Identification of permutations of permission groups having lowest scores
US-2022191207-A1 · Jun 16, 2022 · US
US12028366B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12028366-B2 |
| Application number | US-202117199069-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 11, 2021 |
| Priority date | Dec 18, 2019 |
| Publication date | Jul 2, 2024 |
| Grant date | Jul 2, 2024 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Disclosed embodiments relate to systems and methods for dynamically performing entity-specific security assessments for entities of virtualized network environments. Techniques include identifying an entity associated with a virtualized network environment, identifying a plurality of security factors, determining entity-specific weights to the plurality of security factors, and generating a composite exposure assessment for the entity. Further techniques include selecting at least two security factors of the plurality of security factors, identifying the weights corresponding to the selected security factors, and calculating the composite exposure assessment using the selected security factors and corresponding weights, analyzing the composite exposure assessment, and generating at least one of: a security recommendation based on the analysis to alter a scope of privileges of the entity, a notification providing an indication of the composite exposure assessment, or a visual representation of the composite exposure assessment of the entity.
Opening claim text (preview).
What is claimed is: 1. A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for dynamically performing entity-specific security assessments for entities of virtualized network environments, the operations comprising: identifying an entity associated with a plurality of permissions in a virtualized network environment; determining scores of a plurality of security factors; determining entity-specific weights to the plurality of security factors; generating a composite exposure assessment for the entity across the plurality of permissions, the generating comprising: selecting at least two security factors of the plurality of security factors; identifying the weights corresponding to the selected security factors; and calculating the composite exposure assessment using the selected security factors and corresponding weights; determining a score of a special security factor associated with the entity; modifying the calculated composite exposure assessment based on the determined score of the special security factor; analyzing the modified composite exposure assessment; and generating at least one of: a security recommendation based on the analysis to alter a scope of privileges of the entity; a notification providing an indication of one or more unused permissions of the plurality of permissions; or a visual representation of the modified composite exposure assessment of the entity. 2. The non-transitory computer readable medium of claim 1 , wherein the plurality of security factors include at least one of: a permission type of each of the plurality of permissions; or a usage status of a permission of each of the plurality of permissions. 3. The non-transitory computer readable medium of claim 1 , wherein the calculated composite exposure assessment is further modified based on a customer influence score. 4. The non-transitory computer readable medium of claim 1 , wherein the visual representation comprises a representation of one or more of the plurality of security factors associated with the modified composite exposure assessment. 5. The non-transitory computer readable medium of claim 4 , wherein the visual representation indicates an effect of the one or more of the plurality of security factors on the calculation of the modified composite exposure assessment. 6. The non-transitory computer readable medium of claim 4 , wherein the visual representation indicates a composite exposure assessment score threshold. 7. The non-transitory computer readable medium of claim 1 , wherein selecting the at least two security factors of the plurality of security factors is performed using a machine learning algorithm. 8. The non-transitory computer readable medium of claim 1 , wherein selecting the at least two security factors of the plurality of security factors is based on an entity classification. 9. The non-transitory computer readable medium of claim 8 , wherein the entity classification is generated using a machine learning algorithm. 10. The non-transitory computer readable medium of claim 8 , wherein the entity classification is manually generated. 11. A computer-implemented method for dynamically performing entity-specific security assessments for entities of virtualized network environments, the method comprising: identifying an entity associated with a plurality of permissions in a virtualized network environment; determining scores of a plurality of security factors; determining entity-specific weights to the plurality of security factors; generating a composite exposure assessment for the entity across the plurality of permissions, the generating comprising: selecting at least two security factors of the plurality of security factors; identifying the weights corresponding to the selected security factors; and calculating the composite exposure assessment using the selected security factors and corresponding weights; determining a score of a special security factor associated with the entity; modifying the calculated composite exposure assessment based on the determined score of the special security factor; analyzing the modified composite exposure assessment; and generating at least one of: a security recommendation to revoke one or more unused permissions of the plurality of permissions; a notification providing an indication of the composite exposure assessment; or a visual representation of the composite exposure assessment. 12. The computer-implemented method of claim 11 , wherein the security recommendation is based on one or more of the selected security factors. 13. The computer-implemented method of claim 11 , further comprising: receiving an indication of acceptance of the security recommendation. 14. The computer-implemented method of claim 13 , further comprising: updating, based on the acceptance of the security recommendation, the modified composite exposure assessment. 15. The computer-implemented method of claim 11 , wherein analyzing the composite exposure assessment comprises comparing the modified composite exposure assessment with a reference score. 16. The computer-implemented method of claim 11 , wherein: analyzing the modified composite exposure assessment comprises determining that the modified composite exposure assessment does not exceed a score threshold; and the security recommendation comprises a recommendation to maintain a scope of privileges of the entity. 17. The computer-implemented method of claim 11 , wherein: analyzing the modified composite exposure assessment comprises determining that the modified composite exposure assessment exceeds a score threshold; and the security recommendation comprises a recommendation to reduce a scope of privileges of the entity. 18. The computer-implemented method of claim 17 , further comprising: receiving an indication of acceptance of the security recommendation; updating, based on the acceptance of the security recommendation, the modified composite exposure assessment; analyzing the updated composite exposure assessment; and determining that the updated composite exposure assessment does not exceed a score threshold. 19. The computer-implemented method of claim 11 , wherein the security recommendation comprises a recommendation to audit privilege usage of the entity. 20. The computer-implemented method of claim 11 , further comprising: generating, based on the security recommendation, a second modified composite exposure assessment for the entity, the second modified composite exposure assessment indicating the change in the first composite exposure assessment when the security recommendation is accepted. 21. The computer-implemented method of claim 11 , further comprising: aggregating scores for multiple entities to generate a composite exposure assessment for the virtualized network environment.
Event detection, e.g. attack signature detection · CPC title
Multiple levels of security · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Vulnerability analysis · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.