IP Library Granted Patent US 11,777,976
Granted Patent B2
US 11,777,976 · App. 17/069,151 · Granted Oct 3, 2023

Information technology security assessment system

Inventors: Stephen Wayne Boyer (Waltham, MA); Nagarjuna Venna (Waltham, MA); Megumi Ando (Cambridge, MA)
Assignee: BitSight Technologies, Inc.
H04L63/1433G06Q10/0639H04L43/062H04L43/0876H04L61/5007H04L67/53H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,976
App. No.
17/069,151
Granted
Oct 3, 2023
Kind
B2
Abstract

A method and system for creating a composite security rating from security characterization data of a third party computer system. The security characterization data is derived from externally observable characteristics of the third party computer system. Advantageously, the composite security score has a relatively high likelihood of corresponding to an internal audit score despite use of externally observable security characteristics. Also, the method and system may include use of multiple security characterizations all solely derived from externally observable characteristics of the third party computer system.

Claims (73)

1. A method for determining a security rating of an entity, the method comprising:

determining an internal security rating comprising:

obtaining data indicative of internal security from a plurality of internal data sources;

extracting a plurality of internal security features from the obtained data;

applying a respective transformation function to each of the plurality of internal security features to determine a first plurality of transformed features; and

combining the first plurality of transformed features to form the internal security rating;

determining an external security rating comprising:

obtaining data indicative of external security from a plurality of external data sources;

extracting a plurality of external security features from the obtained data;

applying a respective transformation function to each of the plurality of external security features to determine a second plurality of transformed features; and

combining the second plurality of transformed features to form the external security rating; and

providing, via a reporting facility, a composite security rating for the entity based on the internal security rating and the external security rating, wherein at least one of the internal security features or the external security features indicates malicious activity associated with an IP address of the entity.

2. The method of claim 1 , further comprising:

determining the composite security rating based on a weighted combination of the internal security rating and the external security rating.

3. The method of claim 1 , wherein the plurality of internal data sources comprises:

vulnerability scan data of the entity;

data indicating firewall rules of the entity;

data from security incident reports corresponding to the entity;

data indicative of computer network configurations of the entity;

data indicative of software inventory of the entity;

data indicative of security policies of the entity;

data indicative of security controls of the entity; and

data indicative of user behavior corresponding to the entity.

4. The method of claim 1 , wherein at least one of the internal security features or the external security features comprise at least one of:

a number of remotely exploitable vulnerabilities of the entity;

a number of security incidents; or

a number of vulnerable versions of software of the entity.

5. The method of claim 1 , wherein each respective transformation function is a normalization of the respective feature, and further comprising:

when the normalization is applied to two or more of the internal security features or the external security features, summing the normalized features.

6. The method of claim 1 , wherein determining the internal security rating further comprises weighting the first plurality of transformed features.

7. The method of claim 1 , wherein combining the first plurality of transformed features comprises:

summing the first plurality of transformed features; and

normalizing the summed features by a set of normalization factors.

8. The method of claim 1 , wherein combining the second plurality of transformed features comprises:

summing the second plurality of transformed features; and

normalizing the summed features by a set of normalization factors.

9. A system for determining a security rating of an entity, the system comprising:

one or more computer systems programmed to perform operations comprising:

determining an internal security rating comprising:

obtaining data indicative of internal security from a plurality of internal data sources;

extracting a plurality of internal security features from the obtained data;

applying a transformation function to each of the plurality of internal security features; and

combining the transformed features to form the internal security rating;

determining an external security rating comprising:

obtaining data indicative of external security from a plurality of external data sources;

extracting a plurality of external security features from the obtained data;

applying a transformation function to each of the plurality of external security features; and

combining the transformed features to form the external security rating; and

providing, via a reporting facility, a composite security rating for the entity based on the internal security rating and the external security rating, wherein at least one of the internal security features or the external security features indicates malicious activity associated with an IP address of the entity.

10. The system of claim 9 , wherein the one or more computer systems are further programmed to perform operations comprising:

determining the composite security rating based on a weighted combination of the internal security rating and the external security rating.

11. The system of claim 9 , wherein the plurality of internal data sources comprises:

vulnerability scan data of the entity;

data indicating firewall rules of the entity;

data from security incident reports corresponding to the entity;

data indicative of computer network configurations of the entity;

data indicative of software inventory of the entity;

data indicative of security policies of the entity;

data indicative of security controls of the entity; and

data indicative of user behavior corresponding to the entity.

12. The system of claim 9 , wherein the internal security features and the external security features comprise at least one of:

a number of remotely exploitable vulnerabilities of the entity;

a number of security incidents; or

a number of vulnerable versions of software of the entity.

13. The system of claim 9 , wherein each respective transformation function is a normalization of the respective feature, and wherein the one or more computer systems are further programmed to perform operations comprising:

when the normalization is applied to two or more of the internal security features or the external security features, summing the normalized features.

14. The system of claim 9 , wherein determining the internal security rating further comprises weighting the first plurality of transformed features.

15. The system of claim 1 , wherein combining the first plurality of transformed features further comprises:

summing the first plurality of transformed features; and

normalizing the summed features by a set of normalization factors.

16. The system of claim 9 , wherein combining the second plurality of transformed features further comprises:

summing the second plurality of transformed features; and

normalizing the summed features by a set of normalization factors.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2021
From: BOYER, STEPHEN; VENNA, NAGARJUNA; ANDO, MEGUMI
To: BITSIGHT TECHNOLOGIES, INC.
Reel/Frame 057409/0250 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 054481/0727 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 054481/0739 →
Continuity (4)
Continuation 13240572 · Sep 22, 2011
Provisional Application 61492287 · Jun 1, 2011
Provisional Application 61386156 · Sep 24, 2010
Related Publication 20210211454A1 · Jul 8, 2021
Cited By (7)
US 12,282,564 US 12,335,297 US 12,348,485 US 12,353,563 US 12,425,437 US 12,526,295 US 12,587,555