IP Library Granted Patent US 11,611,480
Granted Patent B2
US 11,611,480 · App. 17/087,196 · Granted Mar 21, 2023

Systems and methods for automated governance, risk, and compliance

Inventors: David Barkovic (San Francisco, CA); Cresta Kirkwood (San Diego, CA); Lal Narayanasamy (Pleasanton, CA); Anushree Randad (Milpitas, CA); Clifford Huntington (Somerville, MA); Richard Reybok (Fremont, CA); Harold Byun (Redwood City, CA)
Assignee: ServiceNow, Inc.
H04L41/0859G06F3/0481G06F3/0482G06F3/0486G06F3/04847G06F9/451G06F9/461G06F9/4881G06F9/5038G06F9/547G06F11/14G06F11/3006G06F11/3452G06F16/1873G06F16/248G06F16/2423G06F16/2474G06F16/2477G06F16/24578G06F16/27G06F16/30G06F16/904G06F16/951G06F40/18G06F40/186G06Q10/067G06Q10/0635G06Q10/06314G06Q10/06315G06Q10/06393G06Q30/018G06Q30/0603G06Q30/0635G06Q30/0641G06Q40/12G06Q50/184H04L41/0803H04L41/0843H04L41/0893H04L41/12H04L41/22H04L41/5006H04L43/045H04L43/08H04L43/50H04L63/10H04L63/1433H04L63/20H04L67/55H04L67/60G06F3/0484G06F9/44505G06F21/53G06F21/577H04L41/0879H04L41/5016H04L67/12H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,611,480
App. No.
17/087,196
Filed
Nov 2, 2020
Granted
Mar 21, 2023
Kind
B2
Art Unit
2492
USPC
726/1
Abstract

Systems and methods for configuration vulnerability checking and remediation are provided. The systems provided herein identify risk based upon service indications of a particular configuration, such that automated risk analysis may be facilitated.

Claims (84)

1. A tangible, non-transitory, machine-readable medium, comprising machine-readable instructions, that when executed by one or more processors, cause the one or more processors to:

retrieve, from one or more application programming interfaces (APIs), configuration test results for one or more sets of configuration tests evaluated against one or more configuration items (CIs), wherein each of the one or more sets of configuration tests corresponds to one or more authoritative policies;

normalize the configuration test results such that configuration test result data from different sources is stored in a common computer-readable format in the machine-readable medium;

determine compliance data for the one or more CIs with the one or more authoritative policies based on the configuration test results;

identify a set of CIs of interest based upon the compliance data, wherein each CI in the set of CIs of interest is in non-compliance with at least one of the one or more authoritative policies;

determine a respective residual risk score for a particular CI in the set of CIs of interest by:

identifying, by accessing data from a data store, an indication of a plurality of services associated with the particular CI;

identifying a highest criticality of the plurality of services; and

setting the respective residual risk score for the particular CI based upon the highest criticality; and

present, in a configuration compliance dashboard rendered on an electronic display, a residual score indication based upon the respective residual risk score associated with each CI of the set of CIs of interest.

2. The machine-readable medium of claim 1 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

calculate an overall risk score for non-compliance by the one or more sets of configuration tests to a policy statement of the one or more authoritative policies based at least in part upon the respective residual risk score for one or more CIs of the set of CIs of interest.

3. The machine-readable medium of claim 2 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

calculate the overall risk score based at least in part upon the respective residual risk score for one or more CIs of the set of CIs of interest and an inherent score for at least one of the one or more sets of configuration tests, the inherent score comprising a score associated with non-compliance to the at least one of the one or more sets of configuration tests, as indicated by the configuration test results.

4. The machine-readable medium of claim 3 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

for each CI of the set of CIs of interest, calculate the overall risk score by combining the respective residual risk score and the inherent score.

5. The machine-readable medium of claim 2 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

calculate the overall risk score by:

identifying a percentage of non-compliance to the policy statement;

maximizing the respective residual risk score and an inherent score for the one or more sets of configuration tests into a maximized score; and

weighing the maximized score by the percentage of non-compliance to the policy statement.

6. The machine-readable medium of claim 2 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

calculate the overall risk score, by:

retrieving an active risk score calculator from a set of available risk score calculators, each of the set of available risk score calculators comprising a respective machine-readable script instructing the one or more processors how to calculate the overall risk score; and

executing the respective machine-readable script of the active risk score calculator to calculate the overall risk score.

7. The machine-readable medium of claim 1 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

enable grouping, via a graphical user interface, of a subset of the configuration test results.

8. The machine-readable medium of claim 1 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

enable deferral of one or more of the configuration test results, via a configuration test result group, for a duration of time, such that the one or more of the configuration test results is not indicated as non-compliant in a subsequent rendering of the configuration compliance dashboard.

9. The machine-readable medium of claim 1 , comprising machine-readable instructions, that when executed by the one or more processors, cause the one or more processors to:

retrieve the one or more authoritative polices, via the one or more APIs; and

map the one or more authoritative policies to relevant subsets of the one or more sets of configuration tests.

10. A computer-implemented method, comprising:

retrieving, from one or more application programming interfaces (APIs), configuration test results for a set of configuration tests evaluated against one or more configuration items (CIs), wherein each configuration test in the set of configuration tests is associated with one or more authoritative policies;

normalizing the configuration test results such that configuration test result data from different sources is stored in a common computer-readable format in a machine-readable medium;

determining compliance data for the one or more CIs with the one or more authorative policies based on the configuration test results;

identifying a set of CIs of interest based upon the compliance data, wherein each CI in the set of CIs of interest is in non-compliance with at least one of the one or more authoritative policies;

determining a respective residual risk score for a particular CI in the set of CIs of interest, by:

identifying, by accessing data from a data store, an indication of a plurality of services associated with the particular CI;

identifying a highest criticality of the plurality of services; and

setting the respective residual risk score for the particular CI based upon the highest criticality; and

presenting, in a configuration compliance dashboard rendered on an electronic display, a residual score indication based upon the respective residual risk score associated with each CI of the set of CIs of interest.

11. The computer-implemented method of claim 10 , comprising:

calculating an overall risk score for non-compliance by the set of configuration tests to a policy statement of the one or more authoritative policies based at least in part upon the respective residual risk score for one or more CIs of the set of CIs of interest.

12. The computer-implemented method of claim 11 , comprising:

calculating the overall risk score based at least in part upon the respective residual risk score for each of the CIs in the set of CIs of interest and an inherent score for the set of configuration tests, the inherent score comprising a score associated with non-compliance to the set of configuration tests, as indicated by the configuration test results.

13. The computer-implemented method of claim 12 , comprising:

calculating the overall risk score by combining the respective residual risk score for each of the CIs of the set of CIs of interest and the inherent score.

14. The computer-implemented method of claim 11 , comprising:

calculating the overall risk score by:

identifying a percentage of non-compliance to the policy statement;

maximizing the respective residual risk score for each of the CIs in the set of CIs of interest and an inherent score for the set of configuration tests into a maximized score; and

weighing the maximized score by a percentage of non-compliance to the policy statement.

15. The computer-implemented method of claim 11 , comprising:

calculating the overall risk score, by:

retrieving an active risk score calculator from a set of available risk score calculators, each of the set of available risk score calculators comprising a respective machine-readable script instructing how to calculate the overall risk score; and

executing the respective machine-readable script of the active risk score calculator to calculate the overall risk score.

16. The computer-implemented method of claim 10 , comprising:

enabling grouping, via a graphical user interface, of a subset of the configuration test results.

17. The computer-implemented method of claim 10 , comprising:

enabling deferral of one or more of the configuration test results, via a configuration test result group, for a duration of time, such that the one or more of the configuration test results is not indicated as non-compliant in a subsequent rendering of the configuration compliance dashboard.

18. The computer-implemented method of claim 10 , comprising:

retrieving the one or more authoritative policies, via the one or more APIs; and

mapping the one or more authoritative policies to relevant subsets of the set of configuration tests.

19. A cloud-computing system, comprising:

a network, comprising a plurality of configuration items (CIs);

a platform configured to present information regarding the plurality of CIs;

a management, instrumentation, and discovery (MID) server, configured to facilitate data transfer between the plurality of CIs and platform, the data enabling presentation of information regarding the plurality of CIs via the platform;

wherein the platform is configured to:

retrieve configuration test results for a set of configuration tests evaluated against the plurality of CIs, wherein each configuration test in the set of configuration tests is associated with one or more authoritative policies;

normalize the configuration test results such that configuration test result data from different sources is stored in a common computer-readable format in a machine-readable medium;

determine compliance data for the plurality of CIs with the one or more authoritative policies based on the configuration test results;

identify a set of CIs of interest based upon the compliance data, wherein each CI in the set of CIs of interest is in non-compliance with at least one of the one or more authoritative policies;

determine a respective residual risk score for a particular CI in the set of CIs of interest:

identifying, by accessing data from a data store, an indication of a plurality of services associated with the particular CI;

identifying a highest criticality of the plurality of services; and

setting the respective residual risk score for the particular CI based upon the highest criticality; and

present, in a configuration compliance dashboard rendered on an electronic display, a residual score indication based upon the respective residual risk score associated with each CI of the set of CIs of interest.

20. The cloud-computing system of claim 19 , wherein the platform is configured to:

calculate an overall risk score by:

combining the respective residual risk score for at least one CI in the set of CIs of interest and an inherent score, the inherent score comprising a score associated with non-compliance to the set of configuration tests, as indicated by the configuration test results; or

identifying a percentage of non-compliance to a policy statement associated with the one or more authoritative policies;

maximizing the respective residual risk score for the at least one CI in the set of CIs of interest and the inherent score for the set of configuration tests into a maximized score; and

weighing the maximized score by the percentage of non-compliance to the policy statement.

Continuity (3)
Continuation 15815129 · Nov 16, 2017
Provisional Application 62568087 · Oct 4, 2017
Related Publication 20210051067A1 · Feb 18, 2021