Patents by Inventor Johnny Al Shaieb
Johnny Al Shaieb has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20250190579Abstract: Mechanisms are provided for assessing control checks and components of a vulnerability management system (VMS) for a computing infrastructure. A security vulnerability risk gap assessment of the VMS is executed to generate result data for a plurality of control checks. For each control check, the mechanisms: classify the control check into a maturity level having a corresponding maturity level value; classify each of a plurality of vulnerability assessment security control rating (VASCR) elements into a predetermined classification having corresponding classification values for the control check; and combine the maturity level value and the VASCR element classification values to generate a prioritization score. A graphical user interface output is generated comprising a representation of a prioritized ranked listing of control checks based on the prioritization scores associated with each of the control checks in the plurality of control checks.Type: ApplicationFiled: December 12, 2023Publication date: June 12, 2025Inventors: Johnny Al Shaieb, Steven Ocepek, Jason A. Nikolai, Melody Leu, Andrew C. Herlands, Michael Redford, Elio Andres Sanabria Echeverria
-
Patent number: 12326941Abstract: A computer-implemented method for prioritizing exclusion renewal records is disclosed. The computer-implemented method includes determining vulnerability factors associated with a vulnerability exclusion record. The computer-implemented method further includes generating a vulnerability factor score for each vulnerability factor associated with the vulnerability exclusion record based, at least in part, on a level of risk associated with the vulnerability factor. The computer-implemented method further includes generating a vulnerability score for the vulnerability exclusion record based, at least in part, on the vulnerability factor score for each vulnerability factor. The computer-implemented method further includes updating a previous vulnerability score of the vulnerability exclusion record.Type: GrantFiled: January 4, 2022Date of Patent: June 10, 2025Assignee: International Business Machines CorporationInventors: Johnny Al Shaieb, Michael Redford, Jason A. Nikolai, Jason Bornheimer, Steven Ocepek, Robert Maier, Christopher Bedell, Seth Grey Glasgow
-
Patent number: 12058161Abstract: The subject matter herein provides an automated system and method for software patch management that ranks patches at least in part according to a score indicative of a complexity (e.g., cost) of remediating a vulnerability. This score is sometimes referred to herein as a vulnerability remediation complexity (VRC) score. A VRC score provides an objective measure by which an organization can determine which patches are most likely to be successfully applied, thus enabling implementation of a patching strategy that preferentially applies most critical, but less impact (in terms of remediation cost) patches first to remediate as must risk as possible as quickly as possible. Thus, for example, the approach herein enables the patching to focus on vulnerabilities of highest severity and small remediation cost over those, for example, representing lower severity and higher remediation cost.Type: GrantFiled: February 27, 2020Date of Patent: August 6, 2024Assignee: International Business Machines CorporationInventors: Johnny Al Shaieb, Jason A. Nikolai, Michael Redford, Steven Ocepek, Jason Bornheimer, Robert Maier
-
Publication number: 20230214495Abstract: A computer-implemented method for prioritizing exclusion renewal records is disclosed. The computer-implemented method includes determining vulnerability factors associated with a vulnerability exclusion record. The computer-implemented method further includes generating a vulnerability factor score for each vulnerability factor associated with the vulnerability exclusion record based, at least in part, on a level of risk associated with the vulnerability factor. The computer-implemented method further includes generating a vulnerability score for the vulnerability exclusion record based, at least in part, on the vulnerability factor score for each vulnerability factor. The computer-implemented method further includes updating a previous vulnerability score of the vulnerability exclusion record.Type: ApplicationFiled: January 4, 2022Publication date: July 6, 2023Inventors: Johnny Al Shaieb, Michael Redford, Jason A. Nikolai, Jason Bornheimer, Steven Ocepek, Robert Maier, Christopher Bedell, Seth Grey Glasgow
-
Publication number: 20210273968Abstract: The subject matter herein provides an automated system and method for software patch management that ranks patches at least in part according to a score indicative of a complexity (e.g., cost) of remediating a vulnerability. This score is sometimes referred to herein as a vulnerability remediation complexity (VRC) score. A VRC score provides an objective measure by which an organization can determine which patches are most likely to be successfully applied, thus enabling implementation of a patching strategy that preferentially applies most critical, but less impact (in terms of remediation cost) patches first to remediate as must risk as possible as quickly as possible. Thus, for example, the approach herein enables the patching to focus on vulnerabilities of highest severity and small remediation cost over those, for example, representing lower severity and higher remediation cost.Type: ApplicationFiled: February 27, 2020Publication date: September 2, 2021Applicant: International Business Machines CorporationInventors: Johnny Al Shaieb, Jason A. Nikolai, Michael Redford, Steven Ocepek, Jason Bornheimer, Robert Maier
-
Patent number: 11048803Abstract: A method, apparatus, system, and computer program product for operating a portable security testing device. The portable security testing device is configured by computer system with an operating system and a starting set of security testing tools. A selected set of the security testing tools is determined by the computer system for the portable security testing device based on information collected about a target by the portable security testing device. The starting set of the security testing tools in the portable security testing device is changed by the computer system to form a current set of the security testing tools in response to the starting set of the security testing tools being different from the selected set of the security testing tools, wherein the current set of the security testing tools operate to perform security tests on the target.Type: GrantFiled: May 8, 2019Date of Patent: June 29, 2021Assignee: International Business Machines CorporationInventors: Jason A. Nikolai, Steven Ocepek, Johnny Al Shaieb
-
Publication number: 20200356674Abstract: A method, apparatus, system, and computer program product for operating a portable security testing device. The portable security testing device is configured by computer system with an operating system and a starting set of security testing tools. A selected set of the security testing tools is determined by the computer system for the portable security testing device based on information collected about a target by the portable security testing device. The starting set of the security testing tools in the portable security testing device is changed by the computer system to form a current set of the security testing tools in response to the starting set of the security testing tools being different from the selected set of the security testing tools, wherein the current set of the security testing tools operate to perform security tests on the target.Type: ApplicationFiled: May 8, 2019Publication date: November 12, 2020Inventors: Jason A. Nikolai, Steven Ocepek, Johnny Al Shaieb