Risk determination system and method

By receiving event information to identify attack paths and adjusting risk levels, the risk determination system is solved, the problem of inefficient risk determination in the prior art is solved, more efficient security threat analysis and risk assessment are achieved, and the security control of software and hardware systems is optimized.

CN120476398APending Publication Date: 2025-08-12C2A SEC LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480005731.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-02-07
Filing Date
2024-02-07
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The existing technology lacks effective risk determination systems and methods in software and hardware development, and cannot efficiently identify and adjust the risk level of assets, resulting in inefficiency in security threat analysis and risk assessment.

Method used

Provide a risk determination system, by receiving event information, identifying attack steps associated with attack paths and assets, adjusting risk levels, and outputting relevant information, and executing corresponding instructions using processors and memory to achieve risk assessment and security control optimization.

Benefits of technology

It improves the efficiency and accuracy of risk determination, can dynamically adjust the risk level of assets, optimize security control, and enhances the security of software and hardware systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120476398A_ABST
    Figure CN120476398A_ABST
Patent Text Reader

Abstract

A risk determination method includes: receiving event information associated with a project, the event information including information about an abnormal behavior detected in the project or information about a vulnerability detected in the project; identifying, based at least in part on the received event information, one or more attack steps of one or more attack paths, each of the one or more attack paths associated with a respective asset of a plurality of assets included within the item; and for each respective asset, adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Israel Patent Application No. 300462, filed February 7, 2023, which is incorporated herein by reference in its entirety. Technical Field

[0003] The present disclosure relates generally to the field of software and hardware testing, and in particular to risk determination systems and methods.

[0004] background

[0005] In programming and software development, as well as hardware design and development, security experts perform threat analysis and risk assessment ("TARA") on high-level software and hardware components. During this process, security experts analyze the risk and impact of cyberattacks on a given component and its functionality. The process typically begins with project definition, identification of threats, an attack tree describing how an attacker could execute their attack, the risks, and recommendations for optional security controls to mitigate them. Software and hardware are used as implementations of the component's functionality.

[0006] Overview

[0007] It is therefore a primary object of the present invention to overcome at least some of the shortcomings of prior art systems and methods for risk determination. In some examples, this is provided by a risk determination system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method.

[0008] In some examples, the method includes receiving event information associated with the project.

[0009] In some examples, the event information includes information about abnormal behavior detected in the project or information about vulnerabilities detected in the project.

[0010] In some examples, based at least in part on the received event information, the method includes one or more attack steps of identifying one or more attack paths, each of the one or more attack paths being associated with a respective asset of a plurality of assets included within the project.

[0011] In some examples, for each respective asset, the method includes adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset.

[0012] In some examples, for each respective asset, the method includes outputting information associated with the adjusted one or more respective risk levels.

[0013] In some examples, a risk determination system is provided that includes one or more processors and a memory, wherein the memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method comprising receiving information regarding a risk level for each of a plurality of assets.

[0014] In some examples, a first asset in the plurality of assets has a lower risk level than a second asset in the plurality of assets.

[0015] In some examples, the method includes receiving information regarding communications between a first asset in the plurality of assets and a second asset in the plurality of assets.

[0016] In some examples, based at least on information received about communications between the first asset in the plurality of assets and the second asset in the plurality of assets, the method includes adjusting the risk level of the first asset in the plurality of assets to be equal to the risk level of the second asset in the plurality of assets.

[0017] In some examples, the method includes outputting information associated with the adjusted risk level.

[0018] In some examples, a risk determination system is provided that includes one or more processors and a memory, wherein the memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method comprising receiving information regarding a risk level for each of a plurality of assets within a project.

[0019] In some examples, the method includes identifying an asset having a highest level of risk among the plurality of assets.

[0020] In some examples, the method includes adjusting the risk level of each of the plurality of assets within the project to be equal to a highest risk level within the project.

[0021] In some examples, the method includes outputting information associated with an adjusted risk level for each of the plurality of assets.

[0022] Additional features and advantages of the invention will become apparent from the following drawings and description.

[0023] Unless otherwise limited, all technical and scientific terms used herein have the same meaning as those of ordinary skill in the art to which the present invention pertains. If conflict occurs, this patent application specification (including definitions) is taken as leading. As used herein, unless context clearly indicates otherwise, the articles "a" and "an" refer to "at least one" or "one or more". As used herein, "and / or" refers to any one or more items in the list connected by "and / or". As an example, "x and / or y" refers to any element in the set {(x), (y), (x, y)} of three elements. In other words, "x and / or y" refers to "x, y or both x and y". As some examples, "x, y and / or z" refers to any element in the set {(x), (y), (z), (x, y), (x, z), (y, z), (x, y, z)} of seven elements.

[0024] In addition, unless expressly stated to the contrary, "or" refers to an inclusive or, not an exclusive or. For example, any of the following satisfies condition A or B: A is true (or exists) and B is false (or does not exist), A is false (or does not exist) and B is true (or exists), and both A and B are true (or exist).

[0025] In addition, "a" or "an" is used to describe elements and components of embodiments of the present inventive concept. This is done merely for convenience and to give a general meaning to the present inventive concept, and "a" and "an" are intended to include one or at least one, and the singular also includes the plural unless it is obvious that it is meant otherwise.

[0026] As used herein, the term "about," when referring to a measurable value (e.g., an amount, a duration, etc.), is meant to encompass deviations of + / - 10%, more preferably + / - 5%, even more preferably + / - 1%, and still more preferably + / - 0.1% from the specified value, as such deviations are suitable for performing the disclosed apparatus and / or methods.

[0027] The following embodiments and aspects thereof of systems, tools and methods are described and illustrated, which are intended to be exemplary and illustrative, rather than limiting in scope. In various embodiments, one or more of the above-mentioned problems have been reduced or eliminated, while other embodiments are directed to other advantages or improvements. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] For a better understanding of the invention and to show how it may be put into effect, reference will now be made, by way of example only, to the accompanying drawings in which like reference numerals designate corresponding parts or elements throughout.

[0030] With specific reference now to the drawings in detail, it is emphasized that the details shown are by way of example and are presented solely for purposes of illustrative discussion of the preferred embodiments of the invention and to provide what is believed to be the most useful and understandable description of the principles and conceptual aspects of the invention. In this regard, no attempt is made to illustrate structural details of the invention in more detail than is necessary for a basic understanding of the invention, and the description taken in conjunction with the drawings will enable those skilled in the art to understand how the invention may be embodied in several forms in practice. In the drawings:

[0031] Figures 1A to 1D shows various parts of a system for security threat handling according to some examples of the present disclosure;

[0032] Figures 2A to 2C Various diagrams illustrating attack paths according to some examples of the present disclosure are shown;

[0033] Figures 3A to 3E Various diagrams illustrating a process for matching security controls to attack steps of an attack path according to some examples of the present disclosure;

[0034] Figures 4A to 4B Various diagrams illustrating a process for matching stored attack paths with new threats according to some examples of the present disclosure;

[0035] 5A to 5D Various diagrams illustrating a process for generating an optimized security control implementation list according to some examples of the present disclosure;

[0036] Figures 6A to 6C Various diagrams illustrating a process of creating a software-implemented database of attack steps mapped to risk analysis information according to some examples of the present disclosure;

[0037] Figure 7 A high-level flow chart illustrating a method for outputting information about signals transmitted between assets; and

[0038] Figure 8 A high-level flow chart of a method for outputting information in response to abnormal behavior is shown.

[0039] Detailed description of specific examples

[0040] In the following description, various aspects of the present disclosure will be described. For the purpose of explanation, specific configurations and details are set forth in order to provide a thorough understanding of the different aspects of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure can be practiced without the specific details presented herein. In addition, well-known features may be omitted or simplified to avoid obscuring the present disclosure. In the accompanying drawings, similar reference numerals always refer to similar parts. In order to avoid excessive confusion due to having too many reference numerals and leads on a particular figure, some components will be introduced by one or more figures without being clearly identified in each subsequent figure containing the component.

[0041] Figure 1A A high-level block diagram of a security control system 10 is shown. In some examples, the system 10 includes: a management subsystem 11, which optionally includes a user interface and / or a command line interface; a security control library 20; a control correlation subsystem 30; an attack step implementation mapping subsystem 40; a template matching subsystem 50; and a security control optimization subsystem 60.

[0042] In some examples, management subsystem 11, control correlation subsystem 30, attack step implementation mapping subsystem 40, template matching subsystem 50, and security control optimization subsystem 60 are each implemented on a dedicated processor or a collection of processors, however, this is not intended to be limiting in any way. In some examples, processor 12 or a group of processors 12 can be used to jointly operate one or more of management subsystem 11, control correlation subsystem 30, attack step implementation mapping subsystem 40, template matching subsystem 50, and security control optimization subsystem 60.

[0043] In some examples, as described below, system 10 outputs: an attack step implementation map 70; and an optimized security control list 80. In some examples, system 10 includes: an input subsystem 120; and an output subsystem 130, which can optionally output the implementation map 70 and the security control list 80. In some examples, as described below, the attack step implementation map 70 includes a list of attack steps and how the attack steps are mapped to specific software and / or hardware implementations.

[0044] In some examples, the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60 are each implemented by a corresponding instruction set stored on the memory 13, which, when executed by one or more processors 12, causes the corresponding processor 12 to perform the function of a corresponding one of the following systems: the management subsystem 11, the control association subsystem 30, the attack step implementation mapping subsystem 40, the template matching subsystem 50, and the security control optimization subsystem 60.

[0045] In some examples, as described below, system 10 also includes a signal priority subsystem 61. In some examples, signal priority subsystem 61 is implemented by a corresponding instruction set that, when executed by one or more processors, causes the corresponding processor 12 to perform the functions of signal priority subsystem 61.

[0046] In some examples, as described below, system 10 also includes a signal subsystem 62. In some examples, signal subsystem 62 is implemented by a corresponding instruction set that, when executed by one or more processors 12, causes the corresponding processor 12 to perform the functions of signal subsystem 62.

[0047] In some examples, as described below, system 10 also includes an identifier (ID) subsystem 63. In some examples, ID subsystem 63 is implemented by a corresponding instruction set that, when executed by one or more processors 12, causes the corresponding processor 12 to perform the functions of ID subsystem 63.

[0048] In some examples, as described below, system 10 also includes a permissions subsystem 64. In some examples, permissions subsystem 64 is implemented by a corresponding instruction set that, when executed by one or more processors 12, causes the corresponding processor 12 to perform the functions of permissions subsystem 64.

[0049] In some examples, as described below, system 10 also includes a risk subsystem 65. In some examples, risk subsystem 65 is implemented by a corresponding instruction set that, when executed by one or more processors 12, causes the corresponding processor 12 to perform the functions of risk subsystem 65.

[0050] In some examples, as described below, the security control library 20 includes: a security control implementation database 201, which includes information about multiple security control implementations; a security control database 202, as described below, which includes information about multiple security controls; and a security control format table 203, as described below.

[0051] In some examples, the control association subsystem 30 includes: a plurality of corresponding instructions 301 for mapping threats to attack paths; an attack path database 302 including a plurality of attack paths; a threat-to-attack path mapping database 303 including a plurality of mappings for mapping threats to attack paths; and a plurality of instructions 304 for matching attack steps with security controls. As described below, when executed by one or more processors, the instructions 301 cause the processors to map threats to attack paths. When executed by one or more processors, the instructions 304 cause the processors to match attack steps with security controls.

[0052] In some examples, the template matching subsystem 50 includes: a plurality of instructions 501 for matching attack steps with templates; a plurality of instructions 502 for matching security controls with templates; and a template database 503 including a plurality of templates. As described below, when executed by one or more processors, the instructions 501 cause the processors to match attack steps with templates. As described below, when executed by one or more processors, the instructions 502 cause the processors to match security controls with templates.

[0053] In some examples, input subsystem 120 and output subsystem 130 each include a communication port. In some examples, input subsystem 120 and output subsystem 130 each communicate with an external server and / or an external software program. Although input subsystem 120 and output subsystem 130 are shown herein as separate units, this is not intended to be limiting in any way, and input subsystem 120 and output subsystem 130 can be implemented using a single hardware device and / or software program.

[0054] In some examples, such as Figure 1A As shown, input subsystem 120 communicates with an organizational software library 170 (such as the Github software tool commercially available from Microsoft of Redmond, Washington, USA). In some examples, software library 170 includes: one or more software packages 171; data 172 used by software packages 171; and software configuration functionality 173 that configures code for software packages 171 to use data 172. In some examples, organizational software library 170 also includes a software bill of materials file ("SBOM") 174. In some examples, SBOM file 174 is a .spdx file. In some examples, SBOM file 174 includes information about related software relationships and a list of software libraries used by software packages 171.

[0055] In some examples, software configuration function 173 includes files that describe network behavior, such as a network communication description file (which may be in .arxml format) or a CAN DBC file (which is a text file containing information for decoding raw CAN bus data into “physical values”).

[0056] In some examples, the SBOM file 174 is stored in an organizational product lifecycle management tool, such as the JIRA software tool commercially available from Atlassian Inc. of Sydney, Australia.

[0057] In some examples, such as Figure 1A As shown, the input subsystem 120 communicates with an organizational hardware library 180 (such as the Altium Designer software tool commercially available from Altium Limited of Chatswood, New South Wales, Australia). In some examples, the organizational hardware library 180 includes: code 181 for implementing various hardware designs; a list of hardware specifications 182 associated with the hardware designs of the code 181; and optionally a hardware bill of materials ("HBOM") list 183 associated with the hardware designs of the code 181. The HBOM list 183 is a list of raw materials, subassemblies, intermediate components, subcomponents, parts, and the quantities of each required to manufacture the final product.

[0058] As described below, in some examples, such as Figure 1A As shown, system 10 receives risk analysis information 190 at input subsystem 120. An example of such a risk analysis information file may be an Excel document containing risk analysis information, commercially available from Microsoft Corporation. In some examples, risk analysis information 190 may be manually input into system 10 using user interface subsystem 11. Note that the use of Excel as an input document is merely an example and not a limitation, as the same information may be stored in other data formats, such as a "comma separated values" (CSV) file or a table of values in a database.

[0059] In some examples, risk analysis information 190 includes a description of the results of an analysis of the risk of predetermined security threats associated with one or more functions. In some examples, the risk analysis information includes threat analysis and risk assessment (TARA) information, such as defined in ISO / SAE 21434. Associating risk analysis information 190 with functions is merely an example and should not be construed as limiting. In some examples, the risk analysis information is associated with: a software asset, a signaling asset, or a data asset; a project that is a container for at least one software asset, signaling asset, or data asset; a system that is a container for at least one project; and / or a system that is a container for at least one software asset, signaling asset, or data asset. In some examples, a collection of systems or projects can be defined as a "model."

[0060] As used herein, the term "asset" means a feature of a function or a resource used to perform a function. For example, such a resource may include a key, a configuration file, or any other suitable resource.

[0061] As used herein, the term "signal asset" means a message that can be sent from a source to a destination. In some examples, a signal asset includes configuration information associated with a message that can be sent.

[0062] As used herein, the term "software asset" means a feature implemented in software that performs at least one function. As used herein, the term "function" means any function that is performed, such as "send a signal," "send an alert," "activate a sensor," and so on. In some examples, these functions are implemented in software by the developer.

[0063] An example of a software asset is a "software update," which is a function that updates software and is implemented by software in a project or system. An example of a data asset is data associated with an "authentication key" used by the software asset to perform its function. An example of a system is an in-vehicle infotainment (IVI) system, which is the collection of hardware and software that provides audio or video entertainment in a car. An example of an item could be one of the hardware components of an IVI system that runs at least one piece of software.

[0064] Figure 1B An example of TARA information 190 is shown. As shown, a model is defined, which is denoted as "Model 1". Model 1 describes at least one system, which includes at least one item, which includes at least one asset. A non-limiting example of such a model is an automotive program for a specific vehicle that includes multiple systems, one of which is an IVI system. The IVI system includes multiple items, such as an application microcontroller and an in-vehicle communication microcontroller. For example, Figure 1B “Project 1” shown in FIG. 5 may represent an application microcontroller, and “Asset 1” may represent a software asset running on the application microcontroller.

[0065] Figure 1B A pair of systems are shown, designated System 1 and System 2 (for simplicity, System 2 is not detailed). Although a pair of systems are shown, this is not meant to be limiting in any way, and any number of systems may be included in risk analysis information 190 .

[0066] exist Figure 1B In the example of , system 1 includes a pair of projects (denoted as project 1 and project 2). Figure 1B In the example shown in FIG, Project 1 has an asset associated with it (denoted as asset 1), and Project 2 has an asset associated with it (denoted as asset 2_1). Although Project 1 and Project 2 are each shown as having a single asset associated with them, this is not meant to be limiting in any way, and each asset can have any number of assets associated with it.

[0067] Figure 1B The TARA information 190 also describes threats associated with the asset. As described above, part of threat analysis and risk assessment is to perform analysis and suggest different threats that could occur if an asset is compromised. In some examples, threats can be labeled by the STRIDE model, which is a model developed by Praerit Garg and Loren Kohnfelder of Microsoft for identifying computer security threats. The STRIDE model provides mnemonics for six categories of security threats. In some examples, threats to an asset can be labeled by the EVITA model of the EVITA project, as is known to those skilled in the art. In some examples, each threat contains a description of methods by which the threat can be caused to occur. This description is typically defined by one or more attack paths, which contain the attack steps necessary to execute an attack that will result in the threat, as will be further described below.

[0068] Asset 1 is associated with a pair of threats (denoted as Threat 1 and Threat 2). Each of Threat 1 and Threat 2 has an associated attack tree, denoted herein as Attack Tree 1 and Attack Tree 2, respectively. Although each threat is shown herein as having a single attack tree, this is not meant to be limiting in any way, and multiple attack trees may be provided for a single threat. Each of Attack Tree 1 and Attack Tree 2 is shown as including two attack steps (denoted as Attack Step 1 and Attack Step 2), however this is not meant to be limiting in any way, and each attack tree may include any number of attack steps.

[0069] Similarly, asset 2_1 is associated with a pair of threats (denoted as threat 2_1_1 and threat 2_1_2). Each of threat 2_1_1 and threat 2_1_2 has an associated attack tree, denoted herein as attack tree 2_1_1 and attack tree 2_1_2, respectively. Although each threat is shown herein as having a single attack tree, this is not meant to be limiting in any way, and multiple attack trees may be provided for a single threat. Each of attack tree 2_1_1 and attack tree 2_1_2 is shown as including two attack steps (denoted as attack step 1 and attack step 2); however, this is not meant to be limiting in any way, and each attack tree may include any number of attack steps.

[0070] Figure 1C A first configuration and method for using system 10 is shown, and Figure 1D A second configuration and method for using system 10 is shown.

[0071] In some examples, such as Figure 1C As shown, the system 10 is in communication with a product lifecycle management (PLM) or application lifecycle management (ALM) system 800. PLM / ALM is the process of managing the entire lifecycle of a product / application from inception through the engineering, design, and manufacturing phases. The Polarion® ALM system is one example of the ALM system 800 and is commercially available from Polarion Software of Siemens AG, Munich, Germany.

[0072] In some examples, the PLM / ALM system 800 provides risk analysis information 190 . Specifically, in some examples, the PLM / ALM system 800 receives risk analysis information 190 from an external source and transmits the received risk analysis information 190 to the input subsystem 120 .

[0073] In some examples, the PLM / ALM system 800 also provides additional information about the information stored in the software library 170 and / or the hardware library 180. Specifically, in some examples, the information provided by the software library 170 and / or the hardware library 180 is transmitted by the PLM / ALM system 800 to the input subsystem 120. In some examples, the information is exported from the PLM / ALM system 800 using an application programming interface (API) of the PLM / ALM system 800, as is known to those skilled in the art. This is a common practice in software development.

[0074] In some examples, as will be described further below, the system 10 outputs an attack step implementation map 70. In some examples, as will be described further below, the system 10 also outputs an optimized security control list 80.

[0075] In some examples, such as Figure 1D As shown, system 10 receives PLM / ALM information 801 from PLM / ALM system 800. For example, PLM / ALM information 801 may include: software implementation task status (e.g., new, in progress, completed); software implementation task effort; software implementation task owner; and / or references ("links") to software implementations of tasks. For example, ALM system 800 may have a list of features that need to be implemented, and each feature may be divided into a "user story." In software development and product management, a user story is an informal, natural language description of a software feature. The task effort to implement a feature can be described in story points, which, as known to those skilled in the art, is a metric used in agile project management and development to estimate the difficulty of implementing a given user story. In some examples, system 10 receives information about the task effort as user story points. In some examples, the task effort can be the time taken to implement, the cost of the implementation, and / or any other suitable metric.

[0076] In some examples, such as Figure 1D As shown, system 10 receives risk analysis information 90 directly from input subsystem 120. Threat analysis and risk assessment ("TARA") information 190 is received directly using subsystem input 120. In some examples, a user may perform TARA tasks using a graphical user interface of management subsystem 11 of system 10.

[0077] In some examples, such as Figure 1D As shown, the system 10 accesses an external security control database 202. In some examples, such as Figure 1A 10 , and in some examples, the security control database 202 is part of the subsystem 20 of the system 10. In some examples, the output optimized security control list 80 is stored in the system 10, but it can also be stored in the PLM / ALM system 800 (optionally using the application programming interface ("API") of the PLM / ALM system 800). In some examples, the PLM / ALM system 800 can present information from the optimized security control list 80 for a development project. Similarly, in some examples, the output attack step implementation map 70 is stored in the system 10, but it can also be stored in the PLM / ALM system 800 (optionally using the API of the PLM / ALM system 800).

[0078] As mentioned above, one step in TARA is to define security threats to an asset. For example, a software asset defined as a "signal router" that routes signals might have a threat defined as "compromise the integrity of the signal router software." Another example of a threat associated with a signal router might be "impersonating a signal." Note that these examples are not meant to be limiting, but rather to help understand the term "threat" with respect to software assets and threat analysis.

[0079] There are different ways to describe how an attacker would be able to achieve a threat, such as by describing an attack path. For example, for a threat defined as "compromise the integrity of the Signal router software", the attack path description could be "Using a malware update, the attacker would modify the Signal router software".

[0080] Another way to describe how an attacker would implement a threat is to use an attack tree or attack path. An attack path is defined herein as a number of sequential attack steps, where an attacker must move through the sequence of additional steps. An attack step is an action that an attacker must perform as part of an attack. In some examples, each attack step includes information about the associated subsystems, subcomponents, or interfaces associated with that attack step of the path.

[0081] An attack tree is a conceptual diagram that shows how an asset or target might be attacked. An attack tree is a multi-level diagram consisting of a root and multiple nodes. Nodes can include leaf nodes and non-leaf nodes. The root node is at the top of the tree, with branches extending downward from it. The root node represents the attacker's overall goal. The lowest-level nodes (leaf nodes) represent the activities performed by the attacker. Nodes between the leaf nodes and the root describe intermediate states or attacker sub-goals. As described above, each node represents an attack step. Non-leaf nodes in an attack tree can be designated as either AND nodes or OR nodes and are typically represented by the familiar Boolean algebra AND / OR shape. An AND node represents a process or procedure. All activities or states represented by the nodes immediately below the AND node must be achieved to achieve the goal or state represented by the AND node. An OR node represents an alternative scenario. If any node immediately below the OR node is achieved, the OR state is also achieved. In an attack tree, each attack path that satisfies the root is a corresponding attack path.

[0082] Figure 2A A diagram of an attack tree is shown. Figure 2A The attack tree includes: a root node 1000; a pair of nodes 1001 and 1002 branching from the root; a pair of nodes 1001_1 and 1001_2 branching from node 1001; and a node 1002_1 branching from node 1002. Note that Figure 2AThe specific configuration of the attack tree is illustrative only, and any number of nodes may be provided in the attack tree.

[0083] exist Figure 2A In the example, the attack tree includes an "OR" condition between leaf nodes 1001 and 1002, which means that one attack path is sufficient to perform the attack. In contrast, the attack tree includes an "AND" condition between leaf nodes 1001_ and 1001_2, which means that both nodes are required to proceed with the attack. Therefore, Figure 2A The attack tree includes two attack paths: a first attack path including nodes 1001, 1001_1, and 1002; and a second attack path including nodes 1002 and 1002_2.

[0084] Figure 2B An example of attack steps of an attack tree is shown in a human-readable description. In some examples, the attack steps can include actions performed on resources. Specifically, Figure 2B A first attack step 1010 is shown, which is for performing action A on resource X. Also shown is the feasibility rating of this attack step; in this case, a high feasibility rating. As used herein, the term "feasibility rating" is a value that represents the chance that the attack will actually occur in the real world, as known to those skilled in the art. In step 1010_1, the result of attack step 1010 is that resource Y can be accessed.

[0085] Attack step 1010_1_1 includes accessing resource Y and has a high feasibility rating. Attack step 1010_1_2 includes performing action B on resource Y and has a low feasibility rating. Figure 2B In the example of , steps 1010_1_1 and 1010_1_2 include an "AND" condition between them, so the combined attack step includes obtaining resource Y and performing action B on resource Y. An example of such a condition could be where resource Y is a "kernel vulnerability," so the attack step includes two sub-steps (1010_1_1 and 1010_1_2), which are discovering a kernel vulnerability (sub-step 1010_1_1) and exploiting the kernel vulnerability (1010_1_2). In other words, as used herein, the term "resource" means anything used to perform an attack. An attack step can include information about the feasibility of performing the step, which, as known to those skilled in the art, can be based on different parameters, such as the expertise required to perform the step, the resources required to perform the attack step, the time it takes to perform the attack step, and other parameters.

[0086] Table 1 describes examples of the format types of attack steps, as follows:

[0087] Table 1

[0088]

[0089] The syntax of an attack step can be described by one of the types in the table. For example, the attack step "ExploitKernel Vulnerability" (in Figure 2B 1 and 1010_1_2) have the format of "predicate, subject, object", i.e., the predicate is "exploit", the subject is "kernel" and the object is "vulnerability".

[0090] In some examples, the attack step format includes more formats than those described in Table 1. In some examples, the attack steps are defined using sentences that are as simple as possible. In some examples, the user can define additional attack step formats using the management subsystem 11 of the system 10. The use of the attack step formats is further described below.

[0091] Figure 2C An attack path with attack steps and security controls is shown. As used herein, the term "security control" refers to a method for reducing the feasibility of an attack step. For example, with respect to an attack step defined as "Send malicious message," which may have a high feasibility rating, implementing the security control "Implement a firewall to prevent unauthorized messages" reduces the feasibility of the attack step to medium. In the threat analysis and risk assessment (TARA) process, having security controls for attack steps is not mandatory, so as described below, the system 10 uses instructions 304 of the control association subsystem 30 to match security controls to each step.

[0092] In some examples, attack path database 302 includes multiple attack trees, each with multiple attack steps. If security control database 202 stores at least one security control that can reduce the feasibility of an attack step, the corresponding security control is associated with the corresponding attack step. Therefore, the attack steps in attack path database 302 include, for each step, a security control that can reduce the feasibility of the attack step.

[0093] In some examples, upon identifying a new security control that is not currently stored in security control database 202, the user may optionally use management subsystem 11 to add the security control to security control database 202. In some examples, as described below, in response to the security control being added to security control database 202, management subsystem 11 initiates a process for matching the added security control with relevant attack steps stored in attack path database 302.

[0094] exist Figure 2C In the example of , a portion of an attack tree is shown, including three attack steps: a first step 1020; a second step 1020_1; and a third step including sub-steps 1020_1_1 and 1020_1_2. As shown, attack step 1020 includes performing action C and is associated with security control 0. Sub-step 1020_1 includes performing action D. Sub-step 1020_1_1 includes accessing resource Z and is associated with security control 1. Sub-step 1020_1_2 includes performing an action using resource Z and is associated with security control 2. Although attack step 1020_1 does not have security controls associated with it, the attack path will be mitigated or recovered due to security controls 0, 1, and 2. As used herein, the term "process" is a combined term that includes mitigation and recovery.

[0095] In some examples, the management subsystem 11 is configured to output a list of attack trees, attack paths, and / or attack steps on a user display (such as a graphical user interface). In some examples, when an attack step is output, the associated security controls are output within the attack step, however, this is not intended to be limiting in any way. In some examples, the associated security controls can be output externally to the corresponding attack step. In some examples, the security controls can be output in a separate list. In some examples, each attack step that has a security control associated with it displays an indication of the presence of such a security control, and the corresponding security control can be output in response to a corresponding user input (e.g., pointing to a predetermined area where the attack step is output).

[0096] Table 2 shows an example of multiple security controls stored in the security control database 202, as follows:

[0097] Table 2

[0098]

[0099] As shown in the example of Table 2, in some examples, each security control has the following characteristics: a corresponding ID value; a name; a description; one or more corresponding templates (described below) associated therewith; one or more corresponding implementations (described below); and an updated value for feasibility, i.e., the new feasibility of the attack step if the security control is used to reduce the feasibility of the attack step. Note that Table 2 is not meant to be limiting, and the security controls stored in security control database 202 may include more or fewer characteristics without exceeding the scope of this disclosure.

[0100] In some examples, as shown in Table 2, security control WP.1 described as "Messages sent on the bus should be protected from modification" can be used to reduce the feasibility of attack steps involving message modification. In some examples, as described below, each template includes different metadata that can be used to describe the security control.

[0101] Specifically, in some examples, template database 503 includes multiple templates. When a new security control is input into system 10 (and, as described above, optionally added to security control database 202), in some examples, management subsystem 11 (using instructions 502) initiates a process to match the added security control with a corresponding one of the multiple templates stored on template database 503, as will be further described below.

[0102] In some examples, as described above, security control implementation database 201 includes information about multiple security control implementations. As used herein, the term "security control implementation" refers to a method for implementing a corresponding security control. Some examples of security control implementations are shown in Tables 3A and 3B, as follows (Tables 3A and 3B are provided separately for simplicity only):

[0103] Table 3A

[0104]

[0105]

[0106] Table 3B

[0107]

[0108] In some cases, there may be multiple options for implementing a security control. In some examples, the primary differences between implementation options are the resources required to implement the security control, the effort / cost of the implementation, and its real-world feasibility. For example, as shown in Tables 3A and 3B, the implementation of the security control "Messages sent on the bus should be protected from modification" can be implemented using either implementation WP.1_impl_1 or implementation WP.1_impl_2. Each option requires different resources—WP.1_impl_1 requires the use of a hardware secure memory ("HSM") to store the key, while WP.1_impl_2 requires no additional hardware and only requires random access memory (RAM). Consequently, WP.1_impl_1 may reduce the feasibility of the corresponding attack step to low, while using WP.1_impl_2 would reduce the feasibility of the corresponding attack step to medium.

[0109] Tables 3A and 3B illustrate examples where security control implementation information includes the following features: ID; ID of the associated security control; type of security control; description of the implementation; hardware dependencies of the implementation; software dependencies of the implementation; time cost (in days) of the implementation; and an updated feasibility value, however this is not intended to be limiting in any way. In some examples, more or fewer features may be provided for each security control implementation without exceeding the scope of this disclosure. As shown above in Table 2, in some examples, each security control has an associated updated feasibility value. In some examples, this value is an updated feasibility value for the security control implementation selected by system 10. The selection of an implementation is further described below. Different security control implementations with different dependencies allow security controls to be implemented on different components with different resources. For example, if the hardware component does not include an HSM, there is no way to implement WP.1_impl_1. To reduce the feasibility of the corresponding attack step, WP.1_impl_2 would need to be implemented, even if it is less secure.

[0110] In some examples, as described below, the security control optimization subsystem 60 generates an optimized security control list 80. In some examples, the security control optimization subsystem 60 considers implementation dependencies when generating the optimized security control list 80. For example, with respect to a particular security control, if the HBOM is associated with a corresponding project associated with the corresponding security control, the security control optimization subsystem 60 will filter out all security control implementation options that cannot be implemented.

[0111] Through template matching

[0112] Table 4 describes an example of the format of the description of the security control, as follows:

[0113] Table 4

[0114]

[0115] Although Table 4 shows eight types of security control formats, this is not intended to be limiting in any way, and more or fewer formats may be provided without exceeding the scope of this disclosure. In some examples, the security control description preferably comprises as simple a sentence as possible. In some examples, the user may add additional security control formats using the management subsystem 11. The use of the security control formats is described below.

[0116] Figure 3AThe overall flow of the method for matching security controls with attack steps using the template matching subsystem 50 is shown. Note that the method described herein is not meant to be limiting, and other suitable methods may be used to match security controls with attack steps without exceeding the scope of this disclosure. In stage 1030, as described below with reference to Figure 3B In stage 1040, one or more attack steps are matched to corresponding templates as described below. In stage 1050, one or more security controls are matched to one or more attack steps as described below.

[0117] Figure 3B An example process of matching security controls with templates stored on a template database 503 using instructions 502 is shown. Note that Figure 3B The process of is not meant to be limiting, and instructions 502 may implement different processes for matching security controls to templates without exceeding the scope of this disclosure. In some examples, iteratively, security controls stored in security control database 202 are analyzed to identify security controls that do not have an associated template. In some examples, a matching process is performed for each of these identified security controls. Figure 3B Method. Figure 3B The security controls described are similar to those in "WP.4" in Table 2.

[0118] In stage 1100, for each security control, a subject, a predicate, and / or an object are extracted from the description of the security control. Table 5 shows examples of different options for the subject and predicate, as follows:

[0119] Table 5

[0120]

[0121] In some examples, the text analysis process is continuously trained using information in the security control library 20, and the trained model is used to extract corresponding features from the description of the security control. Figures 3C to 3D An example describing the process of training such a model.

[0122] In some examples, the process of instruction 502 uses text matching between parsed statements in the security control and templates. In some examples, text matching is performed using software-based techniques for comparing two strings and algorithms for text similarity, such as "tf-id," a numerical statistic intended to reflect the importance of a word to a document in a collection or corpus, as known to those skilled in the art. In stage 1110, the subject of the security control is compared to the subject of the template to determine whether a template contains such a subject.

[0123] although Figure 3B The process of is shown herein as such that the subject is searched before the predicate, but this is not meant to be limiting in any way, and the predicate may be searched before the subject without departing from the scope of this disclosure. Figure 3B The process is shown herein as using the characteristics of each security control to identify a corresponding template, but this is not meant to be limiting in any way. In other examples, the corresponding characteristics of each template can be used to identify a corresponding one of multiple security controls whose description includes the corresponding characteristics.

[0124] If one or more templates that include the subject of the corresponding security control are identified in stage 1110, the process proceeds to extracting predicates from the description of the security control in stage 1120. Specifically, in stage 1130, the predicates of the security control are compared with the templates or predicates of templates identified in stage 1110 to determine whether there is a template that includes such a predicate.

[0125] In some examples, if a template is identified in stage 1130, then in stage 1140, the security control is matched to the identified template, and details of the mapping between the corresponding security control and the corresponding template are optionally stored in a corresponding table (such as Table 5 above). Note that the term "table" as used herein is not meant to be limited to any particular format for storing and / or outputting data, and is merely used to describe a predetermined relationship between stored data / information.

[0126] In some examples, if a template is not successfully identified in stage 1130, then in stage 1150, the management subsystem 11 outputs a list of recommended templates to the user. In some examples, in response to user input selecting one of the recommended templates, the mapping details of the selected template are stored in the security control library 20 and, in some examples, used to improve the trained model for future reuse. In some examples, then, in stage 1140, the mapping details of the selected template are stored in a corresponding table, as described above.

[0127] In some examples, if a template is not successfully identified in stage 1110, then in stage 1160, the management subsystem 11 prompts the user to manually assign a template to the corresponding security control. In some examples, in response to the user input assigning the template to the security control, the mapping details of the selected template are stored in the security control library 20 and, in some examples, used to improve the trained model for future reuse. In some examples, then, in stage 1140, the mapping details of the selected template are stored in the corresponding table, as described above.

[0128] As described above, in some examples, a model is trained to extract corresponding features from descriptions of security controls. As described below, such a model is also trained to extract corresponding features from descriptions of attack steps. In some examples, a normalized dictionary is prepared (optionally manually) for the descriptions of security controls. An example of a portion of such a dictionary is given in Table 6, as follows:

[0129] Table 6

[0130]

[0131]

[0132] The example in Table 6 is given for attack steps, however, in some examples, similar dictionaries are provided for descriptions of security controls. In the example shown in Table 6, a list of possible words from the description of additional steps is stored, along with the type of word (i.e., what the word refers to) and the replacement word for mapping to the template.

[0133] Figure 3C A high-level flow diagram of a process for normalizing the text of a description of a security control is shown, which is performed using instructions 502. Note that, as described below, Figure 3C The process can be similarly applied to the text describing the attack steps. In some examples, in step 1200, the words describing the security control are converted to lowercase. In some examples, in stage 1210, the words are replaced using a stored dictionary as described above with reference to Table 6. In some examples, in stage 1220, repeated words in the description text are identified and replaced with single words. For example (e.g., with respect to the attack steps), if the word sequence is as follows: "send message in network", then the sequence is replaced with the following sequence: "send message in network".

[0134] Figure 3D A high-level flow diagram of a process for training a model to extract corresponding features from a description of a security control is shown, which is performed using instruction 502. Note that, as described below, Figure 3D The process can be similarly used for the description text of the attack steps.

[0135] In some examples, in stage 1230, the description of the security control (or attack step) is normalized, as described above with reference to stages 1200 through 1220. In some examples, in stage 1240, the normalized description in stage 1230 is parsed into tokens. In some examples, parsing is performed using a "part-of-speech tagging" technique, optionally using the spaCy library from spacy.io or the Natural Language Toolkit (NLTK) from nltk.org. An example of parsing using the spaCy coding language in Python is shown below:

[0136]

[0137] In stage 1250, post-processing is performed to define the subject, predicate, and / or object found in the description. In some examples, plural nouns are converted to singular nouns. An example of Python code implementing such a step is shown below:

[0138]

[0139] In some examples, all or some forms of the predicate are converted to a predetermined form, such as the singular form of the simple present tense. In some examples, this can be performed using the .lemma feature of the token from the spaCy library.

[0140] Return to Figure 3A In stage 1040, as described above, one or more attack steps are matched to corresponding templates. In some examples, the process of stages 1100 to 1160 is performed by utilizing instruction set 501 to match the attack steps to corresponding templates, as described above with respect to security controls.

[0141] Similar to the stored mapping of security controls to templates described above with reference to the table, in some examples, a mapping of attack steps to templates is stored. An example of such a mapping table is shown in Table 7, as follows:

[0142] Table 7

[0143]

[0144] Figure 3E A high-level flow diagram illustrates a process for matching attack steps to security controls using instruction set 304. In some examples, the attack step to template mapping table (described above with reference to Table 7) is looped through at stage 1300. Note that this method can be performed on data stored in any format, and that a table is provided as an example only.

[0145] In some examples, for each attack step in the table, in stage 1310, the step control table is analyzed to determine whether an attack step having the same subject, predicate, and / or object is stored in a step control mapping table, wherein for each security control, the data for the corresponding security control is stored along with the corresponding template and the associated one or more security controls. Note that this method can be performed on data stored in any format, and a table is provided as an example only. An example of a step-control mapping table is provided in Table 8, as shown below:

[0146] Table 8

[0147]

[0148] Although Table 8 is shown as including: a description of an attack step and a subject, predicate, and object; an associated template; and one or more associated security controls, this is not meant to be limiting in any way. In some examples, the step-control mapping table includes more or fewer features without exceeding the scope of this disclosure.

[0149] In some examples, if no such attack step is found in the step-control mapping table, then in stage 1320, the process loops through the security control to template mapping table (described above with reference to Table 5) to identify one or more security controls mapped to a template that is also mapped to a corresponding attack step in the template mapping table (described above with reference to Table 7). In some examples, in stage 1330, for each attack step, it is determined whether the security control to template mapping table contains a security control with the same template as the corresponding attack step.

[0150] In some examples, if no such security control is found in the security control to template mapping table, then the process iterates through the security control to template mapping table as described above for each security control stored in the security control to template mapping table in stage 1340. In some examples, in stage 1350, for each attack step, it is determined whether the security control to template mapping table contains a security control whose text has the same subject and / or predicate as the corresponding attack step.

[0151] In some examples, if no such security control is found in the security control to template mapping table, then in stage 1360, the management subsystem 11 prompts the user to manually assign one or more security controls to the corresponding attack steps of the corresponding security control (or manually assign one or more attack steps to the corresponding security control).

[0152] In some examples, in stage 1370, in response to receiving user input assigning a security control to an attack step (or assigning an attack step to a security control), the attack step is associated with the corresponding security control and optionally stored in a step-control mapping table. As used herein, the predicate "associate" means to establish a predetermined relationship between two elements. This may include, but is not limited to: adding information from one element to the data of another element; storing two elements in a specific location or configuration such that when the data of one element is accessed, the data of the other element is also accessed; and / or storing a predetermined indication that two elements are associated with each other, such as in a mapping table.

[0153] In some examples, if it is determined in stage 1350 that a security control with the same subject and / or predicate exists in the security-to-template mapping table, then in stage 1380, the identified security control and the corresponding attack step are output to the user as a recommendation, and in response to user input agreeing to the recommendation, the identified security control is associated with the corresponding attack step and optionally stored in the attack step to security control mapping table.

[0154] In some examples, if it is determined in stage 1330 that an attack step with the same associated template exists in the attack step to template mapping table, then the identified attack step is associated with the corresponding security control and optionally stored in the step-control mapping table in stage 1390. In some examples, the identified attack step and the corresponding security control are output to the user as a recommendation, and in response to user input agreeing to the recommendation, the identified attack step is associated with the corresponding security control.

[0155] Attack Path Mapping

[0156] Figure 4AA high-level flow diagram illustrates a process for mapping attack paths to threats using instruction set 301. Mapping can be performed by mapping one or more attack paths to threats. In some examples, mapping can be performed by mapping an attack tree to a threat, where the attack tree includes one or more attack paths. In some examples, in stage 1400, instruction set 301 analyzes information for each threat in received risk analysis information 190 to identify whether the corresponding information includes a description of an attack path / attack tree and / or a description of an attack. In some examples, a text search is performed to identify one of the terms "attack path," "attack tree," or "attack description." In some examples, the attack description is identified by performing a text search based on predefined attack step types, as described above with reference to Table 1. In some examples, identification is based on information stored in a configuration file regarding the location of potential attack paths / trees / descriptions. In some examples, the attack description is a general description of the attack, while the attack path or attack tree description describes the attack in more detail.

[0157] In some examples, upon determining that the risk analysis information 190 for a particular threat includes a description of an attack path / attack tree or an attack description, the process searches the threat-to-attack path mapping database 303 for a stored mapping in stage 1410. The stored mapping can be a mapping between the identified attack description and a stored attack tree or attack path and / or a mapping between the identified attack path / attack tree description and a stored attack tree or one or more attack paths.

[0158] In some examples, if it is determined in stage 1420 that such a mapping exists, then in stage 1430, the newly received threat is associated with the stored attack tree or attack path. In some examples, if it is determined in stage 1420 that such a mapping does not exist, then in stage 1440, the management subsystem 11 outputs a prompt to the user to manually map the attack path description(s) or attack description(s) of the received threat to a corresponding one of the attack trees or attack paths stored in the attack path database 302. In some examples, the new mapping is stored in the threat-to-attack path mapping database 303. In some examples, if the attack path database 302 does not store an appropriate attack tree, the user can manually create a new attack path and then store the new attack path in the attack path database 302.

[0159] In some examples, if it is determined in stage 1400 that the risk analysis information 190 for a particular threat does not include an attack path description or attack description, then a process is performed in stage 1450 to map an appropriate attack tree or attack path, as will be described with reference to Figure 4B Specifically, Figure 4BA high-level flow of a process for mapping attack trees or attack paths to threats based on threat matching using an instruction set 301 is shown.

[0160] In stage 1500, signature and threat information are retrieved from risk analysis information 190. In some examples, as shown in Table 9 below, the signature information includes: the name of the project associated with the threat; the name of the asset associated with the threat; and the software feature or data asset associated with the threat (e.g., "identity of the fake signal routing"). In some examples, the threat information includes a list of threats. While the table illustrates the above-described signatures, this is not intended to be limiting in any way. In some examples, more or fewer signatures may be extracted without departing from the scope of this disclosure.

[0161] Table 9

[0162]

[0163] In some examples, at stage 1510, the process determines whether the received threat contains required information, such as the information described with reference to Table 9. In some examples, the required information is an asset profile and a threat list. In some examples, the information is identified by performing a text search based on a predefined format for items, assets, characteristics, and / or threats, such as described with reference to Table 9. In some examples, the identification is based on information stored in a configuration file regarding the location of the information.

[0164] In some examples, if the process determines that the received threat contains the required information, in stage 1520, the process searches the threat-to-attack path mapping database 303 to determine whether a mapping exists between the corresponding information (such as the threat's asset profile and threat list) and the stored attack tree or attack path. In some examples, the asset profile contains all the characteristics of the threat. Therefore, in the example shown in Table 9, the process searches for a mapping that contains relevant assets, relevant hardware components, and relevant software characteristics, signal assets, or data assets.

[0165] In some examples, if the process determines in stage 1530 that such a mapping (or mappings) exists, then in stage 1540, the management subsystem 11 outputs to the user a recommended attack path or attack tree for the new threat based on the identified mapping.

[0166] In some examples, if the process determines in stage 1530 that such a mapping does not exist, then in stage 1550, the management subsystem 11 outputs a prompt to the user to manually map the attack path / attack tree or attack description of the received threat to a corresponding one of the plurality of attack trees or plurality of attack paths stored in the attack path database 302. In some examples, the new mapping is stored in the threat-to-attack path mapping database 303. In some examples, if the attack path database 302 does not store an appropriate attack tree or attack path, the user can manually create a new attack tree (or one or more attack paths) and then store the new attack tree (or one or more attack paths) in the attack path database 302.

[0167] Figure 5A A high-level flow chart illustrates the process by which security control optimization subsystem 60 generates a list of security control implementations. In some examples, at stage 1600, an attack tree (or one or more attack paths) stored in attack path database 302 is associated with a hardware item. In some examples, the association is performed based on a mapping stored in threat-to-attack path mapping database 303, as described above. In some examples, at stage 1610, HBOM information is associated with the hardware item of stage 1600. As described above, in some examples, the HBOM is provided by hardware library 180.

[0168] In some examples, in stage 1620, the attack step implementation mapping subsystem 40 scans the HBOM list 183 for specifications, such as a hardware security module (HSM), a memory protection unit (MPU), a system architecture, and / or any related interfaces. In some examples, the HBOM list 183 is scanned using a language comparison, such as a predetermined string search.

[0169] In some examples, at stage 1630, for each project, attack step implementation mapping subsystem 40 generates a cybersecurity specification list based at least in part on the resources identified in HBOM list 183. In some examples, the cybersecurity specification list includes resources of HBOM list 183 that allow for implementation of security controls.

[0170] In some examples, in stage 1640, the security control optimization subsystem 60 filters the security control implementation database 201 to identify only security control implementations that have hardware dependencies (and optionally also software dependencies) on the corresponding cybersecurity specification list for the hardware item.

[0171] In some examples, at stage 1650, the security control optimization subsystem 60 generates a list of identified security control implementations that can be implemented for the corresponding project and are associated with corresponding attack steps of the attack tree (or one or more attack paths) of the corresponding threat. In some examples, the security control optimization subsystem 60 outputs the generated list. In some examples, the management subsystem 11 outputs the generated list on a user display. In some examples, an attack step implementation map 70 is also output.

[0172] In some examples, attack step implementation mapping 70 includes mapping details of security control implementations, such as how security controls are implemented in association with HBOM list 183 and / or SBOM file 174. More examples of attack step implementation mapping 70 are described further below.

[0173] Figure 5B A high-level flow chart illustrates the process by which the security control optimization subsystem 60 further optimizes the list of security control implementations at stage 1650. In some examples, at stage 1700, a risk objective is set for the project. In some examples, the risk objective is based at least in part on data in the risk analysis information 190. In some examples, as described below, a maximum effort and / or cost value is set for the security control optimization subsystem 60. In some examples, a security depth value is set for the security control optimization subsystem 60. As used herein, the term "security depth value" refers to the number of different resources affected by the selected security control implementation.

[0174] In some examples, at stage 1720, optionally, for each security control, the security control optimization subsystem 60 selects a security control implementation that satisfies the desired risk objective with minimal effort and / or cost and / or maximum coverage, as will be described below with reference to Figure 5C Further described. In some examples, multiple security control implementations are selected such that the multiple security control implementations, when combined, meet a desired risk objective. In some examples, the security control implementations are selected such that they meet a desired security depth value.

[0175] In some examples, at stage 1730, the security control optimization subsystem 60 optimizes a list of security control implementations that should be implemented to meet the risk objectives based at least in part on the implementations selected at stage 1720. In some examples, the security control optimization subsystem 60 outputs the generated list. In some examples, the management subsystem 11 outputs the generated list on a user display.

[0176] Figure 5CA high-level flow diagram illustrates a process by which the security control optimization subsystem 60 selects a security control implementation with the least cost investment and / or cost and / or greatest coverage. In some examples, in stage 1800, for each attack step of each attack tree (or each attack path) for each threat for each asset of each project of each threat model, the security control optimization subsystem 60 identifies an associated security control implementation as described above. Note, however, that, as described above, security controls may be assigned to only a portion of the attack steps. In some examples, the data associated with an attack step includes an ID for the corresponding attack step, an ID for the associated security control implementation, a value indicating the risk reduction caused by the security control implementation, the number of attack paths affected by the security control implementation, and the investment required to implement the security control implementation.

[0177] In some examples, in stage 1810 , for each security control implementation, security control optimization subsystem 60 determines the number of attack paths handled by that particular security control implementation.

[0178] In some examples, in stage 1820, the implementation effort value of the corresponding security control implementation is updated by the security control optimization subsystem 60. As used herein, the term "implementation effort" means the amount of time and / or resources required to implement the corresponding security control implementation. In some examples, a predetermined function provides a value based at least in part on a weighted value of time and resources to determine the implementation effort value. In some examples, if the corresponding security control implementation has been implemented, in some examples, the implementation effort value is set to zero. Figure 5D Describes the methods used to check whether the security control implementation has been achieved.

[0179] In some examples, at stage 1830, for each of the security control implementations described above, the security control optimization subsystem 60 determines the impact of the corresponding security control implementation on the overall feasibility of the attack path or attack tree. In some examples, the score is a predetermined function of the coverage of the security control implementation (i.e., how many attack paths or attack steps are addressed by the security control implementation), the implementation input value of the security control implementation, and the amount of risk reduction provided by the corresponding security control implementation. In some examples, the score determined by the security control optimization subsystem 60 is defined as:

[0180] Score = (Coverage x Weight 1 + Reduced_Risk x Weight 2 - Weight 3 x Investment) / Maximum_Score.

[0181] Here, "Coverage" is the number of attack paths or attack steps (i.e., the coverage value) in a single attack tree (or attack path) or in multiple attack trees (or attack paths) across different threat models; "Reduced_Risk" is a value indicating how much the overall risk level has been reduced; and "Maximum_Score" is a value that is updated each time the "Score" is greater than the current "Feasibility Maximum Score." In some examples, "Reduced_Risk" is determined by the risk subsystem 65. It should also be noted that the coverage value includes the number of attack paths addressed by a single security control implementation across multiple threats across multiple projects. In some examples, weights 1 through 3 are adjustable in response to user input. In some examples, the "Score" is continuously calculated until the risk target is met or a predetermined time period has elapsed. In some examples, using the final risk score, the security control optimization subsystem 60 outputs an optimized security control list 80, with the security control implementations having scores associated with them. In some examples, the scores are output. In some examples, the security control implementations are listed in order of their scores.

[0182] Table 10 shows an example of an optimized security control implementation list 80, as follows:

[0183] Table 10

[0184]

[0185] As shown in the example of Table 10, the security control list 80 includes: the ID of the corresponding security control implementation; the ID of the corresponding one or more threats received in the risk analysis information; the implementation input value for the corresponding security control implementation; the number of attack steps handled by the corresponding security control implementation; and the "score".

[0186] In some examples, at stage 1840, if the feasibility of the attack path cannot be reduced and if the risk is still above the defined risk target, the security control optimization subsystem 60 generates an alert. In some examples, the alert includes sending a report, for example, as described in Table 11:

[0187] Table 11

[0188]

[0189] As shown in the example of Table 11, an alert may include IDs of the following items: model, asset, threat, attack path, damage scenario (ie, what can be damaged by the corresponding attack), and risk value.

[0190] In some examples, at stage 1850, for a given HBOM and SBOM, if a particular security control implementation cannot be implemented due to resource dependency issues, the score of the security control implementation is set to zero, so that the security control implementation is no longer used.

[0191] Figure 5D A high-level flow chart of the process by which the security control optimization subsystem 60 determines whether a security control implementation has been implemented is shown. In some examples, at stage 1900, the security control optimization subsystem 60 maps each security control implementation to a corresponding TARA key. As described above with reference to Table 10, each security control implementation can be associated with the ID of one or more corresponding threats. In some examples, each TARA key comprises the following format:

[0192] TARA-model-id: Item-id: TARA-asset-id: TARA-threat-id: TARA-step-id.

[0193] For example, the TARA key can be: Security Control Implementation 1→Model1:Item1:Asset1:Threat1:Attack tree1:Attack step1.

[0194] In some examples, at stage 1920 , for each TARA key, the security control optimization subsystem 60 identifies the state of the corresponding security control implementation in the TARA-to-security implementation data.

[0195] In some examples, for each safety control implementation whose status is set to “complete,” safety control optimization subsystem 60 sets the corresponding implementation input value to zero.

[0196] In some examples, user input is received indicating that a corresponding security control (such as, as described above) is implemented. In some examples, the security control optimization subsystem 60 identifies one or more attack paths associated with the implemented security control. In some examples, such attack paths are identified by identifying one or more attack steps having the corresponding security control associated therewith. In some examples, as described above, an initial risk level for each threat is received. In some examples, the security control optimization subsystem 60 defines a residual risk level for the corresponding threat after the corresponding security control is implemented. As used herein, the term "residual risk level" refers to the risk level after the corresponding security control is implemented. In some examples, the security control optimization subsystem 60 optionally outputs the defined residual security control via the output subsystem 130.

[0197] Figure 6A A high-level flow chart illustrates the process by which the attack step implementation mapping subsystem 40 maps security control implementations to software assets and project development tasks. In some examples, in stage 2000, for each security control implementation, the subsystem 40 optionally generates security requirements within a requirements tool. In some examples, the requirements include: an attack step description; a description of the attack step to be mitigated; and a unique key: for example, TARA-model-id:Item-id:TARA-asset-id:TARA-threat-id:TARA-step-id. For example, the TARA key may be:

[0198] ADAS1223:TCU112:SIGNAL_ROUITING_1:SPOOFING222:STEP123.

[0199] In some examples, in stage 2010, the attack step implementation mapping subsystem 40 maps security control implementations to software assets and project development tasks. In some examples, the TARA threat is made to the software or data assets of the project, for example, impersonating the signal manager of an in-vehicle infotainment (IVI) system, which could compromise the integrity of OTA updates. As described above, security controls are associated with threats and, therefore, with software or data assets. In some examples, the attack step implementation mapping subsystem 40 queries the PLM system 800 for all tasks that have a description containing the name of the software / data asset (e.g., get all tasks of Project X of type Epic that have "software asset" in the name or description).

[0200] In some examples, in stage 2020, for each task received from the management subsystem 11, task information is stored in a data structure, as described below with reference to Figure 6B , further described in the “Task” section of Table 12.

[0201] In some examples, the attack step implementation mapping subsystem 40 updates the task priority based on the above scores. In some examples, using references to corresponding security control implementations, the attack step implementation mapping subsystem 40 pulls some or all of the software and configuration files from the software library 170 and associates the TARA assets with the corresponding attack steps.

[0202] In some examples, at stage 2030, a unique key is provided, such as the following: TARA-model-id:Item-id:TARA-asset-id:TARA-threat-id:TARA-step-id, as described above. In some examples, the attack step implementation mapping subsystem 40 stores some or all of this key information in a storage device. For example, this may be stored in a storage space where there is a key pointing to an object, and the object may be a .zip file containing all the necessary information.

[0203] Figure 6B A high-level flow chart illustrates the process by which the attack step implementation mapping subsystem 40 generates a data structure. In some examples, in stage 2100, software files are scanned using methods such as text search and / or code analysis based on language syntax (C, C++, JAVA). In some examples, the attack step implementation mapping subsystem creates a data structure. As shown below, an example of the data structure is provided in Table 12. As shown, Table 12 includes: a TARA ID; a threat ID; associated tasks; requirements associated with the project; corresponding templates; and SBOM information. In some examples, as shown in Table 12, the template is associated with any one of the software assets, data assets, and / or signal assets associated with the received risk analysis information.

[0204] In some examples, the attack step implementation mapping subsystem 40 scans the binary files of the project to create a list of risk functions to be used. In some examples, the identification of risk functions is performed using a predetermined disassembly method known to those skilled in the art. In some examples, the risk functions are added to the data structure of stage 2100 and / or a new data structure is created for this purpose.

[0205] In some examples, in stage 220, the attack step implementation mapping subsystem 40 scans software configuration files (e.g., Adaptive AUTOSAR manifest platform and manifest files) associated with the project from software repository 170. In some examples, this information is further added to the data structure of stage 2100, and / or a new data structure is created for this purpose.

[0206] Table 12

[0207]

[0208]

[0209] In some examples, the attack step implementation mapping subsystem 40 parses the SBOM file (e.g., SPDX file) to create a list of some or all of the dependencies in stage 2030. In some examples, this information is further added to the data structure of stage 2100, and / or a new data structure is created for this purpose.

[0210] Figure 6C A high-level flow chart illustrates the process by which attack step implementation mapping subsystem 40 maps attack steps to software configuration data. In some examples, in stage 2200, attack step implementation mapping subsystem 40 creates a unique key, as described above. In some examples, a unique key is generated for each attack step, for each asset, for each project, for each threat model, as described above.

[0211] In some examples, at stage 2210, attack step implementation mapping subsystem 40 updates the security control implementation effort estimates stored in security control implementation database 201 based at least in part on the information stored in the "task" portion of the data structure. In some examples, at step 2220, attack step implementation mapping subsystem 40 updates the asset risk level based on the task status of the data structure.

[0212] In some examples, as used herein, the term "risk level" is defined as a predetermined function of a corresponding feasibility rating and a corresponding impact value. In some examples, the impact value is a numerical indication of the effect that a particular threat would have on a corresponding asset (or on the project itself) if the corresponding threat were realized. In some examples, the impact value is assigned a numerical value, as is known to those skilled in the art.

[0213] In some examples, in stage 2230, the attack step implementation mapping subsystem 40 prioritizes the tasks / software based on the scores of the security controls associated therewith (as described above). Thus, the scores can be used to prioritize software testing and validation. In some examples, the attack step implementation mapping 70 includes the priorities of the tasks / software and, optionally, the risk level associated with each project / asset.

[0214] In some examples, the signal priority subsystem 61 defines a priority for a signal asset based at least in part on the risk level of a threat associated with an asset that can transmit a corresponding signal asset, such that an increased risk level of a signal source (e.g., due to a higher feasibility value) translates into a higher priority for the corresponding signal asset. In some examples, the priority is defined based at least in part on the risk level of a threat associated with an asset that can receive a corresponding signal asset, such that an increased risk level of a signal destination (e.g., due to a higher impact value) translates into a higher priority for the corresponding signal asset. In some examples, as described above, a risk level is defined for a signal asset based on risk analysis information associated with the signal asset, and the priority of the signal asset is based on the determined risk level of the signal asset. In some examples, the risk level of a signal asset is based at least in part on the risk level of the asset that can transmit the corresponding signal and / or on the risk level of an asset that can receive the corresponding signal.

[0215] In some examples, the priority is based on any one or a combination of: inherent risk level; or residual risk level. As used herein, the term "inherent risk level" means the risk level of an asset or item that is not addressed by any security controls.

[0216] In some examples, as will be described below, the risk level may be adjusted, for example, in response to event information received by risk subsystem 65. In some examples, in response to an adjustment in the risk level of an asset, the risk level and / or priority value of the signal asset associated therewith is adjusted accordingly.

[0217] In some examples, the signal priority subsystem 61 generates configuration data for the data logger, the configuration data indicating a priority scheme associated with signal assets for the data logger. In some examples, the priority scheme determines which signal assets receive priority for transmission reports. In some examples, the generated configuration data 85 is output. In some examples, the configuration data 85 is stored in a file in a predetermined format.

[0218] Therefore, for a vehicle with a data logger that receives messages from the network and sends samples to the backend for continuous analysis / training, the generated configuration data can be used to prioritize the information sent based on the priority of the signal. So, if there is a constraint on the amount of data that can be sent, the data logger will first record data for signals with high priority.

[0219] In some examples, the signal priority subsystem 61 generates configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme for the IDS related to signal assets. In some examples, as described below, the IDS defines a security policy for a monitoring system. In some examples, the priority scheme defines which signal assets the IDS prioritizes during analysis, such that higher priority signal assets are scrutinized more closely.

[0220] For example, an automotive Ethernet switch may have a ternary content addressable memory (TCAM) cell, which is a type of computer memory used in automotive network switches to quickly route Ethernet traffic through its header. Any TCAM has a maximum depth, which can typically be between 48 and 138 bytes. There are a small number of TCAMs in a switch. The TCAM can be configured so that when a hit (a successful bitwise comparison) occurs, it sends the packet to its destination (which we call a whitelist), to the internal CPU, or to both its destination and the internal CPU. In some examples, as described above, the TCAM is configured according to a priority scheme.

[0221] In some examples, the configuration data includes information associated with each signal asset, and the IDS analyzes the signal assets based on the information contained within the configuration data.

[0222] A code example of configuration data for an IDS may be as follows: Signal asset priority data may include a priority value (1, 2, 3, 4, 5) and a resource value (10, 20, 30, 40, 50) indicating an amount of resources required to analyze the signal.

[0223] signals=[("Signal1", 1,10), ("Signa12", 2,20), ("Signa13", 3,30), ("Signa14", 4, 50),

[0224] ("Signa15",5,50)]

[0225] resources_available=Y

[0226] def allocate_resources(signals,resources_available):

[0227] signals_allocated = []

[0228] signals=sorted(signals,key=lambda x:x[1],reverse=True)#Sort signals based on priority

[0229] for signal in signals:

[0230] name,priority,resources_needed=signal

[0231] if resources_needed<=resources_available:

[0232] signals_allocated.append(signal)

[0233] resources_available=resources_needed

[0234] return signals_allocated

[0235] Although the above examples relate to priority data including both priority values and resource values, this is not meant to be limiting in any way, and priority values may be used without resource values. Additionally, priority values and resource values may be used in separate lists.

[0236] In some examples, the generated configuration data 85 is output. In some examples, the configuration data 85 is stored in a file in a predetermined format.

[0237] Figure 7 A high-level flow chart of a method for outputting information about signals transmitted within a project is shown. In stage 2300, the signal subsystem 62 receives information about at least one signal transmitted within the project. In some examples, the information is received from the ALM system 800. In some examples, the received information includes identification information of an asset within the project that transmits the signal and an asset within the project that receives the signal. In some examples, information about multiple signals within the project is received.

[0238] At stage 2310, in some examples, for each signal of stage 2300, a risk level of one or more threats associated with the asset that received the signal is output (as described above). In some examples, for each signal of stage 2300, a feasibility rating of one or more threats associated with the asset that sent the signal is output (as described above).

[0239] In stage 2320, in some examples, outputting information from stage 2310 includes outputting the received information about the plurality of signals, information about the risk levels of threats associated with the assets that received the plurality of signals, and information about the feasibility ratings of the threats associated with the assets that sent the plurality of signals. Specifically, in some examples, the information about the plurality of signals is arranged together in a predetermined format (such as a graph). In some examples, the information about each of the plurality of signals includes: identification data of the asset that sent the signal and the asset that received the signal; information about the risk levels of one or more threats associated with the asset that received the signal; and information about the risk levels of one or more threats associated with the asset that sent the signal.

[0240] In some examples, signal subsystem 62 also identifies communication paths between assets. In some examples, the communication paths are identified based at least in part on information associated with the received plurality of signals. In some examples, the communication paths between assets can be between assets in the same project, as well as between separate assets, i.e., communication paths that cross between projects.

[0241] In some examples, signal subsystem 62 compares the risk levels of assets being communicated with one another. In some examples, if one or more signals are sent to an asset with a lower risk level than the asset sending the signal, signal subsystem 62 generates an alert. In some examples, the generated alert is output by output subsystem 130. In some examples, the alert notifies the user that an asset with a lower risk level is actually at a higher risk due to communication with a higher-risk asset.

[0242] In some examples, the comparison of risk levels is not limited to two assets in direct communication with each other. In some examples, signaling subsystem 62 identifies an asset chain, wherein each of a plurality of assets communicates with another asset in the asset chain. In some examples, signaling subsystem 62 compares the risk levels of all assets within the chain. In some examples, when one or more assets within the chain have a higher risk level than other assets within the chain, signaling subsystem 62 generates an alert, as described above. In some examples, the generated alert is output by output subsystem 130. In some examples, the alert notifies the user that an asset with a lower risk level is actually at higher risk due to communication with a higher-risk asset.

[0243] In some examples, ID subsystem 63 defines an asset chain identifier (ID) and associates it with each asset. In some examples, the asset chain ID is a unique identifier that identifies threats to each asset within a corresponding asset chain (asset chains as described above). In some examples, ID subsystem 63 is configured to output information about threats to assets of the corresponding chain when a request including the corresponding asset chain ID is received.

[0244] In some examples, the asset chain ID is output by output subsystem 130. In some examples, the output information associated with each asset includes the corresponding asset chain ID. In some examples, ID subsystem 63 defines a requirement for users to add the asset chain ID when performing tasks associated with the corresponding asset (such as tracking errors associated with the asset). In some examples, the requirement can be any type of notification to the user. In some examples, ID subsystem 63 also defines a predefined message format and adds the predefined message format to the requirement, such that users are required to use the predefined message format associated with the corresponding asset chain ID.

[0245] In some examples, permissions subsystem 64 generates information for each asset regarding the resources required by the corresponding asset and the permissions allowed for the corresponding asset. As used herein, the term "permissions" refers to which resources an asset is allowed to access. In some examples, permissions are based at least in part on user input.

[0246] In some examples, permissions subsystem 64 compares the permissions of the corresponding asset to the asset's risk level. In some examples, each risk level has one or more predetermined permissions allowed at that risk level. In some examples, if the permissions of the corresponding asset are not allowed at the corresponding asset's risk level, permissions subsystem 64 generates a corresponding alert. In some examples, the alert is output at output subsystem 130.

[0247] In some examples, as will be described below, the risk level can be adjusted, for example, in response to received event information.In some examples, based at least in part on the adjustment of the risk level, permissions are analyzed again to determine whether they meet predetermined rules regarding risk levels.

[0248] In some examples, security control optimization subsystem 60 outputs information about one or more security controls associated with the corresponding asset so that the risk level of the asset can be reduced to a level that will allow permissions. In some examples, security control optimization subsystem 60 updates security control list 80 accordingly.

[0249] In some examples, permissions subsystem 64 compares the permissions of each asset in a project to the risk level of other assets in the corresponding project. In some examples, if the permissions of the corresponding asset are not allowed at the risk level of any other asset in the corresponding project, permissions subsystem 64 generates a corresponding alert. In some examples, the alert is output at output subsystem 130.

[0250] In some examples, security control optimization subsystem 60 outputs information about one or more security controls associated with the corresponding asset so that the risk level of the asset can be reduced to a level that will allow permissions. In some examples, security control optimization subsystem 60 updates security control list 80 accordingly.

[0251] In some examples, permissions subsystem 64 optionally compares the permissions of each asset to the risk levels of other assets in communication with the asset and / or within the asset chain, based at least in part on the output of signaling subsystem 62. In some examples, permissions subsystem 64 generates a corresponding alert if the risk level of any other asset in communication with the asset does not allow permissions for the asset. In some examples, the alert is output at output subsystem 130.

[0252] In some examples, security control optimization subsystem 60 outputs information about one or more security controls associated with the corresponding asset so that the risk level of the asset can be reduced to a level that will allow permissions. In some examples, security control optimization subsystem 60 updates security control list 80 accordingly.

[0253] Figure 8 A high-level flow chart illustrates a method for outputting information in response to event information. As used herein, the term "event information" refers to information regarding detected abnormal behavior or an indication of a vulnerability that may cause abnormal behavior. As used herein, the term "abnormal behavior" refers to any action that does not satisfy predefined rules. In some examples, abnormal behavior may include message behavior exceeding predetermined parameters and / or an indication of a slow CPU operation speed.

[0254] In some examples, in stage 2400, event information associated with an item is received. In some examples, the item is part of a vehicle, a charger, a connected service, etc. In some examples, the item is at least part of one or more components that communicate with the vehicle. In some examples, as described above, the event information includes information about abnormal behavior detected in the item and / or information about one or more detected vulnerabilities in the item. In some examples, the event information is associated with one or more assets within the item. Specifically, in some examples, the event information includes information about abnormal behavior detected in one or more assets and / or information about one or more vulnerabilities detected in one or more assets.

[0255] In some examples, the event information can be received from a vulnerability management system that receives alerts about Common Vulnerabilities and Exposures (CVEs). In some examples, CVEs are defined in the National Vulnerability Database (NVD). In some examples, the information is received via the ALM system 800. In some examples, the event information is received from an IDS.

[0256] In some examples, the event information is associated with an attack. In some examples, the event information about the attack includes a component associated with the attack. In some examples, the event information is associated with a program error.

[0257] In some examples, the event information includes: an identifier of the corresponding asset; an identifier of the software version of the asset; and / or information about the attack interface (ie, which interface the attack was associated with), if any.

[0258] In some examples, at stage 2410, risk subsystem 65 identifies one or more attack steps of one or more attack paths based at least in part on the received event information, each attack path being associated with a respective asset within the project. In some examples, risk subsystem 65 identifies the one or more attack steps based at least in part on SBOM information associated with the respective assets associated with the one or more attack steps.

[0259] In some examples, as described above with reference to Table 12, each attack step has associated with it information about software dependencies associated with the corresponding attack step. Thus, in such examples, risk subsystem 65 can identify all attack steps that have at least partially identical dependencies on resources of projects and / or assets associated with the event. In some examples, information about these resources is included within the event information.

[0260] In some examples, the identification of each attack step is based at least in part on a linguistic analysis of the textual description contained in the received event information and the textual description contained in the corresponding attack step. In some examples, the linguistic analysis is performed as described above with respect to matching attack steps with security controls. In some examples, the event information includes a textual description of the vulnerability or detected anomalous behavior, and the risk subsystem 65 compares at least a portion of the textual description with the verbs and nouns associated with each attack step to identify an attack step whose description matches the description of the event.

[0261] In some examples, as described above with respect to matching attack steps to security controls, each attack step has a corresponding template associated therewith. In some examples, the description contained within the event information is compared to the terms of the template. In some examples, when a match is found between nouns and / or verbs in the event description and the template, one or more attack steps associated with the corresponding template are identified.

[0262] In some examples, as described above, where the event information is a CVE, the CVE includes information about the software and its versions affected by the detected vulnerability and a text description of the vulnerability.

[0263] In some examples, implementation database 201 has multiple known event identifiers (such as known CVE identifiers) and event information associated with the corresponding event identifiers stored therein. In some examples, the attack steps of the attack paths stored in attack path database 302 are mapped to the stored event identifiers. In some examples, the security controls stored in security control database 202 are mapped to the stored event identifiers. In some examples, the security control implementations stored in implementation database 201 are mapped to the stored event identifiers. In some examples, when event information is received, the identifier of the received event information is compared with the stored event identifiers to determine whether such an event identifier has been stored. In the case where such an event identifier is stored in the implementation database, the corresponding one or more attack steps, security controls, and / or security control implementations are identified according to the predefined mapping.

[0264] In some examples, at stage 2420, risk subsystem 65 adjusts one or more corresponding risk levels based at least in part on the identified one or more attack steps. In some examples, risk subsystem 65 adjusts one or more risk levels of assets associated with the identified attack steps. In some examples, risk subsystem 65 adjusts one or more risk levels of projects associated with the incident. In some examples, the risk level of a project is defined by a predetermined function of the risk levels of assets within the project. Thus, in some examples, adjusting the risk level of an asset adjusts the risk level of the project containing the corresponding asset.

[0265] In some examples, the adjusted one or more risk levels include a residual risk level. As described above, the residual risk level is the risk level after implementing predetermined security controls. Abnormal behavior or vulnerabilities can hinder the impact of security controls on attack steps, thereby increasing the corresponding residual risk. In some examples, events can affect specific security control implementations, thereby affecting the effectiveness of security controls. In some examples, as described above, event information includes indications of program errors or vulnerabilities in corresponding assets and / or projects. In the event that one or more security control implementations are implemented on software affected by the program error / vulnerability, the risk subsystem 65 can determine that the feasibility rating of the corresponding security control implementation (i.e., the extent to which the security control implementation reduces the feasibility of any attack step / attack path) has been reduced, thereby increasing the risk level.

[0266] In some examples, the adjusted risk level is independent of the assets affected by the incident. Specifically, in some examples, upon determining that the feasibility rating of a particular security control implementation has been affected, risk subsystem 65 adjusts the risk level of any assets having attack steps addressed by the affected security control implementation.

[0267] In some examples, where the received event information includes information about a vulnerability in a corresponding resource, risk subsystem 65 identifies one or more security control implementations associated with the corresponding resource. In some examples, the security control implementations are identified based on dependencies of the associated SBOM, as described above. In some examples, the adjustment of one or more risk levels is based at least in part on the identified one or more security control implementations, as described above.

[0268] In some examples, the one or more risk levels adjusted by risk subsystem 65 include an inherent risk level. In some examples, the inherent risk level that is adjusted is the initial risk level, i.e., the risk level provided in the risk analysis information described above. In some examples, the inherent risk level differs from the initial risk level due to a previous adjustment, optionally based on a previous event. In some examples, the inherent risk level is adjusted based at least in part on an adjustment to the feasibility rating, as described above with respect to the residual risk level. In some examples, risk subsystem 65 adjusts both the inherent risk level and the residual risk level.

[0269] In some examples, at stage 2430, risk subsystem 65 outputs information associated with the adjusted one or more risk levels of stage 2420. In some examples, the output information includes the adjusted one or more risk levels. In some examples, the output information includes any one or a combination of the following: an initial risk level for the one or more assets or projects; an inherent risk level for the one or more assets or projects before the adjustment of stage 2420; an inherent risk level for the one or more assets or projects after the adjustment of stage 2420; a residual risk level for the one or more assets or projects before the adjustment of stage 2420; and a residual risk level for the one or more assets or projects after the adjustment of stage 2420.

[0270] In some examples, risk subsystem 65 outputs identifiers of one or more security controls associated with the one or more attack steps identified in stage 2410. In some examples, for each attack step identified in stage 2410, risk subsystem 65 outputs identifiers of one or more security controls associated with the corresponding attack step. In some examples, the corresponding security controls are those included in optimized security control list 80. In some examples, as will be described below, the corresponding security controls are not included in optimized security control list 80. In some examples, as will be described below, outputting the identifiers of the one or more security controls includes updating optimized security control list 80 and outputting the updated security control list 80.

[0271] In some examples, risk subsystem 65 outputs identifiers of one or more security control implementations associated with the one or more attack steps identified in stage 2410. In some examples, for each attack step identified in stage 2410, risk subsystem 65 outputs identifiers of one or more security control implementations associated with the corresponding attack step. In some examples, the corresponding security control implementations are those included in optimized security control list 80. In some examples, as will be described below, the corresponding security control implementations are not included in optimized security control list 80. In some examples, as will be described below, outputting the identifiers of the one or more security control implementations includes updating optimized security control list 80 and outputting the updated security control list 80. In some examples, the identifier of the security control or security control implementation includes an identifier of the user responsible for implementing the security control.

[0272] In some examples, in stage 2440, where the event is associated with one or more specific resources, the security control optimization subsystem 60 identifies one or more security control implementations that are not associated with the corresponding resources. In some examples, as described above, for each security control, multiple security control implementations can be stored in the implementation database 201. In some examples, the security control optimization subsystem 60 identifies that the security control implementation currently included in the optimized security control list 80 is implemented on a resource affected by the event (such as abnormal behavior, vulnerability, or program error).

[0273] In some examples, the security control optimization subsystem 60 identifies different security control implementations for the same security control, where the identified security control implementations are not associated with the resources affected by the event. In some examples, the different security control implementations are associated with corresponding attack steps and / or attack paths identified in stage 2410. As described above, in some examples, each attack step has multiple security control implementations associated with it. In some examples, the security control optimization subsystem 60 outputs an identifier of the identified security control implementation. In some examples, as described above, the optimized security control list 80 is updated with information about the identified security control implementation. In some examples, the identifier of the security control implementation includes an identifier of the user responsible for implementing the security control implementation.

[0274] In some examples, at stage 2450, for at least one of the identified attack steps of stage 2410, the security control optimization subsystem 60 identifies one or more alternative attack steps for the corresponding attack path, the processing of which will process the corresponding attack path. Specifically, as described above, some attack paths have several options for processing, each option including a different subset of attack steps (and different subsets may have overlapping attack steps). Therefore, in some examples, the security control optimization subsystem 60 identifies one or more alternative attack steps to replace one or more attack steps affected by the event in order to process the corresponding attack path. In some examples, the alternative attack steps are independent of the resources affected by the corresponding event.

[0275] In some examples, as described above, security control optimization subsystem 60 selects one or more security controls and / or security control implementations to process the alternative attack steps. In some examples, information about the selected security controls and / or security control implementations (such as their identifiers) is output. In some examples, security control optimization subsystem 60 updates optimized security control list 80 using the selected security controls and / or security control implementations.

[0276] In some examples, in stage 2460, risk subsystem 65 determines, for each of the identified attack steps of stage 2410, whether a previous attack step within the corresponding attack path has been executed. As used herein, the term "previous attack step" means an attack step that precedes the identified attack step of stage 2410. In some examples, the adjustment of one or more risk levels of stage 2420 is based at least in part on determining that a previous attack step within the attack path has been executed.

[0277] Specifically, in some examples, if one or more previous attack steps within an attack path have not been executed, this may indicate that an attack has not yet occurred. Thus, in this case, the risk level may not be adjusted, or may be adjusted by a smaller amount. In some examples, the adjustment of the risk level is a predetermined function of the number of previous attack steps executed and / or the percentage of previous attack steps executed. In some examples, risk subsystem 65 determines whether the previous attack steps were executed within a predetermined time period. In some examples, the predetermined time period is a predetermined portion of a day.

[0278] In some examples, risk subsystem 65 receives information output by one or more security sensors located within or in communication with the project. In some examples, the information output by the one or more security sensors is received from ALM system 800. In some examples, the information output by the one or more security sensors is received from a security operations center (SOC) in communication with input subsystem 120. In some examples, determining whether a previous attack step within a corresponding attack path has been executed is based at least in part on information output by the one or more security sensors received within a predetermined time period.

[0279] In some examples, the security sensor can be a security monitor within or in communication with a project and / or asset. In some examples, the security monitor can identify anomalies in a Linux process, identify crashes, identify excessive CPU load, identify security policy violations, etc. For example, in QNX and SELinux operating systems, these security sensors run security policies that protect processes and output alerts when security policies are violated. In some examples, the security sensor can include one or more intrusion detection systems (IDS), such as one or more antivirus software. For example, in the AUTOSAR basic software module, complex device drivers (CDDs) and software components (SWCs) can act as security sensors, and they report security events (SEv) to the intrusion detection system manager (IDSM).

[0280] In some examples, risk subsystem 65 outputs information about previous attack steps within the corresponding attack path and receives one or more user inputs associated with the output information. In some examples, the user input is received at management subsystem 11. In some examples, the output information provides identifiers and / or descriptions of previous attack steps, and the user input indicates whether these attack steps occurred. Thus, in some examples, determining whether a previous attack step within the corresponding attack path was executed is based at least in part on the one or more received user inputs.

[0281] In some examples, risk subsystem 65 prioritizes the received event information of stage 2400 based at least in part on determining whether previous attack steps within the corresponding attack path have been executed. In some examples, the priority value assigned to the received event information is a predetermined function of the number of previous attack steps executed and / or the percentage of attack steps executed within the attack path. In some examples, a higher percentage and / or a higher number of attack steps executed indicates that an attack has actually occurred, and therefore, the event report should be prioritized.

[0282] In some examples, the priority value determines whether and / or how quickly event information is reported. In some examples, the output subsystem 130 provides priority information to the ALM system 800, and the ALM system 800 transmits event reports to corresponding networks and clients based on the received priority information.

[0283] In some examples, the received event information is prioritized based at least in part on the number of identified attack paths of stage 2410. In some examples, the greater the number of identified attack paths, the greater the defined priority value.

[0284] Some examples of the disclosed technology

[0285] Some examples of the above embodiments are listed below. It should be noted that one feature of an isolated example or a combination of one or more features of the example, and optionally a combination of one or more features of the example with one or more features of one or more of the following examples, also belong to examples within the scope of the disclosure of this application.

[0286] Example A1. A risk determination system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored in the memory, the instructions, when executed by the one or more processors, causing the one or more processors to perform a method, the method comprising: receiving event information associated with a project, the event information comprising information about abnormal behavior detected in the project or information about vulnerabilities detected in the project; identifying one or more attack steps of one or more attack paths based at least in part on the received event information, each of the one or more attack paths being associated with a corresponding asset among a plurality of assets included in the project; for each corresponding asset, adjusting one or more corresponding risk levels based at least in part on the identified one or more attack steps associated with the corresponding asset; and for each corresponding asset, outputting information associated with the adjusted one or more corresponding risk levels.

[0287] Example A2. The system of any example herein, in particular Example A1, wherein, for each respective asset, the one or more respective risk levels that are adjusted include a residual risk level.

[0288] Example A3. The system of any example herein, particularly Examples A1 or A2, wherein, for each respective asset, the one or more respective risk levels that are adjusted are inherent risk levels.

[0289] Example A4. A system according to any example herein, in particular any one of Examples A1 to A3, wherein the method further comprises: for each corresponding asset, outputting an identifier of a user associated with an implementation of the corresponding asset.

[0290] Example A5. A system according to any of the examples herein, in particular any of Examples A1 to A4, wherein one or more attack steps of identifying one or more attack paths associated with the corresponding asset are based at least in part on a software bill of materials (SBOM) associated with the corresponding asset.

[0291] Example A6. A system according to any of the examples herein, in particular any of Examples A1 to A5, wherein identifying each attack step is based at least in part on a linguistic analysis associated with a text description contained within the received event information and a text description contained within the corresponding attack step.

[0292] Example A7. A system according to any example in this document, in particular Example A6, wherein the method further comprises loading a template database, wherein the template database comprises data about a plurality of templates, each template comprising information about associated resources and information about one or more attack steps associated with the corresponding resources, wherein identifying each attack step is based at least in part on the data about the plurality of templates.

[0293] Example A8. A system according to any example in the present document, in particular Example A7, wherein, for each attack step, the method further includes: associating the corresponding attack step with a corresponding template among the multiple templates, wherein the association with the corresponding template includes a corresponding language comparison of the text description of the corresponding attack step with one or more templates among the multiple templates; performing a language comparison of the text description of the received event information with one or more templates among the multiple templates; and matching the received event information with one of the multiple templates based at least in part on the result of the language comparison performed on the text description of the received event information, wherein identifying the corresponding attack step is at least in part based on the association of the corresponding attack step with the matched template.

[0294] Example A9. A system according to any of the examples herein, in particular any of Examples A1 to A8, wherein, for each of the identified attack steps, the method further comprises adjusting the feasibility rating of the corresponding attack step, and wherein the adjustment of the one or more corresponding risk levels is based at least in part on the adjusted feasibility rating of the corresponding attack step.

[0295] Example A10. A system according to any example in this document, in particular any one of Examples A1 to A9, wherein the method further comprises: loading a control database comprising data about a plurality of security controls; and for each identified attack step, outputting an identifier of a corresponding security control among the plurality of security controls, wherein the corresponding security control is associated with the corresponding identified attack step.

[0296] Example A11. A system according to any example in this document, in particular any one of Examples A1 to A9, wherein the method further comprises: loading a control database comprising data about a plurality of security controls; loading an implementation database comprising a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and for each identified attack step, outputting an identifier of a corresponding security control implementation in the plurality of security control implementations, wherein the corresponding security control implementation is associated with the corresponding identified attack step.

[0297] Example A12. A system according to any example in this document, in particular any one of Examples A1 to A9, wherein the received event information includes information about a vulnerability in the corresponding resource, wherein the method further comprises: loading a control database including data about a plurality of security controls; loading an implementation database including a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and identifying one or more security control implementations of the plurality of security control implementations associated with the corresponding resource, and wherein the adjustment of the one or more risk levels is based at least in part on the identified one or more security control implementations.

[0298] Example A13. A system according to any example in this document, in particular Example A12, wherein the method further includes: identifying one or more security control implementations among the multiple security control implementations that are not associated with the corresponding resources; and outputting an identifier of the corresponding security control implementation among the one or more security control implementations that are not associated with the corresponding resources.

[0299] Example A14. A system according to any example herein, in particular Example A13, wherein one or more identified security control implementations of the plurality of security control implementations that are not associated with the corresponding resources are associated with one or more identified attack steps.

[0300] Example A15. A system according to any example in this document, in particular Example A13, wherein one or more identified security control implementations among the multiple security control implementations that are not associated with the corresponding resources are associated with one or more attack paths of the identified one or more attack steps.

[0301] Example A16. A system according to any example in this document, in particular any one of Examples A1 to A9, wherein the method further comprises: for at least one of the identified attack steps, identifying one or more alternative attack steps of the corresponding attack path, and processing of the one or more alternative attack steps will process the corresponding attack path.

[0302] Example A17. A system according to any example herein, in particular any one of Examples A1 to A16, wherein the received event information includes an event identifier, and identifying the one or more attack steps is at least partially based on comparing the event identifier with event identifier information associated with the identified one or more attack steps.

[0303] Example A18. The system of any example herein, in particular Example A17, wherein the event identifier of the received event information is a Common Vulnerabilities and Exposures (CVE) identifier.

[0304] Example A19. A system according to any example in this document, in particular any one of Examples A1 to A18, wherein the method further comprises: for each of the identified attack steps, determining whether a previous attack step within the corresponding attack path has been performed, and wherein adjusting the one or more risk levels is at least partially based on determining that a previous attack step within the attack path has been performed.

[0305] Example A20. A system according to any example herein, in particular Example A19, wherein the method further comprises receiving information output by one or more security sensors, and wherein determining whether a previous attack step within the corresponding attack path has been performed is based at least in part on the information output by the one or more security sensors received within a predetermined time period.

[0306] Example A21. The system of any example herein, in particular Example A20, wherein the information output by the one or more security sensors is received from an application lifecycle management (ALM) system.

[0307] Example A22. The system of any example herein, particularly Example A20, wherein the information output by the one or more security sensors is received from a security operations center (SOC).

[0308] Example A23. A system according to any of the examples herein, in particular Example A19, wherein determining whether a previous attack step within the corresponding attack path has been performed is based at least in part on event information previously received within a predetermined time period.

[0309] Example A24. A system according to any example herein, in particular any one of Examples A19 to A23, wherein the method further comprises, for each of the identified attack steps: outputting information about the previous attack step within the corresponding attack path; and receiving one or more user inputs associated with the output information about the previous attack step, and wherein determining whether the previous attack step within the corresponding attack path has been executed is based at least in part on the one or more user inputs received.

[0310] Example A25. A system according to any of the examples herein, in particular any of Examples A19 to A24, wherein the method further comprises prioritizing the received event information based at least in part on determining whether a previous attack step within the corresponding attack path has been executed.

[0311] Example A26. A system according to any example herein, in particular any one of Examples A1 to A25, wherein the method further comprises prioritizing the received event information based at least in part on the number of identified attack steps.

[0312] Example A27. A system according to any of the examples herein, in particular any of Examples A1 to A25, wherein the method further comprises prioritizing the received event information based at least in part on the number of identified attack paths that include one or more identified attack steps.

[0313] Example A28. A system according to any example in this document, in particular any one of Examples A1 to A27, wherein the method further comprises: loading an attack path database comprising multiple attack paths; and matching the description contained in the received risk analysis information with the corresponding attack path in the multiple attack paths based at least in part on a previous matching of the corresponding attack path with a similar description.

[0314] Example A29. The system of any example herein, in particular Example A28, wherein matching with a corresponding attack path in the plurality of attack paths is based at least in part on a linguistic analysis of the description.

[0315] Example A30. A system according to any example herein, in particular any one of Examples A1 to A29, wherein the one or more corresponding risk levels are associated with the item.

[0316] Example A31. A system according to any example herein, in particular Example A30, wherein the one or more respective risk levels are associated with the respective assets.

[0317] Example A32. A system according to any example herein, in particular Example A31, wherein the method further comprises: comparing one or more permissions of the corresponding asset with one or more adjusted corresponding risk levels; and generating an alert according to predetermined rules based at least in part on a result of the comparison indicating that the one or more permissions are not allowed at the adjusted one or more corresponding risk levels.

[0318] Example A33. A system according to any example herein, in particular Example A31 or A32, wherein at least a subset of the multiple assets are signal assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more corresponding risk levels for each of the signal assets; outputting the generated signal priority data; adjusting the generated signal priority data based at least in part on an adjustment of one or more risk levels for one or more of the signal assets; and outputting the adjusted signal priority data.

[0319] Example A34. The system of any example herein, in particular Example A33, wherein the generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme for the data recorder associated with the signal assets.

[0320] Example A35. A system according to any example herein, in particular Example A33 or A34, wherein the generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal asset with respect to the IDS.

[0321] Example A36. A risk determination system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored in the memory, the instructions, when executed by the one or more processors, causing the one or more processors to perform a method, the method comprising: receiving information about a risk level of each of a plurality of assets, wherein the risk level of a first asset of the plurality of assets is lower than the risk level of a second asset of the plurality of assets; receiving information about communications between the first asset of the plurality of assets and the second asset of the plurality of assets; adjusting the risk level of the first asset of the plurality of assets to be equal to the risk level of the second asset of the plurality of assets based at least on the received information about communications between the first asset of the plurality of assets and the second asset of the plurality of assets; and outputting information associated with the adjusted risk level.

[0322] Example A37. A system according to any of the examples herein, in particular Example A36, wherein at least a subset of the multiple assets form an asset chain, wherein the method further comprises: receiving information about communications passing through the asset chain; identifying assets with the highest risk level in the asset chain; and adjusting the risk level of each asset within the asset chain to be equal to the highest risk level in the asset chain based at least on the received information about communications passing through the asset chain, and wherein the first asset of the multiple assets and the second asset of the multiple assets form at least part of the asset chain.

[0323] Example A38. The system of any example herein, in particular Example A37, wherein at least a first portion of the asset chain is in a first project, and wherein at least a second portion of the asset chain is in a second project.

[0324] Example A39. A system according to any example herein, in particular any one of Examples A36 to A38, wherein the method further comprises receiving information about at least one signal transmitted between the first asset among the plurality of assets and the second asset among the plurality of assets, and wherein the received information about the communication between the first asset among the plurality of assets and the second asset among the plurality of assets includes information about the at least one signal.

[0325] Example A40. The system of any of the examples herein, in particular Example A39, wherein the information about the at least one signal is received from an application lifecycle management (ALM) system.

[0326] Example A41. A system according to any example herein, in particular any one of Examples A36 to A40, wherein the method further comprises: comparing one or more permissions of the first of the multiple assets with an adjusted risk level; and generating an alert according to predetermined rules based at least in part on a result of the comparison indicating that the one or more permissions are not allowed at the adjusted risk level.

[0327] Example A42. A system according to any example herein, in particular any one of Examples A36 to A41, wherein at least a subset of the multiple assets are signal assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more corresponding risk levels of each of the signal assets; outputting the generated signal priority data; adjusting the generated signal priority data based at least in part on an adjustment of one or more risk levels of one or more of the signal assets; and outputting the adjusted signal priority data.

[0328] Example A43. The system of any example herein, in particular Example A42, wherein the generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme associated with the signal assets for the data recorder.

[0329] Example A44. A system according to any example herein, in particular Example A42 or A43, wherein the generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal asset with respect to the IDS.

[0330] Example A45. A risk determination system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored in the memory, the instructions, when executed by the one or more processors, causing the one or more processors to perform a method comprising: receiving information about a risk level of each of a plurality of assets within a project; identifying an asset having a highest risk level among the plurality of assets; adjusting the risk level of each of the plurality of assets within the project to be equal to the highest risk level within the project; and outputting information associated with the adjusted risk level of each of the plurality of assets.

[0331] Example A46. A system according to any example herein, in particular Example A45, wherein the method further comprises: for each of the multiple assets within the project: comparing one or more permissions of the corresponding asset with the adjusted risk level; and generating an alert according to predetermined rules based at least in part on a result of the comparison indicating that the one or more permissions are not allowed at the adjusted risk level.

[0332] Example A47. A system according to any example herein, in particular Example A45 or A46, wherein at least a subset of the multiple assets are signal assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more corresponding risk levels for each of the signal assets; outputting the generated signal priority data; adjusting the generated signal priority data based at least in part on an adjustment of one or more risk levels for one or more of the signal assets; and outputting the adjusted signal priority data.

[0333] Example A48. The system of any example herein, in particular Example A47, wherein the generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme associated with the signal assets for the data recorder.

[0334] Example A49. A system according to any example herein, in particular Example A47 or A48, wherein the generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal asset with respect to the IDS.

[0335] Example B1. A security control system comprising one or more processors and a memory, wherein the memory has a plurality of instructions stored in the memory that, when executed by the one or more processors, cause the one or more processors to perform a method comprising: receiving risk analysis information comprising data about a plurality of threats, each of the plurality of threats being associated with a corresponding asset; loading a control database comprising data about a plurality of security controls; for each of the plurality of threats, matching one or more of the plurality of security controls with one or more attack steps of an attack path associated with the corresponding threat; for each of the plurality of threats, selecting at least a subset of the matched security controls; and for each of the plurality of threats, outputting information about the selected security control, wherein the output information is based at least in part on: expenditure data associated with the corresponding security control, the expenditure data indicating the cost and / or effort required to implement the corresponding security control; and feasibility data associated with the corresponding security control, the feasibility data indicating the extent to which the corresponding security control, when implemented, will reduce a feasibility rating of a corresponding one of a plurality of attack steps.

[0336] Example B2. A system according to any of the examples herein, in particular Example B1, wherein selecting at least a subset of the matching security controls includes selecting the subset of the matching security controls based at least in part on corresponding expenditure data and corresponding feasibility data, and wherein the output information includes information about the selected subset of security controls.

[0337] Example B3. A system according to any of the examples herein, in particular Example B1, wherein the method further comprises determining a corresponding score for each of the plurality of security controls, the corresponding score being based at least in part on corresponding expenditure data and corresponding feasibility data, and wherein the output information is based at least in part on the determined score.

[0338] Example B4. A system according to any of the examples herein, in particular Example B3, wherein selecting at least a subset of the matching security controls includes selecting the subset of the matching security controls based at least in part on the corresponding scores, and wherein the output information includes information about the selected subset of security controls.

[0339] Example B5. The system of any example herein, in particular Example B3, wherein the output information about the selected security controls includes a respective score for each of the selected security controls.

[0340] Example B6. The system of any example herein, particularly Example B3, wherein the output information about the selected security control is ranked based at least in part on a score of the selected security control.

[0341] Example B7. A system according to any example herein, in particular Example B1, wherein, for each of the multiple security controls, the control database also includes dependency requirements associated with the corresponding security control, and wherein the output information is also based on the dependency requirements associated with the matching security control.

[0342] Example B8. A system according to any of the examples herein, in particular Example B7, wherein the method further comprises: receiving information about resources of a project; and comparing the information about the resources of the project with dependency requirements associated with matching security controls associated with corresponding assets within the project, wherein selecting at least a subset of the matching security controls comprises selecting the subset of matching security controls based at least in part on a result of the comparison, and wherein the output information comprises information about the selected subset of security controls.

[0343] Example B9. A system according to any example herein, in particular Example B7 or B8, wherein the dependency requirements include software dependency requirements and hardware dependency requirements.

[0344] Example B10. A system according to any example herein, in particular any one of Examples B7 to B9, wherein the method further comprises receiving a bill of materials comprising information about resources of the asset.

[0345] Example B11. A system according to any of the examples herein, in particular Example B1, wherein, for each attack path, corresponding steps define one or more attack paths, and wherein the method further comprises: determining a corresponding coverage value for each security control that matches a step of the identified attack path, and wherein the output information is also based on the determined coverage value of the selected security control.

[0346] Example B12. A system according to any of the examples herein, in particular Example B11, wherein selecting at least a subset of the matching security controls includes selecting the subset of the matching security controls based at least in part on the determined coverage values of the selected security controls, and wherein the output information includes information about the selected subset of security controls.

[0347] Example B13. The system of any of the examples herein, in particular Example B11, wherein the output information about the selected security controls is ranked based at least in part on the determined coverage values of the selected security controls.

[0348] Example B14. The system of any example herein, in particular any one of Examples B11 to B13, wherein the coverage value is determined for a plurality of items.

[0349] Example B15. A system according to any example in this document, in particular Example B1, wherein the method further comprises: loading an implementation database comprising a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and for each of the plurality of threats, selecting at least a subset of the security control implementations associated with the matching security control, wherein the output information comprises information about the selected security control implementation.

[0350] Example B16. A system according to any of the examples herein, in particular Example B15, wherein selecting at least a subset of the security control implementations includes selecting the subset of the security control implementations based at least in part on corresponding expenditure data and feasibility data associated with the selected security control implementations, and wherein the output information includes information about the selected subset of security control implementations.

[0351] Example B17. A system according to any of the examples herein, in particular Example B16, wherein the method further comprises determining a corresponding score for each of the plurality of security control implementations, the corresponding score being based at least in part on corresponding expenditure data and corresponding feasibility data associated with the corresponding security control implementation, and wherein the output information is based at least in part on the determined score.

[0352] Example B18. A system according to any of the examples herein, in particular Example B17, wherein selecting at least a subset of the security control implementations includes selecting the subset of the security control implementations based at least in part on the corresponding scores, and wherein the output information includes information about the selected subset of security control implementations.

[0353] Example B19. The system of any example herein, particularly Example B17, wherein the output information about the selected security control implementations includes a corresponding score for each of the selected security control implementations.

[0354] Example B20. The system of any example herein, in particular Example B17, wherein the output information about the selected security control implementations is ranked based at least in part on scores of the selected security control implementations.

[0355] Example B21. A system according to any example in this document, in particular Example B15, wherein, for each of the multiple security control implementations, the implementation database also includes dependency requirements associated with the corresponding security control implementation, and wherein the output information is also based on the dependency requirements associated with the selected security control implementation.

[0356] Example B22. A system according to any example herein, in particular Example B21, wherein the method further comprises: receiving information about resources of a project; and comparing the information about the resources of the assets with dependency requirements associated with the security control implementations associated with matching security controls associated with corresponding assets within the project, wherein selecting at least a subset of the security control implementations comprises selecting a subset of the security control implementations associated with the matching security controls based at least in part on a result of the comparison, and wherein the output information comprises information about the selected subset of security control implementations.

[0357] Example B23. The system of any example herein, in particular Example B21 or B22, wherein the dependency requirements include software dependency requirements and hardware dependency requirements.

[0358] Example B24. A system according to any example herein, in particular any one of Examples B21 to B23, wherein the method further comprises receiving a bill of materials comprising information about resources of the asset.

[0359] Example B25. A system according to any of the examples herein, in particular Example B15, wherein, for each attack path, corresponding steps define one or more attack paths, and wherein the method further comprises: determining a corresponding coverage value for each of the security control implementations associated with the security control that matches the steps of the identified attack path, and wherein the output information is also based on the determined coverage value of the selected security control implementation.

[0360] Example B26. A system according to any of the examples herein, in particular Example B25, wherein selecting at least a subset of the security control implementations includes selecting the subset of the security control implementations based at least in part on the determined coverage values of the selected security control implementations, and wherein the output information includes information about the selected subset of security control implementations.

[0361] Example B27. The system of any of the examples herein, particularly Example B25, wherein the output information about the selected security control implementation is sorted based at least in part on the determined coverage value of the selected security control implementation.

[0362] Example B28. A system according to any example herein, in particular any one of Examples B25 to B27, wherein the coverage value is determined for a plurality of items.

[0363] Example B29. A system according to any of the examples herein, in particular any of Examples B1 to B28, wherein, for each attack path, corresponding steps define one or more attack paths, and wherein the method further comprises: receiving an initial risk level, wherein the initial risk level is defined based on the attack paths of the multiple threats; receiving a target risk level; and identifying one or more of the attack steps of the multiple threats, the processing of which will reach the target risk level.

[0364] Example B30. A system according to any example herein, in particular Example B29, wherein the initial risk level is defined as a predetermined function of the corresponding impact value of the corresponding threat and the corresponding feasibility rating of each attack path of each of the multiple threats.

[0365] Example B31. The system according to any example in this document, in particular any one of Examples B29 to B31, further includes: determining whether the target risk level can be achieved for each of the multiple threats; and outputting a list of multiple threats that are determined not to achieve the corresponding target risk level.

[0366] Example B32. The system according to any example in this document, in particular any one of Examples B29 to B32, further includes: receiving user input indicating that a corresponding one of the security controls is implemented; identifying one or more corresponding attack paths associated with the implemented security control; defining a residual risk level in response to the identified one or more corresponding attack paths associated with the implemented security control; and outputting the residual risk level.

[0367] Example B33. A system according to any of the examples herein, in particular Example B32, wherein identifying one or more attack paths whose processing will reach the target risk level includes identifying an attack path that includes: at least one step associated with a first resource, wherein processing at least one step associated with the first resource mitigates or restores the identified attack path; and at least one step associated with a second resource, wherein processing at least one step associated with the second resource mitigates or restores the identified attack path, and wherein the second resource is different from the first resource.

[0368] Example B34. The system according to any example in this document, in particular any one of Examples B1 to B33, further includes: for each of the one or more matched security controls, a corresponding step of adding the corresponding security control to the corresponding attack path.

[0369] Example B35. The system according to any example in this document, in particular Example B34, further includes: receiving user input indicating that a corresponding one of the security controls is implemented; and in response to the received user input indicating that a corresponding one of the security controls is implemented, marking the corresponding one of the security controls as being implemented.

[0370] Example B36. A system according to any of the examples herein, in particular Example B1, wherein the method further comprises loading an attack path database comprising multiple attack paths, wherein, for each of the multiple threats, the method further comprises: matching the description contained in the received risk analysis information with the corresponding attack path based at least in part on a previous matching of the corresponding attack path in the multiple attack paths with a similar description, and wherein the description comprises a description of the attack, a description of the attack path and / or a description of the attack tree.

[0371] Example B37. A system according to any of the examples herein, in particular Example B1, wherein, for each of a plurality of assets, the method further comprises matching the profile of the corresponding asset contained in the corresponding risk analysis information and the threat list associated with the corresponding asset contained in the corresponding risk analysis information with the corresponding attack path based at least in part on a previous matching of the corresponding attack path in the plurality of attack paths with the asset profile and threat list, the asset profile and threat list being at least partially identical to the profile and threat list of the corresponding asset.

[0372] Example B38. A system according to any of the examples herein, in particular Examples B36 or B37, wherein matching with corresponding attack paths in the plurality of attack paths is based at least in part on linguistic analysis.

[0373] Example B39. A system according to any of the examples herein, in particular any of Examples B1 to B38, wherein matching one or more of the multiple security controls with one or more steps of the attack path includes performing corresponding linguistic analysis of the textual description of each of the multiple security controls and each of the steps of the attack path.

[0374] Example B40. A system according to any of the examples herein, in particular Example B39, wherein the linguistic analysis of the textual description of each of the plurality of security controls includes a normalization step, wherein one or more words of the textual description are normalized to a corresponding predetermined format based at least in part on a corresponding predetermined list of terms.

[0375] Example B41. The system according to any example in this document, in particular Example B1 or B40, further includes loading a template database, wherein the template database includes data about multiple templates, each template including information about associated resources and information about one or more attack steps associated with the corresponding resources, wherein matching the one or more security controls of the multiple security controls with the one or more steps of the attack path is at least partially based on the data about the multiple templates.

[0376] Example B42. The system according to any example in this document, in particular Example B41, further includes associating each of the multiple security controls in the control database with a corresponding template in the multiple templates, wherein, for each of one or more of the multiple security controls, a match with one or more steps in the attack path is responsive to the template associated with the corresponding security control.

[0377] Example B43. A system according to any of the examples herein, in particular Example B42, wherein, for each of one or more of the multiple security controls, the association with the corresponding template includes a textual description of the corresponding security control compared with the corresponding languages of the multiple templates.

[0378] Example B44. A system according to any example herein, in particular Example B42 or B43, wherein, for each of one or more steps in the attack path, the method further comprises associating the corresponding step with a corresponding template among the plurality of templates, wherein, for each of one or more steps in the attack path, the matching security control is associated with the corresponding template associated with the corresponding step.

[0379] Example B45. A system according to any of the examples herein, in particular Example B44, wherein, for each of one or more steps in the attack path, the association with the corresponding template includes a textual description of the corresponding attack step compared with the corresponding languages of the multiple templates.

[0380] Example B46. A system according to any of the examples herein, in particular Example B45, wherein the linguistic analysis of the textual description of each of the multiple attack steps includes a normalization step, wherein one or more words of the textual description are normalized to a corresponding predetermined format based at least in part on a corresponding predetermined list of terms.

[0381] Example B47. A system according to any example in this document, in particular any one of Examples B1 to B46, wherein the method further includes, for each of the multiple threats: mapping one or more steps of the attack path to corresponding software implementations; and outputting information about the software implementation mapping of the one or more steps.

[0382] Example B48. A system according to any example in this document, in particular any one of Examples B1 to B47, wherein the method further includes, for each of the multiple threats: mapping one or more steps of the attack path to corresponding hardware implementations; and outputting information about the hardware implementation mapping of the one or more steps.

[0383] Example B49. A system according to any of the examples herein, in particular any of Examples B1 to B48, wherein at least a subset of the matching security controls is selected such that at least a subset of the matching security controls satisfies a predetermined security depth value.

[0384] Example B50. A system according to any example herein, in particular Example B49, wherein the method further comprises receiving corresponding user input indicating a desired safety depth, the predetermined safety depth value being set according to the corresponding user input.

[0385] It will be appreciated that certain features of the invention described in the context of separate embodiments for clarity may also be provided in combination in a single embodiment. Conversely, various features of the invention described in the context of a single embodiment for brevity may also be provided individually or in any suitable subcombination.

[0386] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the invention belongs. Although methods similar or equivalent to those described herein can be used in the practice or testing of the present invention, suitable methods are described herein.

[0387] All publications, patent applications, patents, and other references mentioned herein are incorporated herein by reference in their entirety. In the event of a conflict, the present patent application specification (including definitions) shall prevail. In addition, the materials, methods, and examples are illustrative only and are not intended to be limiting.

[0388] Those skilled in the art will recognize that the present invention is not limited to what has been specifically shown and described above. On the contrary, the scope of the present invention is defined by the claims and includes combinations and subcombinations of the various features described above, as well as changes and modifications thereto that occur to those skilled in the art upon reading the foregoing description.

Claims

1. A risk determination system comprising one or more processors and a memory, wherein: The memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method comprising: receiving event information associated with a project, the event information including information about abnormal behavior detected in the project or information about a vulnerability detected in the project; identifying, based at least in part on the received event information, one or more attack steps of one or more attack paths, each of the one or more attack paths being associated with a respective asset of a plurality of assets included within the project; For each respective asset, adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset; and For each respective asset, information associated with the adjusted one or more respective risk levels is output.

2. The system according to claim 1, wherein: For each respective asset, the one or more respective risk levels that are adjusted comprise a residual risk level.

3. The system according to claim 1 or 2, wherein: For each respective asset, the one or more respective risk levels that are adjusted are inherent risk levels.

4. The system according to any one of claims 1 to 3, wherein: The method further includes outputting, for each respective asset, an identifier of a user associated with an implementation of the respective asset.

5. The system according to any one of claims 1 to 4, wherein: The one or more attack steps of identifying one or more attack paths associated with the respective assets are based at least in part on a software bill of materials (SBOM) associated with the respective assets.

6. The system according to any one of claims 1 to 5, wherein: Identifying each attack step is based at least in part on a linguistic analysis associated with a textual description contained within the received event information and a textual description contained within a corresponding attack step.

7. The system according to claim 6, wherein: The method further includes loading a template database, the template database including data regarding a plurality of templates, each template including information regarding an associated resource and information regarding one or more attack steps associated with the corresponding resource, Wherein, identifying each attack step is based at least in part on data regarding the plurality of templates.

8. The system according to claim 7, wherein: For each attack step, the method further includes: associating the corresponding attack step with a corresponding template of the plurality of templates, wherein associating with the corresponding template comprises comparing a textual description of the corresponding attack step with corresponding language of one or more templates of the plurality of templates; performing a linguistic comparison of a textual description of the received event information with one or more of the plurality of templates; and matching the received event information to one of the plurality of templates based at least in part on a result of the performed linguistic comparison of the textual description of the received event information, Wherein, identifying the corresponding attack step is based at least in part on an association of the corresponding attack step with the matched template.

9. The system according to any one of claims 1 to 8, wherein: For each of the identified attack steps, the method further includes adjusting the feasibility rating of the corresponding attack step, and Wherein, the adjustment of the one or more respective risk levels is based at least in part on the adjusted feasibility rating of the respective attack step.

10. The system according to any one of claims 1 to 9, wherein: The method further comprises: loading a control database comprising data regarding a plurality of security controls; and For each identified attack step, an identifier of a corresponding security control in the plurality of security controls is output, wherein the corresponding security control is associated with the corresponding identified attack step.

11. The system according to any one of claims 1 to 9, wherein: The method further comprises: loading a control database including data regarding a plurality of security controls; loading an implementation database comprising a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and For each identified attack step, an identifier of a corresponding security control implementation from the plurality of security control implementations is output, wherein the corresponding security control implementation is associated with the corresponding identified attack step.

12. The system according to any one of claims 1 to 9, wherein: The received event information includes information about a vulnerability in the corresponding resource, wherein the method further comprises: loading a control database including data regarding a plurality of security controls; loading an implementation database comprising a plurality of security control implementations, each of the plurality of security controls being associated with one or more of the plurality of security control implementations; and identifying one or more security control implementations of the plurality of security control implementations associated with the corresponding resource, and Wherein, the adjustment of the one or more risk levels is based at least in part on the identified one or more security control implementations.

13. The system according to claim 12, wherein: The method further comprises: identifying one or more security control implementations of the plurality of security control implementations that are not associated with the corresponding resource; and An identifier of a corresponding security control implementation of the one or more security control implementations that is not associated with the corresponding resource is output.

14. The system according to claim 13, wherein: The identified one or more security control implementations of the plurality of security control implementations that are not associated with the corresponding resource are associated with the identified one or more attack steps.

15. The system according to claim 13, wherein: The identified one or more security control implementations of the plurality of security control implementations that are not associated with the corresponding resource are associated with one or more attack paths of the identified one or more attack steps.

16. The system according to any one of claims 1 to 9, wherein: The method further includes, for at least one of the identified attack steps, identifying one or more alternative attack steps of a corresponding attack path, processing of the one or more alternative attack steps will process the corresponding attack path.

17. The system according to any one of claims 1 to 16, wherein: The received event information includes an event identifier, and identifying the one or more attack steps is based at least in part on comparing the event identifier with event identifier information associated with the identified one or more attack steps.

18. The system according to claim 17, wherein: The event identifier of the received event information is a Common Vulnerabilities and Exposures (CVE) identifier.

19. The system according to any one of claims 1 to 18, wherein: The method further includes, for each of the identified attack steps, determining whether a previous attack step within the corresponding attack path has been executed, and Wherein adjusting the one or more risk levels is performed based at least in part on determining a previous attack step within the attack path.

20. The system of claim 19, wherein: The method further includes receiving information output by one or more security sensors, and Wherein, determining whether a previous attack step within the corresponding attack path has been performed is based at least in part on information output by the one or more security sensors received within a predetermined time period.

21. The system of claim 20, wherein: Information output by the one or more security sensors is received from an application lifecycle management (ALM) system.

22. The system of claim 20, wherein: Information output by the one or more security sensors is received from a security operations center (SOC).

23. The system of claim 19, wherein: Determining whether a previous attack step within the corresponding attack path has been performed is based at least in part on event information previously received within a predetermined time period.

24. A system according to any one of claims 19 to 23, wherein The method further comprises, for each of the identified attack steps: outputting information about the previous attack step within the corresponding attack path; and receiving one or more user inputs associated with output information regarding the previous attack step, and Wherein, determining whether a previous attack step within the corresponding attack path has been performed is based at least in part on one or more received user inputs.

25. The system according to any one of claims 19 to 24, wherein: The method also includes prioritizing the received event information based at least in part on determining whether a previous attack step within the corresponding attack path has been executed.

26. The system according to any one of claims 1 to 25, wherein: The method also includes prioritizing the received event information based at least in part on the number of identified attack steps.

27. The system according to any one of claims 1 to 25, wherein: The method also includes prioritizing the received event information based at least in part on a number of identified attack paths that include the identified one or more attack steps.

28. The system according to any one of claims 1 to 27, wherein: The method further comprises: loading an attack path database comprising a plurality of attack paths; and Descriptions contained within the received risk analysis information are matched to corresponding attack paths in the plurality of attack paths based at least in part on previous matching of the corresponding attack paths to similar descriptions.

29. The system of claim 28, wherein: The matching to a corresponding attack path of the plurality of attack paths is based at least in part on a linguistic analysis of the description.

30. The system according to any one of claims 1 to 29, wherein: The one or more respective risk levels are associated with the project.

31. The system of claim 30, wherein: The one or more respective risk levels are associated with the respective assets.

32. The system of claim 31 , wherein the method further comprises: comparing the one or more rights of the corresponding asset to the adjusted one or more corresponding risk levels; and An alert is generated according to predetermined rules based at least in part on a result of the comparing indicating that the one or more permissions are not permitted at the adjusted one or more corresponding risk levels.

33. The system of claim 31 or 32, wherein: At least a subset of the plurality of assets are signaling assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more respective risk levels for each of the signal assets; outputting the generated signal priority data; adjusting said generated signal priority data based at least in part on an adjustment of one or more risk levels of one or more of said signal assets; and Outputs the adjusted signal priority data.

34. The system of claim 33, wherein: The generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme associated with the signal assets for the data recorder.

35. The system of claim 33 or 34, wherein: The generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal assets for the IDS.

36. A risk determination system comprising one or more processors and a memory, wherein: The memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method comprising: receiving information regarding a risk level for each of a plurality of assets, wherein the risk level for a first asset in the plurality of assets is lower than the risk level for a second asset in the plurality of assets; receiving information regarding communications between the first asset of the plurality of assets and the second asset of the plurality of assets; adjusting a risk level of the first asset in the plurality of assets to be equal to a risk level of the second asset in the plurality of assets based at least on the received information regarding communications between the first asset in the plurality of assets and the second asset in the plurality of assets; and Output information associated with the adjusted risk level.

37. The system of claim 36, wherein: At least a subset of the plurality of assets forms an asset chain, wherein the method further comprises: receiving information regarding communications traversing the asset chain; Identify the assets in the asset chain with the highest level of risk; and adjusting the risk level of each asset within the asset chain to be equal to the highest risk level in the asset chain based at least on information received about communications traversing the asset chain, and The first asset among the multiple assets and the second asset among the multiple assets form at least a part of the asset chain.

38. The system of claim 37, wherein: At least a first portion of the asset chain is in a first project, and at least a second portion of the asset chain is in a second project.

39. A system according to any one of claims 36 to 38, wherein The method further includes receiving information regarding at least one signal transmitted between the first asset of the plurality of assets and the second asset of the plurality of assets, and The received information about the communication between the first asset among the plurality of assets and the second asset among the plurality of assets includes information about the at least one signal.

40. The system of claim 39, wherein: The information regarding the at least one signal is received from an application lifecycle management (ALM) system.

41. The system of any one of claims 36 to 40, wherein: The method further comprises: comparing one or more entitlements of the first asset of the plurality of assets to the adjusted risk level; and Based at least in part on a result of the comparing indicating that the one or more permissions are not permitted at the adjusted risk level, an alert is generated according to predetermined rules.

42. A system according to any one of claims 36 to 41, wherein At least a subset of the plurality of assets are signaling assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more respective risk levels for each of the signal assets; outputting the generated signal priority data; adjusting said generated signal priority data based at least in part on an adjustment of one or more risk levels of one or more of said signal assets; and Outputs the adjusted signal priority data.

43. The system of claim 42, wherein: The generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme associated with the signal assets for the data recorder.

44. The system of claim 42 or 43, wherein: The generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal assets for the IDS.

45. A risk determination system comprising one or more processors and a memory, wherein: The memory has a plurality of instructions stored therein that, when executed by the one or more processors, cause the one or more processors to perform a method comprising: receiving information regarding a risk level for each of a plurality of assets within a project; identifying an asset having a highest level of risk among the plurality of assets; adjusting the risk level of each of the plurality of assets within the project to be equal to the highest risk level within the project; and Information associated with an adjusted risk level for each of the plurality of assets is output.

46. The system of claim 45, wherein: The method further comprises, for each of the plurality of assets within the project: comparing one or more entitlements of the corresponding asset to the adjusted risk level; and Based at least in part on a result of the comparing indicating that the one or more permissions are not permitted at the adjusted risk level, an alert is generated according to predetermined rules.

47. The system of claim 45 or 46, wherein: At least a subset of the plurality of assets are signaling assets, and wherein the method further comprises: generating signal priority data for the signal assets based at least in part on one or more respective risk levels for each of the signal assets; outputting the generated signal priority data; adjusting said generated signal priority data based at least in part on an adjustment of one or more risk levels of one or more of said signal assets; and Outputs the adjusted signal priority data.

48. The system of claim 47, wherein: The generated signal priority data includes configuration data for a data recorder, the configuration data indicating a priority scheme associated with the signal assets for the data recorder.

49. The system of claim 47 or 48, wherein: The generated signal priority data includes configuration data for an intrusion detection system (IDS), the configuration data indicating a priority scheme associated with the signal assets for the IDS.