Improved methods of ranking network threats and addressing network threats

By collecting threat data from multiple online sources and assessing the attractiveness of honeypots, and adjusting threat ratings and rankings, this technology addresses the problem of lagging network threat assessment in existing technologies, enabling dynamic assessment of network threats and timely defensive measures.

CN122497953APending Publication Date: 2026-07-31COLLISON PLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
COLLISON PLC
Filing Date
2024-10-22
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies are insufficient for effectively assessing and ranking cyber threats, causing defense measures to lag behind changes in attack methods and making it impossible to respond to online threats in a timely manner.

Method used

By collecting threat data from multiple online sources, formatting and storing it in a database, the attractiveness of honeypots to threats is assessed, threat ratings are adjusted, and threats are ranked based on applications, then delivered to users to take appropriate action.

Benefits of technology

It enables dynamic assessment and ranking of network threats, helping users to take timely and targeted defensive measures and improve network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122497953A_ABST
    Figure CN122497953A_ABST
Patent Text Reader

Abstract

One method for assessing threats to a network involves collecting existing threats from multiple online sources, storing these threats in a database, and formatting the data representing the existing threats in the database for easy reference. This method can determine a rating for each existing threat, assess the attractiveness of honeypots to the threats, and adjust the threat rating based on the attractiveness of the honeypots. Furthermore, this method can assess applications on the network, rank threats based on applications, and deliver the rankings to the user.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to U.S. Application No. 18 / 383,796, filed October 25, 2023, entitled “An Improved Method for Ranking Cyber ​​Threats and Addressing Cyber ​​Threats,” the entire contents of which are hereby incorporated by reference. Background Technology

[0003] Even for the most advanced organizations, online threats remain a challenge. Attacks continue to employ new and novel techniques to infiltrate networks and cause problems for victims. Defenders continue to adapt and change in response to new threats. However, online threats remain an issue. Summary of the Invention

[0004] A method for assessing threats to a network is described. This method can collect existing threat data from multiple online sources, store these threats in a database, and format the data representing existing threats in the database for easy viewing. The method can determine a rating for each existing threat, assess the attractiveness of honeypots to threats, and adjust the threat rating based on the attractiveness of the honeypots. The method can also assess applications on the network, rank threats based on applications, and deliver the rankings to the user. Attached Figure Description

[0005] Figure 1 It can demonstrate methods for identifying threats to the network;

[0006] Figure 2 It can demonstrate methods for ranking network threats;

[0007] Figure 3 An embodiment of the method can be shown; and

[0008] Figure 4 A computer system capable of performing this method can be shown.

[0009] Those skilled in the art will understand that the elements in the accompanying drawings are shown for simplicity and clarity, and therefore not all connections and options are shown to avoid obscuring aspects of the invention. For example, common but easily understood elements that are useful or necessary in commercially viable embodiments are generally not depicted to facilitate a clearer view of the various embodiments of this disclosure. It will be further understood that certain actions and / or steps may be described or depicted in a particular order of occurrence, and those skilled in the art will understand that such specificity regarding the order is not actually necessary. It will also be understood that the terms and expressions used herein will be defined relative to their respective fields of inquiry and research, unless otherwise set forth herein with specific meaning. Detailed Implementation

[0010] The system and method claimed herein overcome the limitations of previous systems by providing a system for analyzing available data and information about honeypot methods into information about threats. The method can collect existing threat data from multiple online sources, aggregate existing threats into a database, and format the data representing existing threats in the database for easy viewing. The method can determine a rating for each existing threat, assess the attractiveness of the honeypot to the threat, and adjust the threat rating based on the attractiveness of the honeypot. The method can evaluate applications on the network, rank threats based on applications, and deliver the rankings to the user.

[0011] All dimensions specified in this disclosure are intended to be illustrative only and not restrictive. Furthermore, the scales shown in these figures may not necessarily be drawn to scale. As will be understood, the actual dimensions and scales of any system, device, or part of a system or device disclosed in this disclosure may be determined by its intended use.

[0012] Methods and apparatuses that can implement various features of the invention will now be described with reference to the accompanying drawings. The drawings and related descriptions are provided to illustrate embodiments of the invention, but not to limit the scope of the invention. References to “one embodiment” or “embodiment” in the specification may be intended to indicate that a particular feature, structure, or characteristic described in connection with that embodiment may be included in at least one embodiment of the invention. The phrases “in one embodiment” or “embodiment” appearing throughout the specification may not necessarily refer to the same embodiment.

[0013] Throughout the accompanying drawings, reference numerals may be used repeatedly to indicate the correspondence between referenced elements. As used in this disclosure, unless the context requires otherwise, the term "comprise" and variations thereof, such as "comprising," "comprises," and "comprised," are not intended to exclude additional items, components, technical parameters, or steps.

[0014] In the following description, specific details are set forth to provide a thorough understanding of the embodiments. However, those skilled in the art will understand that the embodiments can be practiced without these specific details. Well-known circuits, structures, and techniques may not be shown in detail to avoid obscuring the embodiments. For example, circuits may be shown as block diagrams to avoid obscuring the embodiments with unnecessary detail.

[0015] It should also be noted that these embodiments may be described as processes depicted as flowcharts, flow diagrams, structural diagrams, or block diagrams. The flowcharts and block diagrams in the accompanying drawings can illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer programs according to the various embodiments disclosed. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code, which may include one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions mentioned in the blocks may occur in a different order than shown in the figures.

[0016] Although flowcharts can describe operations as a sequential process, many operations can be executed in parallel or simultaneously. Furthermore, the order of operations can be rearranged. A process can terminate when its operations are completed. A process can correspond to a method, function, procedure, subroutine, subroutine, etc. When a process corresponds to a function, its termination can correspond to the function returning to the calling function or the main function. Additionally, each box in a block diagram and / or flowchart illustration, and combinations of boxes in block diagrams and / or flowchart illustrations, can be implemented by a system based on dedicated hardware or a combination of dedicated hardware and computer instructions that performs the specified function or action.

[0017] Furthermore, a storage device can refer to one or more devices for storing data, including read-only memory (ROM), random access memory (RAM), magnetic disk storage media, optical storage media, flash memory devices, and / or other non-transitory machine-readable media for storing information. The term "machine-readable media" can include, but is not limited to, portable or fixed storage devices, optical storage devices, wireless channels, and various other non-transitory media capable of storing, including, containing, executing, or carrying (one or more) instructions and / or data.

[0018] Furthermore, embodiments can be implemented using hardware, software, firmware, middleware, microcode, or a combination thereof. When implemented as software, firmware, middleware, or microcode, program code or code segments used to perform the necessary tasks can be stored in a machine-readable medium such as a storage medium or other memory. One or more processors can execute the necessary tasks serially, distributedly, concurrently, or in parallel. Code segments can represent procedures, functions, subroutines, programs, routines, subroutines, modules, software packages, classes, or combinations of instructions, data structures, or program statements. Code segments can be coupled to another code segment or hardware circuitry by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., can be passed, forwarded, or transmitted through suitable means, including memory sharing, messaging, token passing, network transmission, etc., and are also referred to as interfaces, where an interface is a point of interaction with software or computer hardware or peripheral devices.

[0019] refer to Figure 1This could reveal a method and system for addressing online threats. Even for the most advanced organizations, online threats remain a challenge. Attacks continue to employ new and novel techniques to infiltrate networks and cause problems for victims. Defenders continue to adapt and change in response to new threats. However, online threats remain a problem.

[0020] A method for assessing threats to a network is described. This method collects existing threats from multiple online sources, adds them to a database, and formats the data representing existing threats in the database for easy viewing. The method can determine a rating for each existing threat, assess the attractiveness of honeypots to threats, and adjust the threat rating based on the attractiveness of the honeypots. The method can also assess applications on the network, rank threats based on applications, and deliver the rankings to the user.

[0021] At box 100, the method and system can collect existing threats from multiple online sources. Existing threats can be collected from a variety of sources. Some possible sources include national vulnerability databases, vulnerability exploitation prediction scoring systems, exploitDB, GitHub, and social media accounts. As an example, GitHub can have discussions about vulnerabilities and can contain code to resolve them. Similarly, social media accounts can be dedicated to discussing vulnerabilities and possible solutions. Websites and blogs can also contain useful data for identifying and resolving vulnerabilities.

[0022] At box 110, existing threats can be collected into a database. The type of database can vary widely. In one respect, the database may need to be secure and scalable, as solutions to vulnerabilities may generate new threats, and the database of threat information may grow.

[0023] In some embodiments, data regarding existing threats can be formatted for storage in a database for future reference. In one embodiment, formatting the data representing existing threats in the database for future reference may include representing existing threats in numerical form. For example, 1 may indicate the existence of an existing threat, and 0 may indicate the absence of an existing threat. The database format is such that the first entry is a threat to application A, and the second entry is a threat to application B, so that only 1s and 0s need to be stored.

[0024] At box 120, a rating can be determined for each existing threat. The rating can be based on the risk the threat poses to the system. As an example, a threat that allows access to the root of the system could be given a high rating. Similarly, a threat that allows access to personally identifiable information could be given a high rating. Conversely, a threat that only accesses a system that does not contain useful data or is no longer in use could be considered a lower threat. Rating can continue until all available existing threats in question have been assessed, at which point the method can proceed to box 130.

[0025] In box 130, the attractiveness of the honeypot to a threat can be assessed. Attractiveness can be determined in various ways. In some embodiments, the number of hits on the honeypot over a period of time can be used to indicate attractiveness. In another embodiment, the change in the number of hits on the honeypot can be used to indicate attractiveness. In yet another embodiment, the persistence of a single attacker attempting to attack the honeypot can be used to indicate attractiveness. In yet another embodiment, if the attacker is known, the attacker's strength can be used to indicate attractiveness. In yet another aspect, several measures of attractiveness can be combined into an index, and this index can be used to indicate the attractiveness of the honeypot. Of course, other methods are also possible and anticipated. Attractiveness assessment can continue until the honeypot in question has been assessed, after which the method can proceed to box 140.

[0026] At box 140, the threat rating based on the attractiveness of the honeypot can be adjusted. In one aspect, adjusting the threat rating based on the attractiveness of the honeypot may include setting up the honeypot and determining the number of threats accessing the honeypot over a period of time. In one embodiment, the method may determine the origin of the threat, store the origins, compare the origins across multiple honeypots, and rank the origins based on the number of honeypots accessed.

[0027] In box 150, applications on the network can be evaluated. Since some threats may target specific applications, some applications may pose a greater risk than others. Therefore, it may be meaningful to rank applications that are more frequently threatened as more risky.

[0028] At box 160, threats can be ranked based on the applications they target. For example, the system and method can determine a threat's ability to access honeypots and rate the threats based on that ability. Of course, other methods are possible and anticipated.

[0029] Figure 2 One possible method for ranking threats can be shown. At box 200, a honeypot can be set up. A honeypot might appear as an attractive target for a hacker, such as a personal information file or a file containing credit card information. At box 210, the system can determine the number of threats attempting to access the honeypot. This number could be a count of the number of access attempts during a given time period. Sometimes, this count could be the total number of access attempts, or it could be the number of unique access attempts. This box can continue until a count of available threats is made, then control can move to box 220.

[0030] At box 220, the origin of the threat can be determined. In some embodiments, the IP address of the threat can be identified, although the IP address may have limited value because it may be hidden behind a VPN. This box can continue until the available threats have been assessed, and then control can move to box 230. At box 230, the IP address can be added to memory or a database, and widespread use of the same VPN can be logged and stored for future research, even if the real IP address is hidden behind a VPN. For example, the VPN can be contacted to obtain additional information.

[0031] In box 240, IP addresses that have visited multiple honeypots can be analyzed to see if some IP addresses are visiting many honeypots, which can indicate that the IP addresses are particularly active and dangerous. In box 250, source IP addresses can be ranked based on the number of honeypots a single IP address has attempted to access. Of course, other methods for ranking and determining origins are possible and anticipated.

[0032] Refer again Figure 1 At box 170, the ranking can be sent to the user. The user can then decide on the appropriate steps to take based on the ranking. For example, a high-ranking app may require additional security, while a low-ranking app may require less attention. In another embodiment, a threshold can be established, and any threats exceeding the threshold can be sent.

[0033] In some embodiments, solutions to threats to the network may be delivered. In some embodiments, solutions to only threats ranked on the network may be delivered. In other embodiments, the system and method may have appropriate licenses to implement the solution, and the solution may be implemented by the system and method. In other embodiments, license may be requested to install the solution.

[0034] Figure 3 An embodiment of the system and method can be illustrated. In the backend 300 of the Common Exploitation Security System (CESS), data on known threats can be collected. Threats can be collected from one or more of various sources, such as NVD 305, the Exploitation Prediction Scoring System for Common Vulnerabilities and Exposures (CVEs) (EPSS); the Exploitation Database 315, GitHub 320, and Twitter (now known as X 325). Of course, other vulnerability database sources can be used and are anticipated.

[0035] In box 330, the collected data can be fed into the pipeline. In box 335, the data collector can make API calls to open-source sources and internal databases to collect data. In box 340, the feature extractor can aggregate the collected data to create features to be fed into the model. Features can be normalized indicators of vulnerabilities or exploits. For example, a list of vulnerabilities can exist, and vulnerabilities can be assigned 1 or 0 to indicate whether a vulnerability exists.

[0036] At box 345, features can be used to create an exploit availability score, which indicates the probability that an exploit is available. The model can also determine an exploit usage score, which indicates the probability that a vulnerability will be exploited. In some examples, the exploit score can be manually incremented by the model to further investigate a specific vulnerability.

[0037] At box 350, the data store can contain CVE data, extracted features, and a timeline of score changes for each CVE. The data store can be accessed using API 355. Clients can use the API to query a specific CVE 360, retrieve the latest CVE and its score changes 365, track all score changes and mentions for a specific CVE 370, view identified exploits from online media 375, and retrieve other mentions for CVE 380.

[0038] In some embodiments, the client can access the system, whereby the client can communicate with the system using protocols to access APIs and effectively assess risks to the network. In other embodiments, the system can be used to manage the client's network, and the network manager can use protocols and APIs to assess threats and find solutions.

[0039] like Figure 4 As shown, the computing device 401 performing the method may include a processor 402 coupled to an interconnect bus. The processor 402 may include a register set or register space 404, which... Figure 4 The processor is depicted as being entirely on-chip, but it may alternatively be wholly or partially off-chip and directly coupled to processor 402 via dedicated electrical connections and / or via an interconnect bus. Processor 402 may be any suitable processor, processing unit, or microprocessor. Although not described in detail... Figure 4 As shown, however, computing device 401 may be a multiprocessor device, and therefore may include one or more additional processors that are the same as or similar to processor 402 and are communicatively coupled to an interconnect bus.

[0040] Figure 4The processor 402 may be coupled to a chipset 406, which includes a memory controller 408 and a peripheral input / output (I / O) controller 410. Chipsets are known to typically provide I / O and memory management functions, as well as multiple general-purpose and / or special-purpose registers, timers, etc., that can be accessed or used by one or more processors coupled to the chipset 406. The memory controller 408 may perform functions that enable the processor 402 (or multiple processors, if there are multiple processors) to access system memory 412 and mass storage 414, which may include either or both of an in-memory cache (e.g., a cache within memory 412) or an on-disk cache (e.g., a cache within mass storage 414).

[0041] System memory 412 may include any desired type of volatile and / or non-volatile memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), flash memory, read-only memory (ROM), etc. Mass storage memory 414 may include any desired type of mass storage device. For example, computing device 401 may be used to implement module 416 (e.g., various modules as described herein). Mass storage memory 414 may include hard disk drives, optical disk drives, magnetic tape storage devices, solid-state memories (e.g., flash memory, RAM memory, etc.), magnetic memories (e.g., hard disk drives), or any other memory suitable for mass storage. As used herein, the terms module, block, function, operation, process, routine, step, and method refer to tangible computer program logic or tangible computer-executable instructions that provide the specified function to the computing device 401, system, and method described herein. Therefore, modules, blocks, functions, operations, processes, routines, steps, and methods may be implemented in hardware, firmware, and / or software.

[0042] In one embodiment, program modules and routines may be stored in mass storage 414, loaded into system memory 412, and executed by processor 402, or may be provided from a computer program product stored in a tangible computer-readable storage medium (e.g., RAM, hard disk, optical / magnetic media, etc.).

[0043] The peripheral I / O controller 410 can perform functions that enable the processor 402 to communicate with peripheral input / output (I / O) devices 424, network interface 426, and local network transceiver 428 (via network interface 426) via the peripheral I / O bus. I / O device 424 can be any desired type of I / O device, such as a keyboard, display (e.g., liquid crystal display (LCD), cathode ray tube (CRT) display, etc.), navigation device (e.g., mouse, trackball, capacitive touchpad, joystick, etc.), etc. I / O device 424 can be used with modules such as 416 to receive data from transceiver 428, transmit data to components of system 100, and perform any operations related to the methods described herein. Local network transceiver 428 may include support for Wi-Fi networks, Bluetooth, infrared, cellular, or other wireless data transmission protocols. In other embodiments, an element may simultaneously support each of the various wireless protocols employed by computing device 401. For example, software-defined radio may be able to support multiple protocols via downloadable instructions. In operation, computing device 401 may be able to periodically poll visible wireless network transmitters (both cellular and local networks). This polling is possible even when normal wireless traffic is supported on computing device 401. Network interface 426 may be, for example, an Ethernet device, an asynchronous transfer mode (ATM) device, an 802.11 wireless interface device, a DSL modem, a cable modem, a cellular modem, etc., which enables system 100 to communicate with another computer system having at least the elements described with respect to system 100.

[0044] Although the memory controller 408 and the I / O controller 410 are in Figure 4 The modules 416 are depicted as individual functional blocks within chipset 406, but the functions performed by these blocks can be integrated within a single integrated circuit, or implemented using two or more separate integrated circuits. Computing environment 400 may also implement module 416 on remote computing device 430. Remote computing device 430 can communicate with computing device 401 via Ethernet link 432. In some embodiments, module 416 may be retrieved by computing device 401 from cloud computing server 434 via Internet 436. When using cloud computing server 434, the retrieved module 416 can be programmatically linked to computing device 401. Module 416 may be a collection of various software runtime sandboxes, including artificial intelligence software and document creation software, or it may be a Java® applet running in a Java® Virtual Machine (JVM) environment residing within computing device 401 or remote computing device 430. Module 416 may also be a “plugin” suitable for execution in a web browser located on computing devices 401 and 430. In some embodiments, module 416 may communicate with backend component 438 via Internet 436.

[0045] System 400 can be any combination of, but not limited to, LAN, MAN, WAN, mobile, wired or wireless networks, private networks or virtual private networks. Furthermore, although only one remote computing device 430 is shown in Figure 6 for simplification and illustrative purposes, it should be understood that any number of client computers can be supported and can communicate within system 400.

[0046] Additionally, some embodiments herein may be described as including logic or multiple components, modules, blocks, or mechanisms. Modules and method blocks may constitute software modules (e.g., code or instructions embodied on a machine-readable medium or in transmitted signals, wherein the code is executed by a processor) or hardware modules. Hardware modules may be tangible units capable of performing certain operations and may be configured or arranged in a certain manner. In example embodiments, one or more computer systems (e.g., standalone client or server computer systems) or one or more hardware modules of a computer system (e.g., a processor or a group of processors) may be configured by software (e.g., an application or an application portion) to operate as hardware modules to perform certain operations as described herein.

[0047] In various embodiments, the hardware module may be implemented mechanically or electronically. For example, the hardware module may include dedicated circuitry or logic permanently configured to perform certain operations (e.g., as a dedicated processor, such as a field-programmable gate array (FPGA) or application-specific integrated circuit (ASIC)). The hardware module may also include programmable logic or circuitry temporarily configured by software to perform certain operations (e.g., contained within a processor or other programmable processor). It should be understood that the decision to implement the hardware module mechanically in dedicated and permanently configured circuitry or in temporarily configured circuitry (e.g., software-configured) may be driven by cost and time considerations.

[0048] Therefore, the term "hardware module" can be understood to encompass tangible entities, i.e., entities physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate or perform certain operations described herein. As used herein, "hardware-implemented module" can refer to a hardware module. Consider embodiments where hardware modules are temporarily configured (e.g., programmed), and each hardware module does not need to be configured or instantiated at any given time. For example, in cases where hardware modules include processors configured using software, the processor can be configured as corresponding different hardware modules at different times. The software can accordingly configure the processor, for example, to constitute a specific hardware module at one time and different hardware modules at different times.

[0049] Hardware modules can provide and receive information from other hardware modules. Therefore, the described hardware modules can be considered communication-coupled. In the presence of multiple such hardware modules, communication can be achieved through signal transmission connecting the hardware modules (e.g., via appropriate circuitry and buses). In embodiments where multiple hardware modules are configured or instantiated at different times, such communication between hardware modules can be achieved, for example, by storing and retrieving information in a memory structure accessible to the multiple hardware modules. For example, one hardware module can perform an operation and store the output of that operation in a memory device communicationally coupled to it. Another hardware module can then access the memory device at a later time to retrieve and process the stored output. Hardware modules can also initiate communication with input or output devices and can operate on resources (e.g., collections of information).

[0050] The various operations of the example methods described herein can be performed, at least in part, by one or more processors configured, either temporarily (e.g., by software) or permanently, to perform the relevant operations. Whether temporarily or permanently configured, such processors can constitute modules of processor implementations that operate to perform one or more operations or functions. In some example embodiments, the modules referred to herein may include processor-implemented modules.

[0051] The methods or routines described herein may be implemented, at least in part, by a processor. For example, at least some operations of the methods may be performed by one or more processors or hardware modules implemented by processors. The execution of certain operations may be distributed across one or more processors, residing not only within a single machine but also deployed across multiple machines. In some example embodiments, one or more processors may reside in a single location (e.g., in a home environment, an office environment, or as a server cluster), while in other embodiments, the processors may be distributed across multiple locations.

[0052] One or more processors may also operate to support the execution of related operations in a “cloud computing” environment or as “Software as a Service” (SaaS). For example, at least some operations may be performed by a group of computers (as an example of a machine that includes processors), and these operations may be accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., application programming interfaces (APIs)).

[0053] The execution of certain operations can be distributed across one or more processors, residing not only within a single machine but also deployed across multiple machines. In some example embodiments, one or more processors or processor-implemented modules may reside in a single geographic location (e.g., within a home environment, office environment, or server cluster). In other example embodiments, one or more processors or processor-implemented modules may be distributed across multiple geographic locations.

[0054] Some portions of this specification may be presented as algorithms or symbolic representations of operations on data stored as bit or binary digital signals in machine memory (e.g., computer memory). These algorithms or symbolic representations may be examples of techniques used by those skilled in the art of data processing to convey the substance of their work to others skilled in the art. As used herein, an "algorithm" may be a self-consistent sequence of operations or similar processing that leads to a desired result. In this context, algorithms and operations may involve the physical manipulation of physical quantities. Typically, but not necessarily, such quantities may take the form of electrical, magnetic, or optical signals that can be stored, accessed, transmitted, combined, compared, or otherwise manipulated by a machine. Sometimes, primarily for general reasons, it is convenient to use terms such as "data," "content," "bit," "value," "element," "symbol," "character," "term," "number," "numerical value," etc., to refer to such signals. However, these terms may simply be convenient labels and will be associated with appropriate physical quantities.

[0055] Unless otherwise specified, discussions using terms such as “processing,” “computing,” “operation,” “determining,” “presenting,” or “displaying” in this document may refer to the actions or processes of a machine (e.g., a computer) that manipulate or transform data representing physical (e.g., electronic, magnetic, or optical) quantities within one or more memories (e.g., volatile memory, non-volatile memory, or a combination thereof), registers, or other machine components that receive, store, transmit, or display information.

[0056] As used herein, any reference to “embodiment,” “some embodiments,” or “embody” or “teaching” may mean that a particular element, feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment. The phrases “some embodiments” or “teaching” appearing throughout the specification may not necessarily refer to the same embodiment.

[0057] Some embodiments can be described using the expressions “coupled” and “connected”, as well as their derivatives. For example, the term “coupled” can be used to describe some embodiments to indicate that two or more elements are in direct physical or electrical contact. However, the term “coupled” can also mean that two or more elements are not in direct contact with each other, but still cooperate or interact with each other. Embodiments may not be limited to this context.

[0058] Furthermore, the accompanying drawings depict preferred embodiments for illustrative purposes only. Those skilled in the art will readily recognize from the following discussion that alternative embodiments of the structures and methods shown herein can be employed without departing from the principles described herein.

[0059] Upon reading this disclosure, those skilled in the art will understand alternative structural and functional designs for the systems and methods described herein based on the principles disclosed herein. Therefore, while specific embodiments and applications have been shown and described, it should be understood that the disclosed embodiments are not limited to the precise constructions and components disclosed herein. Various modifications, alterations, and variations that are obvious to those skilled in the art may be made to the arrangement, operation, and details of the systems and methods disclosed herein without departing from the spirit and scope defined in any of the appended claims.

Claims

1. A method for assessing threats to computer-based networks, comprising: Collect existing threats from multiple online sources; Collect the existing threats into a database; The data representing the existing threats in the database is formatted for easy access; Determine the rating of each of the existing threats; Assess the attractiveness of honeypots to threats; The rating of each of the existing threats is adjusted based on the attractiveness of the honeypot; Determine the threat's ability to access the honeypot; Evaluate applications on the network; The existing threats are ranked based on the applications on the network, using an adjusted rating for each of the existing threats and the ability to access the honeypot. as well as The rankings are then sent to the user.

2. The method of claim 1, further comprising: Send solutions to the network targeting the top-ranked existing threats.

3. The method according to claim 1, wherein, Online sources include at least two of the following: National vulnerability database; Develop a predictive scoring system; exploitDB; GitHub; and Social media accounts.

4. The method according to claim 1, wherein, Formatting the data representing the existing threats in the database for easy access includes representing the existing threats in numerical form.

5. The method according to claim 1, wherein, Adjusting the rating of each of the existing threats based on the attractiveness of the honeypot includes: Set up a honeypot, and Determine the number of threats that access the honeypot over a period of time.

6. The method according to claim 5, wherein, The method further includes: Determine the origin of the threat; Store the origin; The origins were compared across multiple honeypots; and The origins are ranked based on the number of honeypots visited.

7. A tangible, non-transitory computer-readable medium comprising computer-executable instructions for assessing threats to a network, the computer-executable instructions including instructions for configuring at least one hardware processor to perform the following operations: Collect existing threats from multiple online sources; Collect the existing threats into a database; The data representing the existing threats in the database is formatted for easy access; Determine the rating of each of the existing threats; Assess the attractiveness of honeypots to threats; The rating of each of the existing threats is adjusted based on the attractiveness of the honeypot; Determine the threat's ability to access the honeypot; Evaluate applications on the network; The existing threats are ranked based on the applications on the network, using an adjusted rating for each of the existing threats and the ability to access the honeypot. as well as The rankings are then sent to the user.

8. The computer-readable medium of claim 7 further includes computer-executable instructions for transmitting to the network solutions to the highest-ranking existing threats.

9. The computer-readable medium according to claim 7, wherein, Online sources include at least two of the following: National vulnerability database; Develop a predictive scoring system; exploitDB; GitHub; and Social media accounts.

10. The computer-readable medium according to claim 7, wherein, Formatting the data representing the existing threats in the database for easy access includes representing the existing threats in numerical form.

11. The computer-readable medium according to claim 7, wherein, Adjusting the threat rating based on the attractiveness of the honeypot includes: Setting up a honeypot; and Determine the number of threats that access the honeypot over a period of time.

12. The computer-readable medium of claim 7, further comprising computer-executable instructions for performing the following operations: Determine the origin of the threat; Store the origin; The origins were compared across multiple honeypots; and The origins are ranked based on the number of honeypots visited.

13. A computer system comprising a hardware processor, a memory, and input-output circuitry, the hardware processor being physically configured according to computer-executable instructions for assessing threats to a network, the computer-executable instructions including instructions for performing the following operations: Collect existing threats from multiple online sources; Collect the existing threats into a database; The data representing the existing threats in the database is formatted for easy access; Determine the rating of each of the existing threats; Assess the attractiveness of honeypots to threats; The rating of each of the existing threats is adjusted based on the attractiveness of the honeypot; Determine the threat's ability to access the honeypot; Evaluate applications on the network; The existing threats are ranked based on the applications on the network, using an adjusted rating for each of the existing threats and the ability to access the honeypot. as well as The rankings are then sent to the user.

14. The computer system of claim 13, wherein the computer-executable instructions further include instructions for transmitting to the network a solution to the highest-ranking existing threat.

15. The computer system according to claim 13, wherein, Online sources include at least two of the following: National vulnerability database; Develop a predictive scoring system; exploitDB; GitHub; and Social media accounts.

16. The computer system according to claim 13, wherein, Formatting the data representing the existing threats in the database for easy access includes representing the existing threats in numerical form.

17. The computer system according to claim 13, wherein, Adjusting the threat rating based on the attractiveness of the honeypot includes: Set up a honeypot; Determine the number of threats that access the honeypot over a period of time; Determine the origin of the threat; Store the origin; The origins were compared across multiple honeypots; and The origins are ranked based on the number of honeypots visited.