IP Library Granted Patent US 12,452,289
Granted Patent B2
US 12,452,289 · App. 18/734,707 · Granted Oct 21, 2025

System and method for mitigating cyber security threats by devices using risk factors

Inventors: Nadir Izrael (Mountain View, CA); Shiri Ladelsky Lellouch (Menlo Park, CA); Misha Seltzer (Toronto, CA)
Assignee: Armis Security Ltd.
H04L63/1433G06F21/552G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,289
App. No.
18/734,707
Filed
Jun 5, 2024
Granted
Oct 21, 2025
Kind
B2
Art Unit
2436
USPC
726/25
Abstract

A system and method for mitigating cyber security threats by devices using risk factors. The method includes determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device; determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and performing at least one mitigation action based on the risk score.

Claims (37)

1. A method for mitigating cyber security threats by devices using risk factors, comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device, and wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device;

determining a risk score for the device based on the plurality of risk factors; and

performing at least one mitigation action based on the risk score.

2. The method of claim 1 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

3. The method of claim 1 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, further comprising:

updating the risk score based on the monitored network activity; and

performing at least one subsequent mitigation action based on the updated risk score.

4. The method of claim 1 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on a quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

5. The method of claim 1 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

6. The method of claim 1 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

7. The method of claim 1 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

8. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device, and wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device;

determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and

performing at least one mitigation action based on the risk score.

9. The non-transitory computer readable medium of claim 8 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

10. The non-transitory computer readable medium of claim 8 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, further comprising:

updating the risk score based on the monitored network activity; and

performing at least one subsequent mitigation action based on the updated risk score.

11. The non-transitory computer readable medium of claim 8 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on a quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

12. The non-transitory computer readable medium of claim 8 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

13. The non-transitory computer readable medium of claim 8 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

14. The non-transitory computer readable medium of claim 8 , wherein the plurality of risk factors is determined based further on a plurality of known device behaviors, wherein each of the plurality of known device behaviors is associated with a plurality of known risk factors, wherein each of the plurality of known risk factors is associated with at least one risk behavior.

15. A system for mitigating cyber security threats by devices using risk factors, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

determine a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are determined based on data related to at least one of: configuration of the device, network activity by the device, geographic movement of the device, signal strength of the device, and a protocol used by the device, and wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device;

determine a risk score for the device based on the plurality of risk factors; and

perform at least one mitigation action based on the risk score.

16. The system of claim 15 , wherein the plurality of risk factors is determined for the device when at least one of: the device connects to a network, the device is turned on in physical proximity to a network, and the device becomes physically proximate to network infrastructure.

17. The system of claim 15 , wherein the at least one mitigation action includes monitoring network activity by the device when the risk score is below a threshold, wherein the system is further configured to:

update the risk score based on the monitored network activity; and

perform at least one subsequent mitigation action based on the updated risk score.

18. The system of claim 15 , wherein the plurality of risk factors includes a manufacturer reputation risk factor, wherein the manufacturer reputation risk factor is determined based on a quotient of a number of common vulnerabilities and exposures attributed to a manufacturer of the device over a number of employees of the manufacturer of the device.

19. The system of claim 15 , wherein the plurality of risk factors includes a data entropy risk factor, wherein the data entropy risk factor is determined based on entropy of at least one of: data received by the device, and data sent by the device.

20. The system of claim 15 , wherein the plurality of risk factors includes at least one of: an attack surface exposure risk factor, a cloud synchronization risk factor, a connection security risk factor, a boundary evasion risk factor, a third party application stores risk factor, a malicious domains risk factor, a vulnerability history risk factor, a data-at-rest risk factor, an external connectivity risk factor, a user authentication risk factor, a software version risk factor, a certificate reuse risk factor, a manufacturer reputation risk factor, and a device model reputation risk factor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2024
From: IZRAEL, NADIR; LADELSKY LELLOUCH, SHIRI; SELTZER, MISHA
To: ARMIS SECURITY LTD.
Reel/Frame 067632/0187 →
Continuity (3)
Continuation 17662529 · May 9, 2022
Continuation 16371794 · Apr 1, 2019
Related Publication 20240414187A1 · Dec 12, 2024
References Cited (34)
US 9600320B2 · Hamilton et al. · 2017 [cited by applicant]
US 9894093B2 · Maestas · 2018 [cited by applicant]
US 10095866B2 · Gong et al. · 2018 [cited by applicant]
US 10333965B2 · Gathala et al. · 2019 [cited by applicant]
US 10699018B2 · Hamby · 2020 [cited by applicant]
US 10708291B2 · Findlay · 2020 [cited by applicant]
US 10735456B2 · Crabtree et al. · 2020 [cited by applicant]
US 11363051B2 · Izrael et al. · 2022 [cited by applicant]
US 20130246088A1 · Huster · 2013 [cited by examiner]
US 20150067865A1 · DeLuca et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20160173521A1 · Yampolskiy et al. · 2016 [cited by applicant]
US 20160226911A1 · Boss et al. · 2016 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170223037A1 · Singh · 2017 [cited by examiner]
US 20170264644A1 · Mihan et al. · 2017 [cited by applicant]
US 20180124091A1 · Sweeney · 2018 [cited by examiner]
US 20180144139A1 · Cheng et al. · 2018 [cited by applicant]
US 20180247312A1 · Loganathan et al. · 2018 [cited by applicant]
US 20220263853A1 · Izrael et al. · 2022 [cited by applicant]
CN 114270347A · 2022 [cited by applicant]
EP 3111614B1 · 2018 [cited by applicant]
EP 3948600A1 · 2022 [cited by applicant]
WO WO2014128253A1 · 2014 [cited by applicant]
WO 2020205258A1 · 2020 [cited by applicant]
WO WO202005258A1 · 2020 [cited by applicant]
Mohamed Abomhara; Cyber Security and the Internet of Things:Vulnerabilities, Threats, Intruders and Attacks; University of Agder, Norway; year:2015; pp. 1-24. [cited by examiner]
Lamba, et al., “Mitigating Cyber Security Threats of Industrial Control Systems (Scada & DCS),” International Journal for Technological Research in Engineering, 2017, pp. 31-34. [cited by applicant]
Saleem, Jibran; A state of the art survey—Impact of cyber aacks on SME's; ACM:2017; pp. 1-7. [cited by applicant]
Canadian Office Action from Canadian Patent Application No. 3,135,483, dated Apr. 3, 2023, 5 pages. [cited by applicant]
Office Action, Canadian Intellectual Property Office, CA Application No. 3,135,483, dated Jan. 22, 2024. [cited by applicant]
European Search Report, European Patent Office, Munich, Germany, Dated Nov. 7, 2022. [cited by applicant]
EP Communication under Rule 71(3) EPC, European Patent Office, EP Application No. 20784480.4, dated Jan. 1, 2024. [cited by applicant]
International Search Report and Written Opinion for PCT/US2020/023557; ISA/RU; Moscow, Russia; Dated: Jun. 4, 2020. [cited by applicant]
Cited By (1)
US 12,695,752