Network security device and method for detecting cybersecurity threats and risks across network devices in a network
The network security device addresses the limitations of existing scanning technologies by automatically scanning and scoring cybersecurity risks within private networks, providing detailed threat detection and resolution support.
Patent Information
- Application Number
- GB2023018533
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-11
AI Technical Summary
Existing network scanning devices, such as CyberGuardian and CyberAlarm, fail to provide detailed information about cybersecurity risks within internal private networks, leaving them vulnerable to threats and limiting the effectiveness of network auditing and scanning processes.
A network security device that automatically scans multiple network devices, generates and processes scan information to detect cybersecurity threats and risks, and generates scores and sub-scores for risk assessment, optionally integrating with a server for further analysis and resolution support.
The device and method provide comprehensive cybersecurity threat detection and risk assessment across a private network, enabling automatic scanning, score generation, and intervention plans, enhancing network security and vulnerability identification.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELD The present disclosure relates generally to cybersecurity; more specifically, the present disclosure relates to a network security device and method for detecting cybersecurity threats and risks across a plurality of network devices in a network. BACKGROUND Cybersecurity refers to the practice of protecting computer systems, networks, and digital infrastructure from theft, damage, unauthorized access, and other cyber threats. Cybersecurity in a network involves implementing measures, processes, and technologies to ensure the confidentiality, integrity, and availability of information and systems within the network. Cybersecurity threats are constantly evolving including in the network and typical attacks include Malware, Phishing, Ransomware, and the like. Network auditing and scanning is a process aimed at mitigating numerous cybersecurity risks and challenges inherent in the network. Currently, there are several network scanning devices available in the market, primarily designed for enterprise use and installed in server racks at server hosting centres. Cyber-Guardian is one of the existing network scanning devices designed to alert network managers when there are alterations within the network. Nevertheless, a limitation of the CyberGuardian lies in an inability to provide specific information regarding the risks associated with these changes. Cybersecurity services, like Cyber Alarm, scan external IP addresses to identify potential threats. However, it's important to note that these scanning services are limited to external IP addresses. Cyber-Alarm does not extend its monitoring capabilities to the internal private network, which also results in potential vulnerabilities and risks. Network scanning tools, such as Network Mapper and NMAP are designed to compile lists of hosts and identify potential threats within the network. Typically utilized by Information Technology, IT professionals, often on a commissioned basis, these professionals interpret the results generated by the scanning tools. The professional's expertise allows them to discern the significance of findings and provide detailed written reports to clients. Therefore, there arises a need to address the aforementioned technical drawbacks in existing technologies in detecting cybersecurity threats and risks, and acting to resolve them automatically or with guided human intervention. SUMMARY The present disclosure seeks to provide a network security device and method for detecting cybersecurity threats and risks across a plurality of network devices in a private network. An aim of the present disclosure is to provide a solution that overcomes at least partially the limitations encountered in the prior art. According to a first aspect, there is provided a network security device that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices in the private network, wherein the network security device is configured to: automatically scan the plurality of network devices in the private network; generate and obtain scan information of the plurality of network devices; transmit the scan information to a server; process the scan information at the server, to detect the cybersecurity threats and risks in the scan information and generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enable one or more operations to resolve the cybersecurity threats and risks. Optionally, the network security device is configured to: detect potentially unauthorized network scans in the private network; detect accesses to honeypot services operated on the network security device; and report such detected network scans and honeypot services accesses to the network owner. Optionally, the network security device is configured to: compress and encrypt the scan information; upload the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; and download and display the plurality of scores and sub-scores generated in the server. Optionally, the one or more operations comprise: determine an urgency and priority of the cybersecurity threats and risks by analyzing the scanned information, the plurality of scores and sub-scores of the detected cybersecurity threats and risks; generate an intervention report detailing the list of potential cyber security threats and risks in priority order; enable the network owner to resolve the detected cybersecurity threats and risks in the private network; and enable a cybersecurity support helpdesk operator to resolve the detected cybersecurity threats and risks in the private network. Optionally, the network security device is configured to: allow remote control operation by an authorised cybersecurity helpdesk agent to (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network. Optionally, the network security device is configured to: perform a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network. Optionally, the network security device is configured to: detect an external public IP in the private network during scanning the private network; execute an external port scan at the server to identify open ports, services and vulnerabilities. include external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans. According to a second aspect, there is provided a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server, the method comprising performing the steps of: generating and obtaining scan information of the plurality of network devices from a network security device; detecting, using the server, the cybersecurity threats and risks in the scan information by generating a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enabling one or more operations to be performed in the private network. Optionally, wherein the method comprises: converting the scan information into the plurality of scores and subscores using an algorithm of the server. The network security device and method for detecting cybersecurity threats and risks using a server illustrated in an embodiment of the present disclosure enables the network security device to automatically scan a plurality of network devices in the private network, generate and obtain scan information, transmit the scan information to the server, process the scan information at the server to detect the cybersecurity risks and threats in the scan information by generating a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions, and enable one or more operations to resolve the cybersecurity threats and risks. The network security device and the method of the present disclosure provide an improved solution in the detection and resolution of the cybersecurity threats and risks as the network security device automatically scans the private network, detects the cybersecurity threats and risks by generating the plurality of scores and sub-scores, creates a bespoke cybersecurity improvement plan, and enables one or more operations to resolve the cybersecurity threats and risks. It will be appreciated that the aforesaid present method is not merely "software for a computer, as such", or "methods of doing a mental act, as such", but has a technical effect in that the network security device and method include enabling automatic scanning, scores, and sub-scores generating, cybersecurity threats and risks detecting, and connecting with the cybersecurity support helpdesk to resolve the cybersecurity threats and risks. The present disclosure works as a combination of software and hardware for detecting and resolving the cybersecurity threats and risks in the private network. Additional aspects, advantages, features, and objects of the present disclosure are made apparent from the drawings and the detailed description of the illustrative embodiments construed in conjunction with the appended claims that follow. It will be appreciated that features of the present disclosure are susceptible to being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those in the art will understand that the drawings are not to scale. Wherever possible, like elements have been indicated by identical numbers. Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein: FIG. 1 is a flow diagram that illustrates a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIG. 2 is an illustration of a system for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIG. 3 is an exploded view of a network security device of the system in FIG. 2 in accordance with an embodiment of the present disclosure; FIG. 4 is an exploded view of a server of the system of FIG. 2 in accordance with an embodiment of the present disclosure; FIG. 5 shows an exemplary tabular view of weights to calculate a master score from the plurality of sub-scores in the server in accordance with an embodiment of the present disclosure; FIG. 6 is an interaction diagram of a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIGS. 7A and 7B are flow diagrams that illustrate a process of detecting cybersecurity threats and risks, doing analysis, generating reports, and resolving the cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; and FIG. 8 is an illustration of a computing arrangement that is used in accordance with an embodiment of the present disclosure. In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined number relates to an item identified by a line linking the non-underlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the non-underlined number is used to identify a general item at which the arrow is pointing. DETAILED DESCRIPTION OF EMBODIMENTS The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practicing the present disclosure are also possible. The present disclosure provides a network security device that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices in the private network, wherein the network security device is configured to: automatically scan the plurality of network devices in the private network; generate and obtain scan information of the plurality of network devices; transmit the scan information to a server; process the scan information at the server, to detect the cybersecurity threats and risks in the scan information and generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enable one or more operations to resolve the cybersecurity threats and risks. The present network security device provides Al-powered cybersecurity enabling automatic scanning of the private network and generating the plurality of scores and sub-scores for cybersecurity threats and risks at the server. The present server providing the plurality of scores and subscores can be used to purchase cyber insurance and to validate that the private network is maintained and secured against cybersecurity threats and risks. The network security device may be a physical device or an application running on a user device. Optionally, the user device is at least one of a mobile phone, a smartwatch, a router, a switch, a firewall, a modem, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, smartphone, or a server. The network security device can be installed in the private network. The private network may be an Internet Protocol (IP network), managed by a network router or modem or firewall or network switch. Optionally, the private network can be an internal network or an external network. In an embodiment, the network security device is connected to the private network through a wired network or a wireless network. In another embodiment, the network security device is connected to the private network through an ethernet cable. In yet another embodiment, the network security device is connected to the private network through a Bluetooth module. Optionally, the application running on the user device configures the wireless network connection of the device if required. The plurality of network devices is connected to the private network through a wired network or a wireless network. The plurality of network devices connected in the private network may be at least one of a mobile phone, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, loT device, smart home device, or a smartphone. The network security device scans the private network searching for hosts to detect anomalies in the plurality of network devices and configurations of the plurality of network devices, obtains the scan information comprising a host list with host information and any detected anomalies, and reports the scanned information to the server through an internet connection. The anomalies may be abnormal network activity and configurations in the private network. The network security device may collect (i) an IP address of the plurality of network devices, (ii) information relating to open ports comprising User Datagram Protocol, UDP, and Transmission Control Protocol, TCP, (iii) a Media Access Control, MAC address of the plurality of network devices, (iv) a manufacturer name and details, (v) a hostname, (vi) a last seen status, (vii) a status comprising online or offline, (viii) a device type comprising a make and model of the plurality of network devices, (ix) an Operating System, OS of the plurality of network devices, when scanning the private network. In an embodiment, if the open port is configured to link with an active server, the network security device obtains a page title and page content of the active server and uploads it to the server. The active server may be a Hypertext Transfer Protocol, HTTP web server. Optionally, if the open port links to a Secure Shell, SSH, or telnet service, the network security device is configured to attempt a plurality of password combinations to identify vulnerabilities in the private network. The plurality of password combinations may be a list of default usernames and passwords. Results of the plurality of password combinations may be uploaded to the server. Optionally, the network security device enables network scans to identify an active intrusion. In an embodiment, the network security device probes the host for open ports. Optionally, the network security device is configured to: detect potentially unauthorized network scans in the private network; detect accesses to honeypot services operated on the network security device; and report such detected network scans and honeypot services accesses to an admin of the private network. In an embodiment, the network security device comprises an inbuilt scanning detection that detects any abnormal or unexpected activity comprising scanning or probing the private network, and reports to the server. Optionally, the built-in network activity detection can be a honeypot detection, which enables the network security device to detect unauthorized network activity in the private network. In an embodiment, the network security device runs honeypot services, honeypot web pages, and honeypot files or file servers including files containing honeypot Uniform Resource Locators, URLs to detect unauthorized network accesses. The plurality of scan modes comprises a rapid scan, and a deeper and longer scan to execute in the private network. In an embodiment, the network security device executes the rapid scan of hosts in the private network on a regular basis with random interval periods. Scanning the hosts in the private network with random interval periods may confuse any potential installed threats that might sleep during certain periods of the day or be active during certain foreign time zones. The plurality of scan modes may control the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection. Optionally, the network security device is configured to: detect an external public Internet Protocol, IP address in the private network during scanning the private network; execute an external port scan at the server to identify open ports, services and vulnerabilities; and include external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans Optionally, the network security device comprises a storage disk to store the scan information comprising the host list. The host list may be compressed and encrypted to report to the server. The network security device may upload the compressed and encrypted host list to the server through the internet. Optionally, the one or more operations comprise: prioritize the cyber risks and cybersecurity threats by analyzing the plurality of scores and sub-scores of the detected cybersecurity threats and risks; and enable a cybersecurity support helpdesk to resolve the detected cybersecurity threats and risks in the private network. The network security device is configured to download the plurality of scores and sub-scores from the server. In an embodiment, the network security device comprises at least one output interface to display the plurality of scores and sub-scores of the host list. The at least one output interface in the network security device may be a display screen. Optionally, the display screen is configured to display a status of the network security device, and risk of the detected cybersecurity threats and risks. The status of the network security device comprises any of network scanning status, a firmware upgrading status, configuration and authentication details of the network security device, call verification details with the cybersecurity support helpdesk, potential vulnerabilities, and potential threats. Optionally, when the hosts are detected that match pre-determined criteria running pre-determined services while scanning the private network, the network security device logs into the hosts using a database of a plurality of username and passwords. In an embodiment, the predetermined criteria comprise any of specified hubs, specified routers, specified web admin panels, specified types of hosts, and the like, and the pre-determined services comprise any of web servers, file servers, terminal login protocols, and the like. In yet another embodiment, the database of the plurality of usernames and passwords comprises default usernames and passwords and common passwords. Optionally, when the network security device logs into the hosts with any of the default passwords and common passwords, the specific hosts list will be updated and uploaded to the server. The plurality of network devices found on the private network may be shown to the user through the application running on the user device, which enables the user to confirm the validity and presence of the plurality of network devices on the private network. Optionally, the network security device comprises a button that enables an inbound call to the cybersecurity support helpdesk. In an embodiment, the display in the network security device views a name of an agent of the cybersecurity support helpdesk and a password that will be provided by the cybersecurity support helpdesk to verify the registered user. Optionally, the network security device comprises a fingerprint scanner that is configured to access configurations of the network security device. The fingerprint scanner provides enhanced user security when accessing configurations and enabling the inbound call with the cybersecurity support helpdesk. The fingerprint scanner may be positioned on a case of the network security device to provide easy access. Optionally, the network security device comprises a microphone that is configured to detect ultrasonic sounds often used to gain unauthorized access or control of voice-controlled devices or voice recognition systems in any of home or office, thereby avoiding dolphin attacks. Optionally, one or more profiling questionnaires have to be inputted when one of the plurality of network devices needs to be registered, which enables the network security device to determine a type of test to be executed on the private network. The one or more profiling questionnaires may comprise any of "Do you host online game servers", "Is this a home network, a work network, or a network used for home and home working", "Do you have a qualified network administrator", and the like, which enables the network security device to determine the cybersecurity threats and risks based on inputs of the one or more profiling questionnaires. The one or more profiling questionnaires provide a major context for an analysis of the scanning of the private network with the network security device. The present disclosure also provides a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server, the method comprising performing the steps of: generating and obtaining scan information of the plurality of network devices from a network security device; detecting, using the server, the cybersecurity threats and risks in the scan information to generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enabling one or more operations to be performed in the private network. The advantages of the present method are thus identical to those disclosed above in connection with the present network security device and the embodiments listed above in connection with the network security device apply mutatis mutandis to the method. The server receives the compressed and encrypted host list from the network security device. The server may be an Artificial Intelligence, AI server. In an embodiment, the server decrypts and decompresses the compressed and encrypted host list. The server detects the cybersecurity threats and risks and generates the plurality of scores and sub-scores in the decrypted host list based on cyber threats and cyber risk along with device configurations and vulnerabilities. The device configuration may be a pre-determined arrangement and settings of a plurality of security measures and protocols within the private network. The vulnerabilities may be flaws in the implementation of the device configurations within the private network. The server may generate a tailored report detailing the plurality of network devices and any issues detected in the private network, which enables the server to create a bespoke cybersecurity improvement plan for the user. In an embodiment, the scores and the sub-scores can be improved while the user interacts and responds to the tailored report. In yet another embodiment, a process of generating the tailored report and interaction with the user is known as an intervention program. The server may generate the plurality of scores by analyzing (i) internal network scan data, (ii) external IP address scan data, (iii) engagement of the user with tailored reports and suggestions, (iv) diversity of the plurality of network devices on the private network, (v) a quantity of the plurality of network devices on the private network, (vi) a quantity, diversity, and validity of services running on each of the plurality of network devices, (v) specific vulnerabilities identified on the plurality of network devices, (vi) any active threats detected on the private network through scan detection, honeypot service accesses, (vii) information provided by the admin of the network comprising name, skills, and certifications, and (viii) specific cyber threats and risks that intersect with the plurality of network devices or services operating with the private network. The server may generate the plurality of sub-scores by analyzing, not limited to, (i) a diversity comprising a number of unique host types on the private network, (ii) a size comprising a total number of hosts on the private network, (iii) services comprising a number of unique services or ports on the private network, (iv) potential threats comprising a count of number of non-standard or unknown ports on hosts on the private network, number of unidentified hosts from the database comprising MAC address, re-used MAC address on the private network, (v) network scan identifying active threats including a detection of a specific malware port and trigger of the honeypot service, (vi) active vulnerabilities comprising weak or default passwords identified, unprotected exposed files detected, public IP exposure of services, public IP with weak password, unprotected PI, Personal Information data found, and (vii) proactive user engagement comprising whether the user is regularly accessing the application and the network security device and services, providing information when requested, and interacting with the tailored intervention report. Optionally, each sub-score ranges from 1-100 where 100 represents least risk, and 1 represents high risk. In an embodiment, calibration data for converting measured input values into scores can be derived from aggregate measured input data and can be calculated to move output scores into ranges based on pre-determined percentile ranges. Some subscores can be straight forward % values. Optionally, each score can be weighted average based on the sub-scores utilized and range from 1-1000. In an embodiment, the specific sub-scores and weights can vary from time to time. Optionally, the server comprises an algorithm that is configured to convert the scan information into the plurality of scores and sub-scores. In an embodiment, the algorithm can be accessed using a cloud-hosted Application Program Interface, API. In yet another embodiment, the algorithm can be trained with historical data of scanned information in the private network. The server transmits the plurality of scores and subscores of the host list to the network security device. The server is configured to tabulate and report the plurality of scores and sub-scores of the detected cybersecurity threats and risks to an admin of the private network, and cybersecurity support helpdesk, and enable the cybersecurity support helpdesk to resolve the detected cybersecurity threats and risks in the private network. In an embodiment, the server tabulates and reports the host list comprising the scan information to the cybersecurity support helpdesk through a web portal. The cybersecurity support helpdesk may comprise selected Information Technology, IT professionals to resolve the cybersecurity threats and risks. Optionally, the server enables the cybersecurity support helpdesk to remotely access (i) the user device on the private network, or (ii) the network security device. The server may provide features comprising a scanning control, and remote web browser control to access the plurality of network devices within the private network. The plurality of scores and sub-scores and the host list enables determining of the safety of the private network connected with the plurality of network devices. The plurality of scores and sub-scores may be used to demonstrate cyber-hygiene and cyber security effectiveness to other parties comprising an insurance company, an investor, a company board or shareholders, a potential business acquirer, or the general public. Optionally, the plurality of scores or sub scores of the cybersecurity threats and risks of the private network can be published in a leaderboard, which enables similar companies or providers to quickly compare their cyber-hygiene and cyber security effectiveness. Optionally, data from one or more users of the plurality of network devices can be used to determine normal ground truth data for specific devices. For example, LG television include a web server port that is open, which can be learned by the server. If a new service comprising the web server port is determined on the television with the same make and model of the existing LG television, the server may indicate that the television has been compromised. Embodiments of the present disclosure substantially eliminate or at least partially address the aforementioned technical drawbacks in existing technologies in detecting cybersecurity threats and risks across the plurality of network devices in the private network. DETAILED DESCRIPTION OF THE DRAWINGS Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as "including", "comprising", "incorporating", "have", "is" used to describe and claim the present disclosure are intended to be construed in a nonexclusive manner, namely allowing for items, components, or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. FIG. 1 is a flow diagram that illustrates a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure. At a step 102, the plurality of network devices in the private network is automatically scanned using a network security device. At a step 104, scan information of the plurality of network devices is generated and obtained in the network security device. At a step 106, the scan information is transmitted to a server. At a step 108, the cybersecurity threats and risks are detected in the scan information and a plurality of scores and sub-scores are generated based on cyber risks and potential or active cyber intrusions using the server. At a step 110, one or more operations are enabled to resolve the cybersecurity threats and risks. FIG. 2 is an illustration of a system 200 for detecting cybersecurity threats and risks across a plurality of network devices 204A-N in a private network 202 in accordance with an embodiment of the present disclosure. The system 200 comprises the private network 202, the plurality of network devices 204A-N, a network security device 206, a server 208, a cybersecurity support helpdesk 210, and an internet 212. The private network 202 may be a network router, firewall, broadband modem, or network switch. The plurality of network devices 204A-N, and the network security device 206 are connected to the private network 202 through a wired network or a wireless network. The private network 202 is communicatively connected with the server 208 through the internet 212. The network security device 206 is configured to (i) automatically scan the plurality of network devices 204A-N, (ii) generate and obtain scan information of the plurality of network devices 204A-N (iii) compress and encrypt the scan information, and (iv) upload the encrypted scan information to the server 208. The server 208 is configured to receive the scan information from the network security device 206 and detect the cybersecurity threats and risks in the scan information and will generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. The server 208 comprises an algorithm that is configured to convert the scan information into the plurality of scores and sub-scores. The server 208 transmits the plurality of scores and sub-scores based on the plurality of network devices 204A-N to the network security device 206. The network security device 206 is configured to download and display the plurality of scores and sub-scores generated in the server 208. The network security device 206 is configured to enable one or more operations to resolve the cybersecurity threats and risks. The one or more operations comprise any of (i) determine a prioritized list of cyber risks and cybersecurity threats by analyzing the plurality of scores and sub-scores of the detected cyber threats and risks, and (ii) enable the cybersecurity support helpdesk 210 to resolve the detected cybersecurity threats and risks in the private network 202. The server 208 is configured to tabulate and report the plurality of scores and sub-scores of the detected cybersecurity threats and risks to the cybersecurity support helpdesk 210. The server 208 enables the cybersecurity support helpdesk 210 to resolve the detected cybersecurity threats and risks in the private network 202. FIG. 3 is an exploded view of the network security device 206 of the system 200 in FIG. 2 in accordance with an embodiment of the present disclosure. The exploded view of the network security device 206 includes a screen 302, one or more buttons 304A-N, an operating system and firmware 306, a Central Processing Unit, CPU 308, a Random-Access Memory, RAM 310, an Internet Protocol, IP networking module 312, a Bluetooth module 314, and a microphone 316. The screen 302 is a display screen that is configured to display a status of the network security device 206. The screen 302 may display a scanning status of the network security device 206. The one or more buttons 304A-N enable a user to control the network security device 206 and switch screen modes to display the specific details in the screen 302. In an embodiment, the one or more buttons 304A-N trigger an inbound call with the cybersecurity support helpdesk 210. The operating system and firmware 306 is configured to control the network security device 206 and facilitate scanning and sensing of the private network 202, and display updates on the screen 302. The CPU 308 is configured to execute a code to control the network security device 206. The Random-Access Memory, RAM 310 is a temporary memory used to store the scan information. The IP networking module 312 enables the network security device 206 to connect to the private network 202 through a wired network comprising an ethernet, or a wireless network. The Bluetooth module 314 enables the users to manage the network security device 206 remotely with a user device. The user device may comprise any of a mobile phone, smart watch, a router, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, smartphone, or a server. The microphone 316 is configured to detect ultrasonic sounds often used to gain unauthorized access or control of voice-controlled devices or voice recognition systems in any of home or office, thereby avoiding dolphin attacks. The network security device 206 further comprises a network scanning module that enables automatic scanning of the plurality of network devices 204A-N in the private network 202. The network security device 206 further comprises a scan detection module that detects unauthorized network scans in the private network 202. The network security device 206 further comprises a multi-tiered and random time offset scanning module that is configured to execute a plurality of scan modes in the private network 202. The plurality of scan modes may comprise a rapid scan, and a deeper more detailed longer scan. The network security device 206 further comprises a password scanning module that logs into hosts in the private network 202 using a database of a plurality of passwords comprising default usernames and passwords and common passwords. The network security device 206 further comprises a fingerprint scanner that is configured to access configurations of the network security device 206 and enable the inbound call with the cybersecurity support helpdesk 210. FIG. 4 is an exploded view of the server 208 of the system 200 of FIG. 2 in accordance with an embodiment of the present disclosure. The exploded view of the server 108 includes a webserver and website module 402, a score algorithm module 404, a data storage 406, a cybersecurity support portal 408, a device identification Artificial Intelligence, AI model 410, a device services prediction AI model 412, and an analysis and report generation AI module 414. The webserver and website module 402 is primary web and Application Program Interfaces, APIs for exposing services to the world. The score algorithm module 404 is configured to convert the scan information from the network security device 206 and other collected data into the plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. The data storage 406 is configured to store user data, historic scan data, metadata and reports. The cybersecurity support portal 408 is the API and web portal that enables the cybersecurity support helpdesk 210 to contact the users. In an embodiment, the cybersecurity support portal 408 enables the cybersecurity support helpdesk 210 to view the cybersecurity threats and risks detected in the score algorithm module 404 and resolve the cybersecurity threats and risks. The device identification AI model 410 is a Machine Learning, ML model to predict a network device from the plurality of network devices 204A-N based on the network data collected individually and aggregation of all the plurality of network devices 204A-N. Optionally, the device identification AI model 410 is an Artificial Neural Network (ANN) but not limited to. In this regard, an Artificial Neural Network (ANN) is a machine learning model inspired by the human brain's neural structure as well known in the art. The device services prediction AI model 412 is a ML model that predicts ports or services running on the plurality of network devices 204A-N based on a determined device identification ID. Optionally, the device services prediction AI model 412 is an Artificial Neural Network (ANN) but not limited to. The analysis and report generation AI module 414 is a large language model trained with cybersecurity database comprising cybersecurity knowledge. The analysis and report generation AI module 414 comprises generation of an intervention program. The analysis and report generation AI module 414 is configured to generate factual reports based on the scan information and identify specific vulnerabilities and priorities to create a bespoke intervention program for the user. FIG. 5 shows an exemplary tabular view of weights to calculate a master score from the plurality of sub-scores in the server 208 accordance with an embodiment of the present disclosure. The server 208 is configured to calculate the plurality of scores and sub-scores with a sub-score factor comprising a diversity, a size, services, potential threats, active threats, active vulnerabilities, and proactive user engagement with the interventions. In this embodiment, to calculate the master score of 100%, weights of the sub-scores comprising the diversity is 5%, the size is 10%, the services are 10%, the potential threats are 20%, the active threats are 30%, the active vulnerabilities are 20%, and the proactive user engagement is 5%. The sub-score factors and % weights may vary from time to time. FIG. 6 is an interaction diagram of a method for detecting cybersecurity threats and risks across the plurality of network devices 204A-N in the private network 202 in accordance with an embodiment of the present disclosure. At a step 602, the network security device 206 automatically scans the plurality of network devices 204A-N connected in the private network 202. At a step 604, the network security device 206 generates, and receives the scan information of the plurality of network devices 204A-N connected in the private network 202 At a step 606, the network security device 206 transmits the scan information to the server 208. At a step 608, the server 208 is configured to detect the cybersecurity threats and risks in the scan information and generates the plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. At a step 610, the server 208 transmits the generated plurality of scores and sub-scores to the network security device 206. At a step 612, the server 208 analyzes, tabulates and reports the plurality of scores and sub-scores of the detected cybersecurity threats and risks to the cybersecurity support helpdesk 210. At a step 614, the cybersecurity support helpdesk 210 initiates the inbound call to the network security device 206 and resolves the detected cybersecurity threats or risks in the private network 202. FIGS. 7A and 7B are flow diagrams that illustrates a process of detecting cybersecurity threats and risks, doing analysis, generating reports, and resolving the cybersecurity threats and risks across the plurality of network devices 204A-N in the private network 202 in accordance with an embodiment of the present disclosure. At a step 702, the private network 202 is scanned with the network security device 206. The network security device 206 scans the private network 202 every 24 hours. In an embodiment, scanning includes a network host scan and a host port scan. The scan information obtained in the network security device 206 is uploaded to the server 208 for analysis. At a step 704, device identification information is obtained by identifying the plurality of network devices 204A-N in the server 208. The server 208 identifies each of the plurality of network devices 204A-N with available data. In an embodiment, the server 208 identifies the make and model, and operating system including versions of the plurality of network devices 204A-N. At a step 706, open ports and services are predicted and compared with the device identification information in the server 208. The server 208 predicts which ports and services should be open by using the the device identification information, and compares with the ports and services discovered. In an embodiment, the server 208 identifies exceptions in the discovered ports and services. At a step 708, the plurality of scores and sub-scores are calculated based on the cyber risks and potential or active cyber intrusions in the server 208. The server 208 may also perform network scan sensing and honeypot service access detection for calculating the plurality of sub-scores and generating the plurality of scores with the plurality of sub-scores. The plurality of scores and sub-scored may enable calibration of the server 208 for detecting the cybersecurity threats and risks. At a step 710, a report, and intervention program actions are generated and transmitted to the network security device 206 or a user device from the server 208. The report may be a written report describing the scanned private network. The intervention program actions are generated by identifying and prioritizing necessary actions to increase the plurality of scores and sub-scores. The server 208 transmits the report to the user using PDF, HTML or interactive reports and to the application running on the user device, which enables the server 208 to measure interactions with the suggested actions. At a step 712, the interactions and actions of the user are measured. The server 208 is configured to measure the interactions with proposed interventions using the application, web portal, or email. In an embodiment, any direct corrections to configurations of the network devices 206 can be measured during the next scan. In yet another embodiment, the server 208 enables the interactions to update the plurality of scores and sub-scores. At a step 714, the cybersecurity support helpdesk 210 can be connected using the server 208 to resolve the cybersecurity threats and risks. The cybersecurity support helpdesk 210 may access the latest scan data and reports and control the user device remotely to perform additional scans, or remote control a web browser. In an embodiment, the user controls and allows third-party access. The screen 302 of the network security device 206 may act as a security mechanism that allows the cybersecurity support helpdesk 210 to provide a secure password to the user and vice versa. At a step 716, the cybersecurity threats and risks are resolved, or the cyber risk is reduced. The user remedies the cybersecurity threats and risks by (a) responding to the intervention messages and reports, for example, setting a password where a default password is detected, (b) addressing an issue with the help of the cybersecurity support helpdesk 210, for example, finding an unauthorized device on the private network 202, or (c) answering questions to enable the server 208 learn more about the plurality of network devices 204A-N, for example, answering questions about the plurality of network devices 204A-N identify make and model information, to revise the risk or threat analysis. The cybersecurity threats and risks may be resolved by the admin of the private network 202. For example, if an unidentified device is identified in the private network 202, the network security device 206 reports the scan information about the unidentified device to the admin, and confirms whether the unidentified device is legitimate with an input of the admin. If the unidentified device is not legitimate, the admin may provide instructions to remove. When the cybersecurity threats and risks occur, (i) the network security device 206 automatically fixes the issue, (ii) the admin of the network 202 fixes the issues with help from the cybersecurity support helpdesk, or (iii) an agent from the cybersecurity support helpdesk fixes or helps to fix the issues. FIG. 8 is an illustration of an exemplary system 800 in which the various architectures and functionalities of the various previous embodiments may be implemented. As shown, the system 800 includes at least one processor 804 that is connected to a bus 802, wherein the system 800 may be implemented using any suitable protocol, such as PCI (Peripheral Component Interconnect), PCI-Express, AGP (Accelerated Graphics Port), HyperTransport, or any other bus or point-to-point communication protocol (s). The system 800 also includes a memory 806. Control logic (software) and data are stored in the memory 806 which may take the form of random-access memory (RAM). In the present description, a single semiconductor platform may refer to a sole unitary semiconductor-based integrated circuit or chip. It should be noted that the term single semiconductor platform may also refer to multi-chip modules with increased connectivity which simulate on-chip modules with increased connectivity which simulate on-chip operation and make substantial improvements over utilizing a conventional central processing unit (CPU) and bus implementation. Of course, the various modules may also be situated separately or in various combinations of semiconductor platforms per the desires of the user. The system 800 may also include a secondary storage 810. The secondary storage 810 includes, for example, a hard disk drive and a removable storage drive, representing a floppy disk drive, SD card, a magnetic tape drive, a compact disk drive, digital versatile disk (DVD) drive, recording device, universal serial bus (USB) flash memory. The removable storage drives at least one of reads from and writes to a removable storage unit in a well-known manner. Computer programs, or computer control logic algorithms, may be stored in at least one of the memory 806 and the secondary storage 810. Such computer programs, when executed, enable the system 800 to perform various functions as described in the foregoing. The memory 806, the secondary storage 810, and any other storage are possible examples of computer-readable media. In an embodiment, the architectures and functionalities depicted in the various previous figures may be implemented in the context of the processor 804, a graphics processor coupled to a communication interface 812, an integrated circuit (not shown) that is capable of at least a portion of the capabilities of both the processor 804 and a graphics processor, a chipset (i.e., a group of integrated circuits designed to work and sold as a unit for performing related functions, etc.). Furthermore, the architectures and functionalities depicted in the various previous figures may be implemented in the context of a general computer system, a circuit board system, a single board computer, a game console system dedicated for entertainment purposes, an application-specific system. For example, the system 800 may take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, an embedded system. Furthermore, the system 800 may take the form of various other devices including, but not limited to a personal digital assistant (PDA) device, a mobile phone device, a smart phone, a smart watch, a television, etc. Additionally, although not shown, the system 800 may be coupled to a network (e.g., a telecommunications network, a local area network (LAN), a wireless network, a wide area network (WAN) such as the Internet, a peer-to-peer network, a cable network, a home automation network such as ZWave or Zigbee, or the like) for communication purposes through an I / O interface 808. It should be understood that the arrangement of components illustrated in the figures described are exemplary and that other arrangement may be possible. It should also be understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and means) may be realized, in whole or in part, by at least some of the components illustrated in the arrangements illustrated in the described figures. In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software that when included in an execution environment constitutes a machine, hardware, or a combination of software and hardware. Although the present invention and its advantages have been described in detail, it should be understood that various changes, substitutions and alterations can be made herein without departing from the spirit and scope of the invention as defined by the appended claims.
Claims
1. A network security device that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices in the private network, wherein the network security device is configured to:automatically scan the plurality of network devices in the private network;generate and obtain scan information of the plurality of network devices;transmit the scan information to a server;process the scan information at the server, to detect the cybersecurity threats and risks from the scan information, and generate a plurality of scores, sub-scores, based on cyber risks and potential or active cyber intrusions; andenable one or more operations to resolve the cybersecurity threats and risks.
2. The network security device according to claim 1, wherein the network security device is configured to:detect potentially unauthorized network scans in the private network; anddetect accesses to honeypot services operated on the network security device; andreport such detected network scans and honeypot services accesses to the network owner.
3. The network security device according to claim 1, wherein the network security device is configured to:compress and encrypt the scan information;upload the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; anddownload and display the plurality of scores and sub-scores generated in the server.
4. The network security device according to claim 1, wherein the one or more operations comprise:determine the urgency and priority of the cybersecurity threats and risks by analyzing the plurality of network scan information, scores and sub-scores of the detected cybersecurity threats and risks; andgenerate an intervention report detailing the list of potential cyber security threats and risks in priority order;enable the network owner to resolve the detected cybersecurity threats and risks in the private network; andenable a cybersecurity support helpdesk to resolve or help resolve the detected cybersecurity threats and risks in the private network.
5. The network security device according to claim 1, wherein the network security device is configured to:allow remote control operation by an authorised cybersecurity help desk agent to; (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network.
6. The network security device according to claim 1, wherein the network security device is configured to:perform a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network; andto control the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection.
7. The network security device according to claim 1, wherein the network security device is configured to:detect an external public Internet Protocol, IP address in the private network during scanning the private network;execute an external port scan at the server to identify open ports, services and vulnerabilities; andinclude external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans.
8. A method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server, the method comprising performing the steps of:generating and obtaining scan information of the plurality of network devices from a network security device;detecting, using the server, the cybersecurity threats and risks in the scan information and generating a plurality of scores, sub-scores, reports and intervention plans based on these cyber threats and cyber risks; andenabling one or more operations to be performed in the private network.
9. A method of claim 8, wherein the network security device performs the steps of:detecting potentially unauthorized network scans in the private network; anddetecting accesses to honeypot services operated on the network security device; andreporting such detected network scans and honeypot services accesses to the network owner.
10. The network security device according to claim 9, wherein the network security device further performs the steps of:compressing and encrypting the scan information;uploading the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; anddownloading and displaying the plurality of scores and sub-scores generated in the server.
11. The network security device according to the method claim 8, wherein the one of more operations comprise:determining the urgency and priority of the cybersecurity threats and risks by analyzing the plurality of network scan information, scores and sub-scores of the detected cybersecurity threats and risks; andgenerating an intervention report detailing the list of potential cyber security threats and risks in priority order;enabling the network owner to resolve the detected cybersecurity threats and risks in the private network; andenabling a cybersecurity support helpdesk to resolve or help resolve the detected cybersecurity threats and risks in the private network.
12. The network security device according to the method claim 8, wherein the network security device further performs the step of:allowing remote control operation by an authorised cybersecurity help desk agent to; (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network.
13. The network security device according to the method claim 8, wherein the network security device further performs the steps of:performing a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network; andcontrolling the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection.
14. The network security device according to the method claim 8, wherein the network security device further performs the steps of:detecting an external public Internet Protocol, IP address in the private network during scanning the private network;executing an external port scan at the server to identify open ports, services and vulnerabilities; andincluding external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans.40
Citation Information
Patent Citations
Network security threat intelligence sharing
US20190394227A1
Method and system for prioritizing and remediating security vulnerabilities based on adaptive scoring
US20210211450A1
Prioritizing network security vulnerabilities using accessibility
US8918883B1