Assessing an information security governance of an enterprise
US-9760849-B2 · Sep 12, 2017 · US
US11587177B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11587177-B2 |
| Application number | US-201514919506-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 21, 2015 |
| Priority date | Oct 21, 2014 |
| Publication date | Feb 21, 2023 |
| Grant date | Feb 21, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods, devices, systems and computer program products enable monitoring and responding to cyber security attacks. One such system relates to a consortium of monitoring companies and an infrastructure including one or more central monitoring stations or local handling stations for a monitoring company are provided. A central monitoring station of a monitoring company detects a cyberattack that has been launched against a client computer system, and requests a local station to respond to the cyberattack via onsite visits or requests additional resources from other monitoring companies through the consortium system. The central monitoring station also sends to the consortium system updates on a cyberattack that is detected or mitigated by a central monitoring station or local handling station of the monitoring company. The monitoring consortium enables stronger capabilities than any individual monitoring company can offer by the combination and coordination of the efforts and resources of the members.
Opening claim text (preview).
What is claimed is: 1. A central monitoring station of a monitoring system for detecting and handling cyberattacks to client systems with a management system that manages a consortium of monitoring systems, comprising: a network interface configured to receive and transmit information using a computer network; and a processor and a memory comprising processor executable instructions, the processor executable instructions upon execution by the processor, configuring a plurality of components of the central monitoring station to detect and respond to cyberattacks to client systems, the plurality of components configured to: register the central monitoring station with the management system as a member of the consortium of the monitoring systems; detect a cyberattack to a client computer system; respond to the cyberattack; send an update to the management system on detecting or responding to the cyberattack for sharing by other members of the consortium of monitoring systems; receive data from the management system on detecting and handling a cyberattack created by the management system and other members, wherein each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations associated with one or more specialists with access the client computer systems; and compute a real-time damage assessment based on the detected cyberattack, wherein at least one of the monitoring systems comprises one or more local handling stations, wherein the central monitoring stations and local handling stations in each of the monitoring systems are interconnected with a distinct local network connection; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage; and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems. 2. The central monitoring station of claim 1 , wherein at least one of the plurality of components is further configured to send a notification to the client computer system under attack. 3. The central monitoring station of claim 1 , wherein at least one of the plurality of components sends to the management system information regarding a change in availability of resources associated with the monitoring system or a change of status of detecting or handling the cyberattack by the monitoring system. 4. The central monitoring station of claim 1 , wherein one or more of the plurality of components are further configured to implement predetermined rules to be followed by all central monitoring stations of the members. 5. A computer implemented method of managing a consortium of monitoring systems which detect and handle cyberattacks, comprising: registering each of a plurality of monitoring systems as a member in response to corresponding registration requests for becoming a member of the consortium of monitoring systems, wherein each of the monitoring systems is associated with a distinct, independent business entity and each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations comprising a processor and a memory and monitoring one or more client computer systems for cyberattacks to the client computer systems and associated with one or more specialists who can physically work with the client computer systems, and wherein at least one of the monitoring systems comprises one or more local handling stations; receiving a report in electronic format from a first member coupled to a computer network; processing the electronic report to detect a cyberattack to a client computer system of the first member; responding to the cyberattack with the first member and a second member, wherein the second member assigns computing resources or human resources for mitigating the cyberattack; updating a repository of data related to cyberattacks accessible to members of the consortium; and computing a real-time damage assessment based on the detected cyberattack; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage; and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems. 6. The method of claim 5 , wherein processing the electronic report to detect a cyberattack comprises: receiving the report of the cyberattack from the first member; identifying information relevant to the cyberattack from the repository; sending the identified information to the first member; and logging information included in the report in the repository. 7. A computer program product embodied on one or more non-transitory computer readable media, comprising: program code for registering each of a plurality of monitoring systems as a member in response to corresponding registration requests for becoming a member of a consortium of monitoring systems, wherein each of the monitoring systems is associated with a distinct, independent business entity and each of the monitoring systems comprises one or more central monitoring stations, each of the central monitoring stations comprising a processor and a memory and monitoring one or more client computer systems for cyberattacks to the client computer systems and associated with one or more specialists who can physically work with the client computer systems, and wherein at least one of the monitoring systems comprises one or more local handling stations; program code for receiving a report in electronic format from a first member coupled to a computer network; program code for processing the electronic report to detect a cyberattack to a client computer system of the first member; program code for responding to the cyberattack with the first member and a second member, wherein the second member assigns computing resources or human resources for mitigating the cyberattack; program code for updating a repository of data related to cyberattacks accessible to members of the consortium; and program code for computing a real-time damage assessment based on the detected cyberattack; wherein the real-time damage assessment comprises a weighted average including a first weight indicating a likelihood of one or more cyberattacks, a second weight indicating a likelihood of success of the one or more cyberattacks, and a third weight indicating a measure of severity of damage and wherein the first, second, and third weights are based at least in part on historical information captured by one or more computer systems.
Vulnerability analysis · CPC title
Insurance · CPC title
Event detection, e.g. attack signature detection · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.