IP Library › Granted Patent US 11,948,115
Granted Patent B2
US 11,948,115 · App. 17/669,629 · Granted Apr 2, 2024

Systems and methods for monitoring information security effectiveness

Inventors: Kelly Thomas White (Park City, UT); Michael Vance Fowkes (Salt Lake City, UT); Jesse Duane Card (American Fork, UT); Andrew James Menzel (Tallahassee, FL)
Assignee: RiskRecon Inc.
G06Q10/0635G06F21/552G06F21/6245G06N20/00H04L63/1433H04L63/205G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,948,115
App. No.
17/669,629
Granted
Apr 2, 2024
Kind
B2
Abstract

Systems and methods for automatically assessing and monitoring information security effectiveness using collected indicia of sensitive content and indicia of security measure information for a plurality of networked organizational assets/systems to provide respective asset/system value at risk ratings. Elements of the system include automated asset discovery, automated hosting provider and location discovery, collection of information harvested from public sources and, optionally non-public sources, analysis of the collected information against public, non-public, and proprietary sources, and/or mathematical models used to infer broader security program conclusions and to rank asset/system values at risk. Estimates of values at risk are used to prioritize allocation of security measures.

Claims (96)

1. A method for assessing information technology risk priorities for network computer systems/assets, the method comprising:

receiving, by an electronic processor, a network identifier associated with a network-accessible computer system/asset of an organization;

accessing, via a network, a set of network-accessible computer systems/assets, including the network-accessible computer system/asset and a plurality of related network-accessible computer systems/assets;

determining indicia of content features/characteristics for each of a subset of the set of the network-accessible computer systems/assets;

determining indicia of security features/characteristics of each of the subset of the set of the network-accessible computer systems/assets;

determining network proximity between respective network-accessible computer systems/assets;

assigning a value at risk for each of the subset of the network-accessible computer systems/assets based on a combination of the indicia of content features/characteristics, the indicia of security features/characteristics, and the network proximity between network-accessible computer systems/assets, wherein the value at risk represents a measure of relative organizational risk exposure or loss potential in an event of compromise of a respective network-accessible computer system/asset; and

automatically prioritizing allocation of security controls/measures among the subset of the network-accessible computer systems/assets based on respective assigned values at risk.

2. The method of claim 1 , wherein the indicia of security features/characteristics include one or more of the following:

encryption,

login field,

captcha,

security feature code,

security-related keywords,

security feature configurations,

password field,

security question,

user authentication,

secure cookies,

two-factor authentication,

RSA fraud protection,

software bot detection, and

secure connection protocols.

3. The method of claim 1 , wherein the indicia of content features/characteristics include one or more of the following:

presence of predetermined text,

content subject matter,

purpose of content accessible via the network-accessible computer system/asset,

purpose of content requested via the network-accessible computer system/asset,

functionality of the content,

presence of sensitive data,

collection of sensitive data, and

presence of user-identifiable account data.

4. The method of claim 3 , wherein at least one of a content, a subject, and a purpose of the content features/characteristics includes one or more of the following:

publicly available information,

account data,

financial account data,

personally-identifiable data,

personal health record data,

internal corporate data,

privacy regulated data,

sensitive organizational data, and

sensitive user data.

5. The method of claim 1 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on a network relationship to other network-accessible computer systems/assets with a similar or higher value at risk.

6. The method of claim 1 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on network-accessible computer system/asset functionality.

7. The method of claim 1 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on network-accessible computer system/asset indicia of collection of sensitive.

8. The method of claim 1 , wherein the value at risk represents both a measure of value and risk for any data or functionality, which if accessed by an unauthorized agent, including a person, computer program, or mechanical bot, if used in an unauthorized manner, or if availability or performance characteristics of functionality is degraded, the organization would be exposed to violation of regulations, financial liability, inability to operate related processes to desired levels, harm of reputation, legal liability, or to violation of customer agreements.

9. The method of claim 1 , wherein assigning the value at risk includes estimating a computer system/asset purpose based on one or more of the following: machine learning models, regular expressions, text string matching, natural language understanding, image processing, and text analysis of data available by accessing a given network-accessible computer system/asset.

10. The method of claim 1 , further comprising ranking the subset of the set of the network-accessible as computer systems/assets sets as higher-value-at-risk computer systems/assets to receive one or more of the following: increased security control measures and security control effectiveness monitoring.

11. A non-transitory computer-readable medium having instructions stored thereon, the computer-executable instructions, when executed by a processor, causing the processor to:

receive a network identifier associated with a network-accessible computer system/asset of an organization;

access, via a network, a set of network-accessible computer systems/assets, including the network-accessible computer system/asset and a plurality of related network-accessible computer systems/assets;

determine indicia of content features/characteristics for each of a subset of the set of the network-accessible computer systems/assets;

determine indicia of security features/characteristics of each of the subset of the set of the network-accessible computer systems/assets;

determine network proximity between respective network-accessible computer systems/assets;

assign a value at risk for each of the subset of the network-accessible computer systems/assets based on a combination of the indicia of content features/characteristics, the indicia of security features/characteristics, and the network proximity between network-accessible computer systems/assets, wherein the value at risk represents a measure of relative organizational risk exposure or loss potential in an event of compromise of a respective network-accessible computer system/asset; and

automatically prioritize allocation of security controls/measures among the subset of the network-accessible computer systems/assets based on respective assigned values at risk.

12. The non-transitory computer-readable medium of claim 11 , wherein the indicia of security features/characteristics include one or more of the following:

encryption,

login field,

captcha,

security feature code,

security-related keywords,

security feature configurations,

password field,

security question,

user authentication,

secure cookies,

two-factor authentication,

RSA fraud protection,

software bot detection, and

secure connection protocols.

13. The non-transitory computer-readable medium of claim 11 , wherein the indicia of content features/characteristics include one or more of the following:

presence of predetermined text,

content subject matter,

purpose of content accessible via the network-accessible computer system/asset,

purpose of content requested via the network-accessible computer system/asset,

functionality of the content,

presence of sensitive data,

collection of sensitive data, and

presence of user-identifiable account data.

14. The non-transitory computer-readable medium of claim 13 , wherein at least one of a content, a subject, and a purpose of the content features/characteristics includes one or more of the following:

publicly available information,

account data,

financial account data,

personally-identifiable data,

personal health record data,

internal corporate data,

privacy regulated data,

sensitive organizational data, and

sensitive user data.

15. The non-transitory computer-readable medium of claim 11 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on a network relationship to other network-accessible computer systems/assets with a similar or higher value at risk.

16. The non-transitory computer-readable medium of claim 11 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on network-accessible computer system/asset functionality.

17. The non-transitory computer-readable medium of claim 11 , wherein the value at risk for each network-accessible computer system/asset is assigned in part based on network-accessible computer system/asset indicia of collection of sensitive data.

18. The non-transitory computer-readable medium of claim 11 , wherein the value at risk represents both a measure of value and risk for any data or functionality, which if accessed by an unauthorized agent, including a person, computer program, or mechanical bot, if used in an unauthorized manner, or if availability or performance characteristics of functionality is degraded, the organization would be exposed to violation of regulations, financial liability, inability to operate related processes to desired levels, harm of reputation, legal liability, or to violation of customer agreements.

19. The non-transitory computer-readable medium of claim 11 , wherein assigning the value at risk includes estimating a computer system/asset purpose based on one or more the following: machine learning models, regular expressions, text string matching, natural language understanding, image processing, and text analysis of data available by accessing a given network-accessible computer system/asset.

20. The non-transitory computer-readable medium of claim 11 , further comprising ranking the subset of the set of the network-accessible as computer systems/assets sets as higher-value-at-risk computer systems/assets to receive one or more of the following: increased security control measures and security control effectiveness monitoring.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2022
From: WHITE, KELLY THOMAS; FOWKES, MICHAEL VANCE; CARD, JESSE DUANE; MENZEL, ANDREW JAMES
To: RISKRECON INC.
Reel/Frame 059009/0701 →
Continuity (4)
Division 16278652 · Feb 18, 2019
Continuation In Part 15207395 · Jul 11, 2016
Provisional Application 62191362 · Jul 11, 2015
Related Publication 20220164731A1 · May 26, 2022