IP Library Granted Patent US 12,417,288
Granted Patent B1
US 12,417,288 · App. 18/163,768 · Granted Sep 16, 2025

Software asset health score

Inventors: Brian Matthew White (Charlotte, NC); Richard Lee Goble (Lee's Summit, MO); John Masiliunas (Indianapolis, IN); Matthew Thomas McDonald (Callahan, FL); Michael Sbandi (Harrisburg, NC); Jerry Reynolds (Charlotte, NC); Edward J. Patterson (Huntersville, NC)
Assignee: Wells Fargo Bank, N.A.
G06F21/568G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,288
App. No.
18/163,768
Granted
Sep 16, 2025
Kind
B1
Abstract

Techniques are described for assessing the health of one or more applications. For example, this disclosure describes a computing device configured to obtain information associated with one or more software assets, wherein the information associated with one or more software assets comprises information associated with a lifecycle of the one or more software assets. The computing device is also configured to compute, based on at least a portion of the information associated with the one or more software assets, a health score that indicates a security risk of the one or more software assets. The computing device is further configured to perform an action based on the health score.

Claims (55)

1. A method comprising:

obtaining, by a computing system, information associated with one or more software assets, wherein the information associated with one or more software assets comprises information corresponding to one or more stages of a lifecycle of the one or more software assets;

predicting, by the computing system and based on a health score determined from at least a portion of the information associated with the one or more software assets, a security risk of the one or more software assets; and

performing, by the computing system, an action to remediate the predicted security risk of the one or more software assets.

2. The method of claim 1 , wherein the information corresponding to the one or more stages of the lifecycle of the one or more software assets comprises information associated with at least one of:

a development stage of the one or more software assets;

a testing stage of the one or more software assets; or

a maintenance stage of the one or more software assets.

3. The method of claim 1 , wherein the information associated with the one or more software assets comprises one or more of:

information specifying context and operating environment of the one or more software assets;

information about a channel in which the one or more software assets operate;

information that specifies an importance or criticality of the one or more software assets;

information associated with a custodian of the one or more software assets; or

information that specifies a history of attacks and responses to the attacks to the one or more software assets.

4. The method of claim 1 , wherein performing the action to remediate the predicted security risk comprises:

deploying a control that provides run-time capabilities to remediate the predicted security risk.

5. The method of claim 4 , wherein the control comprises a policy or rule.

6. The method of claim 1 , wherein performing the action to remediate the predicted security risk comprises:

generating one or more recommendations to remediate the predicted security risk; and

outputting the one or more recommendations.

7. The method of claim 1 , wherein performing the action to remediate the predicted security risk comprises:

generating a notification specifying the health score; and

outputting the notification.

8. The method of claim 1 , wherein predicting the security risk of the one or more software assets comprises:

applying a machine learning model to the information associated with the one or more software assets; and

receiving an output of the machine learning model indicating the health score.

9. A computing system comprising:

a memory; and

one or more processors in communication with the memory, the one or more processors configured to:

obtain information associated with one or more software assets, wherein the information associated with one or more software assets comprises information corresponding to one or more stages of a lifecycle of the one or more software assets;

predict, based on a health score determined from at least a portion of the information associated with the one or more software assets, a security risk of the one or more software assets; and

perform an action to remediate the predicted security risk of the one or more software assets.

10. The computing system of claim 9 , wherein the information corresponding to the one or more stages of the lifecycle of the one or more software assets comprises information associated with one or more of a development stage, a testing stage, or a maintenance stage of the one or more software assets.

11. The computing system of claim 9 , wherein the information associated with the one or more software assets comprises one or more of:

information specifying context and operating environment of the one or more software assets;

information about a channel in which the one or more software assets operate;

information that specifies an importance or criticality of the one or more software assets;

information associated with a custodian of the one or more software assets; or

information that specifies a history of attacks and responses to the attacks to the one or more software assets.

12. The computing system of claim 9 , wherein to perform the action to remediate the predicted security risk, the one or more processors are configured to:

deploy a control that provides run-time capabilities to remediate the predicted security risk.

13. The computing system of claim 12 , wherein the control comprises a policy or rule.

14. The computing system of claim 9 , wherein to perform the action to remediate the predicted security risk, the one or more processors are configured to:

generate one or more recommendations to remediate the predicted security risk; and

output the one or more recommendations.

15. The computing system of claim 9 , wherein to perform the action to remediate the predicted security risk, the one or more processors are configured to:

generate a notification specifying the health score; and

output the notification.

16. The computing system of claim 9 , wherein to predict the security risk of the one or more software assets, the one or more processors are configured to:

apply a machine learning model to the information associated with the one or more software assets; and

receive an output of the machine learning model indicating the health score.

17. A computer-readable storage medium comprising instructions that, when executed, cause one or more processors to:

obtain information associated with one or more software assets, wherein the information associated with one or more software assets comprises information corresponding to one or more stages of a lifecycle of the one or more software assets;

predict, based on a health score determined from at least a portion of the information associated with the one or more software assets, a security risk of the one or more software assets; and

perform an action to remediate the predicted security risk of the one or more software assets.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073895/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: WHITE, BRIAN MATTHEW; GOBLE, RICHARD LEE; MASILIUNAS, JOHN; MCDONALD, MATTHEW THOMAS; SBANDI, MICHAEL; REYNOLDS, JERRY; PATTERSON, EDWARD J.
To: WELLS FARGO BANK, N.A.
Reel/Frame 063978/0596 →
References Cited (37)
US 8117487B1 · Raut et al. · 2012 [cited by applicant]
US 8448127B2 · Lindley et al. · 2013 [cited by applicant]
US 8762188B2 · Abercrombie et al. · 2014 [cited by applicant]
US 8762987B1 · Satish · 2014 [cited by applicant]
US 9069967B2 · Wysopal et al. · 2015 [cited by applicant]
US 9542176B2 · Bird et al. · 2017 [cited by applicant]
US 10055277B1 · Niederman et al. · 2018 [cited by applicant]
US 10853489B2 · Savir · 2020 [cited by examiner]
US 11223637B2 · Neuvirth et al. · 2022 [cited by applicant]
US 11403092B2 · Renke · 2022 [cited by examiner]
US 20030110067A1 · Miller et al. · 2003 [cited by applicant]
US 20080263507A1 · Chang et al. · 2008 [cited by applicant]
US 20100192196A1 · Lee · 2010 [cited by examiner]
US 20120317266A1 · Abbott · 2012 [cited by applicant]
US 20140173739A1 · Ahuja · 2014 [cited by examiner]
US 20170097623A1 · Van Camp · 2017 [cited by examiner]
US 20180129483A1 · Biddle et al. · 2018 [cited by applicant]
US 20200210590A1 · Doyle · 2020 [cited by examiner]
US 20210336984A1 · Roytman · 2021 [cited by examiner]
US 20220109689A1 · Hamdi · 2022 [cited by examiner]
US 20230103833A1 · Berls · 2023 [cited by examiner]
US 20230164158A1 · Fellows · 2023 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
US 20230376481A1 · Mayorski et al. · 2023 [cited by applicant]
US 20240193694A1 · Griffin · 2024 [cited by examiner]
US 20240231983A1 · Phan · 2024 [cited by examiner]
US 20240330479A1 · Kamate · 2024 [cited by examiner]
CN 105095747A · 2015 [cited by applicant]
WO WO2019067627A1 · 2019 [cited by examiner]
Calcof et al., “Health modeling and observability of mission-critical workloads on Azure”, Microsoft, Feb. 1, 2023, 20 pp., URL: https://learn.microsoft.com/en-us/azure/architecture/framework/mission-critical/mission-cr… [cited by applicant]
Cisco et al., “Cisco DNA Assurance User Guide, Release 2.1.2, Chapter 8”, Cisco Systems, Inc., Nov. 6, 2020, pp. 135-154, URL: https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-manage… [cited by applicant]
Kraemer et al., “A Human Factors Vulnerability Evaluation Method for Computer and Information Security”, Proceedings of the Human Factors and Ergonomics Society Annual Meeting, vol. 47, No. 12, Oct. 2003, pp. 1389-1393,… [cited by applicant]
Lange et al., “IT Benchmarking Explained: How To Assess Your IT Efforts”, BMC, Apr. 5, 2021, 7 pp., URL: https://www.bmc.com/blogs/it-benchmarking-metrics/. [cited by applicant]
U.S. Appl. No. 18/156,785, filed Jan. 19, 2023, naming inventors Patterson et al. [cited by applicant]
Office Action from U.S. Appl. No. 18/156,785 dated Jun. 12, 2024, 10 pp. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 18/156,785 dated Oct. 15, 2024, 9 pp. [cited by applicant]
Response to Office Action dated Jun. 12, 2024 from U.S. Appl. No. 18/156,785, filed Sep. 11, 2024, 9 pp. [cited by applicant]