IP Library › Granted Patent US 11,630,911
Granted Patent B2
US 11,630,911 · App. 17/231,819 · Granted Apr 18, 2023

Data breach detection and mitigation

Inventors: Alan James Sharp-Paul (Los Altos, CA); Christopher Robert Vickery (Santa Rosa, CA); Jonathan David Hendren (Mountain View, CA); Gregory Ford Pollock (San Jose, CA); Daniel Bradbury (Sydney, AU); Christian Alan Kiely (Sydney, AU); Gavin Richard Turner (Holgate, AU); Michael Franz Baukes (Sunnyvale, CA)
Assignee: UPGUARD, INC.
G06F21/6218G06F16/22G06F16/24578G06F21/604H04L63/083H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,630,911
App. No.
17/231,819
Granted
Apr 18, 2023
Kind
B2
Abstract

A breach detection engine detects and mitigates the effects of breaches across one or more data sources. An index is generated based on one or more data sources and the index is queried using keywords indicative of potential breaches. A database of potential breaches is populated based on the query of the index. The potential breach database is queried using keywords associated with a system identity (e.g., a third party). A likelihood of a candidate breach is identified based on a set of breach criteria weights. A network node associated with a candidate breach determined to be an actual breach is identified for isolation or for the performance of one or more additional security actions.

Claims (52)

1. A method comprising:

querying, by the computer, one or more indexed data sources using keywords indicative of potential breaches to produce first query results;

querying, by the computer, a potential breach database comprising the first query results using keywords associated with a system identity to produce second query results;

identifying, by the computer, a candidate breach associated with the system identity based on the second query results;

computing, by the computer, a likelihood that the candidate breach associated with the system identity is an actual breach based on the second query results and a set of breach criteria weights; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for isolation.

2. The method of claim 1 , wherein each breach criteria weight is associated with a query result of the second query results and corresponds to a correlation between the query result and a breach.

3. The method of claim 1 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

computing, for each query result of the second query results, a breach score;

weighting, for each breach score, the breach score with an associated breach criteria weight to produce a weighted breach score; and

summing the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

4. The method of claim 1 , wherein the likelihood is further computed based on a presence of access credentials included within the second query results.

5. The method of claim 1 , wherein the likelihood is further computed based on a presence of one or more certificate authority keys within the second query results.

6. The method of claim 1 , wherein the likelihood is further computed based on a presence of source code within the second query results.

7. The method of claim 1 , further comprising:

automatically revoking, by the computer, a certificate associated with the candidate breach and initiating a process of resetting the certificate.

8. The method of claim 1 , further comprising:

automatically revoking, by the computer, a password associated with the candidate breach and initiating a process of resetting the password.

9. The method of claim 1 , further comprising:

automatically identifying, by the computer, a port associated with the candidate breach and blocking the port.

10. The method of claim 1 , further comprising:

automatically generating, by the computer, a message indicating the computed likelihood and recommending a corresponding corrective action to take and providing the generated message to a client device associated with the system identity.

11. The method of claim 1 , further comprising:

automatically computing, by the computer, a liability score associated with the system identity based on the computed likelihood and providing the liability score to a client device associated with the system identity.

12. A non-transitory computer-readable storage medium storing instructions for detecting security breaches, the instructions when executed by a processor cause the processor to perform steps including:

querying, by the computer, one or more indexed data sources using keywords indicative of potential breaches to produce first query results;

querying, by the computer, a potential breach database comprising the first query results using keywords associated with a system identity to produce second query results;

identifying, by the computer, a candidate breach associated with the system identity based on the second query results;

computing, by the computer, a likelihood that the candidate breach associated with the system identity is an actual breach based on the second query results and a set of breach criteria weights; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for isolation.

13. The non-transitory computer-readable storage medium of claim 12 , wherein each breach criteria weight is associated with a query result of the second query results and corresponds to a correlation between the query result and a breach.

14. The non-transitory computer-readable storage medium of claim 12 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

compute, for each query result of the second query results, a breach score;

weight, for each breach score, the breach score with an associated breach criteria weight to produce a weighted breach score; and

sum the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

15. The non-transitory computer-readable storage medium of claim 12 , wherein the likelihood is further computed based on one of: a presence of access credentials included within the second query results, a presence of one or more certificate authority keys within the second query, or a presence of source code within the second query results.

16. The non-transitory computer-readable storage medium of claim 12 , wherein the instructions when executed further cause the processor to perform steps including:

automatically revoking, by the computer, a certificate associated with the candidate breach and initiating a process of resetting the certificate.

17. A computing system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions for detecting security breaches, the instructions when executed by the processor cause the processor to perform steps including:

querying, by the computer, one or more indexed data sources using keywords indicative of potential breaches to produce first query results;

querying, by the computer, a potential breach database comprising the first query results using keywords associated with a system identity to produce second query results;

identifying, by the computer, a candidate breach associated with the system identity based on the second query results;

computing, by the computer, a likelihood that the candidate breach associated with the system identity is an actual breach based on the second query results and a set of breach criteria weights; and

in response to the computed likelihood exceeding a breach threshold, identifying, by the computer, a network node associated with the candidate breach for isolation.

18. The computing system of claim 17 , wherein each breach criteria weight is associated with a query result of the second query results and corresponds to a correlation between the query result and a breach.

19. The computing system of claim 17 , wherein computing a likelihood that the candidate breach is an actual breach comprises:

compute, for each query result of the second query results, a breach score;

weight, for each breach score, the breach score with an associated breach criteria weight to produce a weighted breach score; and

sum the weighted breach scores to produce the computed likelihood that the candidate breach is an actual breach.

20. The computing system of claim 17 , wherein the likelihood is further computed based on one of: a presence of access credentials included within the second query results, a presence of one or more certificate authority keys within the second query, or a presence of source code within the second query results.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2021
From: SHARP-PAUL, ALAN JAMES; VICKERY, CHRISTOPHER ROBERT; HENDREN, JONATHAN DAVID; POLLOCK, GREGORY FORD; BRADBURY, DANIEL; KIELY, CHRISTIAN ALAN; TURNER, GAVIN RICHARD; BAUKES, MICHAEL FRANZ
To: UPGUARD, INC.
Reel/Frame 056045/0633 →
Continuity (2)
Continuation 16254605 · Jan 23, 2019
Related Publication 20210232699A1 · Jul 29, 2021
Cited By (1)
US 12,518,042