Systems and methods for intelligently configuring computer security

US10412113B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10412113-B2
Application numberUS-201816215103-A
CountryUS
Kind codeB2
Filing dateDec 10, 2018
Priority dateDec 8, 2017
Publication dateSep 10, 2019
Grant dateSep 10, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method that enables the configuration of computer security of a subject entity at a computer security platform includes collecting a corpus of security data relating to one or more security configurations of the network maintained by the subject entity, analyzing the corpus of security data to determine one or more vulnerability factors and one or more security behaviors relating to the subject entity, generating a security assessment for the subject entity based on the analysis of the corpus of security data, generating a computer security policy for the security environment based on the security assessment, and providing, to the subject entity, a security policy recommendation incorporating at least a subset of the generated computer security policy.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for configuring computer security of a subject entity at a computer security platform, the method comprising: monitoring a security environment maintained by the subject entity; collecting a corpus of security data, the security data comprising security environment data relating to one or more security configurations of a network maintained by the subject entity; analyzing the corpus of security data to determine one or more vulnerability factors and one or more security behaviors relating to the subject entity; generating a security assessment for the subject entity based on the analysis of the corpus of security data; generating a computer security policy for the security environment based on the security assessment, comprising one or more computer security configurations; providing, to the subject entity, a security policy recommendation incorporating at least a subset of the generated computer security policy; receiving a recommendation response from the subject entity declining to accept the security policy recommendation; and responsive to the recommendation response declining to accept the security policy recommendation, providing an alternative security policy recommendation to the subject entity based on the recommendation response. 2. The method of claim 1 , wherein analyzing the corpus of security data, generating the security assessment, and/or generating the computer security policy comprises performing one or more machine learning techniques on one or more neural networks. 3. The method of claim 1 , wherein monitoring the security environment comprises monitoring authentication activity within the security environment. 4. The method of claim 1 , wherein the corpus of security data further comprises historical authentication data relating to one or more authentications performed using authentication services of the computer security platform. 5. The method of claim 4 , wherein the authentication services comprise multi-factor authentication services. 6. The method of claim 1 , wherein the security data further comprises global security environment data aggregated from a plurality of additional subject entities. 7. The method of claim 1 , wherein the security data further comprises user-submitted risk tolerance data. 8. The method of claim 1 , wherein the security data comprises one or more current security policy configurations of the subject entity. 9. The method of claim 1 , wherein the vulnerability factors comprise one or more attack vectors. 10. The method of claim 1 , wherein analyzing the corpus of security data comprises filtering the corpus of security data based on probative security value regarding a state of the network maintained by the subject entity. 11. The method of claim 10 , wherein probative security value relates at least to a probability of the existence of that malicious software exists within the security environment, and wherein analyzing the corpus of security data further comprises detecting one or more predetermined features of known malicious software within the security environment. 12. The method of claim 1 , wherein generating the security assessment comprises generating a risk score for the security environment. 13. The method of claim 1 , wherein generating the computer security policy comprises generating one or more crowd-sourced computer security configurations. 14. The method of claim 1 , further comprising: receiving a second recommendation response from the subject entity accepting the alternative security policy recommendation; and implementing at least a subset of a computer security policy of the alternative security policy recommendation, based on the second recommendation response. 15. The method of claim 1 , further comprising: receiving a second recommendation response from the subject entity adjusting one or more components of the alternative security policy recommendation; and implementing at least a subset of the adjusted security policy of the alternative security policy recommendation, based on the second recommendation response. 16. A system for configuring computer security of a subject entity, the system comprising: a security environment maintained by the subject entity; and a computer security platform implemented via one or more web servers or a distributed computing system, the one or more web servers or the distributed computing system comprising a non-transitory computer-readable medium storing computer instructions that when executed by one or more computer processors enables the computer security platform to: collect a corpus of security data, the security data comprising security environment data relating to one or more security configurations of the security environment maintained by the subject entity; analyze the corpus of security data to determine one or more vulnerability factors and one or more security behaviors relating to the subject entity; generate a security assessment for the subject entity based on the analysis of the corpus of security data; generate a computer security policy for the security environment based on the security assessment, comprising one or more computer security configurations; and provide, to the subject entity, a security policy recommendation incorporating at least a subset of the generated computer security policy; receive a recommendation response from the subject entity declining to accept the security policy recommendation; and responsive to the recommendation response declining to accept the security policy recommendation, provide one or more alternative security policy recommendations to the subject entity based on the recommendation response.

Assignees

Inventors

Classifications

  • Neural networks · CPC title

  • Machine learning · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Vulnerability analysis · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10412113B2 cover?
A system and method that enables the configuration of computer security of a subject entity at a computer security platform includes collecting a corpus of security data relating to one or more security configurations of the network maintained by the subject entity, analyzing the corpus of security data to determine one or more vulnerability factors and one or more security behaviors relating t…
Who is the assignee on this patent?
Duo Security Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 10 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).