IP Library Granted Patent US 12,069,083
Granted Patent B2
US 12,069,083 · App. 17/693,838 · Granted Aug 20, 2024

Assessing security risks of users in a computing network

Inventors: Trevor Tyler Hawthorn (Ashburn, VA); Norman Sadeh-Koniecpol (Pittsburgh, PA); Nathan Miller (Haymarket, VA); Jeff Losapio (Herndon, VA); Kurt Frederick Wescoe (Pittsburgh, PA); Jason R. Brubaker (East Berlin, PA); Jason Hong (Pittsburgh, PA)
Assignee: Proofpoint, Inc.
H04L63/1433G06F21/55H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,069,083
App. No.
17/693,838
Granted
Aug 20, 2024
Kind
B2
Abstract

Various embodiments assess security risks of users in computing networks. In some embodiments, an interaction item is sent to an end user electronic device. When the end user interacts with the interaction item, the system collects feedback data that includes information about the user's interaction with the interaction item, as well as technical information about the electronic device. The feedback is compared to a plurality of security risk scoring metrics. Based on this comparison, a security risk score for the user with respect to a computing network.

Claims (62)

1. A method, comprising:

at a security system comprising at least one processor and memory:

generating an interaction item, wherein the interaction item comprises one or more of a training item or a security item;

transmitting the interaction item to an end user electronic device via a network;

receiving feedback data from the end user electronic device,

wherein the feedback data comprises sensed data relating to an action of a user of the end user electronic device associated with the interaction item, and

wherein the feedback data comprises technical information associated with the end user electronic device;

comparing the feedback data to a plurality of security risk scoring metrics;

based on comparing the feedback data to the plurality of security risk scoring metrics, determining a security risk score, wherein the security risk score quantifies a cybersecurity risk presented by the user of the end user electronic device;

generating a subsequent interaction item based on the security risk score, wherein the subsequent interaction item comprises one or more of a training item or a security item; and

transmitting the subsequent interaction item to the end user electronic device via the network.

2. The method of claim 1 , wherein the plurality of security risk scoring metrics comprise:

a set of metrics assigning a weight to the action of the user of the end user electronic device associated with the interaction item, and

a set of metrics assigning a weight to a technical attribute defined for the technical information associated with the end user electronic device.

3. The method of claim 2 , wherein the technical information comprises one or more of a network address, a device make, a device model, a software version, an operating system version, firewall data, or a platform type.

4. The method of claim 1 , wherein receiving the feedback data from the end user electronic device comprises receiving data sensed by a sensor of the end user electronic device.

5. The method of claim 1 , wherein receiving the feedback data from the end user electronic device comprises receiving security item interaction data received at the end user electronic device via an input/output interface.

6. The method of claim 1 , wherein receiving the feedback data from the end user electronic device comprises receiving training item interaction data received at the end user electronic device via an input/output interface, the training item interaction data comprising completion data.

7. The method of claim 1 , comprising:

adjusting a frequency of presenting one or more subsequent interaction items to the user of the end user electronic device based on the security risk score.

8. The method of claim 1 , comprising:

adjusting network security controls for the user of the end user electronic device based on the security risk score.

9. The method of claim 1 , wherein generating the interaction item comprises generating one or more of a simulated security item, a simulated training item, an actual security item, or an actual training item.

10. The method of claim 1 , comprising:

causing the end user electronic device to present the subsequent interaction item to the user of the end user electronic device, wherein the subsequent interaction item instructs the user of the end user electronic device on how to interact with at least one security item; and

recording an indication that the user of the end user electronic device interacted with the subsequent interaction item based on the subsequent interaction item being presented by the end user electronic device.

11. The method of claim 1 , comprising:

identifying one or more additional users to form a group of users; and

calculating a collective security risk score for the group of users based on an individual risk score calculated for each user in the group of users.

12. A security system, comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the security system to:

generate an interaction item, wherein the interaction item comprises one or more of a training item or a security item;

transmit the interaction item to an end user electronic device via a network;

receive feedback data from the end user electronic device,

wherein the feedback data comprises sensed data relating to an action of a user of the end user electronic device associated with the interaction item, and

wherein the feedback data comprises technical information associated with the end user electronic device;

compare the feedback data to a plurality of security risk scoring metrics;

based on comparing the feedback data to the plurality of security risk scoring metrics, determine a security risk score, wherein the security risk score quantifies a cybersecurity risk presented by the user of the end user electronic device;

generate a subsequent interaction item based on the security risk score, wherein the subsequent interaction item comprises one or more of a training item or a security item; and

transmit the generated subsequent interaction item to the end user electronic device via the network.

13. The security system of claim 12 , wherein the plurality of security risk scoring metrics comprise:

a set of metrics assigning a weight to the action of the user of the end user electronic device associated with the interaction item, and

a set of metrics assigning a weight to a technical attribute defined for the technical information associated with the end user electronic device.

14. The security system of claim 13 , wherein the technical information comprises one or more of a network address, a device make, a device model, a software version, an operating system version, firewall data, or a platform type.

15. The security system of claim 12 , wherein receiving the feedback data from the end user electronic device comprises receiving data sensed by a sensor of the end user electronic device.

16. The security system of claim 12 , wherein receiving the feedback data from the end user electronic device comprises receiving security item interaction data received at the end user electronic device via an input/output interface.

17. The security system of claim 12 , wherein receiving the feedback data from the end user electronic device comprises receiving training item interaction data received at the end user electronic device via an input/output interface, the training item interaction data comprising completion data.

18. The security system of claim 12 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the security system to:

adjust a frequency of presenting one or more subsequent interaction items to the user of the end user electronic device based on the security risk score.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a security system comprising at least one processor and memory, cause the security system to:

generate an interaction item, wherein the interaction item comprises one or more of a training item or a security item;

transmit the interaction item to an end user electronic device via a network;

receive feedback data from the end user electronic device,

wherein the feedback data comprises sensed data relating to an action of a user of the end user electronic device associated with the interaction item, and

wherein the feedback data comprises technical information associated with the end user electronic device;

compare the feedback data to a plurality of security risk scoring metrics;

based on comparing the feedback data to the plurality of security risk scoring metrics, determine a security risk score, wherein the security risk score quantifies a cybersecurity risk presented by the user of the end user electronic device;

generate a subsequent interaction item based on the security risk score, wherein the subsequent interaction item comprises one or more of a training item or a security item; and

transmit the generated subsequent interaction item to the end user electronic device via the network.

20. The one or more non-transitory computer-readable media of claim 19 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the security system to:

adjust a frequency of presenting one or more subsequent interaction items to the user of the end user electronic device based on the security risk score.

Assignments (6)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: HAWTHORN, TREVOR TYLER; MILLER, NATHAN; LOSAPIO, JEFF
To: STRATUM SECURITY, LLC
Reel/Frame 067358/0692 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: SADEH-KONIECPOL, NORMAN; WESCOE, KURT FREDERICK; BRUBAKER, JASON R.; HONG, JASON
To: WOMBAT SECURITY TECHNOLOGIES, INC.
Reel/Frame 067358/0862 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: STRATUM SECURITY, LLC.
To: WOMBAT SECURITY TECHNOLOGIES, INC.
Reel/Frame 067359/0380 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: WOMBAT SECURITY TECHNOLOGIES, INC.
To: PROOFPOINT, INC.
Reel/Frame 067359/0454 →
Continuity (13)
Continuation 16910801 · Jun 24, 2020
Continuation 15492396 · Apr 20, 2017
Continuation In Part 15418867 · Jan 30, 2017
Continuation In Part 14620866 · Feb 12, 2015
Continuation 14216002 · Mar 17, 2014
Continuation In Part 13832070 · Mar 15, 2013
Continuation In Part 13442587 · Apr 9, 2012
Continuation 13442587 · Apr 9, 2012
Provisional Application 61939450 · Feb 13, 2014
Provisional Application 61793011 · Mar 15, 2013
Provisional Application 61473366 · Apr 8, 2011
Provisional Application 61473384 · Apr 8, 2011
Related Publication 20220210181A1 · Jun 30, 2022
Cited By (5)
US 12,401,680 US 12,585,768 US 12,587,562 US 12,603,915 US 12,615,273