Method for estimating a risk score arising from a vulnerability in a computer asset

FR3166718A1Pending Publication Date: 2026-03-27HACKUITY
2 Cites -1 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2026-03-27
Patent Text Reader

Abstract

The invention relates to a method for estimating a risk score arising from a vulnerability in an IT asset, comprising a first step (1) of estimating a criticality score, taking into account the possible attack vector. The method according to the invention is particular in that it comprises the following steps: - a second step (2) of estimating a threat score, taking into account an exploitability score determined by searching a database to see if a proof of concept for exploiting said vulnerability exists, if an exploit kit is published, or if exploitation has already occurred; - a third step (3) of estimating an impact score of said IT asset, taking into account a criticality score of said asset in terms of confidentiality, integrity, and availability; - calculation of said risk score as being proportional to the product of the criticality score, the threat score, and the impact score. Figure for the abstract: Fig 1
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Cybersecurity: reliability of a computer network

    US11483335B1

  • Vulnerability scoring based on organization-specific metrics

    US20240236137A1