发明名称 Security risk aggregation and analysis
摘要 Methods and apparatuses, including computer program products, are described for transaction-based security risk aggregation and analysis. A server computing device receives security risk data elements from a plurality of data sources. The security risk data elements correspond to a transaction submitted by a remote computing device to the server computing device for execution. The server computing device aggregates the security risk data elements into a weighted risk matrix and generates a risk score for the submitted transaction based upon the weighted risk matrix. The server computing device determines a business-level context and an execution priority of the submitted transaction, the business-level context and the execution priority based upon the security risk data elements. The server computing device adjusts the risk score for the submitted transaction based upon the business-level context and the execution priority and determines whether to allow execution of the transaction based upon the adjusted risk score.
申请公布号 US8966640(B1) 申请公布日期 2015.02.24
申请号 US201414341209 申请日期 2014.07.25
申请人 FMR LLC 发明人 Peddada Chalam;Kulkarni Rajandra Laxman
分类号 G06F12/14;G06F21/55 主分类号 G06F12/14
代理机构 Proskauer Rose LLP 代理人 Proskauer Rose LLP
主权项 1. A computerized method for transaction-based security risk aggregation and analysis, the method comprising: receiving, by a server computing device, security risk data elements from a plurality of data sources, the security risk data elements corresponding to a transaction submitted by a remote computing device to the server computing device for execution; aggregating, by the server computing device, the security risk data elements into a weighted risk matrix; generating, by the server computing device, a risk score for the submitted transaction based upon the weighted risk matrix; determining, by the server computing device, a business-level context and an execution priority of the submitted transaction, the business-level context and the execution priority based upon the security risk data elements; adjusting, by the server computing device, the risk score for the submitted transaction based upon the business-level context and the execution priority; determining, by the server computing device, whether to allow execution of the transaction based upon the adjusted risk score; storing, by the server computing device, the security risk data elements, the business-level context, the execution priority, and the adjusted risk score for the transaction in a database; and using, by the server computing device, the stored security risk data elements, the business-level context, the execution priority, and the adjusted risk score to determine whether to allow execution of future transactions.
地址 Boston MA US