System and methods for minimizing organization risk from users associated with a password breach
Abstract
System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek to reduce risk by training staff for this specific issue in a timely and appropriate manner to significantly reduce the risk of a future breach by those identified users. Training can be customized and targeted at those users who attempt to use passwords that have been associated with a breach (either of their own account or of another account on the same or related domain.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
accessing, by one or more processors, passwords used by a plurality of users; determining, by the one or more processors, use of a same password across the plurality of users; modifying, by the one or more processors responsive to the determination, a risk score of the plurality of users; and providing, by the one or more processors, an electronic training to one or more of the plurality of users, the electronic training configured to provide training on using passwords based at least on the determination.
2 . The method of claim 1 , further comprising accessing, by the one or more processors, the passwords stored in a user passwords storage.
3 . The method of claim 1 , further comprising determining, by the one or more processors, use of the same password across the plurality of users over time.
4 . The method of claim 1 , further comprising determining, by the one or more processors, concurrent use of the same password across the plurality of users over time.
5 . The method of claim 1 , further comprising determining, by the one or more processors, use of the same password across the plurality of users over different periods of time.
6 . The method of claim 1 , further comprising creating, by the one or more processors, a policy to prevent a user from setting a specific password.
7 . The method of claim 1 , further comprising creating, by the one or more processors, a policy to prevent a user from using the same password.
8 . The method of claim 1 , further comprising creating, by the one or more processors, a policy to prevent a user from using a password used by another user at any time in the past.
9 . The method of claim 1 , further comprising creating, by the one or more processors, a policy to prevent a user from using a password used by another user a period of time in the past.
10 . The method of claim 1 , further comprising modifying, by the one or more processors responsive to the determination, an entity risk score of an entity associated with the plurality of users.
11 . The method of claim 1 , further comprising determining, by the one or more processors, the one or more users used the same password associated with a breach related to another one or more users of one of a same or a related domain.
12 . A system comprising:
one or more processors, coupled to memory and configured to: access passwords used by a plurality of users; determine use of a same password across the plurality of users; modify, responsive to the determination, a risk score of the plurality of users; and provide an electronic training to one or more of the plurality of users, the electronic training configured to provide training on using passwords based at least on the determination.
13 . The system of claim 12 , wherein the one or more processors are further configured to access the passwords stored in a user passwords storage.
14 . The system of claim 12 , wherein the one or more processors are further configured to determine use of the same password across the plurality of users over time.
15 . The system of claim 12 , wherein the one or more processors are further configured to determine concurrent use of the same password across the plurality of users over time.
16 . The system of claim 12 , wherein the one or more processors are further configured to determine use of the same password across the plurality of users over different periods of time.
17 . The system of claim 12 , wherein the one or more processors are further configured to create a policy to prevent a user from setting a specific password.
18 . The system of claim 12 , wherein the one or more processors are further configured to create a policy to prevent a user from using the same password.
19 . The system of claim 12 , wherein the one or more processors are further configured to create a policy to prevent a user from using a password used by another user at any time in the past.
20 . The system of claim 12 , wherein the one or more processors are further configured to create a policy to prevent a user from using a password used by another user a period of time in the past.
21 . The system of claim 12 , further comprising modifying, by the one or more processors responsive to the determination, an entity risk score of an entity associated with the plurality of users.
22 . The system of claim 12 , further comprising determining, by the one or more processors, the one or more users used the same password associated with a breach related to another one or more users of one of a same or a related domain.Join the waitlist — get patent alerts
Track US2022292181A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.