US2024045972A1PendingUtilityA1

Building management system with cyber health dashboard

Assignee: Johnson Controls Tyco IP Holdings LLPPriority: Aug 28, 2019Filed: Aug 16, 2023Published: Feb 8, 2024
Est. expiryAug 28, 2039(~13.1 yrs left)· nominal 20-yr term from priority
G06F 21/577G06F 9/451G05B 13/02G06F 8/65G06F 21/46G06F 2221/033H04L 63/102G05B 15/02H04L 63/1408H04L 67/12G06F 21/316H04L 67/34H04L 63/1433G05B 2219/2642G05B 2219/163
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for automatically detecting and mitigating risks related to cybersecurity in a Building Management System (BMS) includes evaluating settings of a user account of the BMS; identifying a security risk associated with the settings of the user account; evaluating settings of a network device of the BMS; identifying another security risk associated with the settings of the network device, presenting a user interface, wherein the user interface allows a user to view a policy recommendation associated with either security risk; and implementing the change in the settings of the user account or a change in the settings of the network device based at least in part on an input from the user via the user interface or an automated response to the policy recommendation. The method allows for administrators to easily view and change settings of user accounts and network devices to improve the cybersecurity of the BMS.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for automatically detecting and mitigating risks related to cybersecurity in a Building Management System (BMS), the method comprising:
 identifying a first security risk associated with a user account;   identifying a second security risk associated with a network device;   presenting a user interface to a user on a user device identifying the first security risk and the second security risk and classifying the first security risk and the second security risk by risk type.   
     
     
         22 . The method of  claim 21 , further comprising:
 implementing a change in the user account or a change in the network device within the BMS based at least in part on an input received from the user via the user interface or an automated response to a policy recommendation.   The method of claim  1 , wherein identifying the first security risk comprises at least one selected from a group of:   determining that the user account has an inactive session without a session timeout period;   determining that the user account has a password that does not expire;   determining that the user account does not have a password history policy;   determining that the user account does not have lockout settings;   determining that the user account has a lockout policy that has a number of attempts greater than a first threshold or a lockout time greater than a second threshold;   determining that the user account is dormant;   determining that the user account has a maximum password age greater than a third threshold;   determining that the user account has an inactive session period greater than a fourth threshold; and   determining that the user account is a temporary user account.   
     
     
         23 . The method of  claim 21 , wherein the first security risk is more severe than the second security risk, the method further comprising:
 presenting, on the user interface, the first security risk as a critical issue; and   presenting, on the user interface, the second security risk as a potential risk.   
     
     
         24 . The method of  claim 21 , wherein identifying the second security risk comprises determining that the network device is running outdated software. 
     
     
         25 . The method of  claim 21 , wherein the network device comprises a server of the BMS. 
     
     
         26 . The method of  claim 21 , further comprising presenting, on the user interface, a graph of user activity within the BMS over a period of time, the graph showing at least one selected from a group of:
 a number of successful logins;   a number of unsuccessful logins; and   a number of locked out accounts.   
     
     
         27 . The method of  claim 21 , further comprising presenting, on the user interface, an assessment of all user accounts associated with the BMS and an assessment of all network devices associated with the BMS. 
     
     
         28 . The method of  claim 21 , further comprising implementing a change in settings of the user account comprising at least one selected from a group of implementing a change in password policy settings of the user account and implementing a change in lockout settings of the user account. 
     
     
         29 . The method of  claim 21 , further comprising presenting, on the user interface, a dialog box associated with the user account that allows the user to navigate to a user account page associated with the user account. 
     
     
         30 . The method of  claim 21 , further comprising implementing a change in settings of the network device comprising receiving a software update. 
     
     
         31 . A Building Management System (BMS), comprising:
 one or more processors; and   one or more computer-readable storage media having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to implement operations comprising:   evaluating settings of a user account of the BMS;   identifying a first security risk associated with the settings of the user account;   evaluating settings of a network device of the BMS;   identifying a second security risk associated with the settings of the network device;   presenting a user interface to a user on a user device, wherein the user interface allows the user to view a policy recommendation associated with the first security risk or the second security risk, wherein the user interface identifies the first security risk and the second security risk and classifies the first security risk and the second security risk by risk type.   
     
     
         32 . The system of  claim 31 , wherein identifying the first security risk comprises at least one selected from a group of:
 determining that the user account has an inactive session without a session timeout period;   determining that the user account has a password that does not expire;   determining that the user account does not have a password history policy; and   determining that the user account does not have lockout settings.   
     
     
         33 . The system of  claim 31 , wherein identifying the first security risk comprises at least one selected from a group of:
 determining that the user account has a lockout policy that has a number of attempts greater than a first threshold or a lockout time greater than a second threshold;   determining that the user account is dormant;   determining that the user account has a maximum password age greater than a third threshold;   determining that the user account has an inactive session period greater than a fourth threshold; and   determining that the user account is a temporary user account.   
     
     
         34 . The system of  claim 31 , wherein identifying the second security risk comprises determining that the network device is running outdated software. 
     
     
         35 . The system of  claim 31 , wherein the first security risk is less severe than the second security risk, the operations further comprising:
 presenting, on the user interface, the first security risk as a potential risk; and   presenting, on the user interface, the second security risk as a critical issue.   
     
     
         36 . The system of  claim 31 , further comprising presenting, on the user interface, a graph of user activity within the BMS over a period of time, the graph showing at least one selected from a group of:
 a number of successful logins;   a number of unsuccessful logins; and   a number of locked out accounts.   
     
     
         37 . The system of  claim 31 , further comprising presenting, on the user interface, an assessment of all user accounts associated with the BMS and an assessment of all network devices associated with the BMS. 
     
     
         38 . The system of  claim 31 , wherein implementing the change in the settings of the user account comprises at least one selected from a group of receiving a change in password policy settings of the user account and receiving a change in lockout settings of the user account. 
     
     
         39 . The system of  claim 31 , the operations further comprising presenting, on the user interface, a dialog box associated with the user account that allows the user to navigate to a user account page associated with the user account. 
     
     
         40 . A server for a Building Management System (BMS), the server comprising:
 one or more processors configured to implement operations comprising:
 identifying a first security risk associated with a user account; 
 identifying a second security risk of a network device; 
 presenting a user interface to a user on a user device, wherein the user interface identifies the first security risk and the second security risk and classifies the first security risk and the second security risk by risk type.

Join the waitlist — get patent alerts

Track US2024045972A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.