IP Library › Granted Patent US 12,585,784
Granted Patent B2
US 12,585,784 · App. 18/131,757 · Granted Mar 24, 2026

System for component-level threat assessment in a computing environment

Inventors: Darren Roy Philips (Singapore, SG); Ryan W. Nielsen (Denver, CO); Min Cao (Singapore, SG)
Assignee: BANK OF AMERICA CORPORATION
G06F21/577G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,784
App. No.
18/131,757
Granted
Mar 24, 2026
Kind
B2
Abstract

Systems, computer program products, and methods are described herein for component-level threat assessment in a computing environment. The present disclosure is configured to capture state information associated with a computing environment; determine correlation measures for the components in the computing environment based on at least the state information; determine threat vectors associated with the components; determine mitigation protocols to be implemented on the components in response to an incidence of the threat vectors on the components; determine a first sequence in which the mitigation protocols are to be implemented based on at least the correlation measures for the components; and implement the mitigation protocols on the components in the first sequence to reduce a propagation effect of the threat vectors across the computing environment.

Claims (55)

1 . A system for component-level threat assessment in a computing environment, the system comprising:

a processing device;

a non-transitory storage device containing instructions when executed by the processing device, causes the processing device to:

capture state information associated with a computing environment, wherein the computing environment comprises components, wherein each component is associated with component-level information, wherein the component-level information comprises device characteristics, data usage telemetry, operational statistics, information associated with applications stored thereon, and historical threat vector assessment;

determine correlation measures for the components based on at least the state information, wherein the correlation measures quantify a level of dependency between the components;

determine threat vectors associated with the components;

determine mitigation protocols to be implemented on the components in response to an incidence of the threat vectors on the components;

determine a first sequence in which the mitigation protocols are to be implemented based on at least the correlation measures for the components; and

implement the mitigation protocols on the components in the first sequence to reduce a propagation effect of the threat vectors across the computing environment.

2 . The system of claim 1 , wherein executing the instructions further causes the processing device to:

generate weights for the correlation measures based on at least the component-level information; and

determine weighted correlation measures for the components based on at least the weights and the correlation measures.

3 . The system of claim 2 , wherein the weights indicate a priority level for the components.

4 . The system of claim 2 , wherein executing the instructions further causes the processing device to:

determine a second sequence in which the mitigation protocols are to be implemented based on at least the weighted correlation measures; and

implement the mitigation protocols on the components in the second sequence.

5 . The system of claim 2 , wherein executing the instructions further causes the processing device to:

determine subsets of mitigation protocols corresponding to the weighted correlation measures; and

implement the subsets of mitigation protocols on the components based on at least the weighted correlation measures.

6 . The system of claim 1 , wherein the correlation measures indicate a level of co-linear relationship between the components.

7 . A computer program product for component-level threat assessment in a computing environment, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to:

capture state information associated with a computing environment, wherein the computing environment comprises components, wherein each component is associated with component-level information, wherein the component-level information comprises device characteristics, data usage telemetry, operational statistics, information associated with applications stored thereon, and historical threat vector assessment;

determine correlation measures for the components based on at least the state information, wherein the correlation measures quantify a level of dependency between the components;

determine threat vectors associated with the components;

determine mitigation protocols to be implemented on the components in response to an incidence of the threat vectors on the components;

determine a first sequence in which the mitigation protocols are to be implemented based on at least the correlation measures for the components; and

implement the mitigation protocols on the components in the first sequence to reduce a propagation effect of the threat vectors across the computing environment.

8 . The computer program product of claim 7 , wherein the computer program product is further configured to:

generate one or more weights for the correlation measures based on at least the component-level information; and

determine weighted correlation measures for the components based on at least the weights and the correlation measures.

9 . The computer program product of claim 8 , wherein the weights indicate a priority level for the components.

10 . The computer program product of claim 8 , wherein the computer program product is further configured to:

determine a second sequence in which the mitigation protocols are to be implemented based on at least the weighted correlation measures; and

implement the mitigation protocols on the components in the second sequence.

11 . The computer program product of claim 8 , wherein the computer program product is further configured to:

determine subsets of mitigation protocols corresponding to the weighted correlation measures; and

implement the subsets of mitigation protocols on the components based on at least the weighted correlation measures.

12 . The computer program product of claim 7 , wherein the correlation measures indicate a level of co-linear relationship between the components.

13 . A method for component-level threat assessment in a computing environment, the method comprising:

capturing state information associated with a computing environment, wherein the computing environment comprises components, wherein each component is associated with component-level information, wherein the component-level information comprises device characteristics, data usage telemetry, operational statistics, information associated with applications stored thereon, and historical threat vector assessment;

determining correlation measures for the components based on at least the state information, wherein the correlation measures quantify a level of dependency between the components;

determining threat vectors associated with the components;

determining mitigation protocols to be implemented on the components in response to an incidence of the threat vectors on the components;

determining a first sequence in which the mitigation protocols are to be implemented based on at least the correlation measures for the components; and

implementing the mitigation protocols on the components in the first sequence to reduce a propagation effect of the threat vectors across the computing environment.

14 . The method of claim 13 , wherein the method further comprises:

generating weights for the correlation measures based on at least the component-level information; and

determining weighted correlation measures for the components based on at least the weights and the correlation measures.

15 . The method of claim 14 , wherein the weights indicate a priority level for the components.

16 . The method of claim 14 , wherein the method further comprises:

determining a second sequence in which the mitigation protocols are to be implemented based on at least the weighted correlation measures; and

implementing the mitigation protocols on the components in the second sequence.

17 . The method of claim 14 , wherein the method further comprises:

determining subsets of mitigation protocols corresponding to the weighted correlation measures; and

implementing the subsets of mitigation protocols on the components based on at least the weighted correlation measures.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2024
From: PHILIPS, DARREN
To: BANK OF AMERICA CORPORATION
Reel/Frame 066894/0594 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2023
From: NIELSEN, RYAN W.; CAO, MIN
To: BANK OF AMERICA CORPORATION
Reel/Frame 063248/0992 →
Continuity (1)
Related Publication 20240338454A1 · Oct 10, 2024
References Cited (22)
US 9264444B2 · Moore · 2016 [cited by applicant]
US 9705849B2 · Sood · 2017 [cited by applicant]
US 9807109B2 · Laidlaw · 2017 [cited by applicant]
US 10747886B2 · El-Moussa · 2020 [cited by applicant]
US 10791141B2 · Peteroy · 2020 [cited by applicant]
US 11368473B2 · Weizman · 2022 [cited by applicant]
US 11539720B2 · Reybok, Jr. · 2022 [cited by applicant]
US 11570193B2 · Bhalerao · 2023 [cited by applicant]
US 11671443B2 · Mylavarapu · 2023 [cited by applicant]
US 11683333B1 · Dominessy · 2023 [cited by applicant]
US 11838311B2 · Grounds · 2023 [cited by applicant]
US 11895143B2 · Satish · 2024 [cited by applicant]
US 11916920B2 · Zaki · 2024 [cited by applicant]
US 20210092145A1 · Jaysingh · 2021 [cited by examiner]
US 20220159008A1 · Anbalagan · 2022 [cited by applicant]
US 20220385683A1 · Jones · 2022 [cited by applicant]
US 20230132802A1 · Zoualfaghari · 2023 [cited by examiner]
US 20230179635A1 · Schiel · 2023 [cited by applicant]
US 20230388338A1 · Satish · 2023 [cited by applicant]
US 20240111877A1 · Alimian · 2024 [cited by applicant]
US 20240112115A1 · Ladnai · 2024 [cited by applicant]
US 20240126892A1 · Bolukbas · 2024 [cited by applicant]