Safety control system and method

By receiving risk analysis information, loading the control database, and matching the attack steps of security control and attack paths, selecting the optimal subset output information, the problem of inefficient security threat handling in the existing technology is solved, and more efficient risk assessment and control measures are achieved.

CN120359514APending Publication Date: 2025-07-22C2A SEC LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480005567.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-31
Filing Date
2024-01-31
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the process of security threat processing, the prior art lacks effective methods to match security control and attack paths, resulting in inefficiency of risk assessment and control measures.

Method used

By receiving risk analysis information, loading the control database, matching the attack steps of security control and attack paths, and selecting the optimal subset to output security control information, considering cost and feasibility.

Benefits of technology

It improves the efficiency and accuracy of security threat handling, can more effectively reduce the feasibility of attack steps, and provides support for cost and feasibility assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120359514A_ABST
    Figure CN120359514A_ABST
Patent Text Reader

Abstract

A security control method includes: receiving risk analysis information including data about a plurality of threats, each of the plurality of threats being associated with a respective asset; loading a control database including data about a plurality of security controls; for each of the plurality of threats, matching one or more of the plurality of security controls with one or more attack steps of one or more attack paths associated with the respective threat; for each of the plurality of threats, selecting at least one subset of the matched security controls; and for each of the plurality of threats, outputting information about the selected security control.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related applications

[0002] This application claims priority to Israeli Patent Application No. 300324, filed on January 31, 2023, the entire content of which is incorporated herein by reference. Technical Field

[0003] This disclosure substantially relates to the field of software and hardware testing, and more particularly to security control systems and methods.

[0004] Background

[0005] In programming and software development, as well as in hardware design and development, security experts perform threat analysis and risk assessment ("TARA") on high - level software and hardware components. During this process, security experts analyze the risks and impacts of cyber - attacks on a given component and its functionality. The process typically begins with project definition, threat identification, an attack tree that describes how an attacker executes their attack, risks, and recommended optional security controls to mitigate the risks. Software and hardware are used as the means of implementing the functionality of the components.

[0006] Summary

[0007] Accordingly, a primary object of the present invention is to overcome at least some of the disadvantages of existing art systems and methods for security threat handling. In one embodiment, this is provided by a security threat handling method that includes receiving risk analysis information that includes data regarding a plurality of threats, each of the plurality of threats being associated with a corresponding asset.

[0008] In some examples, the method includes loading a control database that includes data regarding a plurality of security controls.

[0009] In some examples, the method includes: for each of the plurality of threats, matching one or more security controls from the plurality of security controls to one or more attack steps of one or more attack paths associated with the corresponding threat.

[0010] In some examples, the method includes, for each of the plurality of threats, selecting at least one subset of the matched security controls.

[0011] In some examples, the method includes, for each of the plurality of threats, outputting information regarding the selected security controls.

[0012] In some examples, the output information is at least partially based on expenditure data associated with the corresponding security control, the expenditure data indicating the cost and / or effort required to implement the corresponding security control.

[0013] In some examples, the output information is at least partially based on feasibility data associated with a corresponding security control, the feasibility data indicating the extent to which the corresponding security control, when implemented, will reduce the feasibility rating of a corresponding one of a plurality of attack steps.

[0014] Additional features and advantages of the present invention will become apparent from the following drawings and description.

[0015] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. In case of conflict, the present patent application specification (including definitions) will control. As used herein, unless the context clearly indicates otherwise, the articles "a" and "an" refer to "at least one" or "one or more". As used herein, "and / or" refers to any one or more of the items in the list connected by "and / or". As an example, "x and / or y" refers to any element in the three-element set {(x), (y), (x, y)}. In other words, "x and / or y" means "x, y, or both x and y". In some examples, "x, y, and / or z" refers to any element in the seven-element set {(x), (y), (z), (x, y), (x, z), (y, z), (x, y, z)}.

[0016] Furthermore, unless otherwise explicitly stated to the contrary, "or" refers to an inclusive or rather than an exclusive or. For example, any of the following satisfies the condition A or B: A is true (or present) and B is false (or absent), A is false (or absent) and B is true (or present), and both A and B are true (or present).

[0017] In addition, the articles "a" or "an" are used to describe elements and components of embodiments of the inventive concept. This is done merely for convenience and to give a general sense of the inventive concept, and "a" and "an" are intended to include one or at least one, and the singular also includes the plural unless it is obvious that it has a different meaning.

[0018] As used herein, the term "about", when referring to a measurable value (such as an amount, duration, etc.), means including a deviation of + / - 10%, more preferably + / - 5%, even more preferably + / - 1%, and still more preferably + / - 0.1% from the specified value, because such deviations are suitable for implementing the disclosed devices and / or methods.

[0019] The following embodiments and aspects thereof regarding systems, tools, and methods are described and illustrated, which are intended to be exemplary and illustrative and not limiting in scope. In various embodiments, one or more of the above problems have been reduced or eliminated, while other embodiments address other advantages or improvements. Brief Description of the Drawings

[0021] To better understand the present invention and to show how the present invention may be put into practice, reference will now be made, by way of example only, to the accompanying drawings, in which like reference numerals throughout the drawings indicate corresponding parts or elements.

[0022] Now referring specifically to the drawings in detail, it should be emphasized that the details shown are by way of example and for purposes of illustrative discussion of the preferred embodiments of the present invention only, and are presented in order to provide what is considered to be the most useful and readily understood description of the principles and conceptual aspects of the present invention. In this regard, no attempt has been made to show the structural details of the present invention in more detail than is necessary for a fundamental understanding of the present invention, and the description in conjunction with the drawings enables those skilled in the art to understand how several forms of the present invention may be embodied in practice. In the drawings:

[0023] Figures 1A to 1D Shows various parts of a system for security threat handling according to some examples of the present disclosure;

[0024] Figures 2A to 2C Shows various diagrams of an attack tree according to some examples of the present disclosure;

[0025] Figures 3A to 3E Shows various diagrams of a process for matching security controls with attack steps of an attack path according to some examples of the present disclosure;

[0026] Figures 4A to 4B Shows various diagrams of a process for matching stored attack paths with new threats according to some examples of the present disclosure;

[0027] Figures 5A to 5D Shows various diagrams of a process for generating a list of optimized security control implementations according to some examples of the present disclosure;

[0028] Figures 6A to 6C Shows various diagrams of a process for creating a database of software implementations of attack steps mapped to risk analysis information according to some examples of the present disclosure;

[0029] Figure 7 Shows a high-level flowchart of a method for outputting information about signals transmitted between assets; and

[0030] Figure 8Shows a high-level flowchart of a method for outputting information in response to abnormal behavior.

[0031] Detailed description of specific examples

[0032] In the following description, various aspects of the present disclosure will be described. For purposes of explanation, specific configurations and details are set forth in order to provide a thorough understanding of the different aspects of the present disclosure. However, it will also be apparent to those skilled in the art that the present disclosure may be practiced without the specific details presented herein. Additionally, well-known features may be omitted or simplified so as not to obscure the present disclosure. In the drawings, like reference numerals always refer to like parts. To avoid excessive clutter due to having too many reference numerals and leads on a particular drawing, some components will be introduced in one or more of the drawings and not explicitly identified in each subsequent drawing that includes that component.

[0033] Figure 1A Shows a high-level block diagram of a security control system 10. In some examples, system 10 includes: a management subsystem 11, which optionally includes a user interface and / or a command line interface; a security control library 20; a control association subsystem 30; an attack step implementation mapping subsystem 40; a template matching subsystem 50; and a security control optimization subsystem 60.

[0034] In some examples, the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60 are each implemented on a dedicated processor or a set of processors, although this is not meant to be limiting in any way. In some examples, a processor 12 or a group of processors 12 can be used to jointly run more than one of the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60.

[0035] In some examples, as described below, system 10 outputs: an attack step implementation mapping 70; and an optimized security control list 80. In some examples, system 10 includes: an input subsystem 120; and an output subsystem 130, which can optionally output the implementation mapping 70 and the security control list 80. In some examples, as described below, the attack step implementation mapping 70 includes a list of attack steps and how the attack steps are mapped to specific software and / or hardware implementations.

[0036] In some examples, the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60 are each implemented by a corresponding instruction set stored on the memory 13, and the corresponding instruction set, when run by one or more processors 12, causes the corresponding processor 12 to execute the function of the corresponding one of the following systems: the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60.

[0037] In some examples, as described below, the system 10 further includes a data recorder configuration subsystem 61. In some examples, the data recorder configuration subsystem 61 is implemented by a corresponding instruction set, and the corresponding instruction set, when run by one or more processors, causes the corresponding processor 12 to execute the function of the data recorder configuration subsystem 61.

[0038] In some examples, as described below, the system 10 further includes a signal subsystem 62. In some examples, the signal subsystem 62 is implemented by a corresponding instruction set, and the corresponding instruction set, when run by one or more processors 12, causes the corresponding processor 12 to execute the function of the signal subsystem 62.

[0039] In some examples, as described below, the system 10 further includes an identifier (ID) subsystem 63. In some examples, the ID subsystem 63 is implemented by a corresponding instruction set, and the corresponding instruction set, when run by one or more processors 12, causes the corresponding processor 12 to execute the function of the ID subsystem 63.

[0040] In some examples, as described below, the system 10 further includes a permissions subsystem 64. In some examples, the permissions subsystem 64 is implemented by a corresponding instruction set, and the corresponding instruction set, when run by one or more processors 12, causes the corresponding processor 12 to execute the function of the permissions subsystem 64.

[0041] In some examples, as described below, the system 10 further includes a risk subsystem 65. In some examples, the risk subsystem 65 is implemented by a corresponding instruction set, and the corresponding instruction set, when run by one or more processors 12, causes the corresponding processor 12 to execute the function of the risk subsystem 65.

[0042] In some examples, the security control library 20 includes: a security control implementation database 201 as described below, which includes information about multiple security control implementations; a security control database 202 as described below, which includes information about multiple security controls; and a security control format table 203 as described below.

[0043] In some examples, the control association subsystem 30 includes: a plurality of corresponding instructions 301 for mapping threats to an attack tree; an attack path database 302 including a plurality of attack trees; a threat-to-attack path mapping database 303 that includes a plurality of mappings for mapping threats to attack trees; and a plurality of instructions 304 for matching attack steps with security controls. As described below, when run by one or more processors, the instructions 301 cause the processor to map threats to an attack tree. As described below, when run by one or more processors, the instructions 304 cause the processor to match attack steps with security controls.

[0044] In some examples, the template matching subsystem 50 includes: a plurality of instructions 501 for matching attack steps with a template; a plurality of instructions 502 for matching security controls with a template; and a template database 503 including a plurality of templates. As described below, when run by one or more processors, the instructions 501 cause the processor to match attack steps with a template. As described below, when run by one or more processors, the instructions 502 cause the processor to match security controls with a template.

[0045] In some examples, each of the input subsystem 120 and the output subsystem 130 includes a communication port. In some examples, each of the input subsystem 120 and the output subsystem 130 communicates with an external server and / or an external software program. Although the input subsystem 120 and the output subsystem 130 are shown herein as separate units, this is not meant to be limiting in any way, and the input subsystem 120 and the output subsystem 130 can be implemented using a single hardware device and / or software program.

[0046] In some examples, as Figure 1A shown, the input subsystem 120 communicates with an organizational software library 170 (such as the Github software tool commercially available from Microsoft in Redmond, Washington, USA). In some examples, the software library 170 includes: one or more software packages 171; data 172 used by the software packages 171; and a software configuration function 173 that configures the code of the software packages 171 to use the data 172. In some examples, the organizational software library 170 further includes a software bill of materials file (“SBOM”) 174. In some examples, the SBOM file 174 is a.spdx file. In some examples, the SBOM file 174 includes information about related software relationships and a list of software libraries used by the software packages 171.

[0047] In some examples, the software configuration function 173 includes files that describe network behavior, such as network communication description files (which can be in.arxml format) or CAN DBC files (which are text files containing information for decoding raw CAN bus data into "physical values").

[0048] In some examples, the SBOM file 174 is stored in an organizational product lifecycle management tool, such as the JIRA software tool commercially available from Atlassian Corporation in Sydney, Australia.

[0049] In some examples, as Figure 1A shown, the input subsystem 120 communicates with an organizational hardware library 180, such as the Altium Designer software tool commercially available from Altium Limited in Chatswood, New South Wales, Australia. In some examples, the organizational hardware library 180 includes: code 181 for implementing various hardware designs; a list of hardware specifications 182 associated with the hardware designs of the code 181; and an optional list 183 of hardware bills of materials ("HBOMs") associated with the hardware designs of the code 181. The HBOM list 183 is a list of the raw materials, sub-assemblies, intermediate components, sub-parts, parts, and the quantities of each required to manufacture the final product.

[0050] As described below, in some examples, as Figure 1A shown, the system 10 receives risk analysis information 190 at the input subsystem 120. An example of such a risk analysis information file can be an Excel document containing risk analysis information commercially available from Microsoft Corporation. In some examples, the risk analysis information 190 can be manually entered into the system 10 using the user interface subsystem 11. Note that using Excel as the input document is only an example and not a limitation, as the same information can be stored in other data formats, such as "comma-separated values" (CSV) files or value tables in a database.

[0051] In some examples, the risk analysis information 190 includes a description of the analysis results of the risks of predefined security threats associated with one or more functions. In some examples, the risk analysis information includes Threat Analysis and Risk Assessment (TARA) information, such as that defined in ISO / SAE 21434. Associating the risk analysis information 190 with functions is merely an example and should not be construed as a limitation. In some examples, the risk analysis information is associated with: software assets, signal assets, or data assets; an item that is a container for at least one software asset, signal asset, or data asset; a system that is a container for at least one item; and / or a system that is a container for at least one software asset, signal asset, or data asset. In some examples, a collection of systems or items may be defined as a "model".

[0052] As used herein, the term "signal asset" means a message sent from a source to a destination.

[0053] As used herein, the term "software asset" means a feature implemented by software that performs at least one function. As used herein, the term "function" means any function performed, such as "send a signal", "issue an alert", "activate a sensor", etc. In some examples, these functions are implemented by a developer in software.

[0054] An example of a software asset is a "software update", which is a function to update software and is implemented by software in an item or system. An example of a data asset is data associated with an "authentication key" used by a software asset to perform a function. An example of a system is an In-Vehicle Infotainment (IVI) system, which is a collection of hardware and software in a vehicle that provides audio or video entertainment. An example of an item can be one of the hardware components of an IVI system that runs at least one software.

[0055] Figure 1B An example of the TARA information 190 is shown. As shown, a model is defined, which is represented as "Model 1". Model 1 describes at least one system, which includes at least one item, which includes at least one asset. A non-limiting example of such a model is an automotive program for a specific vehicle that includes multiple systems, where one system is an IVI system. The IVI system includes multiple items, such as an application microcontroller and a vehicle communication microcontroller. For example, Figure 1B "Item 1" shown therein may represent an application microcontroller, and "Asset 1" may represent a software asset running on the application microcontroller.

[0056] Figure 1B A pair of systems is shown, represented as System 1 and System 2 (System 2 is not detailed for simplicity). Although a pair of systems is shown, this is not meant to be limiting in any way, and any number of systems may be included in the risk analysis information 190.

[0057] In Figure 1B the example of, System 1 includes a pair of items (represented as Item 1 and Item 2). In Figure 1B the example of, Item 1 has an asset associated therewith (represented as Asset 1), and Item 2 has an asset associated therewith (represented as Asset 2_1). Although each of Item 1 and Item 2 is shown as having a single asset associated therewith, this is not meant to be limiting in any way, and each asset can have any number of assets associated therewith.

[0058] Figure 1B The TARA information 190 of also describes threats associated with the assets. As described above, part of threat analysis and risk assessment is to perform an analysis and recommend different threats that may occur when an asset is compromised. In some examples, threats can be labeled by the STRIDE model, which is a model developed by Praerit Garg and Loren Kohnfelder of Microsoft for identifying computer security threats. The STRIDE model provides mnemonics for six categories of security threats. In some examples, threats to an asset can be labeled by the EVITA model of the EVITA project, as known to those skilled in the art. In some examples, each threat contains a description of the method by which the threat can occur. This description is typically defined by one or more attack paths, which contain the attack steps necessary to perform an attack that will result in the threat, as will be further described below.

[0059] Asset 1 is associated with a pair of threats (represented as Threat 1 and Threat 2). Each of Threat 1 and Threat 2 has an associated attack tree, which are represented herein as Attack Tree 1 and Attack Tree 2, respectively. Although each threat is shown herein as having a single attack tree, this is not meant to be limiting in any way, and multiple attack trees can be provided for a single threat. Each of Attack Tree 1 and Attack Tree 2 is shown as including two attack steps (represented as Attack Step 1 and Attack Step 2), however this is not meant to be limiting in any way, and each attack tree can include any number of attack steps.

[0060] Similarly, Asset 2_1 is associated with a pair of threats, represented as Threat 2_1_1 and Threat 2_1_2. Each of Threat 2_1_1 and Threat 2_1_2 has an associated attack tree, which are represented as Attack Tree 2_1_1 and Attack Tree 2_1_2 respectively herein. Although each threat is shown herein as having a single attack tree, this is not meant to be limiting in any way, and multiple attack trees may be provided for a single threat. Each of Attack Tree 2_1_1 and Attack Tree 2_1_2 is shown as including two attack steps, represented as Attack Step 1 and Attack Step 2; however, this is not meant to be limiting in any way, and each attack tree may include any number of attack steps.

[0061] Figure 1C A first configuration and method for using System 10 are shown, and Figure 1D A second configuration and method for using System 10 are shown.

[0062] In some examples, as Figure 1C shown, System 10 communicates with a Product Lifecycle Management (PLM) or Application Lifecycle Management (ALM) System 800. PLM / ALM is a process for managing the entire lifecycle of a product / application from inception through the engineering, design, and manufacturing phases. An ALM System is an example of ALM System 800 and is commercially available from Polarion Software of Siemens AG in Munich, Germany.

[0063] In some examples, the PLM / ALM System 800 provides risk analysis information 190. Specifically, in some examples, the PLM / ALM System 800 receives risk analysis information 190 from an external source and transmits the received risk analysis information 190 to the input subsystem 120.

[0064] In some examples, the PLM / ALM System 800 also provides additional information about the information stored in the software library 170 and / or the hardware library 180. Specifically, in some examples, the information provided by the software library 170 and / or the hardware library 180 is transmitted by the PLM / ALM System 800 to the input subsystem 120. In some examples, information is output from the PLM / ALM System 800 using the application programming interface (API) of the PLM / ALM System 800, as is known to those skilled in the art. This is a common practice in the software development process.

[0065] In some examples, as will be further described below, System 10 outputs an Attack Step Implementation Mappings 70. In some examples, as will be further described below, System 10 also outputs an Optimized Security Control List 80.

[0066] In some examples, as Figure 1D shown, system 10 receives PLM / ALM information 801 from a PLM / ALM system 800. For example, the PLM / ALM information 801 can include: software implementation task status (e.g., new, in progress, completed); software implementation task effort; software implementation task owner; and / or a reference (“link”) to the software implementation of the task. For example, the ALM system 800 can have a list of functions to be implemented, and each function can be divided into “user stories”. In software development and product management, a user story is an informal, natural language description of a software feature. The effort to implement a feature can be described by story points, which, as known to those skilled in the art, are measures used in flexible project management and development to estimate the difficulty of implementing a given user story. In some examples, system 10 receives information about task effort as user story points. In some examples, the task effort can be the time spent in implementation, the cost of implementation, and / or any other suitable measure.

[0067] In some examples, as Figure 1D shown, system 10 receives risk analysis information 90 directly from an input subsystem 120. Threat analysis and risk assessment (“TARA”) information 190 directly uses the subsystem input 120. In some examples, a user can use the graphical user interface of the management subsystem 11 of system 10 to perform TARA work.

[0068] In some examples, as Figure 1D shown, system 10 accesses an external security control database 202. In some examples, as Figure 1A shown, and in some examples, the security control database 202 is part of a subsystem 20 of system 10. In some examples, the output optimized security control list 80 is stored in system 10, but it can also (optionally using the application programming interface (“API”) of the PLM / ALM system 800) be stored in the PLM / ALM system 800. In some examples, the PLM / ALM system 800 can present information from the optimized security control list 80 for a development project. Similarly, in some examples, the output attack step implementation mapping 70 is stored in system 10, but it can also (optionally using the API of the PLM / ALM system 800) be stored in the PLM / ALM system 800.

[0069] As described above, one step in TARA is to define security threats to assets. For example, a software asset defined as a "signal router" that routes signals may have a threat defined as "compromising the integrity of the signal router software". Another example of a threat associated with the signal router could be "impersonating the identity of the signal". Note that these examples are not meant to be restrictive, but are described to help understand the term "threat" in the context of software assets and threat analysis.

[0070] There are different ways to describe how an attacker would be able to achieve a threat, such as by describing the attack path. For example, for the threat defined as "compromising the integrity of the signal router software", the attack path description could be "using a malware update, the attacker will modify the software of the signal router".

[0071] Another way to describe how an attacker would achieve a threat is to use an attack tree or an attack path. An attack path is defined in this document as multiple sequential attack steps, where the attacker must move through sequential additional steps. An attack step is an action that the attacker must perform as part of the attack. In some examples, each attack step includes information about the associated subsystems, sub-components, or interfaces related to that attack step.

[0072] An attack tree is a conceptual diagram showing how an asset or target might be attacked. An attack tree is a multi-level graph and can consist of a root and multiple nodes. The nodes can include leaf nodes and non-leaf nodes. The root node is at the top of the tree and branches extend downward from this root. The root node represents the attacker's overall goal. The lowest-level nodes (leaf nodes) of the tree represent the activities performed by the attacker. The nodes between the leaf nodes and the root node describe intermediate states or attacker sub-goals. As described above, each node is an attack step. Non-leaf nodes in an attack tree can be designated as "AND" nodes or "OR" nodes and are typically represented by the common Boolean algebra AND / OR shapes. An "AND" node represents a process or program. All the activities or states represented by the nodes directly below the "AND" node must be achieved to achieve the goal or state represented by the "AND" node. An "OR" node represents alternatives. If any of the nodes directly below the "OR" node is obtained, then the "OR" state is also obtained. In an attack tree, each path that satisfies the attack on the root is a corresponding attack path.

[0073] Figure 2A An illustration of an attack tree is shown. Figure 2A The attack tree of includes: a root node 1000; a pair of nodes 1001 and 1002 branching from the root; a pair of nodes 1001_1 and 1001_2 branching from node 1001; and a node 1002_1 branching from node 1002. Note that Figure 2AA specific configuration of the attack tree is merely illustrative and any number of nodes can be provided in the attack tree.

[0074] In Figure 2A 's example, the attack tree includes an "OR" condition between nodes 1001 and 1002, which means that one attack path is sufficient to execute the attack. In contrast, the attack tree includes an "AND" condition between nodes 1001_ and 1001_2, which means that both nodes are required to continue the attack. Thus, Figure 2A 's attack tree includes two attack paths: a first attack path including nodes 1001, 1001_1, and 1002; and a second attack path including nodes 1002 and 1002_2.

[0075] Figure 2B An example of an attack step of the attack tree is shown in a human-readable description. In some examples, the attack step can include an action performed on a resource. Specifically, Figure 2B shows a first attack step 1010 that is used to perform action A on resource X. The feasibility rating of this attack step is also shown; in this case, it is a high feasibility rating. As used herein, the term "feasibility rating" is a value representing the chance that this attack will actually occur in the real world, as known to those skilled in the art. In step 1010_1, the result of attack step 1010 is that resource Y can be accessed.

[0076] Attack step 1010_1_1 includes accessing resource Y and has a high feasibility rating. Attack step 1010_1_2 includes performing action B on resource Y and has a low feasibility rating. In Figure 2B 's example, steps 1010_1_1 and 1010_1_2 include an "AND" condition therebetween, so the combined attack step includes obtaining resource Y and performing action B on resource Y. An example of such a condition can be where resource Y is a "kernel vulnerability", so the attack step includes two sub-steps (1010_1_1 and 1010_1_2), which are discovering the kernel vulnerability (sub-step 1010_1_1) and exploiting the kernel vulnerability (1010_1_2). In other words, as used herein, the term "resource" means anything used to perform an attack. The attack step can include information about the feasibility of performing the step, as known to those skilled in the art. The feasibility of performing an attack step can be based on different parameters, such as: the expertise required to perform the step, the resources required to perform the attack step, the time taken to perform the attack step, and other parameters.

[0077] Table 1 describes an example of the format type of the attack step, as follows:

[0078] Table 1

[0079]

[0080] The syntax of an attack step can be described by one of the types in the table. For example, the attack step "ExploitKernel Vulnerability" (described as sub - steps 1010_1_1 and 1010_1_2 in Figure 2B has the format of "predicate, subject, object", that is, the predicate is "exploit", the subject is "kernel", and the object is "vulnerability".

[0081] In some examples, the format of an attack step includes more formats than those described in Table 1. In some examples, as simple sentences as possible are used to define attack steps. In some examples, by using the management subsystem 11 of the system 10, a user can define additional attack step formats. The use of the attack step format is further described below.

[0082] Figure 2C An attack tree with attack steps and security controls is shown. As used herein, the term "security control" means a method for reducing the feasibility of an attack step. For example, regarding an attack step defined as "Send malicious message" which may have a high feasibility rating, implementing the security control of "Implement a firewall to prevent unauthorized messages" reduces the feasibility of the attack step to medium. In the Threat Analysis and Risk Assessment (TARA) process, having a security control for an attack step is not mandatory. Thus, as described below, the system 10 uses the instruction 304 of the control association subsystem 30 to match security controls to each step.

[0083] In some examples, the attack path database 302 includes multiple attack trees, each attack tree having a corresponding multiple attack steps. In the case where at least one security control that can reduce the feasibility of an attack step is stored in the security control database 202, the corresponding security control is associated with the corresponding attack step. Thus, the attack steps in the attack path database 302 include security controls that have the potential to reduce their feasibility for each step.

[0084] In some examples, in the case where a new security control that is not currently stored in the security control database 202 is identified, a user can optionally use the management subsystem 11 to add the security control to the security control database 202. In some examples, as described below, in response to the security control being added to the security control database 202, the management subsystem 11 initiates a process for matching the added security control to the relevant attack steps stored in the attack path database 302.

[0085] In Figure 2C the example of Figure 2C , a portion of an attack tree is shown, including three attack steps: a first step 1020; a second step 1020_1; and a third step including sub-steps 1020_1_1 and 1020_1_2. As shown, attack step 1020 includes performing action C and has security control 0 associated therewith. Sub-step 1020_1 includes performing action D. Sub-step 1020_1_1 includes accessing resource Z and has security control 1 associated therewith. Sub-step 1020_1_2 includes performing an action using resource Z and has security control 2 associated therewith. Although attack step 1020_1 does not have a security control associated therewith, due to security controls 0, 1, and 2, the attack path will be mitigated or repaired.

[0086] In some examples, the management subsystem 11 is configured to output a list of attack trees, attack paths, and / or attack steps on a user display, such as a graphical user interface. In some examples, when outputting an attack step, the associated security control is output within the attack step, however this is not meant to be limiting in any way. In some examples, the associated security control can be output externally to the corresponding attack step. In some examples, the security controls can be output in a separate list. In some examples, each attack step having a security control associated therewith displays an indication that such a security control exists, and the corresponding security control can be output in response to a corresponding user input (e.g., pointing to a predetermined area of the output attack step).

[0087] Table 2 shows an example of a plurality of security controls stored in the security control database 202, as follows:

[0088] Table 2

[0089]

[0090] As shown in the example of Table 2, in some examples, each security control has the following characteristics: a corresponding ID value; a name; a description; one or more corresponding templates associated therewith (described below); one or more corresponding implementation manners (described below); and an updated value of feasibility, i.e., the new feasibility of the attack step in the case where this security control is used to reduce the feasibility of the attack step. Note that Table 2 is not meant to be limiting, and the security controls stored in the security control database 202 can include more or fewer characteristics without going beyond the scope of the present disclosure.

[0091] In some examples, as shown in Table 2, the security control WP.1 described as "messages sent on the bus should be protected against modification" can be used to reduce the feasibility of attack steps involving message modification. In some examples, as described below, each template includes different metadata that can be used to describe a security control.

[0092] Specifically, in some examples, the template database 503 includes multiple templates. In the case where a new security control is input into the system 10 (and as described above, optionally added to the security control database 202), in some examples, the management subsystem 11 (using the instruction 502) initiates a process to match the added security control with a corresponding one of the multiple templates stored on the template database 503, as will be further described below.

[0093] In some examples, as described above, the security control implementation database 201 includes information about multiple security control implementations. As used herein, the term "security control implementation" means a method of implementing the corresponding security control. Some examples of security control implementations are shown in Table 3A and Table 3B, as follows (provided separately for simplicity only):

[0094] Table 3A

[0095]

[0096] Table 3B

[0097]

[0098] In some cases, there may be multiple options to implement a security control. In some examples, the main differences between implementation options are the resources required to implement the security control, the input / cost of the implementation, and its real-world feasibility. For example, as shown in Table 3A and Table 3B, the security control implementation "messages sent on the bus should be protected against modification" can be implemented with implementation WP.1_impl_1 or implementation WP.1_impl_2. Each option requires different resources, WP.1_impl_1 requires the use of a hardware security memory ("HSM") to store keys, while WP.1_impl_2 does not require additional hardware and only requires random access memory (RAM). Thus, WP.1_impl_1 can reduce the feasibility of the corresponding attack steps to low, while using WP.1_impl_2 will reduce the feasibility of the corresponding attack steps to medium.

[0099] Tables 3A and 3B show examples of security control implementation information including the following characteristics: ID; ID of the associated security control; type of security control; description of the implementation; hardware dependencies of the implementation; software dependencies of the implementation; time cost (days) of the implementation; and updated value of feasibility, however this is not meant to be limiting in any way. In some examples, more or fewer characteristics may be provided for each security control implementation without exceeding the scope of the present disclosure. As shown above in Table 2, in some examples, each security control has a corresponding updated value of feasibility associated therewith. In some examples, this value is the updated value of the feasibility of the implementation of the security control that has been selected by system 10. The selection of the implementation will be further described below. Different security control implementations with different dependencies allow the security control to be implemented on different components with different resources. For example, in the case where the hardware component does not include an HSM, there is no way to implement WP.1_impl_1. In order to reduce the feasibility of the corresponding attack step, it will be necessary to implement WP.1_impl_2, even though it is inferior from a security perspective.

[0100] In some examples, as described below, the security control optimization subsystem 60 generates an optimized security control list 80. In some examples, when generating the optimized security control list 80, the security control optimization subsystem 60 considers implementation dependencies. For example, with respect to a particular security control, in the case where the HBOM is associated with the corresponding item associated with the security control, the security control optimization subsystem 60 will filter out all security control implementation option that cannot be implemented.

[0101] By template matching

[0102] Table 4 describes an example of the format of the description of the security control, as follows:

[0103] Table 4

[0104]

[0105] Although Table 4 shows 8 types of security control formats, this is not meant to be limiting in any way, and more or fewer formats may be provided without exceeding the scope of the present disclosure. In some examples, the security control description preferably includes as simple a sentence as possible. In some examples, using the management subsystem 11, the user can add additional security control formats. The use of the security control format is described below.

[0106] Figure 3AShows the overall process of a method for matching security controls with attack steps using the template matching subsystem 50. Note that the methods described herein are not meant to be limiting, and other suitable methods may be used to match security controls with attack steps without departing from the scope of the present disclosure. In stage 1030, as described below with reference to Figure 3B one or more security controls are matched with corresponding templates. In stage 1040, as described below, one or more attack steps are matched with corresponding templates. In stage 1050, as described below, one or more security controls are matched with one or more attack steps.

[0107] Figure 3B Shows an example process of matching security controls with templates stored on the template database 503 using instruction 502. Note that Figure 3B the process is not meant to be limiting, and instruction 502 may implement different processes for matching security controls with templates without departing from the scope of the present disclosure. In some examples, iteratively, security controls stored in the security control database 202 are analyzed to identify security controls that do not have an associated template. In some examples, for each of these identified security controls, the Figure 3B method is performed. The security control described with reference to Figure 3B is similar to "WP.4" in Table 2.

[0108] In stage 1100, for each security control, the subject, predicate, and / or object are extracted from the description of the security control. Table 5 shows examples of different options for the subject and predicate, as follows:

[0109] Table 5

[0110]

[0111] In some examples, the process of text analysis is continuously trained using the information in the security control library 20, and the trained model is used to extract corresponding features from the description of the security control. An example of the process of training such a model is described below with reference to Figures 3C to 3D

[0112] In some examples, the process of instruction 502 uses text matching between the parsed statements in the security control and the templates. In some examples, text matching is performed using software-based techniques for comparing two strings and algorithms for text similarity, such as "tf–id", known to those skilled in the art, which is a numerical statistic intended to reflect the importance of a term to a document in a collection of documents or corpus. In stage 1110, the subject of the security control is compared with the subject of the template to determine whether there is a template that contains such a subject. ​

[0113] Although Figure 3B the process is shown herein as searching for the subject before the predicate, this is not meant to be limiting in any way and the predicate can be searched for before the subject, and this is not outside the scope of the present disclosure. Although Figure 3B the process is shown herein as using the features of each security control to identify the corresponding template, this is not meant to be limiting in any way. In other examples, the corresponding features of each template can be employed to identify the corresponding one of a plurality of security controls whose description includes that corresponding feature.

[0114] If one or more templates of the subject of the corresponding security control are identified in stage 1110, then in stage 1120, the process proceeds to the predicate extracted from the description of the security control. Specifically, in stage 1130, the predicate of the security control is compared with the template or the predicates of the templates identified in stage 1110 to determine whether there is a template that includes such a predicate.

[0115] In some examples, if a template is identified in stage 1130, then in stage 1140, the security control matches the identified template, and details of the mapping between the corresponding security control and the corresponding template are optionally stored in a corresponding table (such as table 5 above). Note that the term "table" as used herein is not meant to be limited to any particular format for storing and / or outputting data and is only used to describe a predefined relationship between the stored data / information.

[0116] In some examples, if a template is not successfully identified in stage 1130, then in stage 1150, the management subsystem 11 outputs a list of recommended templates to the user. In some examples, in response to a user input selecting one of the recommended templates, the mapping details of the selected template are stored in the security control library 20 and, in some examples, are used to improve the trained model for future reuse. In some examples, then, in stage 1140, the mapping details of the selected template are stored in the corresponding table as described above.

[0117] In some examples, if a template is not successfully identified in stage 1110, then in stage 1160, the management subsystem 11 prompts the user to manually assign a template to the corresponding security control. In some examples, in response to a user input assigning a template to a security control, the mapping details of the selected template are stored in the security control library 20 and, in some examples, are used to improve the trained model for future reuse. In some examples, then, in stage 1140, the mapping details of the selected template are stored in the corresponding table as described above.

[0118] As described above, in some examples, a model is trained to extract corresponding features from a description of a security control. As described below, such a model is also trained to extract corresponding features from a description of an attack step. In some examples, a normalization dictionary is prepared (optionally manually) for the description of the security control. An example of a part of such a dictionary is given in Table 6 as follows:

[0119] Table 6

[0120]

[0121] The example of Table 6 is given for the attack step. However, in some examples, a similar dictionary is provided for the description of the security control. In the example shown in Table 6, a list of possible words from the description of the additional steps, the type of the words (i.e., what the words refer to), and replacement words for mapping to the template are stored.

[0122] Figure 3C A high-level flow of a process for normalizing the description text of a security control is shown, which is executed using instruction 502. Note that, as described below, Figure 3C the process can be similarly used for the description text of the attack step. In some examples, in step 1200, the words of the description of the security control are converted to lowercase. In some examples, in stage 1210, the stored dictionary as described above with reference to Table 6 is used to replace words. In some examples, in stage 1220, duplicate words in the description text are identified and replaced with a single word. For example (e.g., regarding the attack step), if the word sequence is as follows: "send message in network", then this sequence is replaced with the following sequence: "sendmessage in network".

[0123] Figure 3D A high-level flow of a process for training a model to extract corresponding features from a description of a security control is shown, which is executed using instruction 502. Note that, as described below, Figure 3D the process can be similarly used for the description text of the attack step.

[0124] In some examples, in stage 1230, the description of the security control (or attack step) is normalized as described above with reference to stages 1200 to 1220. In some examples, in stage 1240, the normalized description in stage 1230 is parsed into tokens. In some examples, the "part-of-speech tagging" technique is used, optionally using the spaCy library from spacy.io or the Natural Language Toolkit (NLTK) from nltk.org, to perform the parsing. An example of parsing using the spaCy coding language in Python is shown below:

[0125]

[0126] In stage 1250, post-processing is performed to define the subject, predicate, and / or object found in the description. In some examples, plural nouns are converted to singular nouns. An example of Python code implementing such a step is shown below:

[0127]

[0128] In some examples, all or some forms of the predicate are converted to a predetermined form, such as the singular form of the simple present tense. In some examples, this can be performed by using the.lemma feature of the tokens from the spaCy library.

[0129] Return to Figure 3A stage 1040, as described above, to match one or more attack steps to the corresponding templates. In some examples, the processes of stages 1100 to 1160 are performed by leveraging instruction set 501 to match the attack steps to the corresponding templates, as described above with respect to the security control.

[0130] Similar to the stored mapping of security controls to templates described above with reference to the table, in some examples, a mapping of attack steps to templates is stored. An example of such a mapping table is shown in Table 7, as follows:

[0131] Table 7

[0132]

[0133] Figure 3E Figure 304 shows a high-level flow of the process of matching attack steps to security controls using instruction set 304. In some examples, in stage 1300, the attack step-to-template mapping table (described above with reference to Table 7) is looped through. Note that this method can be performed on data stored in any format, and a table is given only as an example.

[0134] In some examples, for each attack step in the table, in stage 1310, the analysis step controls the table to determine whether attack steps with the same subject, predicate, and / or object are stored in the step control mapping table, where for each security control, the data of the corresponding security control is stored together with the corresponding template and one or more associated security controls. Note that this method can be performed on data stored in any format, and only a table is given as an example. An example of the step-control mapping table is given in Table 8 as follows:

[0135] Table 8

[0136]

[0137] Although Table 8 is shown as including: a description of the attack step and the subject, predicate, and object; an associated template; and one or more associated security controls, this is not meant to be limiting in any way. In some examples, the step-control mapping table includes more or fewer features, and this does not exceed the scope of the present disclosure.

[0138] In some examples, if no such attack step is found in the step control mapping table, then in stage 1320, the process cycles through (described above with reference to Table 5) the security control to template mapping table to identify one or more security controls mapped to a template that is also mapped to the corresponding attack step in the template mapping table (described above with reference to Table 7). In some examples, in stage 1330, for each attack step, it is determined whether the security control to template mapping table contains a security control having the same template as the corresponding attack step.

[0139] In some examples, if no such security control is found in the security control to template mapping table, then in stage 1340, for each security control stored in the security control to template mapping table, the process cycles through the security control to template mapping table as described above. In some examples, in stage 1350, for each attack step, it is determined whether the security control to template mapping table contains a security control whose text has the same subject and / or predicate as the corresponding attack step.

[0140] In some examples, if no such security control is found in the security control to template mapping table, then in stage 1360, the management subsystem 11 prompts the user to manually assign one or more security controls to the corresponding attack steps of the corresponding security controls (or manually assign one or more attack steps to the corresponding security controls).

[0141] In some examples, in stage 1370, in response to received user input that assigns a security control to an attack step (or assigns an attack step to a security control), the attack step is associated with the corresponding security control and optionally stored in a step-control mapping table. As used herein, the verb "associate" means to establish a predetermined relationship between two elements. This can include, but is not limited to: adding information of one element to the data of another element; storing the two elements in a particular location or configuration such that when the data of one element is accessed, the data of the other element is also accessed; and / or storing a predetermined indication that the two elements are associated with each other in a mapping table.

[0142] In some examples, if it is determined in stage 1350 that a security control having the same subject and / or predicate exists in the security-to-template mapping table, then in stage 1380, the identified security control and the corresponding attack step are output to the user as a recommendation, and in response to user input agreeing to the recommendation, the identified security control is associated with the corresponding attack step and optionally stored in an attack-step-to-security-control mapping table.

[0143] In some examples, if it is determined in stage 1330 that an attack step having the same associated template exists in the attack-step-to-template mapping table, then in stage 1390, the identified attack step is associated with the corresponding security control and optionally stored in a step-control mapping table. In some examples, the identified attack step and the corresponding security control are output to the user as a recommendation, and in response to user input agreeing to the recommendation, the identified attack step is associated with the corresponding security control.

[0144] Attack path mapping

[0145] Figure 4AShows a high-level process of mapping an attack path to a threat using instruction set 301. The mapping can be performed by mapping one or more attack paths to a threat. In some examples, the mapping can be performed by mapping an attack tree to a threat, where the attack tree includes one or more attack paths. In some examples, in stage 1400, instruction set 301 analyzes the information of each threat in the received risk analysis information 190 to identify whether the corresponding information includes a description of an attack path and / or a description of an attack. In some examples, a text search is performed to identify one of the terms "attack path", "attack tree", or "attack description". In some examples, the attack description is identified by performing a text search based on predefined attack step types as described above with reference to Table 1. In some examples, the location information about potential attack paths / trees / descriptions stored in the configuration file is identified. In some examples, the description of an attack is a general description of the attack, while the description of an attack path or attack tree describes the more detailed steps of the attack.

[0146] In some examples, in the case where it is determined that the risk analysis information 190 of a specific threat contains a description of one / more attack paths or an attack description, in stage 1410, the process searches the threat-to-attack path mapping database 303 for the stored mapping. The stored mapping can be a mapping between the identified attack description and the stored attack tree or one or more attack paths and / or a mapping between the identified attack path / attack path description and the stored attack tree or one or more attack paths.

[0147] In some examples, if it is determined in stage 1420 that such a mapping exists, then in stage 1430, the newly received threat is associated with the stored attack tree or attack path. In some examples, if it is determined in stage 1420 that such a mapping does not exist, then in stage 1440, the management subsystem 11 outputs a prompt to the user to manually map the one / more attack path descriptions or attack descriptions of the received threat to the corresponding one of the multiple attack trees or attack paths stored in the attack path database 302. In some examples, the new mapping is stored in the threat-to-attack path mapping database 303. In some examples, if no appropriate attack tree or attack path is stored in the attack path database 302, the user can manually create a new attack tree or a new attack path and then store the new attack tree (or new attack path) in the attack path database 302.

[0148] In some examples, if it is determined in stage 1400 that the risk analysis information 190 of a specific threat does not contain one / more attack path descriptions or an attack description, then in stage 1450, a process is performed to map an appropriate attack tree or attack path, as will be referred to Figure 4BAs described above. Specifically, Figure 4B shows a high-level process for mapping an attack tree or attack path to a threat based on threat matching using instruction set 301.

[0149] In stage 1500, characteristics and threat information are retrieved from risk analysis information 190. In some examples, as shown in Table 9 below, the characteristic information includes: the name of an item associated with the threat; the name of an asset associated with the threat; and software characteristics or data assets associated with the threat (e.g., "identity of spoofed signal routing"). In some examples, the threat information includes a threat list. Although the table shows the above characteristics, this is not meant to be limiting in any way. In some examples, more or fewer characteristics may be extracted without exceeding the scope of the present disclosure.

[0150] Table 9

[0151]

[0152] In some examples, in stage 1510, the process determines whether the received threat contains the required information, such as the information described with reference to Table 9. In some examples, the required information is an asset profile and a threat list. In some examples, the information is identified by performing a text search based on a predefined format of items, assets, characteristics, and / or threats such as those described with reference to Table 9. In some examples, the identification is based on information about the location of the information stored in a configuration file.

[0153] In some examples, in the case where the process determines that the received threat contains the required information, in stage 1520, the process searches the threat-to-attack path mapping database 303 to determine whether there is a mapping between the corresponding information (such as the asset profile and threat list of the threat) and a stored attack tree or one or more attack paths. In some examples, the asset profile contains all the characteristics of the threat. Thus, in the example shown in Table 9, the process searches for mappings that include the relevant assets, relevant hardware components, and relevant software characteristics, signal assets, or data assets.

[0154] In some examples, if the process determines in stage 1530 that such a mapping (or mappings) exists, then in stage 1540, the management subsystem 11 outputs to the user a recommended attack tree or attack path for the new threat based on the identified mapping.

[0155] In some examples, if the process determines in stage 1530 that such a mapping does not exist, then in stage 1550, the management subsystem 11 outputs a prompt to the user to manually map one or more attack paths or attack descriptions of the received threat to the corresponding one of the multiple attack trees (or attack paths) stored in the attack path database 302. In some examples, the new mapping is stored in the threat-to-attack path mapping database 303. In some examples, if no appropriate attack tree (or one or more attack paths) is stored in the attack path database 302, the user can manually create a new attack tree (or one or more attack paths) and then store the new attack tree (or one or more attack paths) in the attack path database 302.

[0156] Figure 5A Illustrates a high-level flow of the process in which the security control optimization subsystem 60 generates a list of security control implementations. In some examples, in stage 1600, the attack trees (or one or more attack paths) stored in the attack path database 302 are associated with the hardware items. In some examples, as described above, the association is performed according to the mapping stored in the threat-to-attack path mapping database 303. In some examples, in stage 1610, the HBOM information is associated with the hardware items of stage 1600. As described above, in some examples, the HBOM is provided by the hardware library 180.

[0157] In some examples, in stage 1620, the attack step implementation mapping subsystem 40 scans the HBOM list 183 to obtain specifications such as hardware security modules (HSMs), memory protection units (MPUs), system architectures, and / or any relevant interfaces. In some examples, the HBOM list 183 is scanned using a language comparison such as a predefined string search.

[0158] In some examples, in stage 1630, for each item, the attack step implementation mapping subsystem 40 generates a list of cybersecurity specifications based at least in part on the resources identified in the HBOM list 183. In some examples, the list of cybersecurity specifications includes the resources of the HBOM list 183 that allow the implementation of security controls.

[0159] In some examples, in stage 1640, the security control optimization subsystem 60 filters the security control implementation database 201 to identify only the security control implementations that have hardware dependencies (and optionally also software dependencies) on the corresponding list of cybersecurity specifications for the hardware item.

[0160] In some examples, in stage 1650, the security control optimization subsystem 60 generates a list of identified security control implementations associated with respective attack steps of an attack tree (or one or more attack paths) of a respective threat that can be implemented for a respective item. In some examples, the security control optimization subsystem 60 outputs the generated list. In some examples, the management subsystem 11 outputs the generated list on a user display. In some examples, the attack step implementation mapping 70 is also output.

[0161] In some examples, the attack step implementation mapping 70 includes mapping details of security control implementations, e.g., how to implement security controls in association with the HBOM list 183 and / or the SBOM file 174. More examples of the attack step implementation mapping 70 will be described further below.

[0162] Figure 5B A high-level flow showing the process by which the security control optimization subsystem 60 further optimizes the list of security control implementations for stage 1650 is shown. In some examples, in stage 1700, a risk objective for the item is set. In some examples, the risk objective is at least partially based on data in the risk analysis information 190. In some examples, as described below, a maximum investment and / or cost value is set for the security control optimization subsystem 60. In some examples, a security depth value is set for the security control optimization subsystem 60. As used herein, the term "security depth value" means the number of different resources affected by the selected security control implementations.

[0163] In some examples, in stage 1720, optionally, for each security control, the security control optimization subsystem 60 selects security control implementations that meet the desired risk objective with minimum investment and / or cost and / or maximum coverage, as will be further described with reference to Figure 5C below. In some examples, multiple security control implementations are selected such that the multiple security control implementations together meet the desired risk objective. In some examples, the security control implementations are selected such that they meet the required security depth value.

[0164] In some examples, in stage 1730, at least partially based on the selected implementations of stage 1720, the security control optimization subsystem 60 optimizes the list of security control implementations that should be implemented to meet the risk objective. In some examples, the security control optimization subsystem 60 outputs the generated list. In some examples, the management subsystem 11 outputs the generated list on a user display.

[0165] Figure 5CIllustrates a high-level process of the security control optimization subsystem 60 selecting security control implementations with the minimum cost investment and / or cost and / or maximum coverage. In some examples, in stage 1800, for each attack step of each attack tree (or each attack path) of each threat of each asset of each item of each threat model, the security control optimization subsystem 60 identifies the associated security control implementations as described above. However, note that, as described above, security controls may be assigned only to a portion of the attack steps. In some examples, the data associated with an attack step includes the ID of the corresponding attack step, the ID of the associated security control implementation, a value indicating the risk reduction caused by the security control implementation, the number of attack paths affected by the security control implementation, and the investment required to implement the security control implementation.

[0166] In some examples, in stage 1810, for each security control implementation, the security control optimization subsystem 60 determines the number of attack paths processed by that particular security control implementation.

[0167] In some examples, in stage 1820, the security control optimization subsystem 60 updates the implementation investment value of the corresponding security control implementation. As used herein, the term "implementation investment" means the amount of time and / or resources required to implement the corresponding security control implementation. In some examples, a predetermined function provides a value based at least in part on the weighted values of time and resources in order to determine the implementation investment value. In some examples, in the case where the corresponding security control implementation has been implemented, in some examples, the implementation investment value is set to zero. The method for checking whether a security control implementation has been implemented is described below with reference to Figure 5D Describe a method for checking whether a security control implementation has been implemented.

[0168] In some examples, in stage 1830, for each of the above security control implementations, the security control optimization subsystem 60 determines the impact of the corresponding security control implementation on the overall feasibility of the attack path or attack tree. In some examples, the score is a predetermined function of the coverage of the security control implementation (i.e., how many attack paths or attack steps the security control implementation processes), the implementation investment value of the security control implementation, and the amount of risk reduction provided by the corresponding security control implementation. In some examples, the score is determined by the security control optimization subsystem 60 and is defined as:

[0169] Score = (Coverage x Weight 1 + Reduced_Risk x Weight 2 - Weight 3 x Investment) / Maximum_Score.

[0170] Herein, "coverage" is the number of attack paths or attack steps in a single attack tree (or attack path) or in multiple attack trees (or multiple attack paths) of different threat models (i.e., the coverage value); "reduced_risk" is a value indicating how much the overall risk level has been reduced; and "maximum_score" is a value that is updated each time the "score" is greater than the current "maximum feasibility score". In some examples, the "reduced_risk" is determined by the risk subsystem 65. It should also be noted that the coverage value includes the number of attack paths handled by a single security control implementation across multiple threats in multiple projects. In some examples, weights 1 through 3 can be adjusted in response to user input. In some examples, the "score" is calculated continuously until the risk goal is met or a predetermined time period has elapsed. In some examples, using the final risk score, the security control optimization subsystem 60 outputs an optimized list of security controls 80 such that the security control implementations have scores associated with them. In some examples, the score is output. In some examples, the security control implementations are listed in order of their scores.

[0171] Table 10 shows an example of the optimized list of security control implementations 80, as follows:

[0172] Table 10

[0173]

[0174]

[0175] As shown in the example of Table 10, the security control list 80 includes: the ID of the corresponding security control implementation; the ID of the corresponding one or more threats received in the risk analysis information; the implementation input value for the corresponding security control implementation; the number of attack steps handled by the corresponding security control implementation; and the "score".

[0176] In some examples, in phase 1840, if the feasibility of the attack path cannot be reduced and if the risk is still higher than the defined risk goal, the security control optimization subsystem 60 generates a reminder. In some examples, the reminder includes sending a report, for example, as described in Table 11:

[0177] Table 11

[0178]

[0179] As shown in the example of Table 11, the reminder can include the IDs of the following items: model, asset, threat, attack path, damage scenario (i.e., what can be damaged by the corresponding attack), and risk value.

[0180] In some examples, in stage 1850, for a given HBOM and SBOM, if a particular security control implementation cannot be achieved due to resource dependency issues, the score of this security control implementation is set to zero. In this way, this security control implementation is no longer used.

[0181] Figure 5D FIG. shows a high-level flow of the process by which the security control optimization subsystem 60 determines whether a security control implementation has been achieved. In some examples, in stage 1900, the security control optimization subsystem 60 maps each security control implementation to a corresponding TARA key. As described above with reference to Table 10, each security control implementation may be associated with the ID of one or more corresponding threats. In some examples, each TARA key has the following format:

[0182] TARA-model-id: Item-id: TARA-asset-id: TARA-threat-id: TARA-step-id.

[0183] For example, the TARA key may be: Security control implementation 1 → Model1:Item1:Asset1:Threat1:Attack tree1:Attack step1.

[0184] In some examples, in stage 1920, for each TARA key, the security control optimization subsystem 60 identifies the status of the corresponding security control implementation in the TARA-to-security implementation data.

[0185] In some examples, for each security control implementation whose status is set to "completed", the security control optimization subsystem 60 sets the corresponding implementation input value to zero.

[0186] In some examples, user input is received that indicates that a corresponding security control has been implemented (such as, as described above). In some examples, the security control optimization subsystem 60 identifies one or more attack paths associated with the implemented security control. In some examples, such attack paths are identified by identifying one or more attack steps that have the corresponding security control associated with them. In some examples, as described above, the initial risk level of each threat is received. In some examples, the security control optimization subsystem 60 defines the residual risk level of the corresponding threat after implementing the corresponding security control. As used herein, the term "residual risk level" refers to the risk level after implementing the corresponding security control. In some examples, the security control optimization subsystem 60 optionally outputs the defined residual security control via the output subsystem 130.

[0187] Figure 6A It shows a high-level process of the process in which the attack step implementation mapping subsystem 40 maps security control implementations to software assets and project development tasks. In some examples, in stage 2000, for each security control implementation, the subsystem 40 optionally generates security requirements within the requirements tool. In some examples, the requirements include: a description of the attack step; a description of the attack step to be mitigated; and a unique key: for example, TARA-model-id:Item-id:TARA-asset-id:TARA-threat-id:TARA-step-id. For example, the TARA key can be:

[0188] ADAS1223:TCU112:SIGNAL_ROUITING_1:SPOOFING222:STEP123.

[0189] In some examples, in stage 2010, the attack step implementation mapping subsystem 40 maps security control implementations to software assets and project development tasks. In some examples, the TARA threat is against the software or data assets of the project. For example, spoofing the signal manager of an in-vehicle infotainment (IVI) system may compromise the integrity of OTA updates. As described above, the security control is associated with the threat and thus with the software or data asset. In some examples, the attack step implementation mapping subsystem 40 queries the PLM system 800 for all tasks with a description containing the name of the software / data asset (e.g., retrieves all tasks of project X of the Epic type with "software asset" in the name or description).

[0190] In some examples, in stage 2020, for each task received from the management subsystem 11, the task information is stored in a data structure, as further described below with reference to Figure 6B the "Tasks" section of Table 12.

[0191] In some examples, the attack step implementation mapping subsystem 40 updates the task priorities according to the scores described above. In some examples, using the reference to the corresponding security control implementation, the attack step implementation mapping subsystem 40 pulls some or all of the software and configuration files from the software library 170 and associates the TARA assets with the corresponding attack steps.

[0192] In some examples, in stage 2030, a unique key is provided, such as the following: TARA-model-id:Item-id:TARA-asset-id:TARA-threat-id:TARA-step-id as described above. In some examples, the attack step implementation mapping subsystem 40 stores some or all of the information of this key in a storage device. For example, these can be stored in a storage space, where there is a key pointing to an object in the storage space, and the object can be a.zip file containing all the necessary information.

[0193] Figure 6B A high-level process of the attack step implementation mapping subsystem 40 generating a data structure is shown. In some examples, in stage 2100, methods such as text search and / or code analysis based on language grammar (C, C++, JAVA) are used to scan software files. In some examples, the attack step implementation mapping subsystem creates a data structure. As shown below, an example of the data structure is given in Table 12. As shown in the figure, Table 12 includes: TARA ID; threat ID; related tasks; requirements associated with the project; corresponding software components; and SBOM information. In some examples, as shown in Table 12, the software component is associated with any one of the software assets, data assets, and / or signal assets associated with the received risk analysis information.

[0194] In some examples, the attack step implementation mapping subsystem 40 scans the binary files of the project to create a list of risk functions used. In some examples, a predetermined disassembly method known to those skilled in the art is used to perform the identification of risk functions. In some examples, the risk functions are added to the data structure in stage 2100, and / or a new data structure is created for this purpose.

[0195] In some examples, in stage 2020, the attack step implementation mapping subsystem 40 scans software configuration files (e.g., adaptive AUTOSAR inventory platform and inventory files) associated with the project from the software library 170. In some examples, this information is further added to the data structure in stage 2100, and / or a new data structure is created for this purpose.

[0196] Table 12

[0197]

[0198]

[0199] In some examples, in stage 2030, the attack step implementation mapping subsystem 40 parses an SBOM file (e.g., an SPDX file) to create a list of some or all of the dependencies. In some examples, this information is further added to the data structure of stage 2100, and / or a new data structure is created for this purpose.

[0200] Figure 6C A high-level flow showing the process by which the attack step implementation mapping subsystem 40 maps attack steps to software configuration data is shown. In some examples, in stage 2200, as described above, the attack step implementation mapping subsystem 40 creates a unique key. In some examples, as described above, a unique key is generated for each attack step for each asset of each item of each threat model.

[0201] In some examples, in stage 2210, the attack step implementation mapping subsystem 40 updates the input estimate of the security control implementation stored in the security control implementation database 201 based at least in part on the information stored in the "task" section of the above data structure. In some examples, at step 2220, the attack step implementation mapping subsystem 40 updates the asset risk level according to the task status of the data structure.

[0202] In some examples, as used herein, the term "risk level" is defined as a predetermined function of the corresponding feasibility rating and the corresponding impact value. In some examples, the impact value is a numerical indication of the impact that a particular threat would have on the corresponding asset (or on the project itself) if the corresponding threat were realized. In some examples, as is known to those skilled in the art, numerical values are assigned to the impact values.

[0203] In some examples, in stage 2230, the attack step implementation mapping subsystem 40 associates the priority of the task / software based on the score of the security control associated therewith (as described above). Thus, this score can be used to determine the priority of software testing and verification. In some examples, the attack step implementation mapping 70 includes the priority of the task / software and optionally includes the risk level associated with each project / asset.

[0204] In some examples, the data logger configuration subsystem 61 defines the priority of potential signals, which is defined at least in part based on the risk level of the threat associated with the asset that can send the corresponding potential signal, such that an increased risk level of the signal source translates to a higher priority of the corresponding signal. In some examples, the data logger configuration subsystem 61 generates configuration data for the data logger, which indicates the defined priority of the potential signals. In some examples, the generated configuration data 85 is output. In some examples, the configuration data 85 is stored in a file in a predetermined format.

[0205] Thus, for a vehicle with a data logger that receives messages from a network and sends samples to a backend for continuous analysis / training, the generated configuration data can be used to prioritize the sent information based on signal priorities. Thus, if there are constraints on the amount of data that can be sent, the data logger will first record data for signals with high priority. Figure 7 A high-level flowchart of a method for outputting information about signals transmitted within an item is shown. In stage 2300, the signal subsystem 62 receives information about at least one signal transmitted within the item. In some examples, the information is received from the ALM system 800. In some examples, the received information includes identification information of the assets that send signals within the item and the assets that receive signals within the item. In some examples, information about multiple signals within the item is received.

[0206] In stage 2310, in some examples, for each signal in stage 2300, the risk level of one or more threats associated with the asset that received the signal (as described above) is output. In some examples, for each signal in stage 2300, the feasibility rating of one or more threats associated with the asset that sent the signal (as described above) is output.

[0207] In stage 2320, in some examples, the output information in stage 2310 includes outputting the received information about multiple signals and information about the risk level of threats associated with the assets that received the multiple signals and the feasibility rating of threats associated with the assets that sent the multiple signals. Specifically, in some examples, the information about multiple signals is arranged together in a predetermined format (such as in a graph). In some examples, the information for each of the multiple signals includes: identification data of the assets that send and receive the signals; information about the risk level of one or more threats associated with the asset that received the signal; and information about the risk level of one or more threats associated with the asset that sent the signal.

[0208] In some examples, the signal subsystem 62 also identifies the communication paths between assets. In some examples, the communication paths between assets are identified at least in part based on the received information associated with the multiple signals. In some examples, the communication paths between assets can be between assets within the same item and between separate assets, i.e., communication paths that cross between items.

[0209] In some examples, the signal subsystem 62 compares the risk levels of assets that communicate with each other. In some examples, when one or more signals are sent to an asset whose risk level is lower than that of the asset sending the signal, the signal subsystem 62 generates a reminder. In some examples, the generated reminder is output by the output subsystem 130. In some examples, the reminder notifies the user that an asset with a lower risk level is actually at a higher risk due to communication with a high-risk asset.

[0210] In some examples, the comparison of risk levels is not limited to two assets that communicate directly with each other. In some examples, the signal subsystem 62 identifies an asset chain in which each of a plurality of assets communicates with another asset in the asset chain. In some examples, the signal subsystem 62 compares the risk levels of all assets within the chain. In some examples, when one or more assets within the chain have a higher risk level than other assets within the chain, as described above, the signal subsystem 62 generates a reminder. In some examples, the generated reminder is output by the output subsystem 130. In some examples, the reminder notifies the user that an asset with a lower risk level is actually at a higher risk due to communication with a high-risk asset.

[0211] In some examples, the ID subsystem 63 defines an asset chain identifier (ID) and associates it with each asset. In some examples, the asset chain ID is a unique identifier that identifies the threat of each asset within the corresponding asset chain (as described above). In some examples, the ID subsystem 63 is configured to output information about the threat of the assets of the corresponding chain when a request including the corresponding asset chain ID is received.

[0212] In some examples, the asset chain ID is output by the output subsystem 130. In some examples, the output information associated with each asset includes the corresponding asset chain ID. In some examples, the ID subsystem 63 defines the need for the user to add the asset chain ID when performing a task associated with the corresponding asset, such as tracking an error associated with the asset. In some examples, the need can be any type of notification to the user. In some examples, the ID subsystem 63 also defines a predefined message format and adds the predefined message format to the need such that the user is required to use the predefined message format associated with the corresponding asset chain ID.

[0213] In some examples, the permissions subsystem 64 generates information about the resources required for each asset and the permissions allowed for the corresponding asset. As used herein, the term "permissions" refers to which resources an asset is allowed to access. In some examples, the permissions are at least partially based on user input.

[0214] In some examples, the permission subsystem 64 compares the permissions of a corresponding asset with the risk level of the asset. In some examples, each risk level has one or more predefined permissions that are allowed at that risk level. In some examples, if the permission of the corresponding asset is not allowed at the risk level of the corresponding asset, the permission subsystem 64 generates a corresponding reminder. In some examples, the reminder is output at the output subsystem 130.

[0215] In some examples, the security control optimization subsystem 60 outputs information about one or more security controls associated with a corresponding asset such that the risk level of the asset can be reduced to a level that will allow the permission. In some examples, the security control optimization subsystem 60 updates the security control list 80 accordingly.

[0216] In some examples, the permission subsystem 64 compares the permissions of each asset in a project with the risk levels of other assets in the corresponding project. In some examples, if the permission of the corresponding asset is not allowed at the risk level of any other asset in the corresponding project, the permission subsystem 64 generates a corresponding reminder. In some examples, the reminder is output at the output subsystem 130.

[0217] In some examples, the security control optimization subsystem 60 outputs information about one or more security controls associated with a corresponding asset such that the risk level of the asset can be reduced to a level that will allow the permission. In some examples, the security control optimization subsystem 60 updates the security control list 80 accordingly.

[0218] In some examples, the permission subsystem 64 optionally compares the permissions of each asset with the risk levels of other assets that communicate with it and / or are within the asset chain, at least in part based on the output of the signal subsystem 62. In some examples, if the permission of the corresponding asset is not allowed at the risk level of any other asset that communicates with the corresponding asset, the permission subsystem 64 generates a corresponding reminder. In some examples, the reminder is output at the output subsystem 130.

[0219] In some examples, the security control optimization subsystem 60 outputs information about one or more security controls associated with a corresponding asset such that the risk level of the asset can be reduced to a level that will allow the permission. In some examples, the security control optimization subsystem 60 updates the security control list 80 accordingly.

[0220] Figure 8 A high-level flowchart of a method for outputting information in response to abnormal behavior information is shown. As used herein, the term "abnormal behavior information" means information about detected abnormal behavior or an indication of a vulnerability that may lead to abnormal behavior. As used herein, the term "abnormal behavior" means any action that does not satisfy a predefined rule.

[0221] In some examples, during stage 2400, anomalous behavior information associated with one or more assets is received. In some examples, the one or more assets are part of a vehicle. In some examples, the one or more assets are part of one or more components that communicate with the vehicle.

[0222] In some examples, the anomalous behavior information can be received from a vulnerability management system that receives alerts regarding Common Vulnerability Disclosures (CVE). In some examples, the CVE is defined within the National Vulnerability Database (NVD). In some examples, the information is received via the ALM system 800.

[0223] In some examples, the anomalous behavior information is related to an attack. In some examples, the anomalous behavior information regarding the attack includes components associated with the attack. In some examples, the anomalous behavior information is associated with a program error.

[0224] In some examples, the anomalous behavior information includes: an identifier of the corresponding asset; an identifier of the software version of the asset; and / or information regarding an attack interface (i.e., which interface the attack is related to), if any.

[0225] In some examples, at stage 2410, information related to one or more assets of stage 2400 is output. In some examples, the output information includes an attack path associated with one or more assets.

[0226] In some examples, during stage 2420, the risk subsystem 65 updates, at least in part based on the received anomalous behavior information, the risk level associated with each of the identified assets in stages 2400 and 2410. In some examples, the anomalous behavior affects the feasibility of one or more associated attack steps, and thus the risk increases.

[0227] In some examples, the risk subsystem 65 then updates the risk level of each of the identified assets. In some examples, the risk level is updated by updating the feasibility of the corresponding attack steps.

[0228] In some examples, the anomalous behavior information includes an indication of one or more resources and one or more software components. In some examples, the risk subsystem 65 then identifies any assets having the same resources and / or the same software components (such as those defined in Table 12). In some examples, the assets are identified based on a risk analysis identifier associated with the corresponding resource / software component. In some examples, the risk analysis identifier is an identifier associated with the received risk analysis information, such as the TARAID described above.

[0229] In some examples, the output information further includes the attack paths of the identified assets. In some examples, the risk subsystem 65 identifies all relevant attack steps for each of the identified assets.

[0230] In some examples, in stage 2430, the abnormal behavior is associated with software that implements one or more security controls. In some examples, the security control optimization subsystem 60 outputs information about the affected security controls. In some examples, the output information includes the attack steps and / or attack paths processed by the affected security controls. In some examples, the risk subsystem 65 updates the risk levels associated with one or more assets (the threats to which are processed by the affected security controls), and outputs the updated risk levels.

[0231] In some examples, the abnormal behavior is associated with software that implements a function. In some examples, the attack step implementation mode mapping subsystem 40 identifies one or more threats associated with the function, and outputs information about the corresponding one or more threats.

[0232] Some examples of the disclosed technology

[0233] Some examples of the above embodiments are listed below. It should be noted that one feature of an isolated example or a combination of more than one feature of the example, and optionally a combination of more than one feature of the example and one or more features of one or more of the following examples, also belong to the examples within the scope of the disclosure of this application.

[0234] Example 1. A security control method, the method comprising: receiving risk analysis information including data about a plurality of threats, each of the plurality of threats being associated with a corresponding asset; loading a control database including data about a plurality of security controls; for each of the plurality of threats, matching one or more of the plurality of security controls with one or more attack steps of one or more attack paths associated with the corresponding threat; for each of the plurality of threats, selecting at least a subset of the matched security controls; and for each of the plurality of threats, outputting information about the selected security controls, wherein the output information is at least partially based on: expenditure data associated with the corresponding security control, the expenditure data indicating the cost and / or input required to implement the corresponding security control; and feasibility data associated with the corresponding security control, the feasibility data indicating the degree to which the corresponding security control will reduce the feasibility rating of a corresponding one of the plurality of attack steps when implemented.

[0235] Example 2. The method according to any one of the examples herein, particularly the method described in Example 1, wherein selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least in part based on the corresponding expenditure data and the corresponding feasibility data, and wherein the output information includes information about the selected subset of security controls.

[0236] Example 3. The method according to any one of the examples herein, particularly the method described in Example 1, wherein the method further includes determining a corresponding score for each of the plurality of security controls, the corresponding score being at least in part based on the corresponding expenditure data and the corresponding feasibility data, and wherein the output information is at least in part based on the determined scores.

[0237] Example 4. The method according to any one of the examples herein, particularly the method described in Example 3, wherein selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least in part based on the corresponding scores, and wherein the output information includes information about the selected subset of security controls.

[0238] Example 5. The method according to any one of the examples herein, particularly the method described in Example 3, wherein the output information about the selected security controls includes the corresponding scores for each of the selected security controls.

[0239] Example 6. The method according to any one of the examples herein, particularly the method described in Example 3, wherein the output information about the selected security controls is sorted at least in part based on the scores of the selected security controls.

[0240] Example 7. The method according to any one of the examples herein, particularly the method described in Example 1, wherein for each of the plurality of security controls, the control database further includes dependency requirements associated with the corresponding security control, and wherein the output information is further based on the dependency requirements associated with the matched security controls.

[0241] Example 8. The method according to any one of the examples herein, particularly the method described in Example 7, wherein the method further includes: receiving information about the resources of a project; and comparing the information about the resources of the project with the dependency requirements associated with the matched security controls associated with the corresponding assets within the project, wherein selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least in part based on the result of the comparison, and wherein the output information includes information about the selected subset of security controls.

[0242] Example 9. The method according to any one of the examples herein, particularly Example 7 or 8, wherein the dependency requirements include software dependency requirements and hardware dependency requirements.

[0243] Example 10. The method according to any one of the examples herein, particularly any one of Examples 7 to 9, wherein the method further comprises receiving a bill of materials, the bill of materials including information about the resources of the asset.

[0244] Example 11. The method according to any one of the examples herein, particularly Example 1, wherein the method further comprises: for each security control that matches a step of the identified attack path, determining a corresponding coverage value, and wherein the output information is further based on the determined coverage values of the selected security controls.

[0245] Example 12. The method according to any one of the examples herein, particularly Example 11, wherein selecting at least one subset of the matching security controls includes selecting the subset of the matching security controls at least in part based on the determined coverage values of the selected security controls, and wherein the output information includes information about the selected subset of security controls.

[0246] Example 13. The method according to any one of the examples herein, particularly Example 11, wherein the output information about the selected security controls is sorted at least in part based on the determined coverage values of the selected security controls.

[0247] Example 14. The method according to any one of the examples herein, particularly any one of Examples 11 to 13, wherein the coverage values are determined for a plurality of items.

[0248] Example 15. The method according to any one of the examples herein, particularly Example 1, wherein the method further comprises: loading an implementation database including a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and for each of the plurality of threats, selecting at least one subset of the security control implementations associated with the matching security controls, wherein the output information includes information about the selected security control implementations.

[0249] Example 16. The method according to any one of the examples herein, particularly Example 15, wherein selecting at least one subset of the security control implementations includes selecting the subset of the security control implementations at least in part based on corresponding expenditure data and feasibility data associated with the selected security control implementations, and wherein the output information includes information about the selected subset of security control implementations.

[0250] Example 17. The method according to any one of the examples herein, particularly the method described in Example 16, wherein the method further comprises determining a respective score for each of the plurality of security control implementations, the respective score being at least partially based on respective expenditure data and respective feasibility data associated with the respective security control implementation, and wherein the output information is at least partially based on the determined scores.

[0251] Example 18. The method according to any one of the examples herein, particularly the method described in Example 17, wherein selecting at least one subset of the security control implementations comprises selecting the subset of the security control implementations at least partially based on the respective scores, and wherein the output information includes information about the selected subset of the security control implementations.

[0252] Example 19. The method according to any one of the examples herein, particularly the method described in Example 17, wherein the output information about the selected security control implementations includes the respective scores for each of the selected security control implementations.

[0253] Example 20. The method according to any one of the examples herein, particularly the method described in Example 17, wherein the output information about the selected security control implementations is at least partially ordered based on the scores of the selected security control implementations.

[0254] Example 21. The method according to any one of the examples herein, particularly the method described in Example 15, wherein for each of the plurality of security control implementations, the implementation database further includes dependency requirements associated with the respective security control implementation, and wherein the output information is further based on the dependency requirements associated with the selected security control implementations.

[0255] Example 22. The method according to any one of the examples herein, particularly the method described in Example 21, wherein the method further comprises: receiving information about the resources of a project; and comparing the information about the resources of the asset with the dependency requirements associated with the security control implementation associated with a matching security control associated with a respective asset within the project, wherein selecting at least one subset of the security control implementations comprises selecting the subset of the security control implementations associated with the matching security control at least partially based on the result of the comparison, and wherein the output information includes information about the selected subset of the security control implementations.

[0256] Example 23. The method according to any one of the examples herein, particularly example 21 or 22, wherein the dependency requirements include software dependency requirements and hardware dependency requirements.

[0257] Example 24. The method according to any one of the examples herein, particularly any one of examples 21 to 23, wherein the method further comprises receiving a bill of materials, the bill of materials including information about the resources of the asset.

[0258] Example 25. The method according to any one of the examples herein, particularly example 15, wherein the method further comprises: for each of the security control implementations associated with security controls that match steps of the identified attack path, determining a corresponding coverage value, and wherein the output information is further based on the determined coverage values of the selected security control implementations.

[0259] Example 26. The method according to any one of the examples herein, particularly example 25, wherein selecting at least one subset of the security control implementations comprises selecting the subset of the security control implementations at least in part based on the determined coverage values of the selected security control implementations, and wherein the output information includes information about the selected subset of the security control implementations.

[0260] Example 27. The method according to any one of the examples herein, particularly example 25, wherein the output information about the selected security control implementations is sorted at least in part based on the determined coverage values of the selected security control implementations.

[0261] Example 28. The method according to any one of the examples herein, particularly any one of examples 25 to 27, wherein the coverage values are determined for a plurality of items.

[0262] Example 29. The method according to any one of the examples herein, particularly any one of examples 1 to 28, wherein the method further comprises: receiving an initial risk level, the initial risk level being defined according to the attack paths of the plurality of threats; receiving a target risk level; and identifying one or more attack steps among the attack steps of the plurality of threats, the processing of the one or more attack steps among the attack steps of the plurality of threats will achieve the target risk level.

[0263] Example 30. The method according to any one of the examples herein, particularly example 29, wherein the initial risk level is defined as a predetermined function of the corresponding impact value of the corresponding threat and the corresponding feasibility rating of each attack path of each of the plurality of threats.

[0264] Example 31. The method according to any one of the examples herein, particularly any one of Examples 29 to 31, further includes: for each of the plurality of threats, determining whether the target risk level can be achieved; and outputting a list of the plurality of threats for which it is determined that the corresponding target risk level cannot be achieved.

[0265] Example 32. The method according to any one of the examples herein, particularly any one of Examples 29 to 32, further includes: receiving user input indicating that a corresponding one of the security controls has been implemented; identifying one or more corresponding attack paths associated with the implemented security control; defining a residual risk level in response to the identified one or more corresponding attack paths associated with the implemented security control; and outputting the residual risk level.

[0266] Example 33. The method according to any one of the examples herein, particularly Example 32, wherein identifying one or more attack paths for which processing will achieve the target risk level includes identifying an attack path that includes: at least one step associated with a first resource, wherein processing the at least one step associated with the first resource mitigates or remediates the identified attack path; and at least one step associated with a second resource, wherein processing the at least one step associated with the second resource mitigates or remediates the identified attack path, and wherein the second resource is different from the first resource.

[0267] Example 34. The method according to any one of the examples herein, particularly any one of Examples 1 to 33, further includes: for each of the one or more matched security controls, adding the corresponding security control to a corresponding step of a corresponding attack path.

[0268] Example 35. The method according to any one of the examples herein, particularly Example 34, further includes: receiving user input indicating that a corresponding one of the security controls has been implemented; and in response to the received user input indicating that a corresponding one of the security controls has been implemented, marking the corresponding one of the security controls as being implemented.

[0269] Example 36. The method according to any one of the examples herein, particularly Example 1, wherein the method further includes loading an attack path database including a plurality of attack paths, and wherein for each of the plurality of threats, the method further includes: matching a description included in the received risk analysis information with the corresponding attack path at least in part based on a previous match of the corresponding attack path in the plurality of attack paths with a similar description, and wherein the description includes a description of an attack, a description of an attack path, and / or a description of an attack tree.

[0270] Example 37. The method according to any one of the examples herein, particularly the method described in Example 1, wherein for each of the plurality of assets, the method further comprises matching the profile of the corresponding asset included in the corresponding risk analysis information and the threat list associated with the corresponding asset included in the corresponding risk analysis information with the corresponding attack path, at least in part based on a previous match of the corresponding attack path among the plurality of attack paths with the asset profile and the threat list, the asset profile and the threat list being at least in part the same as the asset profile and the threat list of the corresponding asset.

[0271] Example 38. The method according to any one of the examples herein, particularly the method described in Example 36 or 37, wherein the matching with the corresponding attack path among the plurality of attack paths is at least in part based on language analysis.

[0272] Example 39. The method according to any one of the examples herein, particularly any one of Examples 1 to 38, wherein matching one or more of the plurality of security controls with one or more steps of the attack path includes performing a corresponding language analysis on the text description of each of the plurality of security controls and each of the steps of the attack path.

[0273] Example 40. The method according to any one of the examples herein, particularly the method described in Example 39, wherein the language analysis of the text description of each of the plurality of security controls includes a normalization step, wherein one or more words of the text description are normalized to a corresponding predetermined format, at least in part based on a corresponding predetermined list of terms.

[0274] Example 41. The method according to any one of the examples herein, particularly the method described in Example 1 or 40, further comprises loading a template database, the template database including data on a plurality of templates, each template including information on an associated resource and information on one or more attack steps associated with the corresponding resource, wherein matching one or more of the plurality of security controls with one or more steps of the attack path is at least in part based on the data on the plurality of templates.

[0275] Example 42. The method according to any one of the examples herein, particularly the method described in Example 41, further comprises associating each of the plurality of security controls in the control database with a corresponding template among the plurality of templates, wherein for each of one or more of the plurality of security controls, the matching with one or more steps of the attack path is responsive to the template associated with the corresponding security control.

[0276] Example 43. The method according to any one of the examples herein, particularly the method described in Example 42, wherein, for each of one or more of the plurality of security controls, the association with the corresponding template includes a linguistic comparison of the text description of the corresponding security control with the corresponding language of the plurality of templates.

[0277] Example 44. The method according to any one of the examples herein, particularly the method described in Example 42 or 43, wherein, for each of one or more of the steps of the attack path, the method further includes associating the corresponding step with the corresponding template of the plurality of templates, wherein, for each of one or more of the steps of the attack path, the matching security control is associated with the corresponding template associated with the corresponding step.

[0278] Example 45. The method according to any one of the examples herein, particularly the method described in Example 44, wherein, for each of one or more of the steps of the attack path, the association with the corresponding template includes a linguistic comparison of the text description of the corresponding attack step with the corresponding language of the plurality of templates.

[0279] Example 46. The method according to any one of the examples herein, particularly the method described in Example 45, wherein the linguistic analysis of the text description of each of the plurality of attack steps includes a normalization step, wherein, at least in part based on a corresponding predetermined list of terms, one or more words of the text description are normalized to a corresponding predetermined format.

[0280] Example 47. The method according to any one of the examples herein, particularly any one of Examples 1 to 46, wherein the method further includes, for each of the plurality of threats: mapping one or more of the steps of the attack path to a corresponding software implementation; and outputting information about the mapping of the software implementation of the one or more steps.

[0281] Example 48. The method according to any one of the examples herein, particularly any one of Examples 1 to 47, wherein the method further includes, for each of the plurality of threats: mapping one or more of the steps of the attack path to a corresponding hardware implementation; and outputting information about the mapping of the hardware implementation of the one or more steps.

[0282] Example 49. The method according to any one of the examples herein, particularly any one of Examples 1 to 48, wherein at least one subset of the matching security controls is selected such that at least one subset of the matching security controls satisfies a predetermined security depth value.

[0283] Example 50. The method according to any one of the examples herein, particularly Example 49, wherein the method further comprises receiving a corresponding user input indicating a desired safety depth, and the predetermined safety depth value is set according to the corresponding user input.

[0284] Example 51. A safety control system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored therein, and the instructions, when run by the one or more processors, cause the one or more processors to perform the method according to any one of Examples 1 to 50.

[0285] It should be understood that certain features of the present invention described in the context of separate embodiments for clarity may also be provided in combination in a single embodiment. Conversely, the various features of the present invention described in the context of a single embodiment for brevity may also be provided separately or in any suitable sub-combination.

[0286] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. Although methods similar or equivalent to those described herein may be used in the practice or testing of the present invention, suitable methods are described herein.

[0287] All publications, patent applications, patents, and other references mentioned herein are incorporated herein by reference in their entirety. In case of conflict, the present patent application specification (including definitions) shall prevail. Additionally, the materials, methods, and examples are illustrative only and not intended to be limiting.

[0288] Those skilled in the art will recognize that the present invention is not limited to what has been specifically shown and described above. Instead, the scope of the present invention is defined by the claims and includes combinations and sub-combinations of the various features described above, as well as variations and modifications thereof that will occur to those skilled in the art upon reading the foregoing description.

Claims

1. A security control method, the method comprising: Receiving risk analysis information including data on multiple threats, each of the multiple threats being associated with a corresponding asset; Loading a control database including data on multiple security controls; For each of the multiple threats, matching one or more of the multiple security controls with one or more attack steps of one or more attack paths associated with the corresponding threat; For each of the multiple threats, selecting at least one subset of the matched security controls; And For each of the multiple threats, outputting information about the selected security controls, Wherein the output information is at least partially based on: Expenditure data associated with the corresponding security control, the expenditure data indicating the cost and / or input required to implement the corresponding security control; and Feasibility data associated with the corresponding security control, the feasibility data indicating the extent to which the corresponding security control will reduce the feasibility rating of a corresponding one of the multiple attack steps when implemented.

2. The method according to claim 1, wherein Selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least partially based on the corresponding expenditure data and the corresponding feasibility data, and Wherein the output information includes information about the selected subset of security controls.

3. The method according to claim 1, wherein The method further includes determining a corresponding score for each of the multiple security controls, the corresponding score being at least partially based on the corresponding expenditure data and the corresponding feasibility data, and Wherein the output information is at least partially based on the determined scores.

4. The method according to claim 3, wherein Selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least partially based on the corresponding scores, and Wherein the output information includes information about the selected subset of security controls.

5. The method according to claim 3, wherein The output information about the selected security controls includes the corresponding scores of each of the selected security controls.

6. The method according to claim 3, wherein, Sorting the output information about the selected security controls at least partially based on the scores of the selected security controls.

7. The method according to claim 1, wherein For each of the multiple security controls, the control database further includes dependency requirements associated with the corresponding security control, and Wherein the output information is further based on the dependency requirements associated with the matched security controls.

8. The method according to claim 7, wherein The method further includes: Receiving information about the resources of a project; and Comparing the information about the resources of the project with the dependency requirements associated with the matched security control, the matched security control being associated with the corresponding asset within the project, Wherein selecting at least one subset of the matched security controls includes selecting the subset of the matched security controls at least partially based on the result of the comparison, and Wherein the output information includes information about the selected subset of security controls.

9. The method according to claim 7 or 8, wherein, The dependency requirements include software dependency requirements and hardware dependency requirements.

10. The method according to any one of claims 7 to 9, wherein The method further includes receiving a bill of materials that includes information about resources of the asset.

11. The method according to claim 1, wherein, The method further includes: for each security control that matches a step of the identified attack path, determining a corresponding coverage value, and wherein the output information is further based on the determined coverage values of the selected security controls.

12. The method according to claim 11, wherein, Selecting at least one subset of the matching security controls includes selecting the subset of the matching security controls at least in part based on the determined coverage values of the selected security controls, and wherein the output information includes information about the selected subset of security controls.

13. The method according to claim 11, wherein, The output information about the selected security controls is sorted at least in part based on the determined coverage values of the selected security controls.

14. The method according to any one of claims 11 to 13, wherein, Determining the coverage values for a plurality of items.

15. The method according to claim 1, wherein The method further includes: loading an implementation database that includes a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and for each of the plurality of threats, selecting at least one subset of the security control implementations associated with the matching security controls, wherein the output information includes information about the selected security control implementations.

16. The method according to claim 15, wherein, Selecting at least one subset of the security control implementations includes selecting the subset of the security control implementations at least in part based on corresponding expenditure data and feasibility data associated with the selected security control implementations, and wherein the output information includes information about the selected subset of security control implementations.

17. The method according to claim 16, wherein, The method further includes determining a corresponding score for each of the plurality of security control implementations, the corresponding score being at least in part based on the corresponding expenditure data and the corresponding feasibility data associated with the corresponding security control implementation, and wherein the output information is at least in part based on the determined scores.

18. The method according to claim 17, wherein, Selecting at least one subset of the security control implementations includes selecting the subset of the security control implementations at least in part based on the corresponding scores, and wherein the output information includes information about the selected subset of security control implementations.

19. The method according to claim 17, wherein, The output information about the selected security control implementations includes the corresponding scores of each of the selected security control implementations.

20. The method according to claim 17, wherein The output information about the selected security control implementations is sorted at least in part based on the scores of the selected security control implementations.

21. The method according to claim 15, wherein, For each of the plurality of security control implementations, the implementation database further includes dependency requirements associated with the corresponding security control implementation, and wherein the output information is further based on the dependency requirements associated with the selected security control implementations.

22. The method according to claim 21, wherein The method further includes: receiving information about resources of an item; and Compare the information about the resources of the asset with the dependency requirements associated with the security control implementation, where the security control implementation is associated with a matching security control associated with the corresponding asset within the project. Wherein, selecting at least one subset of the security control implementations includes selecting a subset of the security control implementations associated with the matching security control at least in part based on the result of the comparison, and Wherein, the output information includes information about the selected subset of the security control implementations.

23. The method according to claim 21 or 22, wherein The dependency requirements include software dependency requirements and hardware dependency requirements.

24. The method according to any one of claims 21 to 23, wherein The method further includes receiving a bill of materials, the bill of materials including information about the resources of the asset.

25. The method according to claim 15, wherein The method further includes: For each of the security control implementations associated with a security control that matches a step of the identified attack path, determining a corresponding coverage value, and Wherein, the output information is further based on the determined coverage values of the selected security control implementations.

26. The method according to claim 25, wherein, Selecting at least one subset of the security control implementations includes selecting a subset of the security control implementations at least in part based on the determined coverage values of the selected security control implementations, and Wherein, the output information includes information about the selected subset of the security control implementations.

27. The method according to claim 25, wherein The output information about the selected security control implementations is sorted at least in part based on the determined coverage values of the selected security control implementations.

28. The method according to any one of claims 25 to 27, wherein Determine the coverage values for multiple projects.

29. The method according to any one of claims 1 to 28, wherein, The method further includes: Receiving an initial risk level, the initial risk level being defined according to the attack paths of the multiple threats; Receiving a target risk level; and Identifying one or more attack steps among the attack steps of the multiple threats, the processing of the one or more attack steps among the attack steps of the multiple threats will reach the target risk level.

30. The method according to claim 29, wherein, The initial risk level is defined as a predetermined function of the corresponding impact value of the corresponding threat and the corresponding feasibility rating of each attack path of each threat among the multiple threats.

31. The method according to any one of claims 29 to 31, further includes: For each of the multiple threats, determining whether the target risk level can be achieved; And Outputting a list of multiple threats for which it is determined that the corresponding target risk level cannot be achieved.

32. The method according to any one of claims 29 to 32, further includes: Receiving user input indicating that a corresponding one of the security controls is implemented; Identifying one or more corresponding attack paths associated with the implemented security control; Defining a residual risk level in response to the identified one or more corresponding attack paths associated with the implemented security control; And Outputting the residual risk level.

33. The method according to claim 32, wherein, Identifying one or more attack paths for which processing will reach the target risk level includes identifying an attack path that includes: At least one step associated with a first resource, wherein processing the at least one step associated with the first resource mitigates or remediates the identified attack path; and At least one step associated with a second resource, wherein processing the at least one step associated with the second resource mitigates or remediates the identified attack path, and wherein the second resource is different from the first resource.

34. The method according to any one of claims 1 to 33, further comprising: For each of the one or more matched security controls, add the corresponding security control to the corresponding step of the corresponding attack path.

35. The method according to claim 34, further comprising: Receiving user input indicating that a corresponding one of the security controls is implemented; and In response to the received user input indicating that a corresponding one of the security controls is implemented, marking the corresponding one of the security controls as being implemented.

36. The method according to claim 1, wherein, The method further comprises loading an attack path database including multiple attack paths, wherein for each of the multiple threats, the method further comprises: matching a description included in the received risk analysis information with the corresponding attack path at least in part based on a previous match of the corresponding attack path among the multiple attack paths with a similar description, and wherein the description includes a description of an attack, a description of an attack path, and / or a description of an attack tree.

37. The method according to claim 1, wherein, For each of the multiple assets, the method further comprises matching a profile of the corresponding asset included in the corresponding risk analysis information and a threat list associated with the corresponding asset included in the corresponding risk analysis information with the corresponding attack path at least in part based on a previous match of the corresponding attack path among the multiple attack paths with the asset profile and the threat list, the asset profile and the threat list being at least in part the same as the asset profile and the threat list of the corresponding asset.

38. The method according to claim 36 or 37, wherein The matching with the corresponding attack path among the multiple attack paths is at least in part based on language analysis.

39. The method according to any one of claims 1 to 38, wherein, Matching one or more of the multiple security controls with one or more steps of the attack path includes performing a corresponding language analysis on the text description of each of the multiple security controls and each of the steps of the attack path.

40. The method according to claim 39, wherein, The language analysis of the text description of each of the multiple security controls includes a normalization step, wherein one or more words of the text description are normalized to a corresponding predetermined format at least in part based on a corresponding predetermined list of terms.

41. The method according to claim 1 or 40, further comprising loading a template database, the template database including data on multiple templates, each template including information on an associated resource and information on one or more attack steps associated with the corresponding resource, Among them, Matching the one or more of the multiple security controls with the one or more steps of the attack path is at least in part based on the data on the multiple templates.

42. The method according to claim 41 further comprises associating each of the plurality of security controls of the control database with a corresponding template of the plurality of templates, Among them, for each of one or more of the plurality of security controls, the matching with one or more steps of the attack path is responsive to the template associated with the corresponding security control.

43. The method according to claim 42, wherein, For each of one or more of the plurality of security controls, the association with the corresponding template includes a linguistic comparison of the text description of the corresponding security control with the corresponding language of the plurality of templates.

44. The method according to claim 42 or 43, wherein, For each of one or more steps of the attack path, the method further comprises associating the corresponding step with a corresponding template of the plurality of templates, wherein, for each of one or more steps of the attack path, the matching security control is associated with the corresponding template associated with the corresponding step.

45. The method according to claim 44, wherein For each of one or more steps of the attack path, the association with the corresponding template includes a linguistic comparison of the text description of the corresponding attack step with the corresponding language of the plurality of templates.

46. The method according to claim 45, wherein, The linguistic analysis of the text description of each of the plurality of attack steps includes a normalization step, wherein one or more words of the text description are normalized to a corresponding predetermined format, at least in part based on a corresponding predetermined list of terms.

47. The method according to any one of claims 1 to 46, wherein, The method further comprises, for each of the plurality of threats: mapping one or more steps of the attack path to corresponding software implementation means; and outputting information about the mapping of the one or more steps to the software implementation means.

48. The method according to any one of claims 1 to 47, wherein The method further comprises, for each of the plurality of threats: mapping one or more steps of the attack path to corresponding hardware implementation means; and outputting information about the mapping of the one or more steps to the hardware implementation means.

49. The method according to any one of claims 1 to 48, wherein At least one subset of the matching security controls is selected such that at least one subset of the matching security controls meets a predetermined security depth value.

50. The method according to claim 49, wherein, The method further comprises receiving corresponding user input indicating a desired security depth, and the predetermined security depth value is set according to the corresponding user input.

51. A safety control system includes one or more processors and a memory, wherein, The memory has a plurality of instructions stored therein, and the instructions, when run by the one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 50.