IP Library Granted Patent US 12,015,634
Granted Patent B2
US 12,015,634 · App. 17/662,529 · Granted Jun 18, 2024

System and method for mitigating cyber security threats by devices using risk factors

Inventors: Nadir Izrael (Mountain View, CA); Shiri Ladelsky Lellouch (Menlo Park, CA); Misha Seltzer (Toronto, CA)
Assignee: Armis Security Ltd.
H04L63/1433G06F21/552G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,015,634
App. No.
17/662,529
Granted
Jun 18, 2024
Kind
B2
Abstract

A system and method for mitigating cyber security threats by devices using risk factors. The method includes determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device; determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and performing at least one mitigation action based on the risk score.

Claims (35)

1. A method for mitigating cyber security threats by devices using risk factors, comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device;

determining a risk score for the device based on the plurality of risk factors and a plurality of associated weights, wherein each of the plurality of associated weights is applied to one of the plurality of risk factors; and

performing at least one mitigation action based on the risk score.

2. The method of claim 1 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

3. The method of claim 1 , wherein determining the plurality of risk factors further comprises:

determining the assumed risk behaviors based on at least one of: manufacturer reputation information, device model reputation information, known software vulnerabilities, and known operating system vulnerabilities.

4. The method of claim 1 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, further comprising:

updating the risk score based on the monitored network activity; and

performing at least one subsequent mitigation action based on the updated risk score.

5. The method of claim 1 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on a quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

6. The method of claim 1 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

7. The method of claim 1 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

8. The method of claim 1 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device;

determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and

performing at least one mitigation action based on the risk score.

10. A system for mitigating cyber security threats by devices using risk factors, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

determine a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device;

determine a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and

perform at least one mitigation action based on the risk score.

11. The system of claim 10 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

12. The system of claim 10 , wherein the system is further configured to:

determine the assumed risk behaviors based on at least one of: manufacturer reputation information, device model reputation information, known software vulnerabilities, and known operating system vulnerabilities.

13. The system of claim 10 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, wherein the system is further configured to:

update the risk score based on the monitored network activity; and

perform at least one subsequent mitigation action based on the updated risk score.

14. The system of claim 10 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on a quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

15. The system of claim 10 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

16. The system of claim 10 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

17. The system of claim 10 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

18. The method of claim 1 , wherein each of the plurality of associated weights is pre-determined prior to determining the plurality of risk factors for the device, and further wherein each of the plurality of risk behaviors affects at least one of the plurality of risk factors.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2024
From: IZRAEL, NADIR; LADELSKY LELLOUCH, SHIRI; SELTZER, MISHA
To: ARMIS SECURITY LTD.
Reel/Frame 066829/0978 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
Continuity (2)
Continuation 16371794 · Apr 1, 2019
Related Publication 20220263853A1 · Aug 18, 2022
Cited By (4)
US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752