IP Library Granted Patent US 11,997,097
Granted Patent B2
US 11,997,097 · App. 17/666,485 · Granted May 28, 2024

Security vulnerability assessment for users of a cloud computing environment

Inventor: Prasanth Anbalagan (Cary, NC)
Assignee: Red Hat, Inc.
H04L63/102H04L63/105H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,097
App. No.
17/666,485
Granted
May 28, 2024
Kind
B2
Abstract

A method comprises monitoring, by a processing device, usage activity of one or more resource categories of a computing environment by a user of the computing environment in view of a security profile associated with the user, determining a first probability of selecting a particular resource from a resource category of the one or more resource categories in view of the usage activity of the resource category by the user, determining a second probability that the particular resource is associated with a security exploit in view of historical data for the computing environment, determining a resource vulnerability value for the resource category in view of the first probability and the second probability, and determining a security vulnerability value for the user in view of the resource vulnerability value.

Claims (82)

1. A method comprising:

monitoring, by a processing device, usage activity of one or more resource categories of a computing environment by a user of the computing environment in view of a security profile associated with the user;

determining a first probability of selecting a particular resource from a resource category of the one or more resource categories in view of the usage activity of the resource category by the user;

determining a second probability that the particular resource is associated with a security exploit in view of historical data for the computing environment;

determining a first resource vulnerability value for the resource category in view of the first probability and the second probability; and

determining a security vulnerability value for the user in view of the first resource vulnerability value.

2. The method of claim 1 , wherein the one or more resource categories comprise at least one of a file resource category, an application resource category, a security policy resource category, or a system configuration resource category.

3. The method of claim 1 , wherein determining the security vulnerability value comprises:

receiving a request to add the user to the computing environment, wherein the one or more resource categories are available to the user;

generating the security profile for the user, wherein the security profile comprises an attribute associated with usage activity of the resource category of the one or more resource categories;

determining, by the processing device, whether the security vulnerability value satisfies a threshold condition; and

responsive to determining that the security vulnerability value satisfies the threshold condition, executing a security audit operation on the security profile.

4. The method of claim 3 , wherein the security profile for the user further comprises a second attribute associated with usage activity of a second resource category of the one or more resource categories, and wherein determining the security vulnerability value further comprises:

determining a third probability of selecting another particular resource from the second resource category in view of usage activity of the second resource category for the user;

determining a fourth probability that the another particular resource is associated with another security exploit in view of the historical data for the computing environment;

determining a second resource vulnerability value for the second resource category in view of the third probability and the fourth probability; and

determining the security vulnerability value in view of the first resource vulnerability value and the second resource vulnerability value.

5. The method of claim 3 , further comprising:

identifying a plurality of additional users of the computing environment;

selecting a set of additional security profiles associated with the plurality of additional users;

determining a set of additional security vulnerability values, wherein each additional security vulnerability value in the set of additional security vulnerability values is associated with an additional security profile from the set of additional security profiles; and

determining the threshold condition in view of the set of additional security vulnerability values.

6. The method of claim 3 , wherein executing the security audit operation comprises:

sending a notification to an administrator console that indicates that the user is vulnerable to a security exploit.

7. The method of claim 3 , wherein executing the security audit operation comprises:

determining an access privilege level of the resource category for the user; and

modifying the access privilege level of the resource category for the user in view of the security vulnerability value.

8. A computing apparatus comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

monitor usage activity of one or more resource categories of a computing environment by a user of the computing environment in view of a security profile associated with the user;

determine a first probability of selecting a particular resource from a resource category of the one or more resource categories in view of the usage activity of the resource category by the user;

determine a second probability that the particular resource is associated with a security exploit in view of historical data for the computing environment;

determine a first resource vulnerability value for the resource category in view of the first probability and the second probability; and

determine a security vulnerability value for the user in view of the first resource vulnerability value.

9. The computing apparatus of claim 8 , wherein the one or more resource categories comprises at least one of a file resource category, an application resource category, a security policy resource category, or a system configuration resource category.

10. The computing apparatus of claim 8 , wherein to determine the security vulnerability value, the processing device is further to:

receive a request to add the user to the computing environment, wherein the one or more resource categories are available to the user;

generate the security profile for the user, wherein the security profile comprises an attribute associated with usage activity of the resource category of the one or more resource categories;

determine, by the processing device, whether the security vulnerability value satisfies a threshold condition; and

responsive to determining that the security vulnerability value satisfies the threshold condition, execute a security audit operation on the security profile.

11. The computing apparatus of claim 10 , wherein the security profile for the user further comprises a second attribute associated with usage activity of a second resource category of the one or more resource categories, and wherein to determine the security vulnerability value, the processing device is further to:

determine a third probability of selecting another particular resource from the second resource category in view of usage activity of the second resource category for the user;

determine a fourth probability that the another particular resource is associated with another security exploit in view of the historical data for the computing environment;

determine a second resource vulnerability value for the second resource category in view of the third probability and the fourth probability; and

determine the security vulnerability value in view of the first resource vulnerability value and the second resource vulnerability value.

12. The computing apparatus of claim 10 , wherein the processing device is further to:

identify a plurality of additional users of the computing environment;

select a set of additional security profiles associated with the plurality of additional users;

determine a set of additional security vulnerability values, wherein each additional security vulnerability value in the set of additional security vulnerability values is associated with an additional security profile from the set of additional security profiles;

determine the threshold condition in view of the set of additional security vulnerability values; and

determine that the security vulnerability value satisfies the threshold condition.

13. The computing apparatus of claim 12 , wherein the processing device is further to:

send a notification to an administrator console that indicates that the user is vulnerable to a security exploit.

14. The computing apparatus of claim 12 , wherein the processing device is further to:

determine an access privilege level of the resource category for the user; and

modify the access privilege level of the resource category for the user in view of the security vulnerability value.

15. A non-transitory computer readable storage medium, having instructions stored therein, which when executed by a processing device of a computer system, cause the processing device to:

monitor usage activity of one or more resource categories of a computing environment by a user of the computing environment in view of a security profile associated with the user;

determine a first probability of selecting a particular resource from a resource category of the one or more resource categories in view of the usage activity of the resource category by the user;

determine a second probability that the particular resource is associated with a security exploit in view of historical data for the computing environment;

determine a first resource vulnerability value for the resource category in view of the first probability and the second probability; and

determine a security vulnerability value for the user in view of the first resource vulnerability value.

16. The non-transitory computer readable storage medium of claim 15 , wherein the one or more resource categories comprises at least one of a file resource category, an application resource category, a security policy resource category, or a system configuration resource category.

17. The non-transitory computer readable storage medium of claim 15 , wherein to determine the security vulnerability value, the processing device is further to:

receive a request to add the user to the computing environment, wherein the one or more resource categories are available to the user;

generate the security profile for the user, wherein the security profile comprises an attribute associated with usage activity of the resource category of the one or more resource categories;

determine, by the processing device, whether the security vulnerability value satisfies a threshold condition; and

responsive to determining that the security vulnerability value satisfies the threshold condition, execute a security audit operation on the security profile.

18. The non-transitory computer readable storage medium of claim 17 , wherein the security profile for the user further comprises a second attribute associated with usage activity of a second resource category of the one or more resource categories, and wherein to determine the security vulnerability value, the processing device is further to:

determine a third probability of selecting another particular resource from the second resource category in view of usage activity of the second resource category for the user;

determine a fourth probability that the another particular resource is associated with another security exploit in view of the historical data for the computing environment;

determine a second resource vulnerability value for the second resource category in view of the third probability and the fourth probability; and

determine the security vulnerability value in view of the first resource vulnerability value and the second resource vulnerability value.

19. The non-transitory computer readable storage medium of claim 17 , wherein the processing device is further to:

identify a plurality of additional users of the computing environment;

select a set of additional security profiles associated with the plurality of additional users;

determine a set of additional security vulnerability values, wherein each additional security vulnerability value in the set of additional security vulnerability values is associated with an additional security profile from the set of additional security profiles; and

determine the threshold condition in view of the set of additional security vulnerability values.

20. The non-transitory computer readable storage medium of claim 17 , wherein to execute the security audit operation, the processing device is further to:

determine an access privilege level of the resource category for the user; and

modify the access privilege level of the resource category for the user in view of the security vulnerability value.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2022
From: ANBALAGAN, PRASANTH
To: RED HAT, INC.
Reel/Frame 059593/0554 →