Method for estimating a risk score arising from a vulnerability in a computer asset
FR3166718A1Pending Publication Date: 2026-03-27HACKUITY
2 Cites -1 Cited by
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-03-27
Abstract
The invention relates to a method for estimating a risk score arising from a vulnerability in an IT asset, comprising a first step (1) of estimating a criticality score, taking into account the possible attack vector. The method according to the invention is particular in that it comprises the following steps: - a second step (2) of estimating a threat score, taking into account an exploitability score determined by searching a database to see if a proof of concept for exploiting said vulnerability exists, if an exploit kit is published, or if exploitation has already occurred; - a third step (3) of estimating an impact score of said IT asset, taking into account a criticality score of said asset in terms of confidentiality, integrity, and availability; - calculation of said risk score as being proportional to the product of the criticality score, the threat score, and the impact score. Figure for the abstract: Fig 1
Need to check novelty before this filing date? Find Prior Art
Citation Information
Patent Citations
Cybersecurity: reliability of a computer network
US11483335B1
Vulnerability scoring based on organization-specific metrics
US20240236137A1