Threat Condition Management
Abstract
Methods, products, apparatuses, and systems may manage a threat condition. A plurality of triggers may be identified over a period of time. Each of the triggers may be associated with a threat risk value. An accumulation value may be determined based on an aggregation of each threat risk value over the period of time. A set of progressive threshold values associated with a set of progressive threat conditions may be defined. A threat condition from the set of threat conditions may be established for the device based on the accumulation value. The threat condition may be managed, for example by defining an operational mode for the device, in response to the threat condition.
Claims
exact text as granted — not AI-modified1 . An apparatus comprising a processor to:
identify a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device; determine an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time; establish a threat condition based on the accumulation value; and define an operational mode for the device to manager the threat condition.
2 . The apparatus of claim 1 , wherein the processor is to generate the suspicion trigger and the calming trigger absent a security request and a security prompt.
3 . The apparatus of claim 1 , wherein the processor is to generate the suspicion trigger after a preset amount of time that is to indicate persistence of unusual usage of the device.
4 . The apparatus of claim 1 , wherein the processor is to:
generate the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device; and generate the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device.
5 . The apparatus of claim 1 , wherein the processor is to generate the calming trigger based on a disappearance of the suspicion trigger.
6 . The apparatus of claim 1 , wherein the processor is to:
collect data silently that is to indicate a departure from an established usage pattern; and forward the data unintrusively to one or more of another device of an owner of the device, a device of a designated person, and a device of a designated organization.
7 . The apparatus of claim 1 , wherein the processor is to:
determine a correlation among two or more of the triggers; and apply a weight factor to the accumulation value based on the correlation.
8 . A computer program product comprising:
a computer readable storage medium; and computer usable code stored on the computer readable storage medium, where, if executed by a processor, the computer usable code causes a computer to: identify a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device; determine an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time; establish a threat condition based on the accumulation value; and define an operational mode for the device to manager the threat condition.
9 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger and the calming trigger absent a security request and a security prompt.
10 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger after a preset amount of time that is to indicate persistence of unusual usage of the device.
11 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device, wherein the established usage pattern is to include a geospatial travel pattern, a geospatial location pattern, a device handling pattern, a communication pattern, an audio pattern, and a user recognition pattern.
12 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device.
13 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to generate the calming trigger based on a disappearance of the suspicion trigger.
14 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to:
collect data silently that is to indicate a departure from an established usage pattern; and forward the data unintrusively to one or more of another device of an owner of the device, a device of a designated person, and a device of a designated organization.
15 . The computer program product of claim 14 , wherein the computer usable code, if executed, further causes a computer to forward the data to the designated person based on one or more of a list of contacts, a list of social media friends, a relationship, and a calendar for an authorized user of the device, wherein the designated person is to include an individual that is in a meeting with the authorized user of the device to be identified using the calendar, and wherein the organization is to include a law enforcement agency.
16 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer to:
determine a correlation among two or more of the triggers; and apply a weight factor to the accumulation value based on the correlation.
17 . The computer program product of claim 8 , wherein the computer usable code, if executed, further causes a computer establish the threat condition based on a risk profile, wherein the risk profile is to account for one or more of a device to be used, a usage context, and a usage location.
18 . A method comprising:
identifying a plurality of triggers including a suspicion trigger to indicate suspicious activity for a device and a calming trigger to indicate calming activity for the device; determining an accumulation value based on an aggregation of each suspicion trigger and each calming trigger over a period of time; establishing a threat condition based on the accumulation value; and defining an operational mode for the device to manager the threat condition.
19 . The method of claim 18 , further including generating the suspicion trigger and the calming trigger absent a security request and a security prompt.
20 . The method of claim 18 , further including:
generating the suspicion trigger in response to a departure from an established usage pattern that is to indicate unusual usage of the device; and generating the calming trigger in response to a reversion towards an established usage pattern that is to indicate usual usage of the device.Join the waitlist — get patent alerts
Track US2016026793A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.