US2016026793A1PendingUtilityA1

Threat Condition Management

Assignee: GLOBALFOUNDRIES INCPriority: Aug 29, 2013Filed: Jul 20, 2015Published: Jan 28, 2016
Est. expiryAug 29, 2033(~7.1 yrs left)· nominal 20-yr term from priority
G06F 2221/034G06F 21/554
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, products, apparatuses, and systems may manage a threat condition. A plurality of triggers may be identified over a period of time. Each of the triggers may be associated with a threat risk value. An accumulation value may be determined based on an aggregation of each threat risk value over the period of time. A set of progressive threshold values associated with a set of progressive threat conditions may be defined. A threat condition from the set of threat conditions may be established for the device based on the accumulation value. The threat condition may be managed, for example by defining an operational mode for the device, in response to the threat condition.

Claims

exact text as granted — not AI-modified
1 . An apparatus comprising a processor to:
 identify a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device;   determine an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time;   establish a threat condition based on the accumulation value; and   define an operational mode for the device to manager the threat condition.   
     
     
         2 . The apparatus of  claim 1 , wherein the processor is to generate the suspicion trigger and the calming trigger absent a security request and a security prompt. 
     
     
         3 . The apparatus of  claim 1 , wherein the processor is to generate the suspicion trigger after a preset amount of time that is to indicate persistence of unusual usage of the device. 
     
     
         4 . The apparatus of  claim 1 , wherein the processor is to:
 generate the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device; and   generate the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device.   
     
     
         5 . The apparatus of  claim 1 , wherein the processor is to generate the calming trigger based on a disappearance of the suspicion trigger. 
     
     
         6 . The apparatus of  claim 1 , wherein the processor is to:
 collect data silently that is to indicate a departure from an established usage pattern; and   forward the data unintrusively to one or more of another device of an owner of the device, a device of a designated person, and a device of a designated organization.   
     
     
         7 . The apparatus of  claim 1 , wherein the processor is to:
 determine a correlation among two or more of the triggers; and   apply a weight factor to the accumulation value based on the correlation.   
     
     
         8 . A computer program product comprising:
 a computer readable storage medium; and   computer usable code stored on the computer readable storage medium, where, if executed by a processor, the computer usable code causes a computer to:   identify a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device;   determine an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time;   establish a threat condition based on the accumulation value; and   define an operational mode for the device to manager the threat condition.   
     
     
         9 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger and the calming trigger absent a security request and a security prompt. 
     
     
         10 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger after a preset amount of time that is to indicate persistence of unusual usage of the device. 
     
     
         11 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device, wherein the established usage pattern is to include a geospatial travel pattern, a geospatial location pattern, a device handling pattern, a communication pattern, an audio pattern, and a user recognition pattern. 
     
     
         12 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device. 
     
     
         13 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the calming trigger based on a disappearance of the suspicion trigger. 
     
     
         14 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to:
 collect data silently that is to indicate a departure from an established usage pattern; and   forward the data unintrusively to one or more of another device of an owner of the device, a device of a designated person, and a device of a designated organization.   
     
     
         15 . The computer program product of  claim 14 , wherein the computer usable code, if executed, further causes a computer to forward the data to the designated person based on one or more of a list of contacts, a list of social media friends, a relationship, and a calendar for an authorized user of the device, wherein the designated person is to include an individual that is in a meeting with the authorized user of the device to be identified using the calendar, and wherein the organization is to include a law enforcement agency. 
     
     
         16 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer to:
 determine a correlation among two or more of the triggers; and   apply a weight factor to the accumulation value based on the correlation.   
     
     
         17 . The computer program product of  claim 8 , wherein the computer usable code, if executed, further causes a computer establish the threat condition based on a risk profile, wherein the risk profile is to account for one or more of a device to be used, a usage context, and a usage location. 
     
     
         18 . A method comprising:
 identifying a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device;   determining an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time;   establishing a threat condition based on the accumulation value; and   defining an operational mode for the device to manager the threat condition.   
     
     
         19 . The method of  claim 18 , further including generating the suspicion trigger and the calming trigger absent a security request and a security prompt. 
     
     
         20 . The method of  claim 18 , further including:
 generating the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device; and   generating the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device.

Join the waitlist — get patent alerts

Track US2016026793A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.