Trust level modifier
Abstract
A computer establishes normal activity levels of a factor associated with an application, system, network, or computing environment. The computer receives rules prescribing the trust levels assigned to users or devices during normal and abnormal activity levels exhibited by the factor. The computer monitors the activity level exhibited by the factor and determines whether the activity is normal or abnormal. If the computer determines that the factor is exhibiting abnormal activity, the computer modifies the trust level of associated users and devices according to the rules. The computer continues to monitor the activity of the factor until the computer determines that normal activity levels of the factor have returned, at which point the computer modifies the trust level of associated users or devices according to the rules.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for trust level modification, the method comprising:
determining a range of values associated with normal activity corresponding to a factor associated with at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; determining a range of values associated with current activity corresponding to the factor associated with the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; determining whether the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor; and based on determining that the range of values associated with current activity corresponding to the factor is not within the range of values associated with normal activity corresponding to the factor, assigning a trust level associated with abnormal activity to at least one of a user and a device, wherein the trust level associated with abnormal activity provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than a trust level associated with normal activity, wherein one or more steps of the above method are performed using one or more computers.
2 . The method of claim 1 , further comprising:
based on determining that the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor, assigning the trust level associated with normal activity to the at least one of: a user and a device, wherein the trust level associated with normal activity provides more access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the trust level associated with abnormal activity.
3 . The method of claim 1 , wherein the step of determining a range of values associated with current activity corresponding to the factor further comprises:
at least one of: (i) measuring one or more values associated with current activity corresponding to the factor for a period of time and (ii) receiving a user input including information detailing the range of values associated with current activity corresponding to the factor.
4 . The method of claim 1 , wherein the step of assigning a trust level associated with abnormal activity to the at least one of: a user and a device further comprises:
assigning at least one of a first trust level and a second trust level, wherein the second trust level provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the first trust level.
5 . The method of claim 4 , wherein the second trust level provides no access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment.
6 . The method of claim 1 , wherein the factor associated with the at least one of: (i) file, (ii) an application, (iii) a system, (iv) a network, and (v) an environment includes at least one of: (1) a number of access requests, (2) a number of failed access requests, (3) a number of failed access requests prior to gaining access, (4) a number of successful access requests, (5) a number of locked out users, (6) a number of users with concurrent access, (7) an overall percentage of registered users with concurrent access, (8) an amount of resource consumption per hour/day/week/year/event, (9) a number of inter-application communications, (10) a type of inter-application communication, (11) a change to security posture of a communicating application, (12) an aggregated threat index, (13) a threat level prescribed by a security operational center, (14) a vulnerability scanning index, and (15) an antivirus activity level.
7 . A computer program product for trust level modification, the computer program product comprising:
one or more computer-readable storage media and program instructions stored on the one or more computer-readable storage media, the program instructions comprising: program instructions to determine a range of values associated with normal activity corresponding to a factor associated with at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; program instructions to determine a range of values associated with current activity corresponding to the factor associated with the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; program instructions to determine whether the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor; and based on determining that the range of values associated with current activity corresponding to the factor is not within the range of values associated with normal activity corresponding to the factor, program instructions to assign a trust level associated with abnormal activity to at least one of a user and a device, wherein the trust level associated with abnormal activity provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than a trust level associated with normal activity.
8 . The computer program product of claim 7 , further comprising:
based on determining that the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor, program instructions to assign the trust level associated with normal activity to the at least one of a user and a device, wherein the trust level associated with normal activity provides more access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the trust level associated with abnormal activity.
9 . The computer program product of claim 7 , wherein the program instructions to determine a range of values associated with current activity corresponding to the factor further comprises:
at least one of: (i) program instructions to measure one or more values associated with current activity corresponding to the factor for a period of time and (ii) program instructions to receive a user input including information detailing the range of values associated with current activity corresponding to the factor.
10 . The computer program product of claim 7 , wherein the program instructions to assign a trust level associated with abnormal activity to the at least one of a user and a device further comprises:
program instructions to assign at least one of a first trust level and a second trust level, wherein the second trust level provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the first trust level.
11 . The computer program product of claim 10 , wherein the second trust level provides no access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment.
12 . The computer program product of claim 7 , wherein the factor associated with the at least one of: (i) file, (ii) an application, (iii) a system, (iv) a network, and (v) an environment includes at least one of: (1) a number of access requests, (2) a number of failed access requests, (3) a number of failed access requests prior to gaining access, (4) a number of successful access requests, (5) a number of locked out users, (6) a number of users with concurrent access, (7) an overall percentage of registered users with concurrent access, (8) an amount of resource consumption per hour/day/week/year/event, (9) a number of inter-application communications, (10) a type of inter-application communication, (11) a change to security posture of a communicating application, (12) an aggregated threat index, (13) a threat level prescribed by a security operational center, (14) a vulnerability scanning index, and (15) an antivirus activity level.
13 . A computer system for trust level modification, the computer system comprising:
one or more computer processors, one or more computer-readable storage media, and program instructions stored on one or more of the computer-readable storage media for execution by at least one of the one or more processors, the program instructions comprising: program instructions to determine a range of values associated with normal activity corresponding to a factor associated with at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; program instructions to determine a range of values associated with current activity corresponding to the factor associated with the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment; program instructions to determine whether the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor; and based on determining that the range of values associated with current activity corresponding to the factor is not within the range of values associated with normal activity corresponding to the factor, program instructions to assign a trust level associated with abnormal activity to at least one of a user and a device, wherein the trust level associated with abnormal activity provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than a trust level associated with normal activity.
14 . The computer system of claim 13 , further comprising:
based on determining that the range of values associated with current activity corresponding to the factor is within the range of values associated with normal activity corresponding to the factor, program instructions to assign the trust level associated with normal activity to the at least one of a user and a device, wherein the trust level associated with normal activity provides more access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the trust level associated with abnormal activity.
15 . The computer system of claim 13 , wherein the program instructions to determine a range of values associated with current activity corresponding to the factor further comprises:
at least one of: (i) program instructions to measure one or more values associated with current activity corresponding to the factor for a period of time and (ii) program instructions to receive a user input including information detailing the range of values associated with current activity corresponding to the factor.
16 . The computer system of claim 13 , wherein the program instructions to assign a trust level associated with abnormal activity to the at least one of a user and a device further comprises:
program instructions to assign at least one of a first trust level and a second trust level, wherein the second trust level provides less access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment than the first trust level.
17 . The computer system of claim 16 , wherein the second trust level provides no access to the at least one of: (i) a file, (ii) an application, (iii) a system, (iv) a network, and (v) a computing environment.
18 . The computer system of claim 13 , wherein the factor associated with the at least one of: (i) file, (ii) an application, (iii) a system, (iv) a network, and (v) an environment includes at least one of: (1) a number of access requests, (2) a number of failed access requests, (3) a number of failed access requests prior to gaining access, (4) a number of successful access requests, (5) a number of locked out users, (6) a number of users with concurrent access, (7) an overall percentage of registered users with concurrent access, (8) an amount of resource consumption per hour/day/week/year/event, (9) a number of inter-application communications, (10) a type of inter-application communication, (11) a change to security posture of a communicating application, (12) an aggregated threat index, (13) a threat level prescribed by a security operational center, (14) a vulnerability scanning index, and (15) an antivirus activity level.Join the waitlist — get patent alerts
Track US2017149828A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.