IP Library › Granted Patent US 12,737,709
Granted Patent B2
US 12,737,709 · App. 18/613,219 · Granted Sep 15, 2026

Systems and methods for monitoring information security effectiveness

Inventors: Kelly Thomas White (Park City, UT); Michael Vance Fowkes (Salt Lake City, UT); Jesse Duane Card (American Fork, UT); Andrew James Menzel (Tallahassee, FL)
Assignee: RiskRecon Inc.
G06Q10/0635G06F21/552G06F21/6245G06N20/00H04L63/1433H04L63/205G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,709
App. No.
18/613,219
Granted
Sep 15, 2026
Kind
B2
Abstract

Systems and methods for automatically assessing and monitoring information security effectiveness using collected indicia of sensitive content and indicia of security measure information for a plurality of networked organizational assets/systems to provide respective asset/system value at risk ratings. Elements of the system include automated asset discovery, automated hosting provider and location discovery, collection of information harvested from public sources and, optionally non-public sources, analysis of the collected information against public, non-public, and proprietary sources, and/or mathematical models used to infer broader security program conclusions and to rank asset/system values at risk. Estimates of values at risk are used to prioritize allocation of security measures.

Claims (106)

1 . A method for automatically estimating respective values at risk for network computer systems/assets, the method comprising:

receiving, by an electronic processor, a network identifier associated with a network-accessible computer system/asset of an organization;

predicting, by the electronic processor, whether a domain is owned by the organization, the prediction returning a numeric ownership guess score, by:

generating a domain record comprising a data record of domain attributes that is a representation of a public domain registration record for the domain;

comparing attributes of the domain record with attributes of domain records for which ownership was already decided, including domain records previously flagged as related to the organization and domain records previously flagged as not related to the organization;

increasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more of the domain records previously flagged as related to the organization; and

decreasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more of the domain records previously flagged as not related to the organization;

accessing, via a network, the network-accessible computer system/asset and a plurality of related network-accessible computer systems/assets, by:

sending, via a network interface to the network, at least one message to each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets to establish communication,

wherein the at least one message includes one or more inquiries to determine a communication protocol used by each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets,

receiving, from each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, one or more responses to the one or more inquiries, the one or more responses providing information usable to select communication methods,

transmitting, via the network interface to the network, one or more protocol-specific requests to each of the network-accessible computer systems/asset and the plurality of related network-accessible computer systems/assets, based on the information usable to select communication methods, and

automatically receiving one or more responses comprising one or more of the following: HTTP headers, HTML, JavaScript, cookies, DNS records, and encryption certificates and configurations;

determining indicia of content features/characteristics for each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, by analyzing each of the one or more responses using one or more of the following: machine learning models, regular expressions, text string matching, natural-language understanding, image processing, and text analysis;

determining indicia of security features/characteristics of each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, including detecting one or more of the following: encryption, login field, captcha, security feature code, security-related keywords, security feature configurations, password field, security question, user authentication, secure cookies, two-factor authentication, RSA fraud protection, software bot detection, and secure connection protocols;

determining network proximity between respective ones of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets; and

inferring a value at risk for each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets based on, for a respective network-accessible computer system/asset, the indicia of content features/characteristics and the indicia of security features/characteristics, and based on network proximity to other network-accessible computer systems/assets with at least one of similar indicia of content features/characteristics, similar indicia of security features/characteristics, and similar values at risk.

2 . The method of claim 1 , further comprising ranking the network-accessible computer system/asset for allocation of security of measures relative to the plurality of related network-accessible computer systems/assets based on respective values at risk.

3 . The method of claim 1 , wherein the indicia of content features/characteristics include one or more of the following:

presence of predetermined text,

content subject matter,

purpose of content accessible via the network-accessible computer system/asset,

purpose of content requested via the network-accessible computer system/asset,

functionality of content,

presence of sensitive data,

collection of the sensitive data, and

presence of user-identifiable account data.

4 . The method of claim 3 , wherein at least one of the content subject matter and the purpose of the content includes one or more of the following:

publicly available information,

account data,

financial account data,

personally-identifiable data,

personal health record data,

internal corporate data,

privacy regulated data,

sensitive organizational data, and

sensitive user data.

5 . The method of claim 1 , wherein the value at risk represents both a measure of value and risk for any data or functionality, which if accessed by an unauthorized agent, including a person, computer program, or mechanical bot, if used in an unauthorized manner, or if availability or performance characteristics of functionality is degraded, the organization would be exposed to violation of regulations, financial liability, operational disruption of related processes resulting from unavailability or degraded performance of the functionality, harm of reputation, legal liability, or to violation of customer agreements.

6 . A non-transitory computer-readable medium having computer-executable instructions stored thereon, the computer-executable instructions, when executed by a processor, causing the processor to:

receive a network identifier associated with a network-accessible computer system/asset of an organization;

predict whether a domain is owned by the organization, the prediction returning a numeric ownership guess score, by:

generating a domain record comprising a data record of domain attributes that is a representation of a public domain registration record for the domain,

comparing attributes of the domain record with attributes of domain records for which ownership was already decided, including domain records previously flagged as related to the organization and domain records previously flagged as not related to the organization,

increasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more domain records previously flagged as related to the organization, and

decreasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more domain records previously flagged as not related to the organization;

access, via a network, the network-accessible computer system/asset and a plurality of related network-accessible computer systems/assets, by

sending, via a network interface to the network, at least one message to each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets to establish communication,

wherein the at least one message includes one or more inquiries to determine a communication protocol used by each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets,

receiving, from each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, one or more responses to the one or more inquiries, the one or more responses providing information usable to select communication methods,

transmitting, via the network interface to the network, one or more protocol-specific requests to each of the network-accessible computer systems/asset and the plurality of related network-accessible computer systems/assets, based on the information usable to select communication methods, and

automatically receiving one or more responses comprising one or more of the following: HTTP headers, HTML, JavaScript, cookies, DNS records, and encryption certificates and configurations;

determine indicia of content features/characteristics for each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, by analyzing each of the one or more responses using one or more of the following: machine learning models, regular expressions, text string matching, natural-language understanding, image processing, and text analysis;

determine indicia of security features/characteristics of each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, including detecting one or more of the following: encryption, login field, captcha, security feature code, security-related keywords, security feature configurations, password field, security question, user authentication, secure cookies, two-factor authentication, RSA fraud protection, software bot detection, and secure connection protocols;

determine network proximity between respective ones of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets; and

infer a value at risk for each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets based on, for a respective network-accessible computer system/asset, the indicia of content features/characteristics and the indicia of security features/characteristics, and based on network proximity to other network-accessible computer systems/assets with at least one of similar indicia of content features/characteristics, similar indicia of security features/characteristics, and similar values at risk.

7 . The non-transitory computer-readable medium of claim 6 , the computer-executable instructions further causing the processor to rank the network-accessible computer system/asset for allocation of security of measures relative to the plurality of related network-accessible computer systems/assets based on respective values at risk.

8 . The non-transitory computer-readable medium of claim 6 , wherein the indicia of content features/characteristics include one or more of the following:

presence of predetermined text,

content subject matter,

purpose of content accessible via the network-accessible computer system/asset,

purpose of content requested via the network-accessible computer system/asset,

functionality of content,

presence of sensitive data,

collection of the sensitive data, and

presence of user-identifiable account data.

9 . The non-transitory computer-readable medium of claim 8 , wherein at least one of the content subject matter and the purpose of the content includes one or more of the following:

publicly available information,

account data,

financial account data,

personally-identifiable data,

personal health record data,

internal corporate data,

privacy regulated data,

sensitive organizational data, and

sensitive user data.

10 . The non-transitory computer-readable medium of claim 6 , wherein the value at risk represents both a measure of value and risk for any data or functionality, which if accessed by an unauthorized agent, including a person, computer program, or mechanical bot, if used in an unauthorized manner, or if availability or performance characteristics of functionality is degraded, the organization would be exposed to violation of regulations, financial liability, operational disruption of related processes resulting from unavailability or degraded performance of the functionality, harm of reputation, legal liability, or to violation of customer agreements.

11 . A system comprising:

a processor; and

a memory device having computer-executable instructions stored thereon, the computer-executable instructions, when executed by the processor, cause the processor to:

receive a network identifier associated with a network-accessible computer system/asset of an organization;

predict whether a domain is owned by the organization, the prediction returning a numeric ownership guess score, by:

generating a domain record comprising a data record of domain attributes that is a representation of a public domain registration record for the domain,

comparing attributes of the domain record with attributes of domain records for which ownership was already decided, including domain records previously flagged as related to the organization and domain records previously flagged as not related to the organization,

increasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more domain records previously flagged as related to the organization, and

decreasing the numeric ownership guess score when one or more of the compared attributes of the domain record have values that match corresponding attributes of one or more domain records previously flagged as not related to the organization,

access, via a network, the network-accessible computer system/asset and a plurality of related network-accessible computer systems/assets, by:

sending, via a network interface to the network, at least one message to each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets to establish communication,

wherein the at least one message includes one or more inquiries to determine a communication protocol used by each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets,

receiving, from each of the network-accessible computer system/asset and the plurality of related network-accessible computer systems/assets, one or more responses to the one or more inquiries, the one or more responses providing information usable to select communication methods,

transmitting, via the network interface to the network, one or more protocol-specific requests to each of the network-accessible computer systems/asset and the plurality of related network-accessible computer systems/assets, based on the information usable to select communication methods, and

automatically receiving one or more responses comprising one or more of the following: HTTP headers, HTML, JavaScript, cookies, DNS records, and encryption certificates and configurations;

determine indicia of content features/characteristics for each of the network-accessible computer systems/assets, by analyzing each of the one or more responses using one or more of the following: machine learning models, regular expressions, text string matching, natural-language understanding, image processing, and text analysis;

determine indicia of security features/characteristics of each of the network-accessible computer systems/assets, including detecting one or more of the following: encryption, login field, captcha, security feature code, security-related keywords, security feature configurations, password field, security question, user authentication, secure cookies, two-factor authentication, RSA fraud protection, software bot detection, and secure connection protocols;

determine network proximity between respective network-accessible computer systems/assets; and

infer a value at risk for each of the network-accessible computer systems/assets based on, for a respective network-accessible computer system/asset, the indicia of content features/characteristics and the indicia of security features/characteristics, and based on network proximity to other network-accessible computer systems/assets with at least one of similar indicia of content features/characteristics, similar indicia of security features/characteristics, and similar values at risk.

12 . The system of claim 11 , the computer-executable instructions further causing the processor to rank the network-accessible computer system/asset for allocation of security of measures relative to the plurality of related network-accessible computer systems/assets based on respective values at risk.

13 . The system of claim 11 , wherein the indicia of content features/characteristics include one or more of the following:

presence of predetermined text,

content subject matter,

purpose of content accessible via the network-accessible computer system/asset,

purpose of content requested via the network-accessible computer system/asset,

functionality of content,

presence of sensitive data,

collection of the sensitive data, and

presence of user-identifiable account data.

14 . The system of claim 11 , wherein the value at risk represents both a measure of value and risk for any data or functionality, which if accessed by an unauthorized agent, including a person, computer program, or mechanical bot, if used in an unauthorized manner, or if availability or performance characteristics of functionality is degraded, the organization would be exposed to violation of regulations, financial liability, operational disruption of related processes resulting from unavailability or degraded performance of the functionality, harm of reputation, legal liability, or to violation of customer agreements.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2024
From: WHITE, KELLY THOMAS; FOWKES, MICHAEL VANCE; CARD, JESSE DUANE; MENZEL, ANDREW JAMES
To: RISKRECON INC.
Reel/Frame 066879/0115 →
Continuity (5)
Continuation 17669629 · Feb 11, 2022
Division 16278652 · Feb 18, 2019
Continuation In Part 15207395 · Jul 11, 2016
Provisional Application 62191362 · Jul 11, 2015
Related Publication 20240232767A1 · Jul 11, 2024
References Cited (9)
US 20040015728A1 · Cole · 2004 [cited by examiner]
US 20120053981A1 · Lipps · 2012 [cited by examiner]
US 20130074188A1 · Giakouminakis · 2013 [cited by examiner]
US 20130247205A1 · Schrecker · 2013 [cited by examiner]
US 20140046863A1 · Gifford · 2014 [cited by examiner]
US 20140278708A1 · Byk · 2014 [cited by examiner]
US 20160105457A1 · Blake · 2016 [cited by examiner]
US 20180351988A1 · Ahuja · 2018 [cited by examiner]
Sougstad, Ryan Scott. “A Risk Management Approach to IT Services Contract Design.” Order No. 3366928 University Of Minnesota, 2009. Ann Arbor. (Year: 2009). [cited by examiner]