System for determining effectiveness and allocation of information security technologies

US9843600B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9843600-B1
Application numberUS-201715668233-A
CountryUS
Kind codeB1
Filing dateAug 3, 2017
Priority dateDec 21, 2015
Publication dateDec 12, 2017
Grant dateDec 12, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed is a computerized system for determining the collective effectiveness of information security technologies. The system typically includes a processor, a memory, and an information security analysis module stored in the memory. The system for is typically configured for: determining a security score for each element of a security technology defense matrix, a first dimension of the security technology defense matrix corresponding to a plurality of resource classes, and a second dimension of the security technology defense matrix corresponding to a plurality of security operational functions; determining a defense-in-depth score for each resource class and each security operational function; determining an aggregate security score; and providing the aggregate security score the defense-in-depth scores for each resource class and each security operational function to a user computing device. The system may be configured to provide technology deployment recommendations. Based on such recommendations, additional security technologies may be deployed.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computerized system for determining the effectiveness of information security technologies, comprising: an information system having one or more deployed security technologies; a computer apparatus including a processor, a memory, and a network communication device; and an information security analysis module stored in the memory, executable by the processor, and configured to: determine a security score for each element of a security technology defense matrix, each element of the security technology defense matrix being associated with the one or more deployed security technologies of the information system, wherein a first dimension of the security technology defense matrix corresponds to a plurality of resource classes, and a second dimension of the security technology defense matrix corresponds to a plurality of security operational functions, wherein determining a security score for each element of the security technology defense matrix comprises determining a control score C for one or more controls associated with each element, the security score for each element of the security technology defense matrix being equal to 1−(1−C 1 )× . . . ×(1−C x ), wherein x is the total number of controls associated with the particular element; determine a defense-in-depth score D resource for each resource class, wherein the defense-in-depth score D resource for each resource class is equal to 1−(1−E resource1 )×(1−E resource2 )× . . . ×(1−E resourcen ), wherein E resource corresponds to the security score for each element of the security technology defense matrix that is associated with a particular resource class and n is the total number of elements of the security technology defense matrix associated with the particular resource class; determine a defense-in-depth score D operation for each security operational function, wherein the defense-in-depth score D operation for each security operational function is equal to 1−(1−E operation1 )×(1−E operation2 )× . . . ×(1−E operationm ), wherein E operation corresponds to the security score for each element of the security technology defense matrix that is associated with a particular security operational function and m is the total number of elements of the security technology defense matrix associated with the particular security operational function; based on determining the defense-in-depth score D resource for each resource class and determining the defense-in-depth score D operation for each security operational function, determine an aggregate security score; and provide the defense-in-depth score D resource for each resource class, the defense-in-depth score D operation for each security operational function, and the aggregate security score to a user computing device. 2. The computerized system according to claim 1 , wherein the information security analysis module is configured to: receive information regarding a plurality of future deployment scenarios; determine an aggregate security score for each of the plurality of future deployment scenarios; and based on determining an aggregate security score for each of the plurality of future deployment scenarios, provide a technology deployment recommendation to a user computing device. 3. The computerized system according to claim 2 , wherein the technology deployment recommendation is a recommendation to upgrade one or more of the deployed security technologies. 4. The computerized system according to claim 2 , wherein the technology deployment recommendation is a recommendation to deploy one or more additional security technologies. 5. The computerized system according to claim 1 , wherein the information security analysis module is configured to: receive information regarding a plurality of future deployment scenarios; determine a defense-in-depth score for one of the resource classes for each of the plurality of future deployment scenarios; and based on determining a defense-in-depth score for one of the resource classes for each of the plurality of future deployment scenarios, provide a technology deployment recommendation to a user computing device. 6. The computerized system according to claim 5 , wherein the technology deployment recommendation is a recommendation to upgrade one or more of the deployed security technologies. 7. The computerized system according to claim 5 , wherein the technology deployment recommendation is a recommendation to deploy one or more additional security technologies. 8. The computerized system according to claim 1 , wherein the information security analysis module is configured to: receive information regarding a plurality of future deployment scenarios; determine a defense-in-depth score for one of the security operational functions for each of the plurality of future deployment scenarios; and based on determining a defense-in-depth score for one of the security operational functions for each of the plurality of future deployment scenarios, provide a technology deployment recommendation to a user computing device. 9. The computerized system according to claim 8 , wherein the technology deployment recommendation is a recommendation to upgrade one or more of the deployed security technologies. 10. The computerized system according to claim 8 , wherein the technology deployment recommendation is a recommendation to deploy one or more additional security technologies. 11. A computer program product for determining the effectiveness of information security technologies embodied on a non-transitory computer-readable storage medium having computer-executable instructions for: determining, via a computer system configured for information security analysis, a security score for each element of a security technology defense matrix, each element of the security technology defense matrix being associated with one or more deployed security technologies, wherein a first dimension of the security technology defense matrix corresponds to a plurality of resource classes, and a second dimension of the security technology defense matrix corresponds to a plurality of security operational functions, wherein determining a security score for each element of the security technology defense matrix comprises determining a control score C for one or more controls associated with each element, the security score for each element of the security technology defense matrix being equal to 1−(1−C 1 )× . . . ×(1−C x ), wherein x is the total number of controls associated with the particular element; determining, via the computer system configured for information security analysis, a defense-in-depth score D resource for each resource class, wherein the defense-in-depth score D resource for each resource class is equal to 1−(1−E resource1 )×(1−E resource2 )× . . . ×(1−E resourcen ), wherein E resource corresponds to the security score for each element of the security technology defense matrix that is associated with a particular resource class and n is the total number of elements of the security technology defense matrix associated with the particular resource class; determining, via the computer system configured for information security analysis, a defense-in-depth score D operation for each security operational function, wherein the defense-in-depth score D operation for each security operational function is equal to 1−(1−E operation1 )×(1−E operation2 )× . . . ×(1−E operationm ), wherein E operation corresponds to the security score for each element of the security technology defense matrix that is associated with a particular security operational function and m is the total number of elements of the security technology defense matrix ass

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9843600B1 cover?
Disclosed is a computerized system for determining the collective effectiveness of information security technologies. The system typically includes a processor, a memory, and an information security analysis module stored in the memory. The system for is typically configured for: determining a security score for each element of a security technology defense matrix, a first dimension of the secu…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 12 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).