IP Library Granted Patent US 12,028,366
Granted Patent B2
US 12,028,366 · App. 17/199,069 · Granted Jul 2, 2024

Dynamically generating multi-factor entity risk assessments within virtualized environments

Inventors: Niv Rabin (Petach-Tikva, IL); Michael Balber (Beerot Itshak, IL); Noa Moyal (Hod Hasharon, IL); Asaf Hecht (Tel Aviv, IL); Gal Naor (Kefar Sava, IL)
Assignee: CyberArk Software Ltd.
H04L63/1433H04L63/105H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,366
App. No.
17/199,069
Granted
Jul 2, 2024
Kind
B2
Abstract

Disclosed embodiments relate to systems and methods for dynamically performing entity-specific security assessments for entities of virtualized network environments. Techniques include identifying an entity associated with a virtualized network environment, identifying a plurality of security factors, determining entity-specific weights to the plurality of security factors, and generating a composite exposure assessment for the entity. Further techniques include selecting at least two security factors of the plurality of security factors, identifying the weights corresponding to the selected security factors, and calculating the composite exposure assessment using the selected security factors and corresponding weights, analyzing the composite exposure assessment, and generating at least one of: a security recommendation based on the analysis to alter a scope of privileges of the entity, a notification providing an indication of the composite exposure assessment, or a visual representation of the composite exposure assessment of the entity.

Claims (55)

1. A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for dynamically performing entity-specific security assessments for entities of virtualized network environments, the operations comprising:

identifying an entity associated with a plurality of permissions in a virtualized network environment;

determining scores of a plurality of security factors;

determining entity-specific weights to the plurality of security factors;

generating a composite exposure assessment for the entity across the plurality of permissions, the generating comprising:

selecting at least two security factors of the plurality of security factors;

identifying the weights corresponding to the selected security factors; and

calculating the composite exposure assessment using the selected security factors and corresponding weights;

determining a score of a special security factor associated with the entity;

modifying the calculated composite exposure assessment based on the determined score of the special security factor;

analyzing the modified composite exposure assessment; and

generating at least one of:

a security recommendation based on the analysis to alter a scope of privileges of the entity;

a notification providing an indication of one or more unused permissions of the plurality of permissions; or

a visual representation of the modified composite exposure assessment of the entity.

2. The non-transitory computer readable medium of claim 1 , wherein the plurality of security factors include at least one of:

a permission type of each of the plurality of permissions; or

a usage status of a permission of each of the plurality of permissions.

3. The non-transitory computer readable medium of claim 1 , wherein the calculated composite exposure assessment is further modified based on a customer influence score.

4. The non-transitory computer readable medium of claim 1 , wherein the visual representation comprises a representation of one or more of the plurality of security factors associated with the modified composite exposure assessment.

5. The non-transitory computer readable medium of claim 4 , wherein the visual representation indicates an effect of the one or more of the plurality of security factors on the calculation of the modified composite exposure assessment.

6. The non-transitory computer readable medium of claim 4 , wherein the visual representation indicates a composite exposure assessment score threshold.

7. The non-transitory computer readable medium of claim 1 , wherein selecting the at least two security factors of the plurality of security factors is performed using a machine learning algorithm.

8. The non-transitory computer readable medium of claim 1 , wherein selecting the at least two security factors of the plurality of security factors is based on an entity classification.

9. The non-transitory computer readable medium of claim 8 , wherein the entity classification is generated using a machine learning algorithm.

10. The non-transitory computer readable medium of claim 8 , wherein the entity classification is manually generated.

11. A computer-implemented method for dynamically performing entity-specific security assessments for entities of virtualized network environments, the method comprising:

identifying an entity associated with a plurality of permissions in a virtualized network environment;

determining scores of a plurality of security factors;

determining entity-specific weights to the plurality of security factors;

generating a composite exposure assessment for the entity across the plurality of permissions, the generating comprising:

selecting at least two security factors of the plurality of security factors;

identifying the weights corresponding to the selected security factors; and

calculating the composite exposure assessment using the selected security factors and corresponding weights;

determining a score of a special security factor associated with the entity;

modifying the calculated composite exposure assessment based on the determined score of the special security factor;

analyzing the modified composite exposure assessment; and

generating at least one of:

a security recommendation to revoke one or more unused permissions of the plurality of permissions;

a notification providing an indication of the composite exposure assessment; or

a visual representation of the composite exposure assessment.

12. The computer-implemented method of claim 11 , wherein the security recommendation is based on one or more of the selected security factors.

13. The computer-implemented method of claim 11 , further comprising: receiving an indication of acceptance of the security recommendation.

14. The computer-implemented method of claim 13 , further comprising: updating, based on the acceptance of the security recommendation, the modified composite exposure assessment.

15. The computer-implemented method of claim 11 , wherein analyzing the composite exposure assessment comprises comparing the modified composite exposure assessment with a reference score.

16. The computer-implemented method of claim 11 , wherein: analyzing the modified composite exposure assessment comprises determining that the modified composite exposure assessment does not exceed a score threshold; and the security recommendation comprises a recommendation to maintain a scope of privileges of the entity.

17. The computer-implemented method of claim 11 , wherein: analyzing the modified composite exposure assessment comprises determining that the modified composite exposure assessment exceeds a score threshold; and the security recommendation comprises a recommendation to reduce a scope of privileges of the entity.

18. The computer-implemented method of claim 17 , further comprising:

receiving an indication of acceptance of the security recommendation;

updating, based on the acceptance of the security recommendation, the modified composite exposure assessment;

analyzing the updated composite exposure assessment; and

determining that the updated composite exposure assessment does not exceed a score threshold.

19. The computer-implemented method of claim 11 , wherein the security recommendation comprises a recommendation to audit privilege usage of the entity.

20. The computer-implemented method of claim 11 , further comprising: generating, based on the security recommendation, a second modified composite exposure assessment for the entity, the second modified composite exposure assessment indicating the change in the first composite exposure assessment when the security recommendation is accepted.

21. The computer-implemented method of claim 11 , further comprising: aggregating scores for multiple entities to generate a composite exposure assessment for the virtualized network environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2022
From: RABIN, NIV; BALBER, MICHAEL; MOYAL, NOA; HECHT, ASAF; NAOR, GAL
To: CYBERARK SOFTWARE LTD.
Reel/Frame 059755/0259 →
Continuity (2)
Continuation In Part 16719464 · Dec 18, 2019
Related Publication 20210203687A1 · Jul 1, 2021