IP Library Granted Patent US 12,380,222
Granted Patent B2
US 12,380,222 · App. 18/540,980 · Granted Aug 5, 2025

Risk scoring system for vulnerability mitigation

Inventors: Tyler Reguly (Toronto, CA); Lamar Bailey (Cumming, GA); Lane Thames (Atlanta, GA); Craig Young (Alpharetta, GA)
Assignee: TRIPWIRE, INC.
G06F21/577G06F17/11G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,222
App. No.
18/540,980
Granted
Aug 5, 2025
Kind
B2
Abstract

Apparatus, methods, and articles of manufacture or disclosed for implementing risk scoring systems used for vulnerability mitigation in a distributed computing environment. In one disclosed example, a computer-implemented method of mitigating vulnerabilities within a computing environment includes producing a risk score indicating at least one of: a vulnerability component, a security configuration component, or a file integrity component for an object within the computing environment, producing a signal score indicating a factor that contributes to risk for the object, and combining the risk score and the signal score to produce a combined risk score indicating a risk level associated with at least one vulnerability of the computing system object. In some examples, the method further includes mitigating the at least one vulnerability by changing a state of a computing object using the combined risk score.

Claims (51)

1. A computer-implemented method of mitigating vulnerabilities within a computing environment, the method comprising:

producing a risk score based at least in part on a vulnerability component for an object within the computing environment, wherein the vulnerability component comprises at least an age component, wherein the risk score follows a model of:

from a minimum value for the age component, increasing to a local maxima as the age component reaches a first predetermined age,

decreasing to a local minima as the age component approaches a second predetermined age from the first predetermined age, the second predetermined age being greater than the first predetermined age, and

increasing as the age component increases past the second predetermined age,

wherein the risk score indicates a risk level associated with at least one vulnerability of the computing system object; and

mitigating, based on the risk score, a vulnerability in one or more of the object or the computing environment by changing a state of the object within the computing environment.

2. The method of claim 1 , further comprising:

producing a vision score comprising at least one bucket for risk of the vulnerability on the network.

3. The method of claim 1 , further comprising:

displaying the risk score using a graphical display coupled to a computing device within the computing environment.

4. The method of claim 1 , further comprising:

producing a signal score indicating a factor that contributes to risk for the object; and

combining the risk score and the signal score to produce a combined risk score indicating the risk level associated with the at least one vulnerability of the computing system object.

5. The method of claim 4 , wherein:

the producing the risk score and/or the signal score comprises indicating a crowned vulnerability deemed to need immediate mitigation.

6. The method of claim 4 , wherein:

the signal score is based on at least one of: a name component, a description component, a single type component, a criticality component, a data source component, a data value component, a test count, a test method, a per test data component, a test definition component, and execution order component, a data match component, a midpoint identifier component, as no signal match component, or a no data source available component.

7. The method of claim 4 , wherein:

the signal score is determined by evaluating at least one of a single type component, a criticality component, and/or a test component of an object in the computing environment.

8. The method of claim 4 , wherein:

the combining the risk score and the signal score is based on a criticality indicated by the signal score.

9. The method of claim 1 , wherein:

the risk score is determined by combining at least one of the following components: a risk component, a skill component, an age component, or a categorization component.

10. The method of claim 1 , wherein:

the producing the risk score further comprises determining at least one of: the age of the vulnerability, the skill required to exploit the vulnerability, or the outcome of a successful exploitation of the vulnerability.

11. The method of claim 1 , wherein:

the risk score is determined by determining a security configuration management score and/or a file integrity management score.

12. The method of claim 1 , wherein:

the producing the risk score includes a factor that contributes to risk for the object.

13. The method of claim 1 , further comprising computing an overall system risk score by combining two or more risk scores.

14. The method of claim 13 , further comprising displaying the overall system risk score on a display coupled to a computing system, the display including at least one of a numerical indication of the overall system risk score, a graphical indicator of the overall system risk score, or a color shaded indicator of the overall system or score.

15. The method of claim 1 , wherein the risk score is further produced based at least in part on one or more of a security configuration component and a file integrity component for the object within the computing environment.

16. One or more non-transitory computer readable storage media storing computer readable instructions, which when executed by a computer cause the computer to:

produce a risk score based at least in part on a vulnerability component for an object within the computing environment, wherein the vulnerability component comprises at least an age component, wherein the risk score follows a model of:

from a minimum value for the age component, increasing to a local maxima as the age component reaches a first predetermined age,

decreasing to a local minima as the age component approaches a second predetermined age from the first predetermined age, the second predetermined age being greater than the first predetermined age, and

increasing as the age component increases past the second predetermined age,

wherein the risk score indicates a risk level associated with at least one vulnerability of the computing system object; and

mitigate, based on the risk score, a vulnerability in one or more of the object or the computing environment by changing a state of the object within the computing environment.

17. The apparatus of claim 16 , further comprising:

a risk score component implemented with an agent executed by a processor or a device profiler coupled to a compute object for which the risk score is determined.

18. An apparatus, comprising:

a processor; and

one or more non-transitory computer readable storage media storing computer readable instructions, which when executed by the processor cause the apparatus to:

produce a risk score based at least in part on a vulnerability component for an object within the computing environment, wherein the vulnerability component comprises at least an age component, wherein the risk score follows a model of:

from a minimum value for the age component, increasing to a local maxima as the age component reaches a first predetermined age,

decreasing to a local minima as the age component approaches a second predetermined age from the first predetermined age, the second predetermined age being greater than the first predetermined age, and

increasing as the age component increases past the second predetermined age,

wherein the risk score indicates a risk level associated with at least one vulnerability of the computing system object; and

mitigate, based on the risk score, a vulnerability in one or more of the object or the computing environment by changing a state of the object within the computing environment.

Assignments (6)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR'S NAME FROM "TYLER REQULY" TO "TYLER REGULY" PREVIOUSLY RECORDED AT REEL: 66751 FRAME: 859. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 15, 2024
From: REGULY, TYLER; BAILEY, LAMAR; THAMES, LANE; YOUNG, CRAIG
To: TRIPWIRE, INC.
Reel/Frame 067870/0015 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2024
From: REQULY, TYLER; BAILEY, LAMAR; THAMES, LANE; YOUNG, CRAIG
To: TRIPWIRE, INC.
Reel/Frame 066751/0859 →
Continuity (3)
Continuation 17209050 · Mar 22, 2021
Provisional Application 62992790 · Mar 20, 2020
Related Publication 20240193280A1 · Jun 13, 2024
References Cited (45)
US 7243348B2 · Good et al. · 2007 [cited by applicant]
US 7316016B2 · Difalco · 2008 [cited by applicant]
US 7360099B2 · Difalco et al. · 2008 [cited by applicant]
US 7822724B2 · Difalco et al. · 2010 [cited by applicant]
US 8140635B2 · Difalco · 2012 [cited by applicant]
US 8176158B2 · Difalco et al. · 2012 [cited by applicant]
US 8819491B2 · Whitlock et al. · 2014 [cited by applicant]
US 8984643B1 · Krisher · 2015 [cited by examiner]
US 9634951B1 · Hunt et al. · 2017 [cited by applicant]
US 9741017B2 · Good et al. · 2017 [cited by applicant]
US 9766873B2 · Steigleder · 2017 [cited by applicant]
US 10158660B1 · Reguly et al. · 2018 [cited by applicant]
US 10313257B1 · Hunt et al. · 2019 [cited by applicant]
US 10318894B2 · Difalco et al. · 2019 [cited by applicant]
US 10382486B2 · Rivers · 2019 [cited by applicant]
US 10754959B1 · Rajasooriya et al. · 2020 [cited by applicant]
US 20020196330A1 · Park et al. · 2002 [cited by applicant]
US 20040024843A1 · Smith · 2004 [cited by applicant]
US 20040075738A1 · Burke et al. · 2004 [cited by applicant]
US 20040122962A1 · Difalco et al. · 2004 [cited by applicant]
US 20050160480A1 · Birt et al. · 2005 [cited by applicant]
US 20060206883A1 · Sabbouh · 2006 [cited by applicant]
US 20060242277A1 · Torrence et al. · 2006 [cited by applicant]
US 20070124255A1 · Difalco et al. · 2007 [cited by applicant]
US 20070239862A1 · Bronez et al. · 2007 [cited by applicant]
US 20080016501A1 · Muhlestein et al. · 2008 [cited by applicant]
US 20080021912A1 · Seligman et al. · 2008 [cited by applicant]
US 20080168420A1 · Sabbouh · 2008 [cited by applicant]
US 20080189788A1 · Bahl · 2008 [cited by examiner]
US 20100005107A1 · Difalco · 2010 [cited by applicant]
US 20100043066A1 · Miliefsky · 2010 [cited by applicant]
US 20110066951A1 · Ward-Karet et al. · 2011 [cited by applicant]
US 20110138471A1 · Van De Weyer et al. · 2011 [cited by applicant]
US 20110197094A1 · Wagner · 2011 [cited by applicant]
US 20110197189A1 · Wagner et al. · 2011 [cited by applicant]
US 20110197205A1 · Wagner et al. · 2011 [cited by applicant]
US 20110208841A1 · Robertson et al. · 2011 [cited by applicant]
US 20120023076A1 · Torrence et al. · 2012 [cited by applicant]
US 20120179805A1 · Difalco · 2012 [cited by applicant]
US 20120210434A1 · Curtis et al. · 2012 [cited by applicant]
US 20130247205A1 · Schrecker et al. · 2013 [cited by applicant]
US 20200382546A1 · Henderson · 2020 [cited by applicant]
Irfahn Khimji, Tripwire, Inc., “Tripwire Vulnerability Risk Metrics,” White Paper, 2019, 8 pages. [cited by applicant]
Tripwire, Inc., “Advanced Vulnerability Risk Scoring and Prioritization,” Solution Brief, 2019, 3 pages. [cited by applicant]
Tripwire, Inc., “The Tripwire Vulnerability Scoring System,” White Paper, 2020, 8 pages. [cited by applicant]