US2018307843A1PendingUtilityA1

Systems and methods for implementing modular computer system security solutions

Assignee: ARK NETWORK SECURITY SOLUTIONS LLCPriority: Oct 11, 2013Filed: Nov 13, 2017Published: Oct 25, 2018
Est. expiryOct 11, 2033(~7.2 yrs left)· nominal 20-yr term from priority
G06F 21/577G06Q 10/0635
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In some embodiments, an apparatus includes a control chain generation module is configured to receive, from a control database, a security guideline control to be implemented with respect to a hardware asset. The control chain generation module is configured to select, based on requirements to satisfy the security guideline and attributes of the hardware asset, a security implementation control. The control chain generation module is configured to select a control assessor to monitor the compliance of the hardware asset with the security guideline and is configured to define a control chain including the security guideline control, the security implementation control, and the control assessor. The control chain generation module is configured to send an instruction to apply the control chain to the hardware asset such that the control assessor monitors the hardware asset for compliance with the security guideline.

Claims

exact text as granted — not AI-modified
1 . An apparatus, comprising:
 a memory; and   a processor operatively coupled to the memory, the processor configured to receive an indication of a human-readable guideline, the processor configured to translate the indication of the human-readable guideline into a guideline control data structure,   the processor configured to receive, from a first user, a computer-implemented implementation control used to satisfy the human-readable guideline, the processor configured to associate the computer-implemented implementation control with the guideline control data structure,   the processor configured to receive, from a second user, an assessor control used to monitor an asset's compliance with the human-readable guideline, the processor configured to associate the assessor control with the computer-implemented implementation control and the guideline control data structure to define a control chain,   the processor configured to receive, from a third user, a request for a solution associated with the human-readable guideline, the processor configured to provide the control chain to the third user such that the third user can implement the control chain at a hardware asset associated with the third user.   
     
     
         2 . The apparatus of  claim 1 , wherein the processor is configured to store the control chain in a control catalogue database accessible by the first user, the second user and the third user. 
     
     
         3 . The apparatus of  claim 1 , wherein the processor is configured to provide a plurality of control chains for a selection by the third user, each control chain from the plurality of control chains includes a control chain ranking for that control chain from at least one of the first user or the second user. 
     
     
         4 . The apparatus of  claim 1 , wherein the processor is configured to translate the indication of the human-readable guideline into the guideline control data structure having a markup language format. 
     
     
         5 . The apparatus of  claim 1 , wherein the processor is configured to provide the control chain to the third user such that the computer-implemented implementation control is implemented at the hardware asset to improve a security function of the hardware asset and the assessor control is implemented to monitor the hardware asset based on the guideline control data structure for compliance with the human-readable guideline. 
     
     
         6 . The apparatus of  claim 1 , wherein the processor is configured to receive, from the third user and in response to the processor providing the control chain to the third user, an evaluation of at least one of the computer-implemented implementation control or the assessor control. 
     
     
         7 . The apparatus of  claim 1 , wherein the processor is configured to recommend the control chain to the third user in response to the request for the solution based on at least one of a reputation of the first user or a reputation of the second user. 
     
     
         8 . The apparatus of  claim 1 , wherein the processor is configured to provide the control chain to the third user such that the computer-implemented implementation control is added to at least one of software on the hardware asset or firmware on the hardware asset. 
     
     
         9 . The apparatus of  claim 1 , wherein the processor is configured to recommend the control chain to the third user in response to the request for the solution based on a rating associated with at least one of the computer-implemented implementation control or the assessor control. 
     
     
         10 . The apparatus of  claim 1 , wherein the processor is configured to associate the computer-implemented implementation control with the assessor control based on both the computer-implemented implementation control and the assessor control being associated with the guideline control data structure. 
     
     
         11 . The apparatus of  claim 1 , wherein the processor is configured to verify that the assessor control sufficiently evaluates a health of the computer-implemented implementation control. 
     
     
         12 . A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:
 receive an indication of a human-readable guideline;   translate the indication of the human-readable guideline into a machine-readable guideline control data structure;   extract a set of parameters associated with the human-readable guideline from the machine-readable guideline control data structure;   receive, from a first user, an implementation control used to aid in satisfying the set of parameters;   receive an assessor control used to verify that the set of parameters are satisfied;   define a control chain including the machine-readable guideline control data structure, the implementation control and the assessor control, based on an association with the human-readable guideline; and   send the control chain to a hardware asset associated with a second user such that the implementation control is implemented at the hardware asset to improve a security function and the assessor control is implemented at the hardware asset to monitor for compliance with the set of parameters.   
     
     
         13 . The non-transitory processor-readable medium of  claim 12 , wherein the set of parameters associated with the human-readable guideline include at least one of a rule or an attribute associated with the human-readable guideline. 
     
     
         14 . The non-transitory processor-readable medium of  claim 12 , wherein the assessor control is received from a third user different from the first user and the second user. 
     
     
         15 . The non-transitory processor-readable medium of  claim 12 , further comprising code to cause the processor to:
 store the control chain in a memory of an aggregated control catalogue such that users accessing the aggregated control catalogue can identify the control chain as a solution to satisfy the human-readable guideline.   
     
     
         16 . The non-transitory processor-readable medium of  claim 12 , wherein the code to cause the processor to send includes code to cause the processor to send the control chain to a private control catalogue associated with the second user. 
     
     
         17 . A method, comprising:
 receiving an indication of a human-readable guideline;   translating the indication of the human-readable guideline into a machine-readable guideline control data structure;   extracting a set of parameters associated with the human-readable guideline from the machine-readable guideline control data structure;   generating, using the set of parameters as an input to an algorithm, an implementation control;   receiving an assessor control used to verify that the human-readable guideline is satisfied;   defining a control chain including the machine-readable guideline control data structure, the implementation control and the assessor control based on an association with the human-readable guideline;   storing the control chain in a control catalogue database accessible by a plurality of users;   receiving, at a processor associated with the control catalogue database and from a user from the plurality of users, a request for a solution satisfying the human-readable guideline; and   sending, from the processor and in response to the request, the implementation control and the assessor control to a compute device associated with the user such that the implementation control is implemented at a hardware asset associated with the user to improve a security function and the assessor control is implemented at the hardware asset to monitor the for compliance with the human-readable guideline.   
     
     
         18 . The method of  claim 17 , wherein the user is a first user from the plurality of users, the receiving the assessor control is from a second user from the plurality of users and different from the first user. 
     
     
         19 . The method of  claim 17 , wherein the translating includes translating the indication of the human-readable guideline into the machine-readable guideline control data structure having a markup language format. 
     
     
         20 . The method of  claim 17 , wherein the sending includes sending the implementation control to the compute device such that the implementation control is added to at least one of software on the hardware asset or firmware on the hardware asset.

Join the waitlist — get patent alerts

Track US2018307843A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.