IP Library Granted Patent US 11,625,488
Granted Patent B2
US 11,625,488 · App. 16/841,232 · Granted Apr 11, 2023

Continuous risk assessment for electronic protected health information

Inventors: David M. T. Ting (Sudbury, MA); Sean Ting (San Francisco, CA)
Assignee: TAUSIGHT, INC.
G06F21/577G06F21/70G16H10/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,488
App. No.
16/841,232
Granted
Apr 11, 2023
Kind
B2
Abstract

Methods and systems for continuously and quantitatively assessing the risk to data confidentiality, integrity, and availability on identified on endpoints, servers, medical devices, and “Internet of things” devices in a networked healthcare environment monitor resource requests by user applications running on the various device. A map of resource usage by each application may be generated. Based on the map and a risk model (e.g., the contents of a risk database), application events associated with risks are detected and resources vulnerable to the risk may be identified.

Claims (35)

1. A computational system comprising:

a. a processor;

b. an operating system;

c. a computer memory;

d. a plurality of user applications;

e. a risk database;

f. a vulnerabilities database; and

g. at least one agent executable by the processor and configured to

(i) monitor resource requests by the user applications and, based thereon, generate a map of resource usage by each application, the map identifying dependent system resources requested by the applications and security controls that govern read/write access to such resources;

(ii) based on the map and the risk database, detect application events associated with risks;

(iii) upon detection of an event corresponding to a risk, check the event against a minimum cut set of vulnerabilities stored in the vulnerabilities database, wherein the minimum cut set of vulnerabilities is the smallest set of individual component faults required to trigger a root-level fault; and

(iv) determine a set of resources vulnerable to the risk and, based thereon, take an action, wherein a resource is a physical or logical capability managed by the operating system.

2. The system of claim 1 , wherein the action is issuing an alert to a supervisory node responsible for the determined set of resources.

3. The system of claim 1 , wherein the action is updating a computational system-wide risk model.

4. The system of claim 1 , wherein the system is an endpoint device.

5. The system of claim 4 , wherein the system includes an independent sensor associated with each of the user applications.

6. The system of claim 4 , wherein the system includes a single sensor responsible for all of the user applications.

7. The system of claim 1 , wherein the system is a server hosting user application for multiple endpoint devices and users.

8. The system of claim 7 , wherein the system includes an independent sensor associated with each of the user applications.

9. The system of claim 8 , wherein each of the user applications is hosted for multiple simultaneous user sessions.

10. The system of claim 7 , wherein the system includes a single sensor responsible for all of the user applications.

11. A method of detecting and responding to computational risks in a computational system comprising a processor, an operating system, a computer memory, and a plurality of user applications, the method comprising the steps of:

monitoring resource requests by the user applications and, based thereon, generate a map of resource usage by each application, the map identifying dependent system resources requested by the applications and security controls that govern read/write access to such resources;

based on the map and a risk database, detect application events associated with risks;

upon detection of an event corresponding to a risk, check the event against a minimum cut set of vulnerabilities stored in a vulnerabilities database, wherein the minimum cut set of vulnerabilities is the smallest set of individual component faults required to trigger a root-level fault; and

determining a set of resources vulnerable to the risk and, based thereon, taking an action, wherein a resource is a physical or logical capability managed by the operating system.

12. The method of claim 11 , wherein the action is issuing an alert to a supervisory node responsible for the determined set of resources.

13. The method of claim 11 , wherein the action is updating a system-wide computational risk model.

14. The method of claim 11 , wherein the system is an endpoint device.

15. The method of claim 14 , wherein the system includes an independent sensor associated with each of the user applications.

16. The method of claim 14 , wherein the system includes a single sensor responsible for all of the user applications.

17. The method of claim 11 , wherein the system is a server hosting user application for multiple endpoint devices and users.

18. The method of claim 17 , wherein the system includes an independent sensor associated with each of the user applications.

19. The method of claim 18 , wherein each of the user applications is hosted for multiple simultaneous user sessions.

20. The method of claim 17 , wherein the system includes a single sensor responsible for all of the user applications.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2021
From: TING, DAVID M.T.; TING, SEAN
To: TAUSIGHT, INC.
Reel/Frame 055159/0629 →
Continuity (2)
Provisional Application 62829695 · Apr 5, 2019
Related Publication 20200320203A1 · Oct 8, 2020