Building management system with cyber health dashboard
Abstract
A method for automatically detecting and mitigating risks related to cybersecurity in a Building Management System (BMS) includes evaluating settings of a user account of the BMS; identifying a security risk associated with the settings of the user account; evaluating settings of a network device of the BMS; identifying another security risk associated with the settings of the network device, presenting a user interface, wherein the user interface allows a user to view a policy recommendation associated with either security risk; and implementing the change in the settings of the user account or a change in the settings of the network device based at least in part on an input from the user via the user interface or an automated response to the policy recommendation. The method allows for administrators to easily view and change settings of user accounts and network devices to improve the cybersecurity of the BMS.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for automatically detecting and mitigating risks related to cybersecurity in a Building Management System (BMS), the method comprising:
identifying a first security risk associated with a user account; identifying a second security risk associated with a network device; presenting a user interface to a user on a user device identifying the first security risk and the second security risk and classifying the first security risk and the second security risk by risk type.
22 . The method of claim 21 , further comprising:
implementing a change in the user account or a change in the network device within the BMS based at least in part on an input received from the user via the user interface or an automated response to a policy recommendation. The method of claim 1 , wherein identifying the first security risk comprises at least one selected from a group of: determining that the user account has an inactive session without a session timeout period; determining that the user account has a password that does not expire; determining that the user account does not have a password history policy; determining that the user account does not have lockout settings; determining that the user account has a lockout policy that has a number of attempts greater than a first threshold or a lockout time greater than a second threshold; determining that the user account is dormant; determining that the user account has a maximum password age greater than a third threshold; determining that the user account has an inactive session period greater than a fourth threshold; and determining that the user account is a temporary user account.
23 . The method of claim 21 , wherein the first security risk is more severe than the second security risk, the method further comprising:
presenting, on the user interface, the first security risk as a critical issue; and presenting, on the user interface, the second security risk as a potential risk.
24 . The method of claim 21 , wherein identifying the second security risk comprises determining that the network device is running outdated software.
25 . The method of claim 21 , wherein the network device comprises a server of the BMS.
26 . The method of claim 21 , further comprising presenting, on the user interface, a graph of user activity within the BMS over a period of time, the graph showing at least one selected from a group of:
a number of successful logins; a number of unsuccessful logins; and a number of locked out accounts.
27 . The method of claim 21 , further comprising presenting, on the user interface, an assessment of all user accounts associated with the BMS and an assessment of all network devices associated with the BMS.
28 . The method of claim 21 , further comprising implementing a change in settings of the user account comprising at least one selected from a group of implementing a change in password policy settings of the user account and implementing a change in lockout settings of the user account.
29 . The method of claim 21 , further comprising presenting, on the user interface, a dialog box associated with the user account that allows the user to navigate to a user account page associated with the user account.
30 . The method of claim 21 , further comprising implementing a change in settings of the network device comprising receiving a software update.
31 . A Building Management System (BMS), comprising:
one or more processors; and one or more computer-readable storage media having instructions stored thereon that, when executed by the one or more processors, cause the one or more processors to implement operations comprising: evaluating settings of a user account of the BMS; identifying a first security risk associated with the settings of the user account; evaluating settings of a network device of the BMS; identifying a second security risk associated with the settings of the network device; presenting a user interface to a user on a user device, wherein the user interface allows the user to view a policy recommendation associated with the first security risk or the second security risk, wherein the user interface identifies the first security risk and the second security risk and classifies the first security risk and the second security risk by risk type.
32 . The system of claim 31 , wherein identifying the first security risk comprises at least one selected from a group of:
determining that the user account has an inactive session without a session timeout period; determining that the user account has a password that does not expire; determining that the user account does not have a password history policy; and determining that the user account does not have lockout settings.
33 . The system of claim 31 , wherein identifying the first security risk comprises at least one selected from a group of:
determining that the user account has a lockout policy that has a number of attempts greater than a first threshold or a lockout time greater than a second threshold; determining that the user account is dormant; determining that the user account has a maximum password age greater than a third threshold; determining that the user account has an inactive session period greater than a fourth threshold; and determining that the user account is a temporary user account.
34 . The system of claim 31 , wherein identifying the second security risk comprises determining that the network device is running outdated software.
35 . The system of claim 31 , wherein the first security risk is less severe than the second security risk, the operations further comprising:
presenting, on the user interface, the first security risk as a potential risk; and presenting, on the user interface, the second security risk as a critical issue.
36 . The system of claim 31 , further comprising presenting, on the user interface, a graph of user activity within the BMS over a period of time, the graph showing at least one selected from a group of:
a number of successful logins; a number of unsuccessful logins; and a number of locked out accounts.
37 . The system of claim 31 , further comprising presenting, on the user interface, an assessment of all user accounts associated with the BMS and an assessment of all network devices associated with the BMS.
38 . The system of claim 31 , wherein implementing the change in the settings of the user account comprises at least one selected from a group of receiving a change in password policy settings of the user account and receiving a change in lockout settings of the user account.
39 . The system of claim 31 , the operations further comprising presenting, on the user interface, a dialog box associated with the user account that allows the user to navigate to a user account page associated with the user account.
40 . A server for a Building Management System (BMS), the server comprising:
one or more processors configured to implement operations comprising:
identifying a first security risk associated with a user account;
identifying a second security risk of a network device;
presenting a user interface to a user on a user device, wherein the user interface identifies the first security risk and the second security risk and classifies the first security risk and the second security risk by risk type.Join the waitlist — get patent alerts
Track US2024045972A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.