IP Library Granted Patent US 11,483,334
Granted Patent B2
US 11,483,334 · App. 16/909,647 · Granted Oct 25, 2022

Automated asset criticality assessment

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); Sven Schrecker (San Marcos, CA)
Assignee: McAfee, LLC
H04L63/1433G06F21/568G06F21/577H04L63/1408H04L63/1416G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,334
App. No.
16/909,647
Granted
Oct 25, 2022
Kind
B2
Abstract

A set of attributes of a particular asset of a computing environment is identified that are determined from data collected by one or more utilities in the computing environment. A criticality rating is automatically determined for the particular asset based at least in part on the set of attributes. A security activity is caused to be performed relating to the particular asset based on the automatically determined criticality rating of the particular asset.

Claims (33)

1. A method, comprising:

identifying a set of attributes of an asset of a computing environment, wherein the set of attributes identifies an access control deployed in connection with the asset;

determining, using at least one processor, a criticality rating for the asset in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset, wherein the criticality rating is based at least in part on a rule and the access control; and

causing a security activity to be performed based at least in part on the criticality rating.

2. The method of claim 1 , wherein the rule assesses the criticality rating based at least in part on a file size of the asset or whether the asset maintains credit card data.

3. The method of claim 1 , wherein the rule assesses the criticality rating based at least in part on an amount of traffic originating from, passing through, or received at the asset in a window of interest, and the amount of traffic is an average traffic or an overall amount of traffic.

4. The method of claim 1 , wherein the rule assesses the criticality rating based at least in part on an ownership, a creation, a management, or an interaction with a predetermined user.

5. The method of claim 1 , wherein the rule assesses the criticality rating based at least in part on an operating system of the asset or a geographical location of the asset.

6. The method of claim 1 , wherein the security activity is denying the attempt to launch the asset or the application hosted by or interacting with the asset.

7. The method of claim 1 , further comprising:

calculating a risk measure for the asset from the criticality rating, wherein the set of attributes further identifies one or more users or a context of use of the asset by the one or more users, the criticality rating further is based at least in part on the one or more users or the context of use of the asset, and the security activity is caused to be performed based at least in part on the risk measure.

8. At least one non-transitory storage medium having instructions stored thereon, wherein the instructions, when executed on a machine, cause the machine to perform a method comprising:

identifying a set of attributes of an asset of a computing environment, wherein the set of attributes identifies an access control deployed in connection with the asset;

determining a criticality rating for the asset in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset, wherein the criticality rating is based at least in part on a rule and the access control; and

causing a security activity to be performed based at least in part on the criticality rating.

9. The medium of claim 8 , wherein the rule assesses the criticality rating based at least in part on a file size of the asset or whether the asset maintains credit card data.

10. The medium of claim 8 , wherein the rule assesses the criticality rating based at least in part on an amount of traffic originating from, passing through, or received at the asset in a window of interest, and the amount of traffic is an average traffic or an overall amount of traffic.

11. The medium of claim 8 , wherein the rule assesses the criticality rating based at least in part on an ownership, a creation, a management, or an interaction with a predetermined user.

12. The medium of claim 8 , wherein the rule assesses the criticality rating based at least in part on an operating system of the asset or a geographical location of the asset.

13. The medium of claim 8 , wherein the security activity is denying the attempt to launch the asset or the application hosted by or interacting with the asset.

14. The medium of claim 8 , the method further comprising:

calculating a risk measure for the asset from the criticality rating, wherein the set of attributes further identifies one or more users or a context of use of the asset by the one or more users, the criticality rating further is based at least in part on the one or more users or the context of use of the asset, and the security activity is caused to be performed based at least in part on the risk measure.

15. A system, comprising:

at least one memory that stores instructions; and

at least one processor that executes the instructions to

identify a set of attributes of an asset of a computing environment, wherein the set of attributes identifies an access control deployed in connection with the asset;

determine a criticality rating for the asset in response to a countermeasure deployment involving the asset or an attempt to launch the asset or an application hosted by or interacting with the asset, wherein the criticality rating is based at least in part on a rule and the access control; and

cause a security activity to be performed based at least in part on the criticality rating.

16. The system of claim 15 , wherein the rule assesses the criticality rating based at least in part on a file size of the asset or whether the asset maintains credit card data.

17. The system of claim 15 , wherein the rule assesses the criticality rating based at least in part on an amount of traffic originating from, passing through, or received at the asset in a window of interest, and the amount of traffic is an average traffic or an overall amount of traffic.

18. The system of claim 15 , wherein the rule assesses the criticality rating based at least in part on an ownership, a creation, a management, or an interaction with a predetermined user.

19. The system of claim 15 , wherein the rule assesses the criticality rating based at least in part on an operating system of the asset or a geographical location of the asset.

20. The system of claim 15 , wherein the security activity is denying the attempt to launch the asset or the application hosted by or interacting with the asset.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (4)
Continuation 16394351 · Apr 25, 2019
Continuation 15959946 · Apr 23, 2018
Continuation 13718970 · Dec 18, 2012
Related Publication 20200322372A1 · Oct 8, 2020