Method and system for assessing cyber resilience
Patent Information
- Application Number
- KR1020250167064
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-11-07
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2045-11-07
Smart Images

Figure 112025124489425-PAT00005_ABST
Abstract
Description
Technology Field
[0001] A method and system for evaluating cyber resilience are disclosed. More specifically, the present disclosure relates to a method for evaluating the cyber resilience of a specific system and a system to which the method is applied. Background Technology
[0002] Recent cyberattacks have been exhibiting complex and sophisticated characteristics in terms of attack organizations, targets, methods, and fields. Going beyond the mere infringement of individual rights or information assets, the scope of damage and impact have reached a severe level, threatening the national economy and triggering social disruption and inter-state conflicts. In this environment, cyberspace is becoming increasingly closely connected to the physical world and is evolving into a Cyber-Physical Domain where it is impossible to perfectly protect all assets from every threat.
[0003] Existing cyber resilience assessments have primarily focused on the core functions and missions of key assets, remaining at the level of discovering vulnerabilities and analyzing and evaluating damage through automated penetration tests based on simple risk analysis centered on known vulnerabilities. Consequently, there was a limitation in that it was difficult to move beyond a checklist-based evaluation system that assessed only incident response capabilities rather than actual resilience levels.
[0004] Accordingly, an intelligent risk analysis system capable of encompassing new forms of attacks, such as unknown vulnerabilities or AI-based threats, and a customized evaluation item system reflecting the characteristics of each organization and industry are required. The problem to be solved
[0005] The technical problem to be achieved through some embodiments of the present disclosure is to provide a method for establishing different resilience evaluation criteria depending on the scale and industry of the system being evaluated.
[0006] Another technical objective to be achieved through some embodiments of the present disclosure is to provide a method for normalizing non-quantitative evaluation indicators for the cyber resilience of a system under evaluation.
[0007] Another technical objective to be achieved through some embodiments of the present disclosure is to provide a method for determining the weight of each metric of a quantitative evaluation indicator for the cyber resilience of a system under evaluation.
[0008] The technical problems of the present disclosure are not limited to those mentioned above, and other unmentioned technical problems will be clearly understood by those skilled in the art from the description below. means of solving the problem
[0009] A cyber resilience evaluation method according to one embodiment of the present disclosure for solving the above technical problem may include: a step of determining a general element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type of the system to be evaluated; a step of determining a special element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type and industry type of the system to be evaluated; a step of calculating a non-quantitative evaluation score of the system to be evaluated based on the evaluation results for the general element and the special element; a step of calculating a quantitative evaluation score of the system to be evaluated using the values and weights of each of a plurality of metrics of the system to be evaluated; and a step of calculating a resilience score of the system to be evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system to be evaluated.
[0010] In some embodiments, the above method may further include the step of blocking the network connection to the system under evaluation in response to a determination that the resilience score of the system under evaluation is below a threshold.
[0011] In some embodiments, the step of blocking the network connection to the system under evaluation may include the step of determining whether to block the network connection to the system under evaluation based on a predefined importance of the system under evaluation and a resilience score of the system under evaluation.
[0012] In some embodiments, the above method may further include the step of adjusting the weight of a metric associated with a specific attack type among a plurality of metrics included in the quantitative evaluation items of the system being evaluated.
[0013] In some embodiments, the specific attack type may be an attack type related to data obtained as a result of inputting data about the system under evaluation into an artificial intelligence model.
[0014] In some embodiments, the step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated, based on the scale type of the system being evaluated, may include the step of classifying each general element of the system being evaluated into either a mandatory element or an optional element, and the step of determining general elements to be excluded from non-quantitative evaluation items corresponding to the system being evaluated.
[0015] In some embodiments, the step of determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated, based on the scale type and industry type of the system being evaluated, may include the step of classifying each special element of the system being evaluated into either a mandatory element or an optional element, and the step of determining special elements to be excluded from non-quantitative evaluation items corresponding to the system being evaluated.
[0016] In some embodiments, the step of calculating a non-quantitative evaluation score of the system being evaluated may include the step of applying different weights to each of the general element and special element of the system being evaluated, the step of applying different weights to each of the essential element and option element included in the general element of the system being evaluated, the step of applying different weights to each of the essential element and option element included in the special element of the system being evaluated, and the step of calculating a non-quantitative evaluation score of the system being evaluated using the applied weights.
[0017] In some embodiments, the step of calculating the resilience score of the system under evaluation may include the step of adjusting the resilience score in response to a determination that the difference between the non-quantitative score and the quantitative score of the system under evaluation exceeds a threshold.
[0018] In some embodiments, the above method may further include the step of backing up the data of the system under evaluation to the computing system in response to a determination that the resilience score of the system under evaluation is below a threshold.
[0019] A cyber resilience evaluation system according to another embodiment of the present disclosure for solving the above-mentioned technical problem may include one or more processors and a memory that stores a computer program executed by said one or more processors. Herein, said computer program may include instructions that cause said processor to perform the steps of: determining a general element to be included in a non-quantitative evaluation item corresponding to said system based on the scale type of said system to be evaluated; determining a special element to be included in a non-quantitative evaluation item corresponding to said system to be evaluated based on the scale type and industry type of said system to be evaluated; calculating a non-quantitative evaluation score of said system to be evaluated based on the evaluation results for said general element and special element; calculating a quantitative evaluation score of said system to be evaluated using the values and weights of each of a plurality of metrics of said system to be evaluated; and calculating a resilience score of said system to be evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of said system to be evaluated.
[0020] In some embodiments, the computer program may further include instructions that cause the processor to perform the step of blocking the network connection to the system under evaluation in response to a determination that the resilience score of the system under evaluation is below a threshold.
[0021] In some embodiments, the computer program may further include instructions that cause the processor to perform the step of adjusting the weight of a metric associated with a specific attack type among a plurality of metrics included in the quantitative evaluation items of the system being evaluated.
[0022] In some embodiments, the computer program may further include instructions that cause the processor to perform a step of backing up the data of the system under evaluation in response to a determination that the cyber resilience score of the system under evaluation is below a threshold.
[0023] A computer-readable recording medium according to another embodiment of the present disclosure for solving the above-mentioned technical problem may be a computer-readable recording medium in which instructions are stored. Here, the instructions may include a step of determining a general element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type of the system to be evaluated; a step of determining a special element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type and industry type of the system to be evaluated; a step of calculating a non-quantitative evaluation score of the system to be evaluated based on the evaluation results for the general element and the special element; a step of calculating a quantitative evaluation score of the system to be evaluated using the values and weights of each of a plurality of metrics of the system to be evaluated; and a step of calculating a resilience score of the system to be evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system to be evaluated. Brief explanation of the drawing
[0024] FIG. 1 is a drawing illustrating an exemplary environment in which a cyber resilience assessment system according to one embodiment of the present disclosure may be applied. FIG. 2 is a flowchart of a cyber resilience evaluation method according to another embodiment of the present disclosure. FIG. 3 is a table for exemplarily illustrating a non-quantitative evaluation score calculation step that can be performed in some embodiments of the present disclosure. FIG. 4 is a drawing for exemplarily illustrating an artificial intelligence model according to some embodiments of the present disclosure. FIG. 5 is a diagram illustrating, by way of example, the step of determining key metrics according to the type of attack that can be performed in some embodiments of the present disclosure. FIG. 6 is a flowchart of the steps for adjusting network connections for a system under evaluation that may be performed in some embodiments of the present disclosure. FIG. 7 is a flowchart of the step of backing up data of a system under evaluation that can be performed in some embodiments of the present disclosure. FIG. 8 is a drawing for illustratively explaining a computing system according to another embodiment of the present disclosure. Specific details for implementing the invention
[0025] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the attached drawings. The advantages and features of the present invention and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the attached drawings. However, the technical concept of the present invention is not limited to the following embodiments but can be implemented in various different forms. The following embodiments are provided merely to complete the technical concept of the present invention and to fully inform those skilled in the art of the scope of the present invention, and the technical concept of the present invention is defined only by the scope of the claims.
[0026] In describing the present disclosure, if it is determined that a detailed description of related known configurations or functions could obscure the essence of the invention, such detailed description is omitted.
[0027] Unless otherwise defined, terms used in the following embodiments (including technical and scientific terms) may be used in a meaning commonly understood by those skilled in the art to which this disclosure pertains, but this may vary depending on the intent of those skilled in the art, case law, the emergence of new technology, etc. The terms used in this disclosure are for describing the embodiments and are not intended to limit the scope of this disclosure.
[0028] In the following embodiments, singular expressions include plural concepts unless the context clearly specifies them as singular. Additionally, plural expressions include singular concepts unless the context clearly specifies them as plural.
[0029] In addition, terms such as first, second, A, B, (a), (b), etc. used in the following embodiments are used merely to distinguish one component from another, and the essence, order, or sequence of the said component is not limited by such terms.
[0030] Hereinafter, definitions of terms that may appear in some embodiments of the present disclosure will be explained.
[0031] According to some embodiments of the present disclosure, an 'element' may refer to each non-quantitative evaluation item of the system under evaluation. For example, when the non-quantitative evaluation items of the system under evaluation include 'evaluation of the experience and division of roles of the crisis response team and key personnel in the event of a cyber incident' and 'cases of the actual application of the response strategy,' each of the aforementioned items may be understood as a separate element.
[0032] In addition, depending on whether a specific element must be mandatorily included in the non-quantitative evaluation items of a specific system being evaluated, elements can be classified as 'essential elements' and 'option elements'.
[0033] In addition, the first element applicable only to the system being evaluated in a specific industry may be named a 'special element,' and the element that must be included in the non-quantitative evaluation items regardless of the industry of the system being evaluated may be named a 'general element.'
[0034] In the following embodiments, 'metric' may refer to each quantitative evaluation item of the system under evaluation. For example, the network domain of the quantitative evaluation item of the system under evaluation may include at least one of 'latency', 'TPS', or 'CPS', and the service domain may include at least one of 'uptime' or 'time recovery rate'. Here, 'latency', 'uptime', etc. included in each domain may be understood as separate metrics.
[0035] Hereinafter, some embodiments of the present disclosure will be described with reference to the drawings.
[0036] FIG. 1 is a drawing illustrating an exemplary environment in which a cyber resilience evaluation system according to one embodiment of the present disclosure can be applied.
[0037] Each component illustrated in FIG. 1 may refer to software or hardware, such as a Field Programmable Gate Array (FPGA) or an Application-Specific Integrated Circuit (ASIC). However, the components are not limited to software or hardware and may be configured to reside in an addressable storage medium or configured to execute one or more processors. Functions provided within the components may be implemented by more subdivided components, or multiple components may be combined to form a single component that performs a specific function.
[0038] In some embodiments, the cyber resilience assessment system (100) illustrated in FIG. 1 may communicate with other components through a network. The network may be implemented as any type of wired or wireless network, such as a Local Area Network (LAN), a Wide Area Network (WAN), a mobile radio communication network, or Wibro (Wireless Broadband Internet).
[0039] In some embodiments, the plurality of evaluation systems (200-1, 200-2, 200-n) illustrated in FIG. 1 may include a web server, a database server, a file server, an application server, a mail server, a domain name system server, a virtualization server, and a cloud server.
[0040] In some embodiments, the storage (11) of the cyber resilience evaluation system (100) may be a storage that stores a plurality of general elements and special elements of a plurality of systems under evaluation (200-1, 200-2, 200-n). In some other embodiments, the storage (11) of the cyber resilience evaluation system (100) may be a storage that stores quantitative evaluation scores, non-quantitative evaluation scores, and resilience scores of a plurality of systems under evaluation (200-1, 200-2, 200-n).
[0041] In some embodiments, the cyber resilience assessment system (100) may be understood as a system that monitors the operational status of each of a plurality of systems to be assessed (200-1, 200-2, 200-n) in real time, analyzes threats, and assesses the level of resilience.
[0042] Hereinafter, with reference to FIG. 1, the operations that each component illustrated in FIG. 1 can perform will be described.
[0043] A cyber resilience evaluation system (100) according to one embodiment of the present disclosure may receive information related to a plurality of evaluation systems (200-1, 200-2, 200-n). For example, the cyber resilience evaluation system (100) may receive information on the size type of an organization related to each of the plurality of evaluation systems (200-1, 200-2, 200-n), information on the industry type of an organization related to each of the plurality of evaluation systems (200-1, 200-2, 200-n), evaluation results for each non-quantitative evaluation item and values for each quantitative evaluation item of each of the plurality of systems being evaluated (200-1, 200-2, 200-n).
[0044] A cyber resilience evaluation system (100) according to another embodiment of the present disclosure can determine general elements to be included in non-quantitative evaluation items of the first evaluation system (200-1) based on scale type information of the first evaluation system (200-1).
[0045] A cyber resilience evaluation system (100) according to another embodiment of the present disclosure can determine special elements to be included in non-quantitative evaluation items corresponding to the first evaluation system (200-1) based on the scale type and industry type of the first evaluation system (200-1).
[0046] For example, if the first element is a special element corresponding to the financial industry and an element corresponding to a large corporation, and the institution related to the first evaluation system (200-1) is a small or medium-sized enterprise in the financial industry, the first element may be determined to be excluded from the special element of the first evaluation system (200-1).
[0047] In another example, if the second element is a general element, and the institution associated with the first evaluation system (200-1) is a large enterprise and the institution associated with the second evaluation system (200-2) is a medium enterprise, the second element may be determined to be a mandatory element in the first evaluation system (200-1) and an optional element in the second evaluation system (200-2).
[0048] A cyber resilience evaluation system (100) according to another embodiment of the present disclosure can calculate a non-quantitative evaluation score of the first evaluation system (200-1) based on the evaluation results for each of the general element and special element of the first evaluation system (200-1).
[0049] A cyber resilience evaluation system (100) according to another embodiment of the present disclosure can calculate a quantitative evaluation score of a first evaluation system (200-1) using the value of each of a plurality of metrics and the weight of each of a plurality of metrics.
[0050] In some embodiments of the present disclosure, the weight of each metric included in the quantitative evaluation item corresponding to the first evaluation system (200-1) may be determined differently depending on the previously selected attack type, but this will be described later.
[0051] A cyber resilience evaluation system (100) according to another embodiment of the present disclosure may calculate a resilience score of the first evaluation system (200-1) based on a non-quantitative evaluation score and a quantitative evaluation score of the first evaluation system (200-1), but this will be described in detail later.
[0052] Up to now, with reference to FIG. 1, the configuration and operation of the cyber resilience evaluation system (100) and an exemplary environment in which the cyber resilience evaluation system (100) can be applied have been described.
[0053] Next, a cyber resilience evaluation method according to another embodiment of the present disclosure will be described with reference to FIGS. 2 through 7. The cyber resilience evaluation method according to the present embodiment may be performed by one or more computing systems. Additionally, the cyber resilience evaluation method according to the present embodiment may have some operations performed by a first computing device and the remaining operations performed by a second computing device. For example, some operations of the cyber resilience evaluation method according to the present embodiment may be performed by an on-premise physical server and the remaining operations may be performed by a cloud compute instance. Additionally, for example, some operations of the cyber resilience evaluation method according to the present embodiment may be performed by a cyber resilience evaluation system and the remaining operations may be performed by the system being evaluated. Hereinafter, if the entity performing each operation is omitted, it may be understood that the entity performing the operation is the cyber resilience evaluation system.
[0054] In step S100, the cyber resilience evaluation system (100) can receive information about the system being evaluated.
[0055] In some embodiments related to step S100, the information of the system to be evaluated may include one or more of the following: size information of the institution related to the system to be evaluated, industry information of the institution related to the system to be evaluated, information on the evaluation method to be performed on the system to be evaluated, evaluation results for each non-quantitative evaluation item for the system to be evaluated, and values for each quantitative evaluation item.
[0056] In step S200, the cyber resilience assessment system (100) can determine general elements to be included in non-quantitative evaluation items of the system being assessed based on the size type of the system being assessed. Here, the size type may refer to information indicating which of the predefined size types the institution corresponding to the system being assessed corresponds to. For example, the size type may be any one of a public institution, a large enterprise, a small and medium-sized enterprise, or a medium-sized enterprise.
[0057] General elements stored in the storage (11) of the cyber resilience assessment system (100) can be exemplified by the following Table 1. In addition, Table 1 exemplifies whether each general element includes evaluation items according to the type of organization related to the system being evaluated.
[0058] division General element public institutions large corporations mid-sized companies small and medium-sized enterprises 1st general element How well do employees understand the importance of cybersecurity and resilience? essential essential Options X 2nd general element How efficiently does the organization's internal communication system operate in the event of a cyber incident? essential X Options essential 3rd General Element Are you continuously strengthening your security and resilience defense systems? X Options Options X 4th General Element Are employees aware of cybersecurity and complying voluntarily? essential essential essential essential 5th general element Is the experience and division of roles of the cyber resilience crisis response team effective? X essential Options X
[0059] In some embodiments related to step S200, the cyber resilience evaluation system (100) may classify each general element of the system under evaluation into either an essential element or an optional element. Additionally, some of the multiple general elements may be determined not to be included in the non-quantitative evaluation items of the system under evaluation.
[0060] For example, referring to Table 1, if the first evaluation system (200-1) is a system of a small and medium-sized enterprise, the fourth general element can be understood as necessarily being included in the general element of the non-quantitative evaluation item of the first evaluation system (200-1). Therefore, the fourth general element can be understood as an essential general element among the general elements of the first evaluation system (200-1).
[0061] For another example, referring to Table 1, if the first evaluation system (200-1) is a system of a large enterprise, it may be determined that the fifth general element is not included in the non-quantitative evaluation items of the first evaluation system (200-1).
[0062] As another example, referring to Table 1, if the second evaluation system (200-2) corresponds to a medium-sized enterprise, the third general element can be determined to be an optional element of the non-quantitative evaluation item of the second evaluation system (200-2). That is, in the cyber resilience evaluation of the second evaluation system (200-2), it can be understood that the manager of the second evaluation system (200-2) is not required to provide an evaluation response regarding the third general element.
[0063] In step S300, the cyber resilience evaluation system (100) can determine special elements to be included in the non-quantitative evaluation items of the system being evaluated based on the size type and industry type of the system being evaluated. Here, the industry type can be understood as information indicating which of the predefined industry types the system being evaluated corresponds to.
[0064] For example, the industry type can be any one of the financial industry, manufacturing industry, e-commerce industry, trading industry, telecommunications industry, and medical industry.
[0065] In some embodiments related to step S300, the cyber resilience evaluation system (100) can determine a special element to be included in the non-quantitative evaluation item of the system to be evaluated among a plurality of special elements based on the industry type of the system to be evaluated.
[0066] In some other embodiments related to step S300, the cyber resilience evaluation system (100) may classify each special element included in the non-quantitative evaluation item of the system being evaluated into either an essential element or an optional element, based on the scale type of the system being evaluated.
[0067] Special elements stored in the storage (11) of the cyber resilience evaluation system (100) can be exemplified by the following Table 2. In addition, Table 2 exemplifies whether each special element is included in the non-quantitative evaluation item corresponding to the evaluation system according to the industry type of the institution related to the evaluation system.
[0068] In addition, by referring to Table 2, it can be understood that even if certain special elements are included in the non-quantitative evaluation items of the system being evaluated, they may be classified as essential elements or optional elements depending on the size type of the system being evaluated.
[0069] division Special element large corporations in the financial sector large manufacturing companies Small and medium-sized enterprises in the financial sector Medium-sized enterprises in the trading industry 1st special element How quickly can alternative services or backup systems be restored when a financial transaction system is interrupted? essential X Options X 2nd special element How strengthened is the security of IoT devices and industrial robot systems used in smart factories, and are security policies being implemented to prevent hacking? X essential X X 3rd Special Element How well can you maintain service continuity in the event of a cyber attack when providing online stores or digital services? X X X Options 4th Special Element How strong and continuously are the encryption and security procedures for protecting customers' personal and financial data being improved? Options X Options X
[0070] For example, referring to Table 2, if the first evaluation system (200-1) is a large enterprise in the financial industry, it can be understood that the size type of the first evaluation system is 'large enterprise' and the industry type is 'financial industry'. Therefore, the non-quantitative evaluation item of the first evaluation system (200-1) can be understood to include the first special element as a required element.
[0071] For another example, referring to Table 2, if the second evaluation system (200-1) is a small or medium-sized enterprise in the financial industry, the first special element among the special elements of the second evaluation system (200-1) can be determined to be an option element.
[0072] In step S400, the cyber resilience evaluation system (100) receives evaluation results for each general element and each special element of the system being evaluated, and can calculate a non-quantitative evaluation score of the system being evaluated.
[0073] In some embodiments related to step S400, the cyber resilience evaluation system (100) may apply different weights to each of the general element and special element of the system being evaluated.
[0074] In some other embodiments related to step S400, the cyber resilience evaluation system (100) may apply different weights to each of the essential general elements and optional general elements among the general elements of the system to be evaluated.
[0075] In some other embodiments related to step S400, the cyber resilience evaluation system (100) may apply different weights to each of the essential special elements and optional special elements among the special elements of the system being evaluated.
[0076] For example, referring to FIG. 4, the first row (41) can be understood as illustrating an exemplary formula related to calculating the score of the required general element of the first evaluation system (200-1). The denominator, 30a + 30B, may be the value obtained by multiplying 30, which is the total number of items of the general required element, by the weight a, which is weighted to the general element, and the weight B, which is weighted to the required element. Additionally, the numerator, 27a + 27B, may be the value obtained by multiplying 27, which is the number of evaluation responses submitted for the general required element by the institution of the first evaluation system (200-1), by the weight a, which is weighted to the general element, and the weight B, which is weighted to the required element.
[0077] As another example, the second row (42) can be understood as illustrating an exemplary formula related to calculating the score of the option general element of the first evaluation system (200-1). The denominator 20a+20b may be the product of 20, which is the total number of items of the general option element, and the weight a, which is weighted to the general element, and the weight b, which is weighted to the option element. Additionally, the numerator 17a+17b may be the product of 17, which is the number of evaluation responses submitted for the general option element by the institution of the first evaluation system (200-1), and the weight a, which is weighted to the general element, and the weight b, which is weighted to the option element.
[0078] As another example, the third line (43) can be understood as illustrating an exemplary formula related to calculating the score of the required special element of the first evaluation system (200-1). The denominator, 15A+15B, may be the product of 15, the total number of items of the special required element, and the weight A and required element weight B that are weighted to the special element. Additionally, the numerator, 12A+12B, may be the product of 12, the number of evaluation responses submitted for the special required element by the institution of the first evaluation system (200-1), and the weight A and required element weight B that are weighted to the special element.
[0079] As another example, the fourth line (44) can be understood as illustrating an exemplary formula related to calculating the score of a special option element of the first evaluation system (200-1). The denominator 5A+5b may be the product of 5, which is the total number of items of the special option element, and the weight A and option element weight b that are weighted to the special element. Additionally, the numerator 1A+1B may be the product of 1, which is the number of evaluation responses submitted for the special option element by the agency of the first evaluation system (200-1), and the weight A and option element weight b that are weighted to the special element.
[0080] According to the present embodiment, the effect of providing standardized cyber resilience evaluation criteria based on the scale and industry of the system being evaluated can be achieved. Accordingly, compared to conventional methods that evaluate using uniform evaluation items without reflecting the characteristics of the organization, an accurate cyber resilience evaluation can be performed.
[0081] In step S500, the cyber resilience assessment system (100) can determine the weight of each metric of the quantitative assessment items.
[0082] In some embodiments related to step S500, the cyber resilience assessment system (100) may determine a specific type of attack to be used to determine the weight of each metric included in the quantitative assessment items of the system under assessment, based on user input.
[0083] In some other embodiments related to step S500, the cyber resilience assessment system (100) inputs data about the system under assessment into an artificial intelligence model and, based on the output of the artificial intelligence model, can determine a specific type of attack to be used to determine the weight of each metric included in the quantitative assessment items of the system under assessment.
[0084] In some other embodiments related to step S500, with reference to FIG. 4, the artificial intelligence model (32) may be a model that outputs a plurality of attack types (33-1, 33-2, 33-n) corresponding to the system under evaluation in response to receiving system under evaluation data (31) including size type information of the system under evaluation, industry type information of the system under evaluation, a list of core services of the system under evaluation, and asset configuration information of the system under evaluation.
[0085] For example, referring to FIG. 4, the artificial intelligence model (32) can be supervised, semi-supervised, or unsupervised based on a plurality of training data (system data to be evaluated (31)). For example, a training data set including a plurality of positive prompts, a plurality of negative prompts, and a plurality of correct answer data can be applied to the artificial intelligence model (32), so that the artificial intelligence model (32) can be supervised so that the attack type information (33-1, 33-2, 33-n) output from the artificial intelligence model (32) based on the positive prompts / negative prompts becomes similar / identical to the attack type information (33-1, 33-2, 33-n) included in the correct answer data. When the training of the artificial intelligence model (32) is repeated, the weight of each node included in the artificial intelligence model (32) can converge to an optimal value.
[0086] In some other embodiments related to step S500, the cyber resilience assessment system (100) may adjust the weights of some of the metrics of the system being assessed, corresponding to a specific type of attack determined.
[0087] For example, referring to FIG. 5, if the determined attack type corresponds to a third case of a DDOS attack (51), the cyber resilience evaluation system (100) can increase the weight of each of the metrics of the system being evaluated: the latency metric of the network domain (54), the time recovery rate metric of the service domain (55), and the RTO metric of the asset domain (56).
[0088] For another example, referring to FIG. 5, the cyber resilience evaluation system (100) can lower the weight of the CPS metric of the network domain (54) and the recovery success rate metric of the asset domain (56) among the metrics included in the quantitative evaluation items of the second evaluation system (200-2) when the determined attack type for the second evaluation system (200-2) corresponds to a second case of a ransomware attack (52).
[0089] For another example, referring to FIG. 5, the cyber resilience evaluation system (100) can increase the weight of the latency metric of the network domain (54), the uptime metric of the service domain (55), and the RPO metric of the asset domain (56) among the multiple metrics included in the quantitative evaluation items of the second evaluation system (200-2) when the determined attack type for the second evaluation system (200-2) corresponds to a second attack scenario of the XSS attack type (53).
[0090] That is, the cyber resilience evaluation system (100) can be understood as calculating a quantitative evaluation score of the system being evaluated based on the values of all metrics included in the quantitative evaluation items, while focusing on the major types of attacks that the system being evaluated must defend against.
[0091] In step S600, the cyber resilience evaluation system (100) can calculate a quantitative evaluation score of the system to be evaluated based on the weight of each metric of the system to be evaluated determined in step S500 and the value of each metric of the system to be evaluated.
[0092] In step S700, the cyber resilience evaluation system (100) can calculate the resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated.
[0093] In some embodiments related to step S700, the cyber resilience evaluation system (100) may lower the calculated resilience score of the system being evaluated in response to the determination that the difference between the quantitative evaluation score and the non-quantitative evaluation score of the system being evaluated exceeds a reference value.
[0094] According to the present embodiment, even if either the non-quantitative evaluation score or the quantitative evaluation score is evaluated excessively high due to an error, the effect of preventing overestimation of the resilience of a specific system being evaluated due to an error can be achieved through a balanced evaluation method between the non-quantitative evaluation score and the quantitative evaluation score.
[0095] Hereinafter, with reference to FIG. 6, an embodiment in which a cyber resilience evaluation system (100) adjusts a network connection to a system to be evaluated will be described.
[0096] In step S800 illustrated in FIG. 6, the cyber resilience evaluation system (100) can evaluate whether the resilience score of the system being evaluated is below a threshold value.
[0097] In step S900-1, the cyber resilience assessment system (100) can adjust the network connection to the system under assessment in response to the determination that the resilience score of the system under assessment is below a threshold.
[0098] In some embodiments related to step S900-1, the cyber resilience assessment system (100) can determine whether to block network connections to the system under assessment based on the previously defined importance of the system under assessment and the resilience score of the system under assessment.
[0099] According to the present embodiment, the effect of blocking the influence of a system being evaluated whose resilience is below a threshold value can be achieved before it affects a plurality of other systems being evaluated connected to the cyber resilience evaluation system (100). Additionally, even if the risk to other systems increases due to a system being evaluated whose resilience is below a threshold value, if the importance of the system being evaluated is high, the network may not be blocked, thereby preventing a situation where an important service is unexpectedly terminated.
[0100] Hereinafter, with reference to FIG. 7, an embodiment in which a cyber resilience evaluation system (100) backs up data of a system to be evaluated will be described.
[0101] In step S800 illustrated in FIG. 7, the cyber resilience evaluation system (100) can evaluate whether the resilience score of the system being evaluated is below a threshold value.
[0102] In step S900-1, the cyber resilience evaluation system (100) can automatically back up the data of the system being evaluated to the storage (11) of the cyber resilience evaluation system (100) based on the determination that the resilience score of the system being evaluated is below a threshold value.
[0103] In some embodiments related to step S900-1, the cyber resilience evaluation system (100) measures the resilience scores of a plurality of systems to be evaluated (200-1, 200-2, 200-n) at predetermined intervals, and in response to a determination that the resilience score of the first system to be evaluated (200-1) is below a threshold value, the system to be evaluated (200-1) can automatically back up the data up to that point.
[0104] According to the present embodiment, if a critical attack occurs against a specific system under evaluation and the evaluation grade decreases rapidly, the effect of automatically restoring essential functions required for the services provided by the specific system under evaluation can be achieved to prevent the complete interruption of services operating on the specific system under evaluation.
[0105] Up to now, a method for evaluating cyber resilience according to another embodiment of the present disclosure has been described with reference to FIGS. 2 through 7. The embodiments described above should be understood as illustrative in all respects and not restrictive.
[0106] FIG. 8 is a hardware configuration diagram of a computing system (1000) according to some embodiments of the present disclosure. The computing system (1000) of FIG. 8 may refer to, for example, the cyber resilience assessment system (100) described with reference to FIG. 1. The computing system (1000) may include one or more processors (1100), a system bus (1600), a communication interface (1200), a memory (1400) for loading a computer program (1500) executed by the processor (1100), and a storage (1300) for storing the computer program (1500).
[0107] The processor (1100) controls the overall operation of each component of the computing system (1000). The processor (1100) may perform operations on at least one application or program for executing methods / operations according to various embodiments of the present disclosure. Memory (1400) stores various data, instructions and / or information. Memory (1400) may load one or more computer programs (1500) from storage (1300) to execute methods / operations according to various embodiments of the present disclosure. A bus (1600) provides communication functions between components of the computing system (1000). A communication interface (1200) supports internet communication of the computing system (1000). Storage (1300) may non-temporarily store one or more computer programs (1500). A computer program (1500) may include one or more instructions in which methods / operations according to various embodiments of the present disclosure are implemented. When a computer program (1500) is loaded into memory (1400), the processor (1100) can perform methods / operations according to various embodiments of the present disclosure by executing one or more of the instructions.
[0108] In some embodiments, the computing system (1000) described with reference to FIG. 8 may be configured using one or more physical servers included in a server farm based on cloud technology such as a virtual machine. In this case, at least some of the components shown in FIG. 8, such as the processor (1100), memory (1400), and storage (1300), may be virtual hardware, and the communication interface (1200) may also be configured as a virtualized networking element such as a virtual switch.
[0109] A computer program (1500) according to some embodiments of the present disclosure may include instructions for performing steps of: determining a general element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the size type of the system to be evaluated based on the size type and industry type of the system to be evaluated based on the system to be evaluated based on the system to be evaluated based on the system to be evaluated based on the system to be evaluated based on the system to be evaluated based on the system to be evaluated based on the general element and the special element to be evaluated based on the evaluation results of the general element and the special element to be evaluated based on the system to be evaluated based on the general element and the special element to be evaluated based on the general element and the special element to be evaluated based on the general element and the special element to be evaluated based on the general element and the general element to be evaluated based on the value and weight of each of the multiple metrics of the system to be evaluated based on the system to be evaluated based on the general element and the general element
[0110] Various embodiments of the present disclosure and effects according to those embodiments have been described with reference to FIGS. 1 through 8. The effects according to the technical concept of the present disclosure are not limited to those mentioned above, and other unmentioned effects will be clearly understood by a person skilled in the art from the description below.
[0111] The technical concept of the present disclosure described above may be implemented as computer-readable code on a computer-readable medium. The computer program recorded on the computer-readable recording medium may be transmitted to another computing device via a network such as the Internet and installed on the other computing device, thereby being used on the other computing device.
[0112] Although operations are depicted in a specific order in the drawings, it should not be understood that the operations must necessarily be executed in the specific order depicted or in a sequential order, or that all depicted operations must be executed to obtain the desired result. In certain situations, multitasking and parallel processing may be advantageous. Although embodiments of the present disclosure have been described above with reference to the attached drawings, those skilled in the art will understand that the present invention may be practiced in other specific forms without altering the technical concept or essential features thereof. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. The scope of protection of the present invention shall be interpreted by the claims below, and all technical concepts within the equivalent scope shall be interpreted as being included within the scope of rights of the technical concept defined by the present disclosure.
Claims
Claim 1 A method for evaluating cyber resilience performed by a computing system, comprising: a step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type of the system being evaluated; a step of determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type and industry type of the system being evaluated; a step of calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general elements and special elements; a step of calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and a step of calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type of the system being evaluated comprises: a step of classifying each general element of the system being evaluated into either a mandatory element or an optional element; and a step of determining general elements to be excluded from non-quantitative evaluation items corresponding to the system being evaluated. Claim 2 A cyber resilience evaluation method according to claim 1, further comprising the step of blocking a network connection to the system under evaluation in response to a determination that the resilience score of the system under evaluation is below a reference value. Claim 3 A cyber resilience evaluation method according to claim 2, wherein the step of blocking a network connection to the system to be evaluated includes the step of determining whether to block the network connection to the system to be evaluated based on a predefined importance of the system to be evaluated and a resilience score of the system to be evaluated. Claim 4 A cyber resilience evaluation method according to claim 1, further comprising the step of adjusting the weight of a metric associated with a specific attack type among a plurality of metrics included in the quantitative evaluation items of the evaluation system. Claim 5 In claim 4, the specific attack type is an attack type related to data obtained as a result of inputting data about the system to be evaluated into an artificial intelligence model, a cyber resilience evaluation method. Claim 6 delete Claim 7 A method for evaluating cyber resilience performed by a computing system, comprising: a step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type of the system being evaluated; a step of determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type and industry type of the system being evaluated; a step of calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general elements and special elements; a step of calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and a step of calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the size type and industry type of the system being evaluated comprises: a step of classifying each special element of the system being evaluated into either an essential element or an optional element; and a step of determining special elements to be excluded from non-quantitative evaluation items corresponding to the system being evaluated. Claim 8 A method for evaluating cyber resilience performed by a computing system comprises: a step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the scale type of the system being evaluated; a step of determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the scale type and industry type of the system being evaluated; a step of calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general elements and special elements; a step of calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and a step of calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of calculating the non-quantitative evaluation score of the system being evaluated comprises: a step of applying different weights to each of the general elements and special elements of the system being evaluated; a step of applying different weights to each of the essential elements and option elements included in the general elements of the system being evaluated; and a step of applying different weights to each of the essential elements and option elements included in the special elements of the system being evaluated. A cyber resilience evaluation method comprising the step of calculating a non-quantitative evaluation score of the system under evaluation using the weights applied above. Claim 9 A cyber resilience evaluation method performed by a computing system, comprising: a step of determining a general element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the size type of the system being evaluated; a step of determining a special element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the size type and industry type of the system being evaluated; a step of calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general element and the special element; a step of calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and a step of calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of calculating the resilience score of the system being evaluated includes a step of adjusting the resilience score in response to a judgment that the difference between the non-quantitative score and the quantitative score of the system being evaluated exceeds a threshold. Claim 10 A cyber resilience evaluation method according to claim 1, further comprising the step of backing up the data of the system to be evaluated to the computing system in response to a determination that the resilience score of the system to be evaluated is below a reference value. Claim 11 The method comprises one or more processors; and a memory for storing a computer program executed by the one or more processors, wherein the computer program includes instructions that cause the processor to perform the steps of: determining a general element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type of the system being evaluated; determining a special element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type and industry type of the system being evaluated; calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general element and the special element; calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of determining a general element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type of the system being evaluated includes the step of classifying each general element of the system being evaluated into either a mandatory element or an optional element. A cyber resilience evaluation system comprising the step of determining general elements excluded from non-quantitative evaluation items corresponding to the above-mentioned evaluation system. Claim 12 A cyber resilience evaluation system according to claim 11, wherein the computer program further comprises instructions that cause the processor to perform the step of blocking the network connection to the system under evaluation in response to a determination that the resilience score of the system under evaluation is below a reference value. Claim 13 In claim 12, the step of blocking a network connection to the system under evaluation comprises a step of determining whether to block the network connection to the system under evaluation based on a predefined importance of the system under evaluation and a resilience score of the system under evaluation, in a cyber resilience evaluation system. Claim 14 A cyber resilience evaluation system according to claim 11, wherein the computer program further comprises instructions that cause the processor to perform the step of adjusting the weight of a metric associated with a specific attack type among a plurality of metrics included in the quantitative evaluation items of the system being evaluated. Claim 15 In claim 14, the specific attack type is a cyber resilience evaluation system, which is an attack type related to data obtained as a result of inputting data about the system to be evaluated into an artificial intelligence model. Claim 16 delete Claim 17 The method comprises one or more processors; and a memory for storing a computer program executed by the one or more processors, wherein the computer program includes instructions that cause the processor to perform the steps of: determining a general element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type of the system being evaluated; determining a special element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type and industry type of the system being evaluated; calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general element and the special element; calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of determining a special element to be included in a non-quantitative evaluation item corresponding to the system being evaluated based on the scale type and industry type of the system being evaluated includes the step of classifying each special element of the system being evaluated into either a mandatory element or an optional element. A cyber resilience evaluation system comprising the step of determining special elements excluded from non-quantitative evaluation items corresponding to the above-mentioned evaluation system. Claim 18 One or more processors; and a memory for storing a computer program executed by the one or more processors, wherein the computer program comprises: a step of determining a general element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type of the system to be evaluated; a step of determining a special element to be included in a non-quantitative evaluation item corresponding to the system to be evaluated based on the scale type and industry type of the system to be evaluated; a step of calculating a non-quantitative evaluation score of the system to be evaluated based on the evaluation results for the general element and the special element; and a step of calculating a quantitative evaluation score of the system to be evaluated using the values and weights of each of a plurality of metrics of the system to be evaluated. A cyber resilience evaluation system comprising instructions for performing a step of calculating a resilience score of a system to be evaluated based on a non-quantitative evaluation score and a quantitative evaluation score of the system to be evaluated, wherein the step of calculating a non-quantitative evaluation score of the system to be evaluated comprises: a step of applying different weights to each of the general element and special element of the system to be evaluated; a step of applying different weights to each of the essential element and option element included in the general element of the system to be evaluated; a step of applying different weights to each of the essential element and option element included in the special element of the system to be evaluated; and a step of calculating a non-quantitative evaluation score of the system to be evaluated using the applied weights. Claim 19 A cyber resilience evaluation system according to claim 11, wherein the computer program further comprises instructions that cause the processor to perform the step of backing up the data of the system to be evaluated to storage in response to a determination that the cyber resilience score of the system to be evaluated is below a reference value. Claim 20 A computer-readable recording medium storing instructions, wherein the instructions are configured to perform the following steps: determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the scale type of the system being evaluated; determining special elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the scale type and industry type of the system being evaluated; calculating a non-quantitative evaluation score of the system being evaluated based on the evaluation results for the general elements and special elements; calculating a quantitative evaluation score of the system being evaluated using the values and weights of each of a plurality of metrics of the system being evaluated; and calculating a resilience score of the system being evaluated based on the non-quantitative evaluation score and the quantitative evaluation score of the system being evaluated, wherein the step of determining general elements to be included in non-quantitative evaluation items corresponding to the system being evaluated based on the scale type of the system being evaluated comprises the step of classifying each general element of the system being evaluated into either a mandatory element or an optional element. A computer-readable recording medium comprising the step of determining a general element to be excluded from a non-quantitative evaluation item corresponding to the above-mentioned evaluation system.
Citation Information
Patent Citations
Control items and compliance management system for acceptable general-purpose regulations / rules of information security management system
KR101560259B1
Inferential Analysis Using Feedback for Extracting and Combining Cyber Risk Information
US20160248799A1
Systems and methods for security operations maturity assessment
US20220092510A1