Method and system for evaluating effect of cybersecurity measures on business processes

The system evaluates cybersecurity countermeasures' impact on business processes, providing an analytical assessment to prioritize and schedule them effectively, addressing the challenge of process-level evaluation and minimizing operational disruptions.

JP2025181656APending Publication Date: 2025-12-11HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025041426
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-31
Filing Date
2025-03-14
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Existing cybersecurity measures are evaluated at the industrial process level, neglecting their impact on business processes, leading to potential disruptions and inefficiencies in implementing countermeasures.

Method used

A system and method to evaluate cybersecurity countermeasures by assessing their impact on business processes using asset network topology, measuring asset parameters, and generating an analytical assessment report to prioritize and schedule countermeasures based on their business-level impact.

Benefits of technology

Enables informed decision-making by system administrators in implementing countermeasures that minimize disruption to business processes, ensuring effective cybersecurity without significant operational interruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025181656000001_ABST
    Figure 2025181656000001_ABST
Patent Text Reader

Abstract

To provide a method and a system for evaluating the effect of cybersecurity measures on business processes.SOLUTION: The method includes: receiving data associated with vulnerabilities from a simulation unit associated with a business process, the data including at least one countermeasure, an asset network topology, and at least one asset including a vulnerable device and a target device; defining, for at least one of the countermeasures, a plurality of asset parameters corresponding to the target device and neighboring devices; measuring, at the simulation unit, values of the plurality of asset parameters associated with the target device and neighboring devices; and assessing an aggregated impact of the corresponding countermeasure on individual tasks of the business process on the basis of the measured values of the plurality of asset parameters.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to cybersecurity, and more particularly, the present disclosure relates to methods and systems for assessing the effectiveness of cybersecurity measures on business processes. [Background technology]

[0002] The information disclosed in the Background section of this disclosure is intended merely to enhance understanding of the general background of the present invention and should not be construed as an admission or in any way representing that this information forms prior art already known to those skilled in the art.

[0003] Cybersecurity has emerged as a critical concern as organizations across various industries increasingly rely on digital technologies to execute business processes. The rapid proliferation of interconnected systems, cloud computing, and mobile devices has optimized business processes and operations by improving accuracy and reliability along with speed. However, this has also resulted in an expansion of the cybersecurity attack surface, exposing enterprise organizations to an ever-growing array of cybersecurity threats.

[0004] A business process is a predefined business goal that is achieved by a systematic, structured series of operations or tasks within an organization, each performed in a specific order (order refers to sequence of time, location, etc.). These tasks are interrelated and contribute to the overall efficiency, effectiveness, and performance of a particular business operation or function.

[0005] To combat these ever-increasing cybersecurity threats, traditional security measures such as firewalls, antivirus software, security incident and event management (SIEM) tools, and intrusion detection systems (IDS) have provided a fundamental layer of defense. These security systems detect cybersecurity threats to systems that run business processes and facilitate providing one or more countermeasures that can be implemented to mitigate the cybersecurity threat. After receiving information about a cybersecurity threat or vulnerability detection from an internal or external security system, system administrators implement one or more countermeasures to mitigate the cybersecurity threat.

[0006] Implementing a countermeasure may require powering off one or more systems that perform different tasks in a business process. For example, if a system needs to be updated to implement the countermeasure, it may have to be taken offline. This will result in an interruption to the business process while the countermeasure is implemented, resulting in losses. System administrators are therefore tasked with balancing business continuity with ensuring the security effectiveness of implementing the countermeasure.

[0007] Currently, the evaluation of countermeasures is based on the security achieved, the performance of the target system, the cost, and the effort required to deploy the countermeasure. Therefore, the security effectiveness of the countermeasure is evaluated at the industrial process level, not the industrial execution level, and therefore the business impact is not evaluated. Although there are systems in place to analyze the implementation of countermeasures on systems, there are no options for system administrators to understand the impact that the implementation of these countermeasures has on business processes. To address these challenges, there is an increasing need to evaluate the effectiveness of cybersecurity countermeasures on business processes. Summary of the Invention

[0008] Listed below are some of the objectives of the present disclosure that will be met by at least one embodiment disclosed herein.

[0009] One object of the present disclosure is to provide a system and method for evaluating countermeasures taking into account the impact that implementing the countermeasures will have on a business process.

[0010] Another object of the present disclosure is to assist system administrators in assessing the side effects of countermeasures against business key performance indicators (KPIs) and improving decision making.

[0011] Yet another object of the present disclosure is to categorize countermeasures based on business-level impact.

[0012] The present disclosure overcomes one or more shortcomings of the prior art and provides additional advantages discussed throughout this disclosure. Additional features and advantages are realized through the techniques of the present disclosure. Other embodiments and embodiments of the present disclosure are described in detail herein.

[0013] In one embodiment of the present disclosure, a method for evaluating the effectiveness of cybersecurity countermeasures on a business process is disclosed. The method includes receiving data associated with vulnerabilities from a simulation unit associated with the business process, the data including at least one countermeasure, an asset network topology, and at least one asset. The at least one asset includes a vulnerable device and a target device. The method then includes defining, for at least one of the countermeasures, a plurality of asset parameters corresponding to the target device and adjacent devices. The method further includes measuring, in the simulation unit, values ​​of the plurality of asset parameters associated with the target device and adjacent devices. The method finally includes assessing an aggregate impact of the corresponding countermeasures on individual tasks of the business process based on the measured values ​​of the plurality of asset parameters.

[0014] In one embodiment, assessing the aggregate impact of corresponding measures on individual tasks of the business process includes calculating the impact of each measure on individual tasks linked to assets in the asset network topology.

[0015] In one embodiment, the method further includes categorizing an impact of each measure on the individual tasks of the business process based on an aggregate impact of each measure on the individual tasks of the business process, and generating an analytical assessment report based on the categorization of the impact of each measure.

[0016] In yet another embodiment, the method further includes displaying a taxonomy for selecting at least one countermeasure for prioritization, scheduling, and implementation.

[0017] In one embodiment, the asset network topology includes assets and edges present in the network, where edges represent network connections between assets and between assets and tasks.

[0018] In one embodiment, the method further includes generating a test case array for each measure based on at least the asset network topology and the predefined asset capability information to measure values ​​of a plurality of asset parameters associated with the target device and the neighboring devices. The test case array further defines a plurality of asset parameters corresponding to the target device and the neighboring devices. The method further includes applying the generated test case array for each measure to a simulation unit to measure values ​​of the plurality of asset parameters associated with the test case array.

[0019] In one embodiment, to generate a test case array for each countermeasure, the method further includes identifying at least one target device and at least one neighboring device for each countermeasure based on the asset network topology, generating a test case array for each countermeasure based at least on the predefined asset capability information and the identified target and neighboring devices, and eliminating one or more duplicate test cases from the generated test case array.

[0020] In one embodiment, the method further includes receiving, from the simulation unit, a list of tasks to which the target device and neighboring devices contribute, and location-based parameters including path lengths and numbers of edges; and then determining an effect of each countermeasure on the target device and neighboring devices based on at least one of the measurements of the asset parameters, the list of tasks to which the target device and neighboring devices contribute, and the location-based parameters.

[0021] In one embodiment, the plurality of asset parameters includes at least one or more of a read time, a write time, a response time, a processing time, and a sensing time.

[0022] In one embodiment of the present disclosure, the method further includes receiving a dataset from the memory. The dataset includes a list of business processes, a domain-specific dataset, and feedback-looped simulation data. The method further includes generating an analytical model from the dataset based on one or more analytical criteria. The analytical criteria include at least physical parameters, location-based parameters, and time-based parameters.

[0023] In another embodiment, a system for evaluating the effectiveness of cybersecurity countermeasures on a business process includes a memory and one or more processors coupled to the memory. The one or more processors are configured to receive data associated with vulnerabilities from a simulation unit associated with the business process, the data including at least one countermeasure, an asset network topology, and at least one asset. The at least one asset includes a vulnerable device and a target device. The one or more processors are further configured to define, for at least one of the countermeasures, a plurality of asset parameters corresponding to the target device and adjacent devices. The one or more processors are further configured to measure, at the simulation unit, values ​​of the plurality of asset parameters associated with the target device and adjacent devices. The one or more processors are further configured to assess, based on the measured values ​​of the plurality of asset parameters, an aggregate impact of the corresponding countermeasures on individual tasks of the business process.

[0024] The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the exemplary embodiments and features described above, further embodiments and features will become apparent by reference to the drawings and the following detailed description.

[0025] The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate exemplary embodiments and, together with the description, explain the principles of the disclosure. In the drawings, the left-most digit(s) of a reference number identifies the drawing in which the reference number first appears. The same numbers are used throughout the drawings to refer to features and components. Some embodiments of systems and / or methods in accordance with embodiments of the present subject matter are described below, by way of example only, with reference to the accompanying drawings, in which: [Brief explanation of the drawings]

[0026] [Figure 1]FIG. 1 illustrates an exemplary representation of an environment for evaluating the effectiveness of cybersecurity measures on business processes, according to some embodiments of the present disclosure. [Figure 2] FIG. 2 illustrates an example asset network topology of vulnerable devices, according to some embodiments of the present disclosure. [Figure 3A] FIG. 1 illustrates an exemplary remote implementation of a system according to some embodiments of the present disclosure. [Figure 3B] FIG. 1 illustrates an exemplary centralized implementation of a system according to some embodiments of the present disclosure. [Figure 4] FIG. 1 is a block diagram illustrating a system for evaluating the effectiveness of cybersecurity measures on a business process, according to some embodiments of the present disclosure. [Figure 5] 1 is a flowchart illustrating a method for evaluating the effectiveness of cybersecurity measures on a business process, according to some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0027] Those skilled in the art should appreciate that any block diagrams herein represent conceptual views of illustrative systems embodying principles of the inventive subject matter. Similarly, it will be appreciated that any flowcharts, flow diagrams, state transition diagrams, pseudocode, and the like, may be substantially represented on a computer-readable medium and represent various processes that may be executed by a computer or processor (whether or not such computer or processor is explicitly shown).

[0028] In this document, the word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the inventive subject matter described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments.

[0029] Throughout this specification, references to "one embodiment" or "an embodiment" or "an example" or "one example" mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of the invention. Thus, the appearances of the phrase "in one embodiment" or "in an embodiment" in various places throughout this specification do not necessarily all refer to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0030] Also, it should be noted that particular embodiments may be described as a process, which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. While a flowchart may describe operations as a sequential process, many of the operations may be performed in parallel or simultaneously. Additionally, the order of operations may be re-arranged. A process terminates when its operations are completed, but may have additional steps not included in the diagram. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination corresponds to a return of the function to the calling function or main function.

[0031] While the present disclosure is susceptible to various modifications and alternative forms, specific embodiments thereof have been shown by way of example in the drawings and are described in detail below. It is to be understood, however, that it is not intended to limit the disclosure to the particular forms disclosed, but on the contrary, the disclosure is to cover all modifications, equivalents, and alternatives falling within the scope of the present disclosure.

[0032] The terms "comprises," "comprising," "including," or any other variation thereof, are intended to cover non-exclusive inclusions, so that a setup, device, or method comprising a series of components or steps does not include only those components or steps, but may also include other components or steps not expressly listed or inherent in such setup or device or method. In other words, one or more elements of a system or apparatus preceding "comprises" does not, without further constraints, exclude other or additional elements from being present in the system or method.

[0033] In the following detailed description of embodiments of the present disclosure, reference is made to the accompanying drawings which form a part hereof, and in which is shown by way of illustration specific embodiments in which the disclosure may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the disclosure, it being understood that other embodiments may be utilized and changes may be made without departing from the scope of the disclosure. Accordingly, the following description is not to be taken in a limiting sense.

[0034] The terms "processor" or "one or more processors" in this application are to be interpreted in their broadest sense and should not be construed to limit the claims to any particular type, architecture, or configuration of processing hardware. The inventions described herein may be implemented using various types of processors or combinations thereof, depending on the particular requirements and design considerations of the application. These terms encompass a wide range of hardware implementations, including, but not limited to, central processing units (CPUs), graphics processing units (GPUs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and other types of processing devices.

[0035] The terms "cybersecurity countermeasures" and "countermeasures" have the same meaning and are used interchangeably throughout the specification.

[0036] FIG. 1 illustrates an example representation of an environment 100 for evaluating the effectiveness of cybersecurity measures on business processes, according to some embodiments of the present disclosure.

[0037] In one embodiment of the present disclosure, the environment 100 includes a vulnerability database 102, a simulation unit 104, a logic unit 106, an evaluation unit 108, a business process unit 110, a domain-specific unit 112, a feedback unit 114, and an enterprise system 116. The logic unit 106 further includes a mapper unit 1062 and a generation unit 1064. In one non-limiting embodiment, the units 102-114 may include the necessary hardware components to perform the functionality / operations discussed in the embodiments described below. In another non-limiting embodiment, the units 102-114 may include the necessary hardware components along with software components to perform the functionality / operations discussed in the embodiments described below.

[0038] In an embodiment of the present disclosure, the vulnerability database 102 may be a structured collection of information about security vulnerabilities and exposures in software, hardware, or systems. The vulnerability database 102 may serve as a centralized repository that lists and tracks various types of vulnerabilities, including any flaws, weaknesses, deficiencies, or errors that an attacker may exploit to compromise the integrity, confidentiality, or availability of a system. The vulnerability database 102 provides information consisting of vulnerable devices and information related to the types of vulnerabilities to the simulation unit 104.

[0039] The simulation unit 104 refers to a virtual representation of a real-world process, system, or network in an operational technology (OT) environment. The simulation unit 104 includes virtual representations of physical devices, machines, sensors, actuators, and other components present in the real-world OT environment. The simulation unit 104 simulates the dynamic behavior of physical processes, such as temperature changes, pressure fluctuations, and mechanical motion, and introduces simulated vulnerabilities and cybersecurity threats to assess the cybersecurity resilience of the OT system model.

[0040] In one embodiment of the present disclosure, the logic unit 106 may interact with the simulation unit 104 and the evaluation unit 108. The logic unit 106 may receive data associated with vulnerabilities as input from the simulation unit 104. The data associated with vulnerabilities may include vulnerabilities, asset network topology, and one or more countermeasures associated with at least one asset.

[0041] The logic unit 106 may be configured with a mapper unit 1062 that analyzes the links of the asset network topology received from the simulation unit 104. The mapper unit 1062 identifies neighbors of the asset. The mapper unit 1062 then maps the target and neighboring devices along with their master and slave capabilities to identify the capabilities of the target and neighboring devices.

[0042] The logic unit 106 may further comprise a test case generation unit 1064 for generating multiple test cases or test case arrays based on the capabilities of each asset and taking into account its inherent interactions with neighboring assets. The test case generation unit 1064 is configured to generate a test case array for each of the countermeasures received from the vulnerability database 102. The logic unit 106 may receive from the simulation unit 104 device / asset information regarding which countermeasures to apply, i.e., the target device, vulnerable device information, an asset network topology showing the path from the vulnerable device to the target device, and at least one hop radius device for all intermediate nodes from the vulnerable device to the target device.

[0043] The test case generation unit 1064 may access the capabilities of each asset from predefined asset capability information. For example, the capabilities of a PLC may be defined as shown in Table 1 below. Here, a master device refers to a device that sends a command, and a slave device refers to a device that executes the command. Asset parameters that need to be tested on each master-slave device may be defined by a system administrator as shown in Table 1 below.

[0044] [Table 1]

[0045] The logic unit 106 sends the test case array for each generated countermeasure to the simulation unit 104. The simulation unit 104 may execute the test case array and measure values ​​of asset parameters. The logic unit receives the asset parameter measurements and analyzes side effects for each task. The logic unit 106 analyzes side effects for each task by comparing the asset parameter measurements with respective predefined thresholds. In one non-limiting embodiment, the side effects may be analyzed by the simulation unit 104.

[0046] The logic unit 106 provides the side effects for each task as input to the evaluation unit 108. Additionally, the evaluation unit 108 receives a list of business processes from the business process unit 110, feedback loop simulation data from the feedback unit 116, and data sets from the domain specific unit 112.

[0047] The evaluation unit 108 is capable of one or more functionalities, such as processing large amounts of data to generate analytical models that illustrate industry trends. The analytical models are trained using inputs received from the business process unit 110, the feedback unit 116, and the domain-specific unit 112. The analytical models learn industry trends and a list of tasks associated with business processes from the business unit 110.

[0048] The domain-specific units 112 include asset uptime, downtime, production numbers, cycle time, and quality metrics. Data from the domain-specific units 112 can range from revenue logs and machine logs to sensors and quality control systems. Data may be curated by analyzing data captured during specific events, such as machine failures. The analytical models are further trained using feedback-looped simulation data from the feedback unit 116.

[0049] Additionally, the evaluation unit 108 may use a graphical representation or an analytical model to measure the effect on the inputs and score the inputs received from the logic unit 106. The evaluation unit 108 may also generate an assessment report based on the inputs received from the logic unit 106. After receiving the side effects for each task from the logic unit 106, the inputs are fed to the analytical model for interpretation by the evaluation unit 108. The analytical model may use supervised learning techniques, such as feedback-looped simulation data, with labeled datasets from domain-specific sources to generate decision boundaries in multi-class categorization. For example, for a given countermeasure and business process, the evaluation unit 108 may identify the greatest impact on all tasks.

[0050] Additionally, the business process unit 110 includes a list of tasks in a business process. The term "business process" refers to a given business objective that is accomplished through an organized, systematic series of tasks or operations that are performed in a particular order within an organization (where "order" refers to ordering in time, space, etc.). These tasks are interrelated and contribute to the overall efficiency, effectiveness, and completion of a particular business operation or function.

[0051] The enterprise system 116 may be able to consume and process the scoring data and assessment reports received from the assessment unit 108. For example, the enterprise system 116 may be a risk management system or a countermeasure scheduling system. The enterprise system 116 may also provide data to the feedback unit 116 to further retrain and improve the analytical model. The enterprise system 116 may prioritize, schedule, and implement countermeasures via a system or a human.

[0052] FIG. 2 illustrates an example asset network topology of vulnerable devices according to some embodiments of the present disclosure.

[0053] In one embodiment of the present disclosure, the asset network topology of vulnerable devices may be received from the simulation unit 104 or the vulnerability database 102. As shown in FIG. 2, the asset network topology consists of a vulnerable device (dv), a target device for countermeasure 1 (dt1), and a target device for countermeasure 2 (dt2). The vulnerable device is an asset where a vulnerability is detected, and the target device is an asset where a countermeasure should be implemented to mitigate the vulnerability. Furthermore, the asset network topology consists of an asset layer and a process layer. The asset layer includes all assets, and the process layer includes information flows between assets that are mapped to tasks that constitute processes.

[0054] As shown in Figure 2, the vulnerability is detected in PLC1, and therefore, PLC1 is a vulnerable device. For Countermeasure 1, the target device is PLC1, where Countermeasure 1 must be implemented to mitigate cybersecurity threats. Therefore, for Countermeasure 1, the vulnerable device and the target device are the same. Therefore, the path length for the countermeasure is zero. The path length is defined as the distance between the vulnerable device and the target device. Furthermore, as shown in Figure 2, links are used to identify neighboring nodes of each target device; therefore, for Countermeasure 1, the target device is PLC1, and the neighboring device is one of SCADA1, Sensor1, or Actuator1.

[0055] Furthermore, as shown in Figure 2, for Countermeasure 2, the target device is Human Machine Interface (HMI) 1 (dt2). The path length for the countermeasure is 2 hops (PLC1-SCADA1-HMI1). The longer the path length, the higher the probability of the countermeasure's side effects on the business process. Furthermore, as shown in Figure 2, links are used to identify the neighboring nodes of each target device; therefore, for Countermeasure 2, the target device is HMI1 and the neighboring device is SCADA1.

[0056] In one non-limiting embodiment, the simulation unit 104 (as shown in FIG. 1) may be an emulator, a digital twin, or a security digital twin (SDT) simulator.<V,E> The process layer contains a collection of nodes and edges, with two main layers represented as: the asset layer and the process layer.<V,E> The nodes "V" in the diagram represent tasks in the system, and the edges "E" represent connections between tasks within a process.<V,E> The nodes “V” in represent the physical assets / devices in the system, and the edges “E” represent the network connections between assets-to-assets and asset-to-tasks, as well as the connections between assets and tasks.

[0057] FIG. 3A illustrates an exemplary implementation of a system according to some embodiments of the present disclosure.

[0058] As shown in FIG. 3A , the evaluation unit 108 may be deployed in a centralized cloud server, and multiple logical units 106 a-106 c may be deployed in different geographic locations. The above configuration is applicable to industries where business process tasks are performed in separate geographic locations. These multiple logical units 106 a-106 c then send results from different segments to the centralized evaluation unit 108 to gain insight into the overall business impact. This reconciliation process is efficiently performed within a separate cloud-based environment, and an assessment report is sent to a system administrator 124. For example, industries may require such a setup in assembly industries such as automotive or aerospace, or resource-sharing industries such as healthcare, construction, and retail.

[0059] FIG. 3B illustrates an exemplary implementation of a system according to some embodiments of the present disclosure.

[0060] As shown in Figure 3B, a centralized architecture configuration is shown where a business operates within a centralized asset network topology, and thus it is possible to integrate both the logical unit 106 and the valuation unit 108 within the same database. This reconciliation process is efficiently performed within the centralized database environment, and valuation reports are sent to a system administrator 124. For example, industries such as energy, finance, etc. may require such a setup.

[0061] FIG. 4 illustrates a block diagram of a system 400 for assessing the effectiveness of cybersecurity measures on business processes, according to some embodiments of the present disclosure.

[0062] The system 400 may include the simulation unit 104, the memory 118, one or more processors 120, the business process unit 110, the domain-specific unit 112, the feedback unit 114, the display unit 122, and the system administrator 124, as discussed in the above embodiments. The system 400 further includes the memory 118 and one or more processors 120 connected to the memory 118. In one implementation, the system 400 may also implement a method for evaluating the effectiveness of cybersecurity measures on a business process. In another implementation, the system 400 itself implements the method for evaluating the effectiveness of cybersecurity measures on a business process by using one or more units configured within the system 400, and the one or more units may implement features as disclosed in the present disclosure.

[0063] The one or more processors 120 are configured to receive data associated with vulnerabilities from the simulation unit 104 related to the business process, the data including at least one countermeasure, an asset network topology, and at least one asset, the at least one asset including a vulnerable device and a target device.

[0064] In one embodiment of the present disclosure, a vulnerability or cybersecurity threat is detected on a vulnerable device and a countermeasure is implemented on a target device, hi another embodiment, a countermeasure may be implemented on a vulnerable device, which then becomes a target device.

[0065] Additionally, there may be one or more countermeasures available for the detected vulnerability, which may be implemented in one or more target devices to mitigate the vulnerability or cybersecurity threat. Thus, the data also includes information on the target devices on which the countermeasures should be implemented. For every detected vulnerability, one or more countermeasures may be available, and there may be a dedicated target device for every one or more countermeasures.

[0066] In one embodiment of the present disclosure, the simulation unit 104 may be an emulator, a digital twin, or<V,E> The network topology may be a security digital twin (SDT), which is a collection of nodes and edges with two main layers, namely, an asset layer and a process layer, represented as follows: The simulation unit 104 can virtually project the physical environment, allowing the system to virtually implement countermeasures and learn real-world effects. Furthermore, the asset network topology received from the simulation unit 104 includes the assets and edges present in the network. The edges represent network connections between assets and between assets and tasks.

[0067] The one or more processors 120 may be configured to define a plurality of asset parameters corresponding to the target device and neighboring devices for at least one of the countermeasures. In one embodiment of the present disclosure, the plurality of asset parameters include at least one or more of read time, write time, response time, processing time, and sensing time. However, the present disclosure is not limited to these example parameters, and any other parameters associated with an asset are well within the scope of the present disclosure. Furthermore, the asset parameters that need to be tested for each target and neighboring device may be defined by the system administrator 124. Neighboring devices are identified using information provided by the asset network topology and the links contained therein.

[0068] The one or more processors 120 may then be configured to measure values ​​of a plurality of asset parameters associated with the target device and neighboring devices in the simulation unit 104. In one embodiment of the present disclosure, the one or more processors 120 may be configured to generate a test case array for each countermeasure based on at least the asset network topology and the predefined asset capability information. The test case array further defines a plurality of asset parameters corresponding to the target device and neighboring devices. The generated test case array is then executed in the simulation unit 104 for each countermeasure to measure values ​​of the plurality of asset parameters associated with the test case array.

[0069] The predefined asset capability information includes the capabilities of each asset. The predefined asset capability information helps identify the master and slave capabilities of target and neighboring devices. For example, the capabilities of a PLC may be defined by the predefined asset capability information as a master device with a master capability such as "send commands" and a slave device with a slave capability of "execute commands." The predefined asset capability information may be defined as shown in Table 1 above. The predefined asset capability information includes identification information (ID), master device, slave device, and asset parameters defined by the system administrator 124 as mentioned in Table 1 above.

[0070] In one embodiment of the present disclosure, to generate a test case array for each countermeasure, the one or more processors 120 may be configured to identify at least one target device and at least one neighboring device for each countermeasure based on the asset network topology and generate a test case array for each countermeasure based on at least predefined asset capability information and the identified target and neighboring devices. For example, each target device (N1) and neighboring device (N2) may be identified for a countermeasure, and the one or more processors 120 may further identify a category for device N1 and store it as C1, e.g., PLC_id is the PLC category, and identify a category for device N2 and store it as category C2, e.g., SCADA1 is the Scada category. However, the present disclosure is not limited to these example categories, and any other category associated with an asset is well within the scope of the present disclosure. Furthermore, the one or more processors 120 may fetch all test cases associated with the predefined asset capability information and replace the category name with the Node ID. Furthermore, the one or more processors 120 may be configured to remove one or more duplicate test cases from the generated test case array.

[0071] In one embodiment of the present disclosure, the one or more processors 120 are further configured to receive from the simulation unit 104 a list of tasks to which the target device and neighboring devices contribute, and location-based parameters including the path length and number of edges, determine an effect of each countermeasure on the target device and neighboring devices based on at least one of the measured values ​​of the asset parameters, and compare it with respective thresholds, the list of tasks to which the target device and neighboring devices contribute, and the location-based parameters. Further, the thresholds of the asset parameters to be tested for each target and neighboring device may be defined by the system administrator 124. Further, the one or more processors 120 are configured to compare the measured values ​​of the asset parameters with thresholds defined by the system administrator 124, and filter null test case arrays by removing test case arrays whose measured values ​​of the asset parameters are lower than the thresholds.

[0072] Furthermore, the list of tasks that an asset contributes to is important information as it helps in analyzing the evaluation of countermeasures against business processes. Furthermore, location-based parameters, such as path length, which is the distance between the vulnerable device and the target device, are another important feature. The side effects of implementing a countermeasure are directly proportional to the path length, and unknown side effects on the system will increase with increasing path length.

[0073] The one or more processors 120 may then be configured to assess an aggregate impact of the corresponding countermeasures on the individual tasks of the business process based on the measurements of the multiple asset parameters. In one embodiment of the present disclosure, when assessing the aggregate impact of the corresponding countermeasures on the individual tasks of the business process, the one or more processors 120 are configured to calculate the impact of each countermeasure on the individual tasks linked to the assets in the asset network topology.

[0074] In one embodiment of the present disclosure, the one or more processors 120 are further configured to categorize the impact of each measure on individual tasks of the business process based on the aggregate impact of each measure on the individual tasks of the business process, and generate an analytical assessment report based on the categorization of each measure's impact. The assessment report further includes a system report for the enterprise system 116 and a graphic assessment report for the human system administrator 124. For example, the impact of each measure may be categorized as at least one or more of low impact, medium impact, and high impact. Furthermore, the one or more processors 120 are also configured to display the categorization for selecting at least one measure for prioritization, scheduling, and implementation. The impact categorization of the measures is included in the assessment report, as shown in Table 2 below.

[0075] [Table 2]

[0076] Referring to Table 2, CM refers to a measure, CM1 is measure 1, and CM2 is measure 2. Device refers to a target device, with PLC being the target device for CM1 and HMI being the target device for CM2. The business process includes tasks t1, t2, t3, and t4, where tasks t1 and t2 are affected by the implementation of CM1 and tasks t3 and t4 are affected by the implementation of CM2. CM1 is classified as a high-impact measure, and CM2 is classified as a low-impact measure. Device locations may be understood with reference to FIG. 2, and tasks contributing to a business process may be understood with reference to FIG. 3.

[0077] The prioritization feature assists the system administrator 124 in making informed decisions when prioritizing business activity over the implementation of countermeasures, or when prioritizing countermeasures with low business impact over high-impact countermeasures. Additionally, in the event that a high-impact countermeasure is appropriate, the system administrator 124 may schedule the implementation of the high-impact countermeasure when it will cause the least disruption to business processes and operations.

[0078] In one embodiment of the present disclosure, the one or more processors 120 are further configured to receive datasets from the memory 118. The datasets include a list of business processes, domain-specific datasets, and feedback-looped simulation data, and generate an analytical model from the datasets based on one or more analytical criteria. The analytical criteria include at least physical parameters such as temperature, location-based parameters such as path length, and time-based parameters such as latency. The domain-specific datasets may be constructed by collecting relevant information from an industrial environment. This information encompasses asset uptime, downtime, production numbers, cycle times, and quality metrics. Sources for this data may range from revenue logs and machine logs to sensors and quality control systems. The datasets are curated by analyzing data captured during specific events, such as a machine failure. However, the present disclosure is not limited to these example parameters, and any other parameters associated with an asset are well within the scope of the present disclosure.

[0079] Additionally, information is collected from a variety of sources, including operations and maintenance logs, documentation, and experimental data from test labs, as examples of measurements such as temperature and latency rise. Feedback loop simulation data refers to data received from enterprise systems 116 to fine-tune and train analytical models.

[0080] Additionally, the adverse impact on the task is assessed based on analytical criteria such as asset unavailability measured in terms of latency, downtime, etc., or environmental conditions such as high CPU temperature, increased vibration, and asset location. These may be a minimum set of classifications, and multiple analytical criteria may be used to understand the effect of the asset when compared to task performance. Task performance may be metrics such as overall equipment effectiveness (OEE), production yield, or quality performance.

[0081] In one non-limiting embodiment of the present solution, the analytical model may be modeled based on a graphical analysis of industry trends. In particular, the graphical analysis may include plots of multidimensional distributions of parameters, which may be the initial learning curve. The parameters may be physical parameters, such as temperature, location-based parameters, such as path length, and time-based parameters, such as latency. However, the present disclosure is not limited to these example parameters, and any other parameters associated with the asset are well within the scope of the present disclosure. The graphical analysis may be used to extract insights from the initial learning curve and gather additional data, such as data from the business process unit 110 and the domain-specific unit 112, to generate an improved learning curve. The analytical model then interprets the improved learning curve using a pre-designed mathematical model.

[0082] In one embodiment, a learning curve inference system may be implemented to derive a mathematical model based on the learning curve, in that the curve is transformed into the mathematical model shown in the following equation: OEE=F(t,p,m) For example, at b +c.p+dm e ……(1) where a, b, c, d, and e are coefficients or parameters that may be determined based on training data, and OEE is the overall equipment effectiveness. In one non-limiting embodiment, the parameters t, p, and m may represent time, path length, and temperature, respectively.

[0083] In one embodiment, the evaluation unit 108 may include a learning curve for every task in the business process, which may be fine-tuned based on an evolving dataset through a batch-wise retraining process via the feedback unit 114.

[0084] FIG. 5 is a flow chart illustrating a method 500 for assessing the effectiveness of cybersecurity measures on a business process, according to some embodiments of the present disclosure.

[0085] At step 502, the method 500 discloses receiving data associated with vulnerabilities from the simulation unit 104 associated with the business process, the data including at least one countermeasure, an asset network topology, and at least one asset. The at least one asset includes a vulnerable device and a target device. In one embodiment of the present disclosure, the vulnerability or cybersecurity threat is detected at the vulnerable device, and the countermeasure is implemented at the target device. In another embodiment, the countermeasure may be implemented at the vulnerable device, and the vulnerable device then becomes the target device.

[0086] Additionally, there may be one or more countermeasures available for the detected vulnerability, which may be implemented in one or more target devices to mitigate the vulnerability or cybersecurity threat. Thus, the data also includes information on the target devices on which the countermeasures should be implemented. For every detected vulnerability, one or more countermeasures may be available, and there may be a dedicated target device for every one or more countermeasures.

[0087] In one embodiment of the present disclosure, the simulation unit 104 may be an emulator, a digital twin, or<V,E> The network topology may be a security digital twin (SDT), which is a collection of nodes and edges with two main layers, namely, an asset layer and a process layer, represented as follows: The simulation unit 104 can virtually project the physical environment, allowing the system to virtually implement countermeasures and learn real-world effects. Furthermore, the asset network topology received from the simulation unit 104 includes the assets and edges present in the network. The edges represent network connections between assets and between assets and tasks.

[0088] At step 504, method 500 discloses defining a plurality of asset parameters corresponding to the target device and neighboring devices for at least one of the countermeasures. In one embodiment of the present disclosure, the plurality of asset parameters include at least one or more of read time, write time, response time, processing time, and sensing time. However, the present disclosure is not limited to these example parameters, and any other parameters associated with an asset are well within the scope of the present disclosure. Furthermore, the asset parameters that need to be tested for each target and neighboring device may be defined by the system administrator 124. Neighboring devices are identified by using information provided by the asset network topology and the links contained therein.

[0089] At step 506, the method 500 discloses measuring, in the simulation unit 104, values ​​of a plurality of asset parameters associated with the target device and the neighboring devices. In one embodiment of the present disclosure, the method 500 further includes generating a test case array for each countermeasure based on at least the asset network topology and the predefined asset capability information. The test case array further defines a plurality of asset parameters corresponding to the target device and the neighboring devices. The generated test case array is then executed in the simulation unit 104 for each countermeasure to measure values ​​of the plurality of asset parameters associated with the test case array.

[0090] The predefined asset capability information includes the capabilities of each asset. The predefined asset capability information helps identify the master and slave capabilities of target and neighboring devices. For example, the capabilities of a PLC may be defined by the predefined asset capability information as a master device configured with a master capability such as "send commands" and a slave device with a slave capability of "execute commands." The predefined asset capability information may be defined as shown in Table 1 above. The predefined asset capability information includes identification information (ID), master device, slave device, and asset parameters defined by the system administrator 124 as mentioned in Table 1 above.

[0091] In one embodiment of the present disclosure, a test case array is generated for each countermeasure by identifying at least one target device and at least one neighboring device for each countermeasure based on the asset network topology and generating a test case array for each countermeasure based on at least predefined asset capability information and the identified target and neighboring devices. For example, each target device (N1) and neighboring device (N2) are identified for the countermeasure, and method 500 further identifies the category of device N1 and stores it as C1, e.g., PLC_id is the PLC category, and identifies the category of device N2 and stores it as category C2, e.g., SCADA1 is the Scada category. However, the present disclosure is not limited to these example categories, and any other category associated with an asset is well within the scope of the present disclosure. Furthermore, method 500 fetches all test cases associated with the predefined asset capability information and replaces the category name with the Node ID. Furthermore, method 500 includes eliminating one or more duplicate test cases from the generated test case array.

[0092] In one embodiment of the present disclosure, the method 500 further includes receiving, from the simulation unit 104, a list of tasks to which the target device and neighboring devices contribute, and location-based parameters including the path length and number of edges; and determining an effect of each countermeasure on the target device and neighboring devices based on at least one of the measured values ​​of the asset parameters and comparing it to a respective threshold, the list of tasks to which the target device and neighboring devices contribute, and the location-based parameters. Further, the threshold values ​​of the asset parameters to be tested for each target and neighboring device may be defined by the system administrator 124. Further, the method 500 includes filtering null test case arrays by comparing the measured values ​​of the asset parameters with threshold values ​​defined by the system administrator 124, and removing test case arrays for which the measured values ​​of the asset parameters are lower than the threshold values.

[0093] Furthermore, the list of tasks that an asset contributes to is important information as it helps in analyzing the evaluation of countermeasures against business processes. Furthermore, location-based parameters, such as path length, which is the distance between the vulnerable device and the target device, are another important feature. The side effects of implementing a countermeasure are directly proportional to the path length, and unknown side effects on the system will increase with increasing path length.

[0094] At step 508, method 500 discloses assessing an aggregate impact of corresponding countermeasures on individual tasks of the business process based on the measurements of the multiple asset parameters. In one embodiment of the present disclosure, when assessing the aggregate impact of corresponding countermeasures on individual tasks of the business process, method 500 includes calculating the impact of each countermeasure on individual tasks linked to assets in the asset network topology.

[0095] In one embodiment of the present disclosure, the method 500 further includes categorizing the impact of each measure on individual tasks of the business process based on the aggregate impact of each measure on the individual tasks of the business process, and generating an analytical assessment report based on the categorization of each measure's impact. The assessment report further includes a system report for the enterprise system 116 and a graphic assessment report for the human system administrator 124. For example, the impact of each measure may be categorized as at least one or more of low impact, medium impact, and high impact. Furthermore, the method 500 also includes displaying a categorization for selecting at least one measure for prioritization, scheduling, and implementation. The impact categorization of the measures is included in the assessment report, as shown in Table 3 below.

[0096] [Table 3]

[0097] Referring to Table 3, CM refers to a measure, with CM1 being measure 1 and CM2 being measure 2. Device refers to a target device, with PLC being the target device for CM1 and SCADA being the target device for CM2. The business process includes tasks t1, t2, t3, and t4, with tasks t1 and t2 being affected by the implementation of CM1 and tasks t3 and t4 being affected by the implementation of CM2. CM1 is classified as a low-impact measure and CM2 is classified as a high-impact measure. Device locations can be understood with reference to Figure 2, and tasks contributing to the business process can be understood with reference to Figure 3.

[0098] The prioritization feature assists the system administrator 124 in making informed decisions when prioritizing business activity over the implementation of countermeasures, or when prioritizing countermeasures with low business impact over high-impact countermeasures. Additionally, in the event that a high-impact countermeasure is appropriate, the system administrator 124 may schedule the implementation of the high-impact countermeasure when it will cause the least disruption to business processes and operations.

[0099] In one embodiment of the present disclosure, the method 500 further includes receiving a dataset from the memory 118. The dataset includes a list of business processes, a domain-specific dataset, and feedback-looped simulation data, and generating an analytical model from the dataset based on one or more analytical criteria. The analytical criteria include at least physical parameters such as temperature, location-based parameters such as path length, and time-based parameters such as latency. The domain-specific dataset may be constructed by collecting relevant information from an industrial environment. This information encompasses asset uptime, downtime, production counts, cycle times, and quality metrics. Sources of this data may range from revenue logs and machine logs to sensors and quality control systems. The dataset is curated by analyzing data captured during a specific event, such as a machine failure. However, the present disclosure is not limited to these example parameters, and any other parameters associated with an asset are well within the scope of the present disclosure.

[0100] Additionally, information is collected from a variety of sources, including operations and maintenance logs, documentation, and experimental data from test labs, as examples of measurements such as temperature and latency rise. Feedback loop simulation data refers to data received from enterprise systems 116 to fine-tune and train analytical models.

[0101] Additionally, the adverse impact on the task is assessed based on analytical criteria such as asset unavailability measured in terms of latency, downtime, etc., or environmental conditions such as high CPU temperature, increased vibration, and asset location. These may be a minimum set of classifications, and multiple analytical criteria may be used to understand the effect of the asset when compared to task performance. Task performance may be metrics such as overall equipment effectiveness (OEE), production yield, or quality performance.

[0102] In one non-limiting embodiment of the present solution, the analytical model may be modeled based on a graphical analysis of industry trends. In particular, the graphical analysis may include plots of multidimensional distributions of parameters, which may be the initial learning curve. The parameters may be physical parameters, such as temperature, location-based parameters, such as path length, and time-based parameters, such as latency. However, the present disclosure is not limited to these example parameters, and any other parameters associated with the asset are well within the scope of the present disclosure. The graphical analysis may be used to extract insights from the initial learning curve and gather additional data, such as data from the business process unit 110 and the domain-specific unit 112, to generate an improved learning curve. The analytical model then interprets the improved learning curve using a pre-designed mathematical model.

[0103] In one embodiment, a learning curve inference system may be implemented to derive a mathematical model based on the learning curve, in that the curve is transformed into the mathematical model shown in the following equation: OEE=F(t,p,m) For example, at b +c.p+dm e ……(1) where a, b, c, d, and e are coefficients or parameters that may be determined based on training data, and OEE is the overall equipment effectiveness. In one non-limiting embodiment, the parameters t, p, and m may represent time, path length, and temperature, respectively.

[0104] In one embodiment, the evaluation unit 108 may include a learning curve for every task in the business process, which may be fine-tuned based on an evolving dataset through a batch-wise retraining process via the feedback unit 114.

[0105] Thus, the method 500 facilitates evaluation of the effectiveness of cybersecurity measures on business processes.

[0106] The order in which method 500 is described should not be construed as a limitation, as any number of the described method blocks can be combined in any order to implement the method. Additionally, individual blocks may be omitted from the method without departing from the scope of the subject matter described herein. Furthermore, the method can be implemented in any suitable hardware, software, firmware, or combination thereof.

[0107] The present disclosure includes many advantages over current systems employed in industry, such as providing a single-pane-of-glass view for security and system administrators to plan or schedule security actions on OT assets. Furthermore, the present disclosure provides an overview of adverse impacts on all linked assets that may accomplish a given task and form part of a business process. Furthermore, the present disclosure provides a categorical scoring of the severity of the impact on business KPIs. Additionally, the present disclosure provides integration into security action management systems, such as patch management and software update management, to automate deployments.

[0108] A description of an embodiment having several components in communication with each other does not imply that all such components are required. On the contrary, a variety of optional components are described to illustrate the wide variety of possible embodiments of the present invention.

[0109] Where a single device or article is described herein, it will be apparent that more than one device / article (whether in cooperation or not) may be used in place of the single device / article. Similarly, where more than one device / article is described herein (whether in cooperation or not), it will be apparent that a single device / article may be used in place of the more than one device / article, or that a different number of devices / articles may be used in place of the number of devices / articles shown. The functionality and / or features of a device may alternatively be embodied by one or more other devices not explicitly described as having such functionality / features. Thus, other embodiments of the present invention need not include the device itself.

[0110] Finally, the language used herein has been chosen primarily for readability and instructional purposes, and may not be chosen to delineate or limit the subject matter of the present invention.

[0111] While various embodiments have been disclosed herein, other embodiments will become apparent to those skilled in the art. The various embodiments disclosed herein are for illustrative purposes only and are not intended to be limiting, with the true scope and spirit being indicated by the detailed description.

Claims

1. 1. A method for evaluating the effectiveness of cybersecurity measures on a business process, comprising: receiving data associated with vulnerabilities from a simulation unit associated with the business process, the data including at least one countermeasure, an asset network topology, and at least one asset including a vulnerable device and a target device; defining a plurality of asset parameters corresponding to the target device and neighboring devices for the at least one countermeasure; measuring, in the simulation unit, values ​​of the plurality of asset parameters associated with the target device and the neighboring devices; assessing an aggregate impact of corresponding countermeasures on individual tasks of the business process based on the measured values ​​of the plurality of asset parameters.

2. 2. The method of claim 1, wherein assessing the aggregate impact of corresponding measures on individual tasks of the business process comprises calculating the impact of each measure on individual tasks linked to assets in the asset network topology.

3. categorizing the impact of each measure on the individual tasks of the business process based on the aggregate impact of each measure on the individual tasks of the business process; The method of claim 1 , further comprising: generating an analytical assessment report based on the classification of the impact of each countermeasure.

4. The method of claim 3 , further comprising displaying the classification for selection of at least one countermeasure for prioritization, scheduling, and implementation.

5. The method of claim 1 , wherein the asset network topology includes assets and edges present in a network, the edges representing network connections between assets and between assets and tasks.

6. measuring values ​​of the plurality of asset parameters associated with the target device and the neighboring devices; generating a test case array for each countermeasure based on at least the asset network topology and predefined asset capability information, the test case array further defining a plurality of asset parameters corresponding to the target device and neighboring devices; and applying the test case array generated for each countermeasure to the simulation unit to measure values ​​of the plurality of asset parameters associated with the test case array.

7. generating the test case array for each countermeasure, identifying at least one target device and at least one neighboring device for each countermeasure based on the asset network topology; generating the test case array for each countermeasure based on at least the predefined asset capability information and the identified target and neighboring devices; and eliminating one or more duplicate test cases from the generated test case array.

8. receiving from the simulation unit a list of tasks to which the target device and the neighboring devices contribute, and location-based parameters including path lengths and numbers of edges; 2. The method of claim 1, further comprising: determining an effect of each countermeasure on the target device and the neighboring devices based on at least one of the asset parameter measurements, the list of tasks to which the target device and the neighboring devices contribute, and the location-based parameters.

9. The method of claim 1 , wherein the plurality of asset parameters includes at least one or more of a read time, a write time, a response time, a processing time, and a sensing time.

10. receiving from a memory a dataset including a list of business processes, a domain-specific dataset, and feedback looped simulation data; 10. The method of claim 1, further comprising: generating an analytical model from the dataset based on one or more analytical criteria including at least physical parameters, location-based parameters, and time-based parameters.

11. A system for evaluating the effectiveness of cybersecurity measures on business processes, Memory and one or more processors coupled to the memory, the one or more processors: receiving data associated with vulnerabilities from a simulation unit associated with the business process, the data including at least one countermeasure, an asset network topology, and at least one asset including a vulnerable device and a target device; defining a plurality of asset parameters corresponding to the target device and neighboring devices for the at least one countermeasure; measuring, in the simulation unit, values ​​of the plurality of asset parameters associated with the target device and the neighboring devices; assessing an aggregate impact of corresponding countermeasures on individual tasks of the business process based on the measured values ​​of the plurality of asset parameters.

12. 12. The system of claim 11, wherein assessing the aggregate impact of corresponding measures on individual tasks of the business process includes calculating the impact of each measure on individual tasks linked to assets in the asset network topology.

13. the one or more processors: categorizing the impact of each measure on the individual tasks of the business process based on the aggregate impact of each measure on the individual tasks of the business process; The system of claim 11 , further configured to: generate an analytical assessment report based on the classification of the impact of each countermeasure.

14. The system of claim 13 , wherein the one or more processors are further configured to display the classification for selecting at least one countermeasure for prioritization, scheduling, and implementation.

15. The system of claim 11 , wherein the asset network topology includes assets and edges present in a network, the edges representing network connections between assets and tasks.

16. In measuring values ​​of the plurality of asset parameters associated with the target device and the neighboring devices, the one or more processors: generating a test case array for each countermeasure based on at least the asset network topology and predefined asset capability information, the test case array further defining a plurality of asset parameters corresponding to the target device and neighboring devices; and applying the test case array generated for each countermeasure to the simulation unit 104 to measure values ​​of the plurality of asset parameters associated with the test case array.

17. In generating the test case array for each countermeasure, the one or more processors: identifying at least one target device and at least one neighboring device for each countermeasure based on the asset network topology; generating the test case array for each countermeasure based on at least the predefined asset capability information and the identified target and neighboring devices; and eliminating one or more duplicate test cases from the generated array of test cases.

18. the one or more processors: receiving from the simulation unit a list of tasks to which the target device and the neighboring devices contribute, and location-based parameters including path lengths and numbers of edges; 12. The system of claim 11, further configured to: determine an effect of each countermeasure on the target device and the neighboring devices based on at least one of the asset parameter measurements, the list of tasks to which the target device and the neighboring devices contribute, and the location-based parameters.

19. The system of claim 11 , wherein the plurality of asset parameters includes at least one or more of a read time, a write time, a response time, a processing time, and a sensing time.

20. the one or more processors: receiving from a memory a dataset including a list of business processes, a domain-specific dataset, and feedback looped simulation data; 12. The system of claim 11, further configured to: generate an analytical model from the dataset based on one or more analytical criteria including at least physical parameters, location-based parameters, and time-based parameters.

Citation Information

Patent Citations

  • Assessing effectiveness of cybersecurity technologies

    WO2017116525A2