2016. [cited by applicant]
Raftery et al., “Variable Selection for Model-Based Clustering,” Journal of the American Statistical Association, Mar. 2006, pp. 168-178, http://www.stat.washington.edu/rattery/Research/PDF/dean2006.pdf. [cited by applicant]
Scarfone et al. NIST Special Publication 800-118. “Guide to Enterprise Password Management (Draft)”, Apr. 2009, NIST (National Institute of Standards and Technology), pp. 1-40. [cited by applicant]
U.S. Appl. No. 14/614,897, filed Feb. 5, 2015. [cited by applicant]