IP Library Granted Patent US 11,790,091
Granted Patent B2
US 11,790,091 · App. 18/074,070 · Granted Oct 17, 2023

Monitoring information-security coverage to identify an exploitable weakness in the information-securing coverage

Inventors: Stuart Sloan (Huntersville, NC); Aleksey Vladimirovich Rogozhin (Cary, NC); Glenn Bernstein (Durham, NC); Jesse Daniel Bikman (Durham, NC)
Assignee: Truist Bank
G06F21/577G06F16/285G06F21/604G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,790,091
App. No.
18/074,070
Granted
Oct 17, 2023
Kind
B2
Abstract

Systems and methods are provided for monitoring information-security coverage to identify a vulnerability or risk in the information-security coverage. An information-security system can include computing systems, databases, a security server, etc. that can communicate data via a network. The server can be used to obtain data indicating a process for managing or monitoring information-security in the system and data indicating activity on the network, computing systems, server, or databases. The server then determines a metric based on the obtained data and the metric can indicate a risk or vulnerability in information-security coverage in the system. The server can then aggregate the data and transmit the aggregated data to a computing device. The computing device can generate an interface for outputting data for monitoring information-security coverage or identifying a vulnerability or risk in information-security coverage, which can improve the security of the information-security system.

Claims (69)

1. A method comprising:

receiving, by a processing device, information-security data that indicates information-security activity detected in a computing environment by one or more information-security measurement modules;

determining, by the processing device, a plurality of information-security metrics based on the information-security data; and

generating, by the processing device, an interactive user interface for display that includes the plurality of information-security metrics categorized into one or more groups, the interactive user interface being usable by a user for improving a security level of the computing environment.

2. The method of claim 1 , further comprising aggregating the plurality of information-security metrics to form the one or more groups by:

comparing, by the processing device, a first information-security metric and a second information-security metric to determine a similarity between the first information-security metric and the second information-security metric, the similarity indicating that the first information-security metric and the second information-security metric are associated with a particular control of a plurality of controls; and

grouping, by the processing device, the first information-security metric and the second information-security metric to form an information-security metric group based on the similarity.

3. The method of claim 2 , further comprising:

displaying, by the processing device, a user interface that includes the particular control associated with the first information-security metric and the second information-security metric, wherein the user interface further includes a user selectable portion associated with the particular control;

receiving, by the processing device, a selection of the user selectable portion; and

displaying, by the processing device, the first information-security metric or the second information-security metric in response to receiving the selection of the user selectable portion.

4. The method of claim 1 , wherein the information-security data comprises data indicating whether a computing device, a network, a server, or a database contains computational logic with an associated vulnerability.

5. The method of claim 1 , wherein determining the plurality of information-security metrics comprises:

determining, by the processing device, a number of computing devices in the computing environment that are associated with a vulnerability;

determining, by the processing device, a tolerable number of computing devices in the computing environment that can be associated with vulnerabilities; and

determining, by the processing device, an information-security metric by comparing the number of computing devices associated with the vulnerability to the tolerable number of computing devices that can be associated with vulnerabilities.

6. The method of claim 1 , further comprising:

determining, by the processing device, a maturity level of an information-security metric of the plurality of information-security metrics by:

determining a quality of the information-security data; and

determining the maturity level of the information-security metric based on the quality of the information-security data, wherein the maturity level of the information-security metric indicates a reliability of the information-security metric for monitoring the security level of the computing environment or identifying an exploitable weakness of the computing environment.

7. The method of claim 6 , further comprising:

determining, by the processing device, the maturity level of the information-security metric based on an availability of data for determining the information-security metric or a process for delivering the data for determining the information-security metric.

8. The method of claim 1 , further comprising:

determining, by the processing device, an importance of an information-security metric among the plurality of information-security metrics by:

obtaining data indicating a weight value associated with the information-security metric; and

determining the importance of the information-security metric based on the weight value.

9. The method of claim 1 , further comprising:

receiving, by the processing device, the information-security data from a computing device; and

determining, by the processing device, a maturity level of the computing device for providing the information-security data by:

determining a quality of the computing device for providing the information-security data; and

determining the maturity level of the of the computing device based on the quality of the computing device for providing the information-security data, wherein the maturity level of the computing device indicates a reliability of the computing device for use in detecting information-security data usable to monitor the security level of the computing environment or identify an exploitable weakness in the computing environment.

10. The method of claim 1 , further comprising:

aggregating, by the processing device, the information-security data over a period of time; and

generating, by the processing device, an interface for display that includes the aggregated information-security data for monitoring the security level of the computing environment or identifying an exploitable weakness in the computing environment.

11. A system comprising:

a processing device; and

a non-transitory computer-readable medium communicatively coupled to the processing device, wherein the processing device is configured to perform operations comprising:

receiving information-security data that indicates information-security activity detected in a computing environment by one or more information-security measurement modules;

determining a plurality of information-security metrics based on the information-security data; and

generating an interactive user interface for display that includes the plurality of information-security metrics categorized into one or more groups, the interactive user interface being usable by a user for improving a security level of the computing environment.

12. The system of claim 11 , wherein the processing device is further configured to aggregate the plurality of information-security metrics to form the one or more groups by:

comparing a first information-security metric and a second information-security metric to determine a similarity between the first information-security metric and the second information-security metric, the similarity indicating that the first information-security metric and the second information-security metric are associated with a particular control of a plurality of controls; and

grouping the first information-security metric and the second information-security metric to form an information-security metric group based on the similarity.

13. The system of claim 12 , wherein the processing device is further configured to:

display a user interface that includes the particular control associated with the first information-security metric and the second information-security metric, wherein the user interface further includes a user selectable portion associated with the particular control;

receive a selection of the user selectable portion; and

display the first information-security metric or the second information-security metric in response to receiving the selection of the user selectable portion.

14. The system of claim 11 , wherein the information-security data comprises data indicating whether a computing device, a network, a server, or a database contains computational logic with an associated vulnerability.

15. The system of claim 11 , wherein the processing device is further configured to determine the plurality of information-security metrics by:

determining a number of computing devices in the computing environment that are associated with a vulnerability;

determining a tolerable number of computing devices in the computing environment that can be associated with vulnerabilities; and

determining an information-security metric by comparing the number of computing devices associated with the vulnerability to the tolerable number of computing devices that can be associated with vulnerabilities.

16. The system of claim 11 , wherein the processing device is further configured to determine a maturity level of an information-security metric of the plurality of information-security metrics by:

determining a quality of the information-security data; and

determining the maturity level of the information-security metric based on the quality of the information-security data, wherein the maturity level of the information-security metric indicates a reliability of the information-security metric for monitoring the security level of the computing environment or identifying an exploitable weakness of the computing environment.

17. The system of claim 16 , wherein the processing device is further configured to:

determine the maturity level of the information-security metric based on an availability of data for determining the information-security metric or a process for delivering the data for determining the information-security metric.

18. The system of claim 11 , wherein the processing device is further configured to determine an importance of an information-security metric among the plurality of information-security metrics by:

obtaining data indicating a weight value associated with the information-security metric; and

determining the importance of the information-security metric based on the weight value.

19. The system of claim 11 , wherein the processing device is further configured to:

receive the information-security data from a computing device; and

determine a maturity level of the computing device for providing the information-security data by:

determining a quality of the computing device for providing the information-security data; and

determining the maturity level of the of the computing device based on the quality of the computing device for providing the information-security data, wherein the maturity level of the computing device indicates a reliability of the computing device for use in detecting information-security data usable to monitor the security level of the computing environment or identify an exploitable weakness in the computing environment.

20. A non-transitory computer-readable medium comprising program code that is executable by a processing device for causing the processing device to perform operations including:

receiving information-security data that indicates information-security activity detected in a computing environment by one or more information-security measurement modules;

determining a plurality of information-security metrics based on the information-security data; and

generating an interactive user interface for display that includes the plurality of information-security metrics categorized into one or more groups, the interactive user interface being usable by a user for improving a security level of the computing environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2023
From: SLOAN, STUART; ROGOZHIN, ALEKSEY VLADIMIROVICH; BERNSTEIN, GLENN; BIKMAN, JESSE DANIEL
To: BRANCH BANKING AND TRUST COMPANY
Reel/Frame 064797/0275 →
MERGER AND CHANGE OF NAME Recorded Sep 5, 2023
From: BRANCH BANKING AND TRUST COMPANY; TRUIST BANK
To: TRUIST BANK
Reel/Frame 064798/0231 →
Continuity (4)
Continuation 17145713 · Jan 11, 2021
Continuation 16047151 · Jul 27, 2018
Provisional Application 62537515 · Jul 27, 2017
Related Publication 20230101394A1 · Mar 30, 2023