Patents Assigned to SECURITYMETRICS, INC.
-
Patent number: 12015627Abstract: A method to monitor integrity of webpages. The method may include obtaining a destination of outgoing network traffic resulting from rendered code of a webpage. The rendered code may be generated using source code of the webpage that is obtained in response to a request to a webserver that hosts the webpage. The method may also include obtaining a previous destination of previous outgoing network traffic resulting from previous rendered code of the webpage. The previous rendered code may be generated before the request is sent to the webserver for the source code used to generate the rendered code. The method may also include comparing the destination and the previous destination to determine a change in integrity of security of the webpage. In response to the change in the integrity of security of the webpage, an alert regarding the integrity of security of the webpage may be generated.Type: GrantFiled: July 20, 2023Date of Patent: June 18, 2024Assignee: SecurityMetrics, Inc.Inventor: Aaron Willis
-
Patent number: 11934463Abstract: Methods for identifying potentially sensitive information and protecting such potentially sensitive information include scanning systems that collect and/or disseminate such information. Without limitation, systems collect and/or disseminate personal identification numbers (e.g., personal identification numbers, tax identification numbers, etc.), such as merchant systems, bank systems, healthcare systems, and the like, that collect, use, or disseminate sensitive information may be scanned to identify sequences of data that are likely to be sensitive, and may take actions to protect such sequences of data. Scanning and protection systems are also disclosed.Type: GrantFiled: November 9, 2021Date of Patent: March 19, 2024Assignee: SecurityMetrics, Inc.Inventors: Bradley R. Caldwell, Alan B. Butt
-
Patent number: 11704672Abstract: A data string that includes potentially sensitive information, such as an account number for a payment card, may be evaluated to determine whether or not any portion of the data string encodes a known identifier of sensitive information, such as a known bank identification number (BIN). A fixed number of bytes of the data string may be analyzed using a trie algorithm, in which the value of a first byte is compared with the value of a corresponding first character of the known identifier. A second byte is then compared with a set of values of corresponding second characters, which accompany the first character of the known identifier. Then the value of a third byte of the data string is compared with a set of values of corresponding third values, which accompany the first and second characters of the known identifier. The use of a trie algorithm decreases the length of the search process by several orders of magnitude.Type: GrantFiled: June 9, 2020Date of Patent: July 18, 2023Assignee: SecurityMetrics, Inc.Inventor: Alan B. Butt
-
Patent number: 11500979Abstract: A method to monitor integrity of webpages. The method includes obtaining rendered code generated using source code of a webpage from a server that hosts the webpage and using remotely called code referenced in the source code, the rendered code used to display the webpage. The method also includes determining a difference between the rendered code and previous rendered code of the webpage. The previous rendered code may be generated before obtaining the rendered code. The method further includes analyzing the difference between the rendered code and the previous rendered code to determine a change in integrity of security of the webpage and in response to a change in the integrity of security of the webpage, generating an alert regarding the integrity of security of the webpage that may indicate the integrity of the webpage may have changed.Type: GrantFiled: May 10, 2019Date of Patent: November 15, 2022Assignee: SecurityMetrics, Inc.Inventor: Aaron Willis
-
Patent number: 11368477Abstract: A method to monitor integrity of webpages. The method may include obtaining a destination of outgoing network traffic resulting from rendered code of a webpage. The rendered code may be generated using source code of the webpage that is obtained in response to a request to a webserver that hosts the webpage. The method may also include obtaining a previous destination of previous outgoing network traffic resulting from previous rendered code of the webpage. The previous rendered code may be generated before the request is sent to the webserver for the source code used to generate the rendered code. The method may also include comparing the destination and the previous destination to determine a change in integrity of security of the webpage. In response to the change in the integrity of security of the webpage, an alert regarding the integrity of security of the webpage may be generated.Type: GrantFiled: May 13, 2019Date of Patent: June 21, 2022Assignee: SecurityMetrics, Inc.Inventor: Aaron Willis
-
Patent number: 11170052Abstract: Methods for identifying potentially sensitive information and protecting such potentially sensitive information include scanning systems that collect and/or disseminate such information. Without limitation, systems collect and/or disseminate personal identification numbers (e.g., personal identification numbers, tax identification numbers, etc.), such as merchant systems, bank systems, healthcare systems, and the like, that collect, use, or disseminate sensitive information may be scanned to identify sequences of data that are likely to be sensitive, and may take actions to protect such sequences of data. Scanning and protection systems are also disclosed.Type: GrantFiled: September 17, 2019Date of Patent: November 9, 2021Assignee: SecurityMetrics, Inc.Inventors: Bradley R. Caldwell, Alan B. Butt
-
Patent number: 11012464Abstract: A method to assess network vulnerabilities of devices may include accessing, by a relay device, a network that includes a firewall to separate the network from external networks such that the relay device is coupled to the network from behind the firewall attached to the network. The method may further include establishing a communication channel over a secondary network between the relay device and a monitor system. The method may further include detecting one or more devices behind the firewall attached to the network by the relay device. The method may also include after establishing the communication channel and detecting the one or more devices and while the relay device is coupled to the network from behind the firewall attached to the network, performing, by the monitor system, one or more network vulnerability assessments on the one or more devices via network communications that pass through the relay device.Type: GrantFiled: April 5, 2019Date of Patent: May 18, 2021Assignee: SecurityMetrics, Inc.Inventors: Brad Caldwell, Ken Lawrence, R. Trent Gundersen
-
Patent number: 10679218Abstract: A data string that includes potentially sensitive information, such as an account number for a payment card, may be evaluated to determine whether or not any portion of the data string encodes a known identifier of sensitive information, such as a known bank identification number (BIN). A fixed number of bytes of the data string may be analyzed using a trie algorithm, in which the value of a first byte is compared with the value of a corresponding first character of the known identifier. A second byte is then compared with a set of values of corresponding second characters, which accompany the first character of the known identifier. Then the value of a third byte of the data string is compared with a set of values of corresponding third values, which accompany the first and second characters of the known identifier. The use of a trie algorithm decreases the length of the search process by several orders of magnitude.Type: GrantFiled: May 31, 2011Date of Patent: June 9, 2020Assignee: SecurityMetrics, Inc.Inventor: Alan B. Butt
-
Patent number: 10417283Abstract: Methods for identifying potentially sensitive information and protecting such potentially sensitive information include scanning systems that collect and/or disseminate such information. Without limitation, systems collect and/or disseminate personal identification numbers (e.g., personal identification numbers, tax identification numbers, etc.), such as merchant systems, bank systems, healthcare systems, and the like, that collect, use, or disseminate sensitive information may be scanned to identify sequences of data that are likely to be sensitive, and may take actions to protect such sequences of data. Scanning and protection systems are also disclosed.Type: GrantFiled: July 14, 2017Date of Patent: September 17, 2019Assignee: Securitymetrics, Inc.Inventors: Bradley R. Caldwell, Alan B. Butt
-
Patent number: 10298611Abstract: A method to assess network vulnerabilities of devices may include accessing, by a relay device, a network that includes a firewall to separate the network from external networks such that the relay device is coupled to the network from behind the firewall attached to the network. The method may further include establishing a communication channel over a secondary network between the relay device and a monitor system. The method may further include detecting one or more devices behind the firewall attached to the network by the relay device. The method may also include after establishing the communication channel and detecting the one or more devices and while the relay device is coupled to the network from behind the firewall attached to the network, performing, by the monitor system, one or more network vulnerability assessments on the one or more devices via network communications that pass through the relay device.Type: GrantFiled: December 10, 2018Date of Patent: May 21, 2019Assignee: SecurityMetrics, Inc.Inventors: Brad Caldwell, Ken Lawrence, R. Trent Gundersen
-
Patent number: 10289836Abstract: A method to monitor integrity of webpages. The method includes obtaining rendered code generated using source code of a webpage from a server that hosts the webpage and using remotely called code referenced in the source code, the rendered code used to display the webpage. The method also includes determining a difference between the rendered code and previous rendered code of the webpage. The previous rendered code may be generated before obtaining the rendered code. The method further includes analyzing the difference between the rendered code and the previous rendered code to determine a change in integrity of security of the webpage and in response to a change in the integrity of security of the webpage, generating an alert regarding the integrity of security of the webpage that may indicate the integrity of the webpage may have changed.Type: GrantFiled: May 18, 2018Date of Patent: May 14, 2019Assignee: SecurityMetrics, Inc.Inventor: Aaron Willis
-
Patent number: 8616443Abstract: A data string that includes potentially sensitive information, such as an account number for a payment card, may be evaluated using a delimiter search to provide an increased level of confidence that the data string encodes the sensitive information of interest. A delimiter search may include an evaluation of the bytes adjacent to the beginning and end of the data to determine whether or not those bytes have values that correspond to the values of known delimiters. A data string that is not surrounded by known delimiters may be disregarded (i.e., considered not to comprise sensitive information of interest), while a data string that is surrounded by known delimiters may warrant further evaluation.Type: GrantFiled: May 31, 2011Date of Patent: December 31, 2013Assignee: SecurityMetrics, Inc.Inventors: Alan B. Butt, Nathan K. Stocks
-
Patent number: 8608063Abstract: Potentially sensitive information (e.g., account numbers for payment cards, etc.) may be identified from data by use of an “interval scanning” technique, in which a string of data is evaluated in intervals. When a system employs an interval scanning technique, data is evaluated by analyzing bytes of data in periodic sequence (e.g., every thirteenth byte, etc.), while the bytes between the analyzed bytes are initially ignored. If the value of an analyzed byte corresponds to a character of interest (e.g., a decimal numeral or numeric digit (i.e., a character having a value that corresponds to a base-ten, or Arabic, number, 0, 1, 2, 3, 4, 5, 6, 7, 8, or 9), etc.), that byte is identified as a “base byte,” from which a more focused evaluation (e.g., a byte-by-byte analysis, or sequential analysis, etc.) may then commence.Type: GrantFiled: May 31, 2011Date of Patent: December 17, 2013Assignee: SecurityMetrics, Inc.Inventors: Alan B. Butt, Nathan K. Stocks
-
Publication number: 20120023117Abstract: Potentially sensitive information (e.g., account numbers for payment cards, etc.) may be identified from data by use of an “interval scanning” technique, in which a string of data is evaluated in intervals. When a system employs an interval scanning technique, data is evaluated by analyzing bytes of data in periodic sequence (e.g., every thirteenth byte, etc.), while the bytes between the analyzed bytes are initially ignored. If the value of an analyzed byte corresponds to a character of interest (e.g., a decimal numeral or numeric digit (i.e., a character having a value that corresponds to a base-ten, or Arabic, number, 0, 1, 2, 3, 4, 5, 6, 7, 8, or 9), etc.), that byte is identified as a “base byte,” from which a more focused evaluation (e.g., a byte-by-byte analysis, or sequential analysis, etc.) may then commence.Type: ApplicationFiled: May 31, 2011Publication date: January 26, 2012Applicant: SECURITYMETRICS, INC.Inventors: Alan B. Butt, Nathan K. Stocks
-
Publication number: 20120016896Abstract: A data string that includes potentially sensitive information, such as an account number for a payment card, may be evaluated to determine whether or not any portion of the data string encodes a known identifier of sensitive information, such as a known bank identification number (BIN). A fixed number of bytes of the data string may be analyzed using a trie algorithm, in which the value of a first byte is compared with the value of a corresponding first character of the known identifier. A second byte is then compared with a set of values of corresponding second characters, which accompany the first character of the known identifier. Then the value of a third byte of the data string is compared with a set of values of corresponding third values, which accompany the first and second characters of the known identifier. The use of a trie algorithm decreases the length of the search process by several orders of magnitude.Type: ApplicationFiled: May 31, 2011Publication date: January 19, 2012Applicant: SECURITYMETRICS, INC.Inventor: Alan B. Butt
-
Publication number: 20120016895Abstract: A data string that includes potentially sensitive information, such as an account number for a payment card, may be evaluated using a delimiter search to provide an increased level of confidence that the data string encodes the sensitive information of interest. A delimiter search may include an evaluation of the bytes adjacent to the beginning and end of the data to determine whether or not those bytes have values that correspond to the values of known delimiters. A data string that is not surrounded by known delimiters may be disregarded (i.e., considered not to comprise sensitive information of interest), while a data string that is surrounded by known delimiters may warrant further evaluation.Type: ApplicationFiled: May 31, 2011Publication date: January 19, 2012Applicant: SECURITYMETRICS, INC.Inventors: Alan B. Butt, Nathan K. Stocks