IP Library › Granted Patent US 11,283,841
Granted Patent B2
US 11,283,841 · App. 16/257,351 · Granted Mar 22, 2022

Community-based anomaly detection policy sharing among organizations

Inventors: Alex Zaslavsky (Brookline, MA); Salah E. Machani (Medford, MA)
Assignee: EMC IP Holding Company LLC
H04L63/205H04L41/0893H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,841
App. No.
16/257,351
Granted
Mar 22, 2022
Kind
B2
Abstract

Techniques are provided for community-based anomaly detection policy sharing among organizations. One method comprises obtaining a cluster of organizations derived from clustering multiple organizations based on predefined clustering parameters; obtaining multiple policies from the organizations in the cluster; selecting one of the obtained plurality of policies based on a predefined policy sharing criteria; and sharing the selected policy with one or more of the organizations in the cluster. A use of the selected policy by one or more of the organizations may be simulated to evaluate a performance of the selected policy. The selected policy may be normalized and/or abstracted prior to being shared with organizations in the cluster. A given policy obtained from the organizations in the cluster may be weighted based on an influence rating of one or more source organizations that provided the given policy.

Claims (35)

1. A method, comprising:

obtaining a first cluster, of a plurality of clusters, comprised of a plurality of first organizations derived from clustering a plurality of organizations based on one or more predefined clustering parameters;

obtaining a plurality of policies from at least one of the plurality of first organizations in the first cluster;

selecting, using at least one processing device, at least one of the obtained plurality of policies based at least in part on one or more of: (i) a percentage and (ii) a total number of first organizations in the first cluster that employ the at least one selected policy; and

sharing the at least one selected policy with one or more of the first organizations in the first cluster, wherein the total number of first organizations in the first cluster that employ the at least one selected policy is determined prior to the sharing;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 , further comprising simulating a use of the at least one selected policy by one or more of the plurality of organizations to evaluate a performance of the at least one selected policy.

3. The method of claim 1 , further comprising normalizing the at least one selected policy prior to the sharing step.

4. The method of claim 1 , further comprising abstracting the at least one selected policy prior to the sharing step.

5. The method of claim 1 , wherein the predefined clustering parameters comprise one or more of an industry type, a number of users, a number of locations, a number of protected applications, an application type, a customer characterization and an overall security score.

6. The method of claim 1 , further comprising ranking the at least one selected policy based at least in part on the percentage of first organizations that share each of the plurality of policies as an indicator of importance.

7. The method of claim 1 , further comprising weighting a given policy obtained from the plurality of first organizations in the first cluster based on an influence rating of one or more source organizations that provided the given policy.

8. The method of claim 1 , further comprising determining whether to share the at least one selected policy to each of the first organizations that did not employ the at least one selected policy prior to the sharing.

9. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

obtaining a first cluster, of a plurality of clusters, comprised of a plurality of first organizations derived from clustering a plurality of organizations based on one or more predefined clustering parameters;

obtaining a plurality of policies from at least one of the plurality of first organizations in the first cluster;

selecting, using at least one processing device, at least one of the obtained plurality of policies based at least in part on one or more of: (i) a percentage and (ii) a total number of first organizations in the first cluster that employ the at least one selected policy; and

sharing the at least one selected policy with one or more of the first organizations in the first cluster, wherein the total number of first organizations in the first cluster that employ the at least one selected policy is determined prior to the sharing.

10. The system of claim 9 , further comprising the step of simulating a use of the at least one selected policy by one or more of the plurality of organizations to evaluate a performance of the at least one selected policy.

11. The system of claim 9 , further comprising the step of one or more of normalizing and abstracting the at least one selected policy prior to the sharing step.

12. The system of claim 9 , wherein the predefined clustering parameters comprise one or more of an industry type, a number of users, a number of locations, a number of protected applications, an application type, a customer characterization and an overall security score.

13. The system of claim 9 , further comprising the step of ranking the at least one selected policy based at least in part on the percentage of first organizations that share each of the plurality of policies as an indicator of importance.

14. The system of claim 9 , further comprising the step of weighting a given policy obtained from the plurality of first organizations in the first cluster based on an influence rating of one or more source organizations that provided the given policy.

15. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

obtaining a first cluster, of a plurality of clusters, comprised of a plurality of first organizations derived from clustering a plurality of organizations based on one or more predefined clustering parameters;

obtaining a plurality of policies from at least one of the plurality of first organizations in the first cluster;

selecting, using at least one processing device, at least one of the obtained plurality of policies based at least in part on one or more of: (i) a percentage and (ii) a total number of first organizations in the first cluster that employ the at least one selected policy; and

sharing the at least one selected policy with one or more of the first organizations in the first cluster, wherein the total number of first organizations in the first cluster that employ the at least one selected policy is determined prior to the sharing.

16. The computer program product of claim 15 , further comprising the step of simulating a use of the at least one selected policy by one or more of the plurality of organizations to evaluate a performance of the at least one selected policy.

17. The computer program product of claim 15 , further comprising the step of one or more of normalizing and abstracting the at least one selected policy prior to the sharing step.

18. The computer program product of claim 15 , wherein the predefined clustering parameters comprise one or more of an industry type, a number of users, a number of locations, a number of protected applications, an application type, a customer characterization and an overall security score.

19. The computer program product of claim 15 , further comprising the step of ranking the at least one selected policy based at least in part on the percentage of first organizations that share each of the plurality of policies as an indicator of importance.

20. The computer program product of claim 15 , further comprising the step of weighting a given policy obtained from the plurality of first organizations in the first cluster based on an influence rating of one or more source organizations that provided the given policy.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2019
From: ZASLAVSKY, ALEX; MACHANI, SALAH E.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048135/0851 →
Continuity (1)
Related Publication 20200244705A1 · Jul 30, 2020