Patents Assigned to BITSIGHT TECHNOLOGIES, INC.
-
Patent number: 12273367Abstract: Computer-implemented methods are provided herein for quantifying correlated risk in a network of a plurality of assets having at least one dependency, where each asset belongs to at least one entity. The method includes generating a dependency graph based on relationships between the assets, at least one dependency, and at least one entity, and executing a plurality of Monte Carlo simulations over the dependency graph. Executing a plurality of Monte Carlo simulations includes generating a seed event in the dependency graph, where the seed event has a probability distribution, and propagating disruption through the dependency graph based on the seed event. The method further includes assessing loss for each of the assets, and aggregating losses for two or more assets to determine correlated risk in the network.Type: GrantFiled: August 4, 2023Date of Patent: April 8, 2025Assignee: BitSight Technologies, Inc.Inventors: Ethan Geil, Marc Light
-
Patent number: 12223060Abstract: A computer-implemented method is provided for statistical modeling of entities of a particular type. The method can include obtaining entity data including a plurality of entity data sets, each entity data set associated with a respective entity and including values for one or more static parameters indicative of a type of the entity. Each entity data set can include (i) values for input parameter(s) indicative of a security profile of the entity and (ii) a value of a security class parameter indicative of a security class of the entity based on the values of the input parameters. The method can include training a statistical classifier to infer a value of the security class parameter indicative of the security class of a particular entity of the particular type based on values of one or more of the input parameters indicative of a security profile of the particular entity.Type: GrantFiled: April 25, 2023Date of Patent: February 11, 2025Assignee: BitSight Technologies, Inc.Inventor: Marc Noel Light
-
Patent number: 12200006Abstract: A cybersecurity risk management method may include recommending, for each of a plurality of affiliates of an entity, a respective cybersecurity criticality tier selected from a set of cybersecurity criticality tiers; receiving user input adjusting and/or adopting the recommended cybersecurity criticality tier for each of the affiliates; assigning each of the affiliates to the respective adjusted or adopted cybersecurity criticality tier; obtaining respective security scores for the affiliates; and displaying a user interface component configured to show a visualization of a cybersecurity risk management plan of the entity with respect to the plurality of affiliates, wherein the risk management plan partitions the affiliates into a plurality of affiliate sets based on the security scores and the assigned cybersecurity criticality tiers of the affiliates and specifies, for each of the affiliate sets, an action to be taken by the entity with respect to the affiliates in the affiliate set.Type: GrantFiled: May 1, 2023Date of Patent: January 14, 2025Assignee: BitSight Technologies, Inc.Inventors: Tianyi Cai, Thomas Erhardt Montroy, Marc Noel Light
-
Patent number: 12099605Abstract: Computer-implemented methods and systems are provided for the detection of software presence remotely through the web browser by detecting the presence of webinjects in a web browser that visits a detection webpage. The methods can include delivering a detection webpage to a web browser, in which the detection webpage has detection code configured to detect a presence of the webinject in the detection webpage; and inspecting, by the detection code, rendering of content of the detection webpage in the browser to detect webinject content in the detection webpage by the webinject, the webinject content including one or more Hypertext Markup Language (HTML) components. The method can further include, if webinject content is detected, generating a fingerprint for each of the one or more HTML components; transmitting the one or more fingerprints to an external server; and classifying, by the external server, the webinject based on the one or more fingerprints.Type: GrantFiled: June 13, 2023Date of Patent: September 24, 2024Assignee: BitSight Technologies, Inc.Inventor: Tiago Bagulho Monteiro Pereira
-
Patent number: 12099608Abstract: A system and method for setting alert thresholds related to cybersecurity ratings of one or more affiliate entities. An example method includes: obtaining entity data including cybersecurity event data for an affiliate entity; calculating a time-series cybersecurity rating for the affiliate entity based on the entity data; associating an alert reporting threshold with the time-series cybersecurity rating, wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the affiliate entity; applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the affiliate entity; and updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.Type: GrantFiled: June 15, 2023Date of Patent: September 24, 2024Assignee: BitSight Technologies, Inc.Inventors: Marc Noel Light, Tianyi Cai, Thomas Erhardt Montroy
-
Patent number: 12079347Abstract: Methods and systems are provide for assessing the cybersecurity state of entities based on extended-computer network characteristics. A method can include obtaining, for a plurality of computer networks associated with an entity and not associated with the entity, a first and second network dataset. The first and second network datasets can be combined. A plurality of Internet Protocol (IP) addresses associated with the entity and associated with a plurality of entities can be obtained, where the entity and the plurality of entities each associated with a unique identifier (UID). The method can include determining whether each of the plurality of computer networks not associated with the entity comprises a remote office network. A cybersecurity state of the entity can be determined based on an evaluation of security characteristics of the IP addresses associated with the entity and of one or more IP addresses attributed to the remote office networks.Type: GrantFiled: March 31, 2022Date of Patent: September 3, 2024Assignee: BitSight Technologies, Inc.Inventors: Daniel Dahlberg, Stephen Boyer, Philip John Steuart Gladstone
-
Patent number: 12010137Abstract: A method and system for creating a composite security rating from security characterization data of a third party computer system. The security characterization data is derived from externally observable characteristics of the third party computer system. Advantageously, the composite security score has a relatively high likelihood of corresponding to an internal audit score despite use of externally observable security characteristics. Also, the method and system may include use of multiple security characterizations all solely derived from externally observable characteristics of the third party computer system.Type: GrantFiled: August 22, 2023Date of Patent: June 11, 2024Assignee: BitSight Technologies, Inc.Inventors: Stephen Wayne Boyer, Nagarjuna Venna, Megumi Ando
-
Patent number: 11956265Abstract: A number of techniques facilitate generation of data points from observations about network traffic. An inferencing system can use these data points to determine whether a relationship exists between two entities or whether an existing relationship has terminated, without any external knowledge of the existence of or termination of such a relationship.Type: GrantFiled: August 23, 2019Date of Patent: April 9, 2024Assignee: BitSight Technologies, Inc.Inventor: Daniel Dahlberg
-
Patent number: 11949655Abstract: Disclosed are computer-implemented methods for ranking importance of assets of an entity, in which the assets can include hosts and/or IP addresses associated with the entity. The exemplary methods can include receiving datasets from one or more sources indicating frequency of system access, system configuration, and/or application configuration. The methods can include determining one or more input data based on the datasets. The methods can include determining, for each host and/or IP address associated with the entity, an importance ranking based on the input data. In some examples, the importance ranking may be based on a weighting of two or more input data.Type: GrantFiled: May 14, 2021Date of Patent: April 2, 2024Assignee: BitSight Technologies, Inc.Inventor: Daniel Dahlberg
-
Patent number: 11882146Abstract: A method and system for creating a composite security rating from security characterization data of a third party computer system. The security characterization data is derived from externally observable characteristics of the third party computer system. Advantageously, the composite security score has a relatively high likelihood of corresponding to an internal audit score despite use of externally observable security characteristics. Also, the method and system may include use of multiple security characterizations all solely derived from externally observable characteristics of the third party computer system.Type: GrantFiled: September 5, 2023Date of Patent: January 23, 2024Assignee: BitSight Technologies, Inc.Inventors: Stephen Wayne Boyer, Nagarjuna Venna, Megumi Ando
-
Patent number: 11783052Abstract: Disclosed herein are computer-implemented methods and systems for forecasting security ratings for an entity. The methods and systems can include generating a plurality of simulated instantiations of a security scenario for the entity, in which the security scenario characterized by a plurality of security events associated with at least one event type. The methods and systems can further include determining a security rating for each instantiation of the plurality of instantiations; and generating a forecast cone based on the determined security ratings for the plurality of instantiations. In some examples, for each event type of the at least one event type, the methods and systems can include determining a rate, duration, and/or temporal placement of the security events associated with the event type over a forecasting period.Type: GrantFiled: November 10, 2021Date of Patent: October 10, 2023Assignee: BitSight Technologies, Inc.Inventors: Marc Noel Light, Liwei Lin, Thomas Erhardt Montroy
-
Patent number: 11777976Abstract: A method and system for creating a composite security rating from security characterization data of a third party computer system. The security characterization data is derived from externally observable characteristics of the third party computer system. Advantageously, the composite security score has a relatively high likelihood of corresponding to an internal audit score despite use of externally observable security characteristics. Also, the method and system may include use of multiple security characterizations all solely derived from externally observable characteristics of the third party computer system.Type: GrantFiled: October 13, 2020Date of Patent: October 3, 2023Assignee: BitSight Technologies, Inc.Inventors: Stephen Wayne Boyer, Nagarjuna Venna, Megumi Ando
-
Patent number: 11777983Abstract: A system for determining an entity's security rating may include a ratings engine and a security database. The security database may include a manifest and a distributed index containing security records. Each of the security records may have a key (e.g., a network identifier of a network asset) and a value (e.g., security information associated with the network asset identified by the key). The keyspace may be partitioned into multiple key ranges. The manifest may contain references to segments of the distributed index. Each segment may be associated with a key range and may index a group of security records having keys within the key range. The manifest and the segments may be stored in an object storage system. The ratings engine may determine the security rating of an entity based on security records of the entity's network assets, which may be retrieved from the database.Type: GrantFiled: January 24, 2023Date of Patent: October 3, 2023Assignee: BitSight Technologies, Inc.Inventors: Ethan Geil, Bryan Turcotte
-
Patent number: 11770401Abstract: Computer-implemented methods are provided herein for quantifying correlated risk in a network of a plurality of assets having at least one dependency, where each asset belongs to at least one entity. The method includes generating a dependency graph based on relationships between the assets, at least one dependency, and at least one entity, and executing a plurality of Monte Carlo simulations over the dependency graph. Executing a plurality of Monte Carlo simulations includes generating a seed event in the dependency graph, where the seed event has a probability distribution, and propagating disruption through the dependency graph based on the seed event. The method further includes assessing loss for each of the assets, and aggregating losses for two or more assets to determine correlated risk in the network.Type: GrantFiled: February 19, 2021Date of Patent: September 26, 2023Assignee: BitSight Technologies, Inc.Inventors: Ethan Geil, Marc Light
-
Publication number: 20230269265Abstract: A cybersecurity risk management method may include recommending, for each of a plurality of affiliates of an entity, a respective cybersecurity criticality tier selected from a set of cybersecurity criticality tiers; receiving user input adjusting and/or adopting the recommended cybersecurity criticality tier for each of the affiliates; assigning each of the affiliates to the respective adjusted or adopted cybersecurity criticality tier; obtaining respective security scores for the affiliates; and displaying a user interface component configured to show a visualization of a cybersecurity risk management plan of the entity with respect to the plurality of affiliates, wherein the risk management plan partitions the affiliates into a plurality of affiliate sets based on the security scores and the assigned cybersecurity criticality tiers of the affiliates and specifies, for each of the affiliate sets, an action to be taken by the entity with respect to the affiliates in the affiliate set.Type: ApplicationFiled: May 1, 2023Publication date: August 24, 2023Applicant: BitSight Technologies, Inc.Inventors: Tianyi Cai, Thomas Erhardt Montroy, Marc Noel Light
-
Patent number: 11727114Abstract: Computer-implemented methods and systems are provided for the detection of software presence remotely through the web browser by detecting the presence of webinjects in a web browser that visits a detection webpage. The methods can include delivering a detection webpage to a web browser, in which the detection webpage has detection code configured to detect a presence of the webinject in the detection webpage; and inspecting, by the detection code, rendering of content of the detection webpage in the browser to detect webinject content in the detection webpage by the webinject, the webinject content including one or more Hypertext Markup Language (HTML) components. The method can further include, if webinject content is detected, generating a fingerprint for each of the one or more HTML components; transmitting the one or more fingerprints to an external server; and classifying, by the external server, the webinject based on the one or more fingerprints.Type: GrantFiled: August 13, 2021Date of Patent: August 15, 2023Assignee: BitSight Technologies, Inc.Inventor: Tiago Bagulho Monteiro Pereira
-
Patent number: 11720679Abstract: A system and method for setting alert thresholds related to cybersecurity ratings of one or more affiliate entities. An example method includes: obtaining entity data including cybersecurity event data for an affiliate entity; calculating a time-series cybersecurity rating for the affiliate entity based on the entity data; associating an alert reporting threshold with the time-series cybersecurity rating, wherein a comparison of the alert reporting threshold to the time-series cybersecurity rating determines a number of alerts reported for the affiliate entity; applying an alternative alert reporting threshold against the time-series cybersecurity rating to determine an alternative number of alerts reported for the affiliate entity; and updating the alert reporting threshold for the time-series cybersecurity rating to the alternative alert reporting threshold.Type: GrantFiled: April 21, 2021Date of Patent: August 8, 2023Assignee: BitSight Technologies, Inc.Inventors: Marc Noel Light, Tianyi Cai, Thomas Erhardt Montroy
-
Patent number: D1010666Type: GrantFiled: November 17, 2021Date of Patent: January 9, 2024Assignee: BitSight Technologies, Inc.Inventors: Tianyi Cai, Thomas Erhardt Montroy, Marc Noel Light, Blythe Meyer, Amanda Ravanesi, Vanessa Jankowski
-
Patent number: D1038972Type: GrantFiled: November 13, 2023Date of Patent: August 13, 2024Assignee: BitSight Technologies, Inc.Inventors: Tianyi Cai, Thomas Erhardt Montroy, Marc Noel Light, Blythe Meyer, Amanda Ravanesi, Vanessa Jankowski
-
Patent number: D1038973Type: GrantFiled: November 13, 2023Date of Patent: August 13, 2024Assignee: BitSight Technologies, Inc.Inventors: Tianyi Cai, Thomas Erhardt Montroy, Marc Noel Light, Blythe Meyer, Amanda Ravanesi, Vanessa Jankowski