×

Apparatus and method for automatic handling of cyber-security risk events

  • US 10,021,119 B2
  • Filed: 09/30/2015
  • Issued: 07/10/2018
  • Est. Priority Date: 02/06/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • detecting, by a monitoring system, a first event associated with a device in a computing system;

    in response to detecting the event, initializing a risk item corresponding to the first event, by the monitoring system, and setting the risk item to a full risk value;

    determining, by the monitoring system, whether a second event, corresponding to the first event, has been detected, wherein the second event corresponds to the first event when the second event is a repeat of the first event, is a same type of event as the first event, or is generated by a same process, system, or device as the first event;

    in response to determining, by the monitoring system, that no second event has been detected, reducing the risk value over time;

    in response to determining, by the monitoring system, that multiple corresponding second events have been detected, increasing the risk value to value that is greater than the full risk value;

    altering, by the monitoring system, when no second event has been detected, the risk value by reducing the risk value according to a decay function wherein the decay function is defined as;


    For t<

    P
    ;

    Risk=R*(1−

    (t/P))
    For t>

    =P
    ;

    Risk=0,where Risk represents an adjusted risk value, R represents the full risk value, P represents a decay period of time, and t represents an amount of time that has passed since the first event occurred was detected;

    determining, by the monitoring system, if the risk value for the risk item has passed a threshold; and

    clearing the event, by the monitoring system, in response to the risk value passing the threshold.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×