IP Library Patent Application 15150592
Patent Application
App. No. 15/150,592

DETERMINING A THREAT SEVERITY ASSOCIATED WITH AN EVENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/150,592
Abstract

Systems and techniques for assessing a risk associated with a data loss prevention (DLP) policy violation are described. Characteristics of data associated with the DLP policy violation and user information associated with a participant associated with the DLP policy violation may be determined. An expertise and a position of the participant may be determined and correlated with the one or more characteristics of the data to determine a risk assessment associated with the DLP policy violation. After determining that the risk assessment satisfies a threshold, a subject matter expert may be determined based on the characteristics of the data, and an alert may be sent to the subject matter expert requesting review of the DLP policy violation.

Claims (83)

1 . A computer-implemented method, comprising:

determining that a data loss prevention (DLP) policy violation has occurred;

determining one or more characteristics of data associated with the DLP policy violation;

determining user information associated with a participant associated with the DLP policy violation, the user information including a user identifier associated with the participant, an expertise of the participant, and a position of the participant;

correlating the expertise and the position of the participant with the one or more characteristics of the data to create a correlation factor;

determining a risk assessment associated with the DLP policy violation based on the correlation factor;

determining that the risk assessment satisfies a threshold;

determining a subject matter expert based on at least one of the one or more characteristics of the data; and

sending an alert to the subject matter expert to review the DLP policy violation.

2 . The computer-implemented method of claim 1 , wherein the one or more characteristics of the data include:

a classification comprising one of a public document classification, an internal document classification, a confidential document classification, or a restricted document classification;

a topic associated with the data; and

a privilege level to access the data.

3 . The computer-implemented method of claim 1 , wherein determining the expertise of the participant associated with the DLP policy violation comprises:

identifying documents associated with the participant, the documents accessible via external data sources and enterprise data sources;

identifying communications associated with the participant; and

analyzing the documents and the communications to determine the expertise of the participant.

4 . The computer-implemented method of claim 3 , wherein the external data sources include a patent publication database and a technical publication database.

5 . The computer-implemented method of claim 1 , further comprising:

displaying to the subject matter expert, via a user interface, a plurality of actions;

receiving a selection of an action from the plurality of actions; and

performing the action.

6 . The computer-implemented method of claim 5 , wherein the action comprises modifying credentials associated with the participant to prevent the participant from performing an additional DLP policy violation.

7 . The computer-implemented method of claim 1 , wherein the alert includes:

the one or more characteristics of the data associated with the DLP policy violation; and

the expertise and the position of the participant, wherein the position includes a current title of the participant and an indication of a placement of the participant in a hierarchical organization.

8 . One or more non-transitory computer-readable media storing instructions that are executable by one or more processors to perform operations comprising:

determining that a data loss prevention (DLP) policy violation has occurred;

determining one or more characteristics of data associated with the DLP policy violation;

determining user information associated with a participant associated with the DLP policy violation;

determining an expertise and a position of the participant;

correlating the expertise and the position of the participant with the one or more characteristics of the data to create a correlation factor;

determining a risk assessment associated with the DLP policy violation based on the correlation factor;

determining that the risk assessment satisfies a threshold;

determining a subject matter expert based on at least one of the one or more characteristics of the data; and

sending an alert to the subject matter expert to review the DLP policy violation.

9 . The one or more non-transitory computer-readable media of claim 8 , wherein the one or more characteristics of the data include:

a classification characteristic comprising one of a public document classification, an internal document classification, a confidential document classification, or a restricted document classification;

a topic associated with the data; and

a privilege level to access the data.

10 . The one or more non-transitory computer-readable media of claim 8 , wherein determining the expertise of the participant associated with the DLP policy violation comprises:

identifying documents associated with the participant, the documents accessible via external data sources and enterprise data sources;

identifying communications associated with the participant; and

analyzing the documents and the communications to determine the expertise of the participant.

11 . The one or more non-transitory computer-readable media of claim 10 , wherein the external data sources include a patent publication database and a technical publication database.

12 . The one or more non-transitory computer-readable media of claim 8 , the operations further comprising:

displaying to the subject matter expert, via a user interface, a plurality of actions;

receiving a selection of an action from the plurality of actions; and

modifying credentials associated with the participant to prevent the participant from performing an additional DLP policy violation.

13 . The one or more non-transitory computer-readable media of claim 8 , wherein the alert includes:

the one or more characteristics of the data associated with the DLP policy violation; and

the expertise and the position of the participant, wherein the position includes a current title of the participant and an indication of a placement of the participant in a hierarchical organization.

14 . A server, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that are executable by the one or more processors to perform operations comprising:

determining that a data loss prevention (DLP) policy violation has occurred;

determining one or more characteristics of data associated with the DLP policy violation;

determining user information associated with a participant associated with the DLP policy violation;

determining an expertise and a position of the participant;

correlating the expertise and the position of the participant with the one or more characteristics of the data to create a correlation factor;

determining a risk assessment associated with the DLP policy violation based on the correlation factor;

determining that the risk assessment satisfies a threshold;

determining a subject matter expert based on at least one of the one or more characteristics of the data; and

sending an alert to the subject matter expert to review the DLP policy violation.

15 . The server of claim 14 , wherein the one or more characteristics of the data include:

a classification characteristic comprising one of a public document classification, an internal document classification, a confidential document classification, or a restricted document classification;

a topic associated with the data; and

a privilege level to access the data.

16 . The server of claim 14 , wherein determining the expertise of the participant associated with the DLP policy violation comprises:

identifying documents associated with the participant, the documents accessible via external data sources and enterprise data sources;

identifying communications associated with the participant; and

analyzing the documents and the communications to determine the expertise of the participant.

17 . The server of claim 16 , wherein:

the external data sources include a patent publication database and a technical publication database; and

the enterprise data sources include a directory service, an internal document database, an email service, an instant messaging service, and a conferencing service.

18 . The server of claim 14 , further comprising:

displaying to the subject matter expert, via a user interface, a plurality of actions;

receiving a selection of an action from the plurality of actions; and

performing the action.

19 . The server of claim 18 , wherein the action comprises modifying credentials associated with the participant to prevent the participant from performing an additional DLP policy violation.

20 . The server of claim 14 , wherein the alert includes:

the one or more characteristics of the data associated with the DLP policy violation; and

the expertise and the position of the participant, wherein the position includes a current title of the participant and an indication of a placement of the participant in a hierarchical organization.

Assignments (20)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
CHANGE OF NAME Recorded Jun 19, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046393/0009 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SEC. INT. IN PATENTS (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0329 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SEC. INT. IN PATENTS (NOTES) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040026/0710 →
RELEASE OF SEC. INT. IN PATENTS (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040013/0733 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 10, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 039643/0953 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 10, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 039644/0084 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 10, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 039719/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2016
From: BRISEBOIS, MICHEL ALBERT; JOHNSTONE, CURTIS
To: DELL SOFTWARE, INC.
Reel/Frame 038531/0876 →