IP Library Granted Patent US 12,592,869
Granted Patent B2
US 12,592,869 · App. 18/187,461 · Granted Mar 31, 2026

Cloud residual risk assessment tool

Inventor: Tanweer Surve (Coppell, TX)
Assignee: Wells Fargo Bank, N.A.
H04L41/5009H04L41/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,869
App. No.
18/187,461
Granted
Mar 31, 2026
Kind
B2
Abstract

A computing device comprising a memory and one or more processors in communication with the memory and configured to: obtain data defining a first plurality of risks for a current host; determine, a first set of residual risk scores for each risk of the first plurality of risks; aggregate the first set of residual risk scores associated with the current host to form a first aggregate residual risk score; obtain data defining a second plurality of risks of a future host; determine a second set of residual risk scores for each risk of the second plurality of risks; aggregate the second set of residual risk scores associated with the future host to form a second aggregate residual risk score; determine whether the second aggregate residual risk score is less than the first aggregate residual risk score; and migrate assets from the current host to the future host.

Claims (79)

1 . A method, comprising:

obtaining, by one or more processors, data defining a first plurality of risks for a current host, wherein the data defining the first plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determining, by the one or more processors, a first set of residual risk scores for each risk of the first plurality of risks;

aggregating, by the one or more processors, the first set of residual risk scores associated with the current host to form a first aggregate residual risk score;

generating, by the one or more processors, a synthetic application that embodies characteristics of an application on the current host and deploying the synthetic application to a future host;

obtaining, by the one or more processors, data defining a second plurality of risks for the future host by monitoring performance of the future host with the synthetic application, wherein the data defining the second plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determining, by the one or more processors, a second set of residual risk scores for each risk of the second plurality of risks after it is determined that the future host has met control objectives of a control adherence framework;

aggregating, by the one or more processors, the second set of residual risk scores associated with the future host to form a second aggregate residual risk score;

determining, by the one or more processors, whether the second aggregate residual risk score is less than the first aggregate residual risk score; and

in response to determining the second aggregate residual risk score is less than the first aggregate residual risk score, migrating, by the one or more processors, assets from the current host to the future host.

2 . The method of claim 1 , wherein the first plurality of risks and the second plurality of risks are associated with a domain of a plurality of domains, wherein the plurality of domains comprises the application domain, the hosting service domain, and the data center domain.

3 . The method of claim 1 , further comprising, in response to migrating, by the one or more processors, the assets from the current host to the future host, continuously determining, by the one or more processors, a residual risk score of the future host.

4 . The method of claim 1 , further comprising, in response to determining the second aggregate residual risk score is greater than the first aggregate residual risk score, sending, by the one or more processors, a warning via a user interface.

5 . The method of claim 1 , wherein obtaining the second plurality of risks of the future host further comprises:

sending, by the one or more processors, synthetic data to the future host;

monitoring the future host processing the synthetic data; and

determining, by the one or more processors, the second plurality of risks based on the monitoring.

6 . The method of claim 1 , wherein each risk of the first plurality of risks and the second plurality of risks are associated with a corresponding risk factor of a plurality of risk factors, and wherein determining the first and second sets of residual risk scores for each of the respective first and second plurality of risks further comprises:

establishing a plurality of groups associated with each respective risk factor, wherein each group of the plurality of groups comprises a risk score;

determining, by the one or more processors, a value of each risk of the first plurality of risks and the second plurality of risks;

assigning, by the one or more processors, each risk of the first plurality of risks and the second plurality of risks to a group of the plurality of groups associated with the corresponding risk factor based on the value of each risk; and

determining, by the one or more processors, the residual risk score for each risk of the first plurality of risks and the second plurality of risks based on the risk score of the assigned group.

7 . The method of claim 6 , wherein the plurality of risk factors further comprises:

one or more quantitative risk factors, wherein the one or more quantitative risk factors includes at least one of:

policy exceptions,

control applicability, and

open issues; and

one or more qualitative risk factors, wherein the one or more qualitative risk factors includes at least one of:

an organizational training score,

an organizational modernization score, and

a migration strategy score.

8 . The method of claim 1 , wherein obtaining, by the one or more processors, the data defining the first plurality of risks and the data defining the second plurality of risks further comprises:

executing, by the one or more processors, one or more software tools designed to collect records associated with the first plurality of risks and the second plurality of risks; and

generating, by the one or more software tools, the data defining the first plurality of risks and the second plurality of risks based on the records.

9 . The method of claim 1 , further comprising:

in response to determining, by the one or more processors, whether the second aggregate residual risk score is less than the first aggregate residual risk score, displaying, by the one or more processors and with an interface, the first aggregate residual risk score, the second aggregate residual risk score, the data defining the first plurality of risks, and the data defining the second plurality of risks.

10 . A computing device comprising:

a memory; and

one or more processors in communication with the memory and configured to:

obtain data defining a first plurality of risks for a current host, wherein the data defining the first plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determine a first set of residual risk scores for each risk of the first plurality of risks;

aggregate the first set of residual risk scores associated with the current host to form a first aggregate residual risk score;

generate a synthetic application that embodies characteristics of an application on the current host and deploy the synthetic application to a future host;

obtain data defining a second plurality of risks of the future host by monitoring performance of the future host with the synthetic application, wherein the data defining the second plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determine a second set of residual risk scores for each risk of the second plurality of risks after it is determined that the future host has met control objectives of a control adherence framework;

aggregate the second set of residual risk scores associated with the future host to form a second aggregate residual risk score;

determine whether the second aggregate residual risk score is less than the first aggregate residual risk score; and

migrate assets from the current host to the future host.

11 . The computing device of claim 10 , wherein the first plurality of risks and the second plurality of risks are associated with a domain of a plurality of domains, wherein the plurality of domains comprises the application domain, the hosting service domain, and the data center domain.

12 . The computing device of claim 10 , wherein the one or more processors are further configured to:

in response to migrating the assets from the current host to the future host, continuously determine a residual risk score of the future host.

13 . The computing device of claim 10 , wherein the one or more processors are further configured to:

in response to determining the second aggregate residual risk score is greater than the first aggregate residual risk score, send a warning via a user interface.

14 . The computing device of claim 10 , wherein the one or more processors are further configured to:

send synthetic data to the future host;

monitor the future host processing the synthetic data; and

determine the second plurality of risks based on the monitoring.

15 . The computing device of claim 10 , wherein each risk of the first plurality of risks and the second plurality of risks are associated with a corresponding risk factor of a plurality of risk factors, and wherein the one or more processors are further configured to:

establish a plurality of groups associated with each respective risk factor, wherein each group of the plurality of groups comprises a risk score;

determine a value of each risk of the first plurality of risks and the second plurality of risks;

assign each risk of the first plurality of risks and the second plurality of risks to a group of the plurality of groups associated with the corresponding risk factor based on the value of each risk; and

determine the residual risk score for each risk of the first plurality of risks and the second plurality of risks based on the risk score of the assigned group.

16 . The computing device of claim 10 , wherein the one or more processors are further configured to:

execute one or more software tools designed to collect records associated with the first plurality of risks and the second plurality of risks; and

generate, by the one or more software tools, the data defining the first plurality of risks and the second plurality of risks based on the records.

17 . The computing device of claim 10 , wherein the one or more processors are further configured to:

in response to determining whether the second aggregate residual risk score is less than the first aggregate residual risk score, display, with an interface, the first aggregate residual risk score, the second aggregate residual risk score, the data defining the first plurality of risks, and the data defining the second plurality of risks.

18 . A non-transitory computer-readable storage medium storing instructions that, when executed, cause one or more processors of a server device to:

obtain data defining a first plurality of risks for a current host, wherein the data defining the first plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determine, a first set of residual risk scores for each risk of the first plurality of risks;

aggregate the first set of residual risk scores associated with the current host to form a first aggregate residual risk score;

generate a synthetic application that embodies characteristics of an application on the current host and deploy the synthetic application to a future host;

obtain data defining a second plurality of risks of the future host by monitoring performance of the future host with the synthetic application, wherein the data defining the second plurality of risks corresponds to one or more risk factors for each of two or more of an application domain, a hosting service domain, or a data center domain;

determine a second set of residual risk scores for each risk of the second plurality of risks after it is determined that the future host has met control objectives of a control adherence framework;

aggregate the second set of residual risk scores associated with the future host to form a second aggregate residual risk score;

determine whether the second aggregate residual risk score is less than the first aggregate residual risk score; and

migrate assets from the current host to the future host.

19 . The method of claim 1 , wherein the one or more risk factors comprise capability and security for the hosting service domain.

20 . The method of claim 1 , wherein the one or more risk factors comprise resiliency, capability, and security for the data center domain.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073896/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2023
From: SURVE, TANWEER
To: WELLS FARGO BANK, N.A.
Reel/Frame 063540/0284 →
Continuity (1)
Related Publication 20240323104A1 · Sep 26, 2024
References Cited (23)
US 7552480B1 · Voss · 2009 [cited by examiner]
US 7975165B2 · Shneorson et al. · 2011 [cited by applicant]
US 9591016B1 · Palmieri et al. · 2017 [cited by applicant]
US 10262145B2 · Hoernecke et al. · 2019 [cited by applicant]
US 10318740B2 · Toledano et al. · 2019 [cited by applicant]
US 10379910B2 · Balasubramanian et al. · 2019 [cited by applicant]
US 10673900B2 · Nagaratnam et al. · 2020 [cited by applicant]
US 10691796B1 · Stolte et al. · 2020 [cited by applicant]
US 10740469B2 · Zheng et al. · 2020 [cited by applicant]
US 11088920B2 · Firment et al. · 2021 [cited by applicant]
US 11093618B2 · Murano et al. · 2021 [cited by applicant]
US 11223552B1 · Anderson · 2022 [cited by examiner]
US 11636213B1 · Elgressy · 2023 [cited by examiner]
US 20100332889A1 · Shneorson · 2010 [cited by examiner]
US 20170063622A1 · Yoshida · 2017 [cited by examiner]
US 20180068243A1 · Vescio · 2018 [cited by examiner]
US 20190235449A1 · Slessman · 2019 [cited by examiner]
US 20200137097A1 · Zimmermann et al. · 2020 [cited by applicant]
US 20210165688A1 · Reyes · 2021 [cited by examiner]
CN 103607300B · 2017 [cited by applicant]
Flores et al., “Cloud-GMR: A Qualitative Framework for Governance and Risk Management of Cloud-hosted Public Services”, 2020 XLVI Latin American Computing Conference (CLEI), Oct. 19, 2020, 10 pp. [cited by applicant]
Mackita et al., “ERMOCTAVE: A Risk Management Framework for IT Systems Which Adopt Cloud Computing”, Future Internet, Sep. 10, 2019, 21 pp. [cited by applicant]
Rahman et al., “A Risk Management Approach for a Sustainable Cloud Migration”, Journal of Risk and Financial Management, Nov. 9, 2017, 19 pp. [cited by applicant]