Building risk analysis system with dynamic modification of asset-threat weights

US10559180B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10559180-B2
Application numberUS-201816143247-A
CountryUS
Kind codeB2
Filing dateSep 26, 2018
Priority dateSep 27, 2017
Publication dateFeb 11, 2020
Grant dateFeb 11, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A building management system includes one or more computer-readable storage media having a data structure, wherein the data structure comprises a plurality of vulnerabilities and a plurality of pairs, each of the plurality of pairs comprising one of a plurality of assets and one of the plurality of threat types, wherein each of the plurality of pairs is associated with one of the plurality of vulnerabilities and instructions. The instructions cause one or more processors to receive a threat, the threat comprising a particular threat type of the plurality of threat types, the threat indicating an incident affecting a risk value associated with a particular asset of the plurality of assets, identify a particular vulnerability of the data structure based on the particular threat type and the particular asset, and determine, based on the particular vulnerability and the threat, the risk value associated with the particular asset.

First claim

Opening claim text (preview).

What is claimed is: 1. A building management system comprising: one or more computer-readable storage media having: a data structure, wherein the data structure comprises a plurality of vulnerabilities and a plurality of pairs, each of the plurality of pairs comprising one of a plurality of assets and one of a plurality of threat types, wherein each of the plurality of pairs is associated with one of the plurality of vulnerabilities; and instructions stored thereon that, when executed by one or more processors, cause the one or more processors to: receive a threat, the threat comprising a particular threat type of the plurality of threat types, the threat indicating an incident affecting a risk value associated with a particular asset of the plurality of assets; identify a particular vulnerability of the data structure based on the particular threat type and the particular asset; determine, based on the particular vulnerability and the threat, the risk value associated with the particular asset; receive, via a user interface, an update to the particular vulnerability associated with the particular asset and the particular threat type; update the data structure with the update to the particular vulnerability; generate, for the particular asset, a list of threat types that the particular asset is vulnerable to based on the data structure, wherein the list of threat types are threat types that affect a risk score of the particular asset; cause the user interface to display the list; receive, via the user interface, an update to the list, the update to the list comprising an indication to add one or more new threat types, wherein the data structure does not indicate that the risk score of the particular asset is affected by the one or more new threat types; and update the plurality of vulnerabilities of the data structure based on the update to the list by adding one or more vulnerabilities based on the indication to add the one or more new threat types of the list. 2. The building management system of claim 1 , wherein each of the plurality of vulnerabilities comprise a binary indication of whether the plurality of assets are affected by the plurality of threat types. 3. The building management system of claim 1 , wherein each of the plurality of vulnerabilities is a numeric value indicating an amount that the plurality of assets are affected by each of the plurality of threat types, wherein the numeric value is between zero and one. 4. The building management system of claim 1 , wherein the data structure is a matrix comprising a first dimension and a second dimension, wherein the plurality of assets are associated with the first dimension and the plurality of threat types are associated with the second dimension. 5. The building management system of claim 1 , wherein the instructions cause the one or more processors to: provide a data structure retrieve endpoint, wherein the data structure retrieve endpoint is configured to provide the data structure to a requesting device; and provide a data structure update endpoint, wherein the data structure update endpoint is configured to update the vulnerabilities of the data structure based on updates received from the requesting device. 6. The building management system of claim 1 , wherein the instructions cause the one or more processors to: generate a second list indicating identifiers of each of the plurality of assets; cause the user interface to display the second list indicating the identifiers of each of the plurality of assets; receive a selection of the particular asset from the second list indicating the identifiers of each of the plurality of assets; and update the plurality of vulnerabilities of the data structure in response to receiving the selection of the particular asset. 7. The building management system of claim 1 , wherein the instructions cause the one or more processors to: receive an indication of a set of assets of the plurality of assets, the set of assets associated with a particular asset category; generate, for the set of assets, a second list of threat types that the set of assets is vulnerable to based on the data structure, wherein the list of threat types are threat types that affect risk scores of the set of assets; cause the user interface to display the second list; receive, via the user interface, an update to the second list, the update comprising an indication to add one or more second new threat types, wherein the data structure does not indicate that the risk scores of the set of assets are affected by the one or more second new threat types; and update the plurality of vulnerabilities of the data structure based on the update by adding second vulnerabilities based on the indication to add the one or more second new threat types. 8. The building management system of claim 7 , wherein the instructions cause the one or more processors to: generate a third list indicating a plurality of asset categories; cause the user interface to display the third list indicating the plurality of asset categories; receive a selection of the particular asset category from the third list indicating the plurality of asset categories; and update the plurality of vulnerabilities of the data structure in response to receiving the selection of the particular asset category. 9. A method for risk analysis, the method comprising: receiving a threat, the threat comprising a particular threat type of a plurality of threat types, the threat indicating an incident affecting a risk value associated with a particular asset of a plurality of assets; identifying a particular vulnerability of a data structure based on the particular threat type and the particular asset, wherein the data structure comprises a plurality of vulnerabilities and a plurality of pairs, each of the plurality of pairs comprising one of the plurality of assets and one of the plurality of threat types, wherein each of the plurality of pairs is associated with one of the plurality of vulnerabilities; determining, based on the particular vulnerability and the threat, the risk value associated with the particular asset; receiving, via a user interface, an update to the particular vulnerability associated with the particular asset and the particular threat type; updating the data structure with the update to the particular vulnerability; generating, for the particular asset, a list of threat types that the particular asset is vulnerable to based on the data structure, wherein the list of threat types are threat types that affect a risk score of the particular asset; causing the user interface to display the list; receiving, via the user interface, an update to the list, the update to the list comprising an indication to add one or more new threat types, wherein the data structure does not indicate that the risk score of the particular asset is affected by the one or more new threat types; and updating the plurality of vulnerabilities of the data structure based on the update to the list by adding one or more vulnerabilities based on the indication to add the one or more new threat types. 10. The method of claim 9 , wherein each of the plurality of vulnerabilities comprise a binary indication of whether the plurality of assets are affected by the plurality of threat types. 11. The method of claim 9 , wherein determining, based on the particular vulnerability and the threat, the risk value associated with the particular asset is further based on: a vulnerability parameter associated with the particular asset; an asset cost parameter associated with the particular asset; a severity associated with the threat; and a geographic distanc

Assignees

Inventors

Classifications

  • Status alarms (G08B21/02 takes precedence) · CPC title

  • Level alarms, e.g. alarms responsive to variables exceeding a threshold · CPC title

  • Ensemble learning · CPC title

  • Real estate management · CPC title

  • Predictive alarm systems characterised by extrapolation or other computation using updated historic data · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10559180B2 cover?
A building management system includes one or more computer-readable storage media having a data structure, wherein the data structure comprises a plurality of vulnerabilities and a plurality of pairs, each of the plurality of pairs comprising one of a plurality of assets and one of the plurality of threat types, wherein each of the plurality of pairs is associated with one of the plurality of v…
Who is the assignee on this patent?
Johnson Controls Tech Co
What technology area does this patent fall under?
Primary CPC classification H04W4/021. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 11 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).