Policy-based compliance management and remediation of devices in an enterprise system
US-2016088021-A1 · Mar 24, 2016 · US
US10084809B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-10084809-B1 |
| Application number | US-201615148766-A |
| Country | US |
| Kind code | B1 |
| Filing date | May 6, 2016 |
| Priority date | May 6, 2016 |
| Publication date | Sep 25, 2018 |
| Grant date | Sep 25, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system for managing security within an enterprise includes a computing device that receives a vulnerability, generates a user score for each user within the enterprise and generates a threat score for the vulnerability. A user device score may also be generated for each device associated with a user. Based on the user score and the threat score, a composite score is generated. After acquiring a security measure, the security measure is implemented based on the composite score and, at times, the user score.
Opening claim text (preview).
The invention claimed is: 1. An electronic computing device comprising: a processing unit; and system memory, the system memory including instructions that, when executed by the processing unit, cause the electronic computing device to: receive a vulnerability; generate a user score for each of a plurality of users within an enterprise, wherein the user score is generated based on a set of characteristics including: behavioral data, user device data, and user status data; generate a threat score for the vulnerability: based on the user score and the threat score, generate a composite score for each of the plurality of users within the enterprise; generate a user rank using the user score generated for each of the plurality of users within the enterprise; acquire the security patch that addresses the vulnerability; and based on the composite score, implement a security measure across the enterprise in a sequential order according to the user rank; wherein implementing the security measure includes publishing the security patch to the plurality of users according to the user rank. 2. The electronic computing device of claim 1 , wherein the security measure is a security patch. 3. The electronic computing device of claim 1 , wherein publishing the security patch includes sending a reminder to update after a predetermined period of time. 4. The electronic computing device of claim 3 , wherein the behavioral data include behavioral patterns and access patterns; wherein the user device data includes at least one of: a type of a user device associated with a user and a type of processes used by the user device associated with the user; and wherein the user status data includes at least one of: a corporate rank of the user and a system access level for the user. 5. The electronic computing device of claim 4 , wherein the behavioral patterns include at least one of the following: a browsing history of the user, a volume of junkmail, a previous computing device infection, a volume of phishing email; and wherein the access patterns include at least one of the following: a quantity of unique devices used by the user to access enterprise-related data, and an access pattern of the user including time of day. 6. The electronic computing device of claim 1 , wherein the threat score is generated based on a third party vulnerability score and an internal vulnerability score. 7. The electronic computing device of claim 6 , wherein the third party vulnerability score is publicly available; and wherein the internal vulnerability score is generated based on a system or a device type affected by the vulnerability. 8. The electronic computing device of claim 7 , wherein the internal vulnerability score is additionally generated based on at least one of the following: a device level importance, a regulation status, and a data sensitivity level. 9. The electronic computing device of claim 1 , wherein if a user does not perform an update with the security patch within a first predetermined time period, the system memory further includes instructions that, when executed by the processing unit, cause the electronic computing device to: activate a security module on a user device to lock out a device capability affected by the vulnerability on the user device. 10. The electronic computing device of claim 9 , wherein if the user does not perform the update with the security patch within a second predetermined time period, the system memory further includes instructions that, when executed by the processing unit, cause the electronic computing device to: deactivate a user's access to data within the enterprise. 11. A computer-implemented method, comprising: receiving a vulnerability; generating a user score for each of a plurality of users within an enterprise; generating a threat score for the vulnerability, wherein the threat score is generated based on a third party vulnerability score and an internal vulnerability score; based on the user score and the threat score, generating a composite score; generating a user rank using the user score generated for each of the plurality of users, the user rank being generated for each of the plurality of users within the enterprise; receiving a security measure; and based on the composite score and the user rank, implementing the security measure across the enterprise in a sequential order according to the user rank, wherein implementing the security measure includes publishing a security patch to the plurality of users according to the user rank. 12. The method of claim 11 , wherein the security measure is a patch or an update. 13. The method of claim 12 , wherein the user score is generated based on a set of characteristics including: behavioral data, user device data, and user status data. 14. The method of claim 13 , wherein the behavioral data include behavioral patterns and access patterns; wherein the user device data includes at least one of: a type of a user device associated with a user and a type of processes used by the user device associated with the user; wherein the user status data includes at least one of: a corporate rank of the user and a system access level for the user; wherein the behavioral patterns include at least one of the following: a browsing history of the user, a volume of junkmail, a previous computing device infection, a volume of phishing email; and wherein the access patterns include at least one of the following: a quantity of unique devices used by the user to access enterprise-related data, and an access pattern of the user including time of day. 15. The method of claim 14 , wherein the third party vulnerability score is publicly available; and wherein the internal vulnerability score is generated based on an enterprise device report, the enterprise device report including a system or a device affected by the vulnerability. 16. The method of claim 15 , wherein the internal vulnerability score is additionally generated based on at least one of the following: a device level importance, a regulation status, an internally- versus externally-facing status, and a data sensitivity level; wherein if the user does not install the patch or the update within a first predetermined time period, activating a security module on the user device to lock out the vulnerability on the user device; and wherein if the user does not install the patch or the update within a second predetermined time period, deactivating a user access to data within the enterprise. 17. A system for managing security within an enterprise, comprising: a computer-readable, non-transitory data storage memory comprising instructions that, when executed by a processing unit of an electronic computing device, cause the processing unit to: receive a vulnerability; generate a user device score for each of a plurality of user devices within the enterprise based on user device data, wherein the user device data includes at least one of: a type of a user device and a type of data processes used by the user device; generate a threat score for the vulnerability, wherein the threat score is generated based on a third party vulnerability score and an internal vulnerability score; based on the user device score and the threat score, generate a composite score; generate a user score for each of a plurality of users within the enterprise, wherein the user score is generated based on a set of characteristics including: behavioral data and user status data; wherein the behavioral data include behavioral patterns and access patte
Assessing vulnerabilities and evaluating computer system security · CPC title
Vulnerability analysis · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Updates (security arrangements therefor G06F21/57) · CPC title
Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.