System and methods for minimizing organization risk from users associated with a password breach

US11036848B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11036848-B2
Application numberUS-202016746662-A
CountryUS
Kind codeB2
Filing dateJan 17, 2020
Priority dateSep 19, 2018
Publication dateJun 15, 2021
Grant dateJun 15, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek to reduce risk by training staff for this specific issue in a timely and appropriate manner to significantly reduce the risk of a future breach by those identified users. Training can be customized and targeted at those users who attempt to use passwords that have been associated with a breach (either of their own account or of another account on the same or related domain.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising establishing, by one or more processors, a user risk score for each user of a plurality of users based at least on a type of password breach selected for each user from a plurality of types of password breach identified from one or more data breaches associated with the plurality of users; identifying, by the one or more processors, one or more users of the plurality of users based at least on the user risk score of the one or more users; identifying, by the one or more processors, an electronic training campaign configured to train the one or more users on using passwords based at least on the type of password breach selected for the one or more users from the plurality of types of password breach identified from the one or more data breaches; and communicating, by the one or more processors, the first electronic training campaign to one or more devices of the one or more users. 2. The method of claim 1 , further comprising identifying, by the one or more processors, the plurality of users with passwords associated with the one or more data breaches. 3. The method of claim 2 , further comprising determining, by the one or more processors, for each of the plurality of users a corresponding type of password breach from a plurality of types of password breach. 4. The method of claim 1 , wherein the type of password breach comprises a password of a user being subject to a data breach associated with that user. 5. The method of claim 1 , wherein the type of password breach comprises a password of a user being subject to a data breach associated with another user. 6. The method of claim 5 , wherein the another user is in a same domain as the user. 7. The method of claim 1 , further comprising modifying, by the one or more processors, the user risk score for at least one user of the first one or more users based at least on a result of the first electronic training campaign. 8. The method of claim 1 , further comprising selecting the one or more users based at least on a number of times the one or more users have been subject to the one or more data breaches. 9. The method of claim 1 , further comprising generating the electronic campaign responsive to identifying the one or more users. 10. The method of claim 1 , further comprising changing one or more user properties of a user of the one or more users responsive to the risk score of that user. 11. A system comprising one or more processors, coupled to memory and configured to: establish a user risk score for each user of a plurality of users based at least on a type of password breach selected for each user from a plurality of types of password breach identified from of one or more data breaches associated with the plurality of users; identify one or more users of the plurality of users based at least on the user risk score of the one or more users; identify, an electronic training campaign configured to train the one or more users on using passwords based at least on the type of password breach selected for the one or more users from the plurality of types of password breach identified from the one or more data breaches; and communicate, the first electronic training campaign to one or more devices of the one or more users. 12. The system of claim 11 , wherein the one or more processors are further configured to identify the plurality of users with passwords associated with the one or more data breaches. 13. The system of claim 12 , wherein the one or more processors are further configured to determine for each of the plurality of users a corresponding type of password breach from a plurality of types of password breach. 14. The system of claim 11 , wherein the type of password breach comprises a password of a user being subject to a data breach associated with that user. 15. The system of claim 11 , wherein the type of password breach comprises a password of a user being subject to a data breach associated with another user. 16. The system of claim 15 , wherein the another user is in a same domain as the user. 17. The system of claim 11 , wherein the one or more processors are further configured to modify the user risk score for at least one user of the first one or more users based at least on a result of the first electronic training campaign. 18. The system of claim 11 , wherein the one or more processors are further configured to select the one or more users based at least on a number of times the one or more users have been subject to the one or more data breaches. 19. The system of claim 11 , wherein the one or more processors are further configured generate the electronic campaign responsive to identifying the one or more users. 20. A system comprising: one or more processors, coupled to memory and configured to: establish a user risk score for each of a plurality of users based on a corresponding type of password breach from a plurality of types of password breach associated with one or more data breaches associated with the plurality of users; identify one or more users of the plurality of users based at least on the user risk score of the one or more users; identify, an electronic training campaign configured to train the one or more users on using passwords based at least on the type of password breach; communicate, the first electronic training campaign to one or more devices of the one or more users; and modify the user risk score for at least one user of the plurality of users based at least on a result of the first electronic training.

Assignees

Inventors

Classifications

  • Electrically-operated educational appliances (working with questions and answers G09B7/00; simulators G09B9/00; advertising or displaying in general G09F) · CPC title

  • G06F21/46Primary

    by designing passwords or checking the strength of passwords · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

  • Simulators for teaching or training purposes (for the use of weapons F41; computing aspects G06; {protocols for games, networked simulations or virtual reality H04L67/131}) · CPC title

  • Test or assess a computer or a system · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11036848B2 cover?
System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek …
Who is the assignee on this patent?
Knowbe4 Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/46. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 15 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).