IP Library Granted Patent US 9,015,795
Granted Patent B2
US 9,015,795 · App. 13/932,265 · Granted Apr 21, 2015

Reputation-based auditing of enterprise application authorization models

Inventors: Reza B'Far (Huntington Beach, CA); Kent Spaulding (Portland, OR); Yasin Cengiz (Irvine, CA); Americo Caves (Irvine, CA); Paiting Ou (Irvine, CA); Christopher Hluchan (Glendale, CO); Venkata Sree Ramya Manchikanti (Irvine, CA)
Assignee: Oracle International Corporation
H04L63/20H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,015,795
App. No.
13/932,265
Granted
Apr 21, 2015
Kind
B2
Abstract

Reputation metrics are used to gauge risk of individuals to an organization, such as employees of a business. The reputation metrics may be calculated from both internal and external data sources, including social network profiles of the individuals. Calculations of risk are used to make determinations regarding the activities the individuals are authorized to engage in.

Claims (66)

1. A method for managing one or more computer authorization policies of an enterprise based on electronic reputation auditing of employees of the enterprise, the method comprising:

obtaining electronic information associated with an employee of the enterprise from each of a plurality of electronic data sources, wherein the plurality of electronic data sources include at least one data source internal to the enterprise and at least one data source external to the enterprise;

accessing electronically stored reputation information for the employee, the reputation information including one or more reputation metrics, the one or more reputation metrics indicating an influence of the employee to be a risk to the enterprise associated with the employee;

updating the one or more reputation metrics for the employee based on the obtained electronic information;

via one or more computer processors selectively iterating;

calculating a risk score for the employee using the electronically stored one or more reputation metrics;

calculating a risk score for the employee using the updated one or more reputation metrics;

selectively determining to update the one or more computer authorization policies of the enterprise responsive to determining a change in the risk scores exceeds a predetermined threshold amount; and

updating the one or more computer authorization policies of the enterprise based at least in part on the selectively determining, wherein the updating the one or more computer authorization policies comprises selectively increasing and selectively decreasing the employee's level of access to data and program features within the enterprise.

2. The method of claim 1 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

making a numerical estimate of a derivative of the risk score calculated using the electronically stored one or more reputation metrics and the risk score calculated using the updated one or more reputation metrics; and

determining to update the one or more computer authorization policies of the enterprise when the numerical estimate of the derivative of the risk scores indicates a change in the risk scores that exceeds a threshold amount.

3. The method of claim 1 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

generating a user interface including an indication of a change in risk associated with the employee based on updating the one or more reputation metrics for the employee;

presenting the user interface to a user;

receiving from the user through the user interface an indication of an update to the one or more computer authorization policies of the enterprise; and

updating the one or more computer authorization policies of the enterprise based at least in part on the received indication.

4. The method of claim 1 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

accessing a credit score of the employee; and

calculating at least one of the one or more reputation metrics based on the credit score of the employee.

5. The method of claim 1 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises: increasing an amount of activities in which the employee is allowed to engage, when updating the one or more reputation metrics for the employee, based on the obtained information, results in an increase in the one or more reputation metrics.

6. The method of claim 1 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises: decreasing an amount of activities in which the employee is allowed to engage, when updating the one or more reputation metrics for the employee, based on the obtained information, results in a decrease in the one or more reputation metrics.

7. A system comprising:

a processor; and

a memory coupled with and readable by the processor and storing therein a set of instructions which, when executed by the processor, causes the processor to manage one or more computer authorization policies of an enterprise based on electronic reputation auditing of employees of the enterprise by:

obtaining electronic information associated with an employee of the enterprise from each of a plurality of electronic data sources, wherein the plurality of electronic data sources include at least one data source internal to the enterprise and at least one data source external to the enterprise;

accessing electronically stored reputation information for the employee, the reputation information including one or more reputation metrics, the one or more reputation metrics indicating an influence of the employee to be a risk to the enterprise associated with the employee; updating the one or more reputation metrics for the employee based on the obtained electronic information;

via one or more computer processors selectively iterating:

calculating a risk score for the employee using the electronically stored one or more reputation metrics:

calculating a risk score for the employee using the updated one or more reputation metrics:

selectively determining to update the one or more computer authorization policies of the enterprise responsive to determining a change in the risk scores exceeds a predetermined threshold amount; and

updating the one or more computer authorization policies of the enterprise based at least in part on the selectively determining, wherein the updating the one or more computer authorization policies comprises selectively increasing and selectively decreasing the employee's level of access to data and program features within the enterprise.

8. The system of claim 7 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

making a numerical estimate of a derivative of the risk score calculated using the electronically stored one or more reputation metrics and the risk score calculated using the updated one or more reputation metrics; and

determining to update the one or more computer authorization policies of the enterprise when the numerical estimate of the derivative of the risk scores indicates a change in the risk scores that exceeds a threshold amount.

9. The system of claim 7 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

generating a user interface including an indication of a change in risk associated with the employee based on updating the one or more reputation metrics for the employee;

presenting the user interface to a user;

receiving from the user through the user interface an indication of an update to the one or more computer authorization policies of the enterprise; and

updating the one or more computer authorization policies of the enterprise based at least in part on the received indication.

10. The system of claim 7 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

accessing a credit score of the employee; and

calculating at least one of the one or more reputation metrics based on the credit score of the employee.

11. The system of claim 7 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises: increasing an amount of activities in which the employee is allowed to engage, when updating the one or more reputation metrics for the employee, based on the obtained information, results in an increase in the one or more reputation metrics.

12. The system of claim 7 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises: decreasing an amount of activities in which the employee is allowed to engage, when updating the one or more reputation metrics for the employee , based on the obtained information, results in a decrease in the one or more reputation metrics.

13. A computer-readable memory comprising a set of instructions stored therein which, when executed by a processor, causes the processor to manage one or more computer authorization policies of an enterprise based on electronic reputation auditing of employees of the enterprise by:

obtaining electronic information associated with an employee of the enterprise from each of a plurality of electronic data sources, wherein the plurality of electronic data sources include at least one data source internal to the enterprise and at least one data source external to the enterprise;

accessing electronically stored reputation information for the employee, the reputation information including one or more reputation metrics, the one or more reputation metrics indicating an influence of the employee to be a risk to the enterprise associated with the employee;

updating the one or more reputation metrics for the employee based on the obtained electronic information;

via one or more computer processors selectively iterating:

calculating a risk score for the employee using the electronically stored one or more reputation metrics:

calculating a risk score for the employee using the updated one or more reputation metrics:

selectively determining to update the one or more computer authorization policies of the enterprise responsive to determining a change in the risk scores exceeds a predetermined threshold amount; and

updating the one or more computer authorization policies of the enterprise based at least in part on the selectively determining, wherein the updating the one or more computer authorization policies comprises selectively increasing and selectively decreasing the employee's level of access to data and program features within the enterprise.

14. The computer-readable memory of claim 13 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

making a numerical estimate of a derivative of the risk score calculated using the electronically stored one or more reputation metrics and the risk score calculated using the updated one or more reputation metrics; and

determining to update the one or more computer authorization policies of the enterprise when the numerical estimate of the derivative of the risk scores indicates a change in the risk scores that exceeds a threshold amount.

15. The computer-readable memory of claim 13 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

generating a user interface including an indication of a change in risk associated with the employee based on updating the one or more reputation metrics for the employee;

presenting the user interface to a user;

receiving from the user through the user interface an indication of an update to the one or more computer authorization policies of the enterprise; and

updating the one or more computer authorization policies of the enterprise based at least in part on the received indication.

16. The computer-readable memory of claim 13 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises:

accessing a credit score of the employee; and

calculating at least one of the one or more reputation metrics based on the credit score of the employee.

17. The computer-readable memory of claim 13 , wherein selectively determining to update the one or more computer authorization policies of the enterprise comprises: increasing an amount of activities in which the employee is allowed to engage, when updating the one or more reputation metrics for the employee, based on the obtained information, results in an increase in the one or more reputation metrics.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2013
From: B'FAR, REZA; SPAULDING, KENT; CENGIZ, YASIN; CAVES, AMERICO; OU, PAITING; HLUCHAN, CHRISTOPHER; MANCHIKANTI, VENKATA SREE RAMYA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 030722/0442 →
Continuity (2)
Provisional Application 61699238 · Sep 10, 2012
Related Publication 20140075500A1 · Mar 13, 2014