DEVICE, SYSTEM, AND METHOD FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON DOMAIN REDIRECTIONS - Patent application

JP2025507698A5Pending Publication Date: 2026-03-03BLUEVOYANT LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-02-20
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Existing methods struggle to accurately and efficiently identify cyber assets and generate cyber risk mitigation measures, particularly due to the complexity and scale of domain identification and the incompleteness of registration information.

Method used

The method involves selecting an entity for evaluation, identifying seed domains, fetching candidate domains to determine routing information, classifying associated domains, and generating an entity asset database to inform cyber risk mitigation measures.

Benefits of technology

This approach enables the accurate identification of cyber assets and the generation of effective cyber risk mitigation measures, reducing the resource intensity and improving the accuracy of cyber asset identification and risk management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for identifying cyber assets and performing cyber risk mitigation actions based on domain redirection is disclosed, the method includes selecting an entity for evaluation, identifying one or more seed domains of the entity, identifying candidate domains based on at least one of public data sources, proprietary data sources, or a combination thereof, fetching the candidate domains and determining routing information for each of the candidate domains, classifying each candidate domain that redirects to the one or more seed domains as an associated domain based on the routing information, where each associated domain is considered to be an asset of the entity, generating an entity asset database based on the one or more seed domains and the associated domains, and generating cyber risk mitigation actions based on the entity asset database.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application is related to U.S. Provisional Patent Application No. 63 / 313,422, filed on February 24, 2022, and entitled “DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON DOMAIN REDIRECTS,” the disclosure of which is incorporated by reference in its entirety herein.

[0002] The present disclosure relates generally to network security, and more specifically to improved devices, systems, and methods for identifying cyber assets and performing cyber risk mitigation actions based on domain redirection. Summary of the Invention

[0003] The following summary is provided to facilitate understanding of some of the innovative features unique to the aspects disclosed herein and is not intended to be a complete description, A complete understanding of the various aspects can be obtained by taking the specification, claims, and abstract in their entirety.

[0004] In various aspects, a method is disclosed for identifying cyber assets and generating cyber risk mitigation measures. In one aspect, the method includes selecting, by a processor, an entity for evaluation; identifying, by a processor, one or more seed domains of the entity; identifying candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetching, by a processor, the candidate domains and determining routing information for each of the candidate domains; classifying, by the processor, each candidate domain that redirects to the one or more seed domains as an associated domain based on the routing information, where each associated domain is considered to be an asset of the entity; generating, by the processor, an entity asset database based on the one or more seed domains and the associated domains; and generating, by the processor, a cyber risk mitigation measure based on the entity asset database.

[0005] In various aspects, a non-transitory computer-readable storage medium includes instructions executable by a processor to select an entity for evaluation; identify one or more seed domains for the entity; identify candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetch the candidate domains and determine routing information for each of the candidate domains; classify each candidate domain that redirects to the one or more seed domains based on the routing information as an associated domain that is considered to be an asset of the entity, respectively; generate an entity asset database based on the one or more seed domains and the associated domains; and generate cyber risk mitigation measures based on the entity asset database.

[0006] These and other objects, features, and characteristics of the present disclosure, as well as the method of operation of the associated structural elements, functions, combinations of parts, and economies of manufacture, will become more apparent from a consideration of the following description and appended claims, which refer to the accompanying drawings, all of which form a part of this specification, and in which like reference characters designate corresponding parts in the various views, It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the invention.

[0007] Various features of the aspects described herein are set forth with particularity in the appended claims. However, the various aspects, both as to organization and method of operation, and their advantages may be understood by reference to the following description taken in conjunction with the accompanying drawings, as follows: [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 illustrates a diagram of a system configured to identify cybersecurity assets and generate cyber risk mitigation measures for multiple entities in accordance with at least one non-limiting aspect of the present disclosure. [Diagram 2] FIG. 2 illustrates a flowchart of a method for identifying cyber assets associated with multiple entities in accordance with at least one non-limiting aspect of the present disclosure. [Diagram 3] FIG. 3 illustrates a flowchart of a process for generating cyber risk mitigation measures across multiple entities based on the cyber assets identified in FIG. 1 in accordance with at least one non-limiting aspect of the present disclosure. [Figure 4A] 4A and 4B illustrate a flowchart of a process for generating cyber risk mitigation measures based on an entity domain database in accordance with at least one non-limiting aspect of the present disclosure. [Figure 4B]4A and 4B illustrate a flowchart of a process for generating cyber risk mitigation measures based on an entity domain database in accordance with at least one non-limiting aspect of the present disclosure. [Figure 4C] FIG. 4C illustrates a flowchart of an example process execution for fetching domains, which may be executed by the process for generating cyber risk mitigation measures based on the entity domain database of FIGS. 4A and 4B in accordance with at least one non-limiting aspect of the present disclosure. [Diagram 5] FIG. 5 illustrates a flowchart of an example process for discovering known redirect domains in accordance with at least one non-limiting aspect of the present disclosure. [Figure 6] FIG. 6 illustrates a diagram of a computing system in accordance with at least one non-limiting aspect of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Corresponding reference characters indicate corresponding parts throughout the several views. The implementations described herein are illustrative of various aspects of the invention in one form only, and such implementations should not be construed as limiting the scope of the invention in any way.

[0010] The applicant of this application owns the following U.S. provisional patent applications, the disclosures of each of which are incorporated herein by reference in their entirety: -U.S. Provisional Patent Application No. 63 / 196,458, filed on June 3, 2021, entitled “DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS”; -U.S. Provisional Patent Application No. 63 / 196,991, filed on June 4, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS"; -U.S. Provisional Patent Application No. 63 / 294,570, filed on December 29, 2021, entitled "DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS"; -U.S. Provisional Patent Application No. 63 / 295,150, filed on December 30, 2021, entitled “DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS”; -U.S. Provisional Patent Application No. 63 / 302,828, filed on January 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION'S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE"; -U.S. Provisional Patent Application No. 63 / 313,422, filed on February 24, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS"; -U.S. Provisional Patent Application No. 63 / 341,264, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS," filed on May 12, 2022; -U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS"; -U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, entitled “DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM”; -International Patent Application No. PCT / US22 / 72739, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS"; -International Patent Application No. PCT / US22 / 72743, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS"; -U.S. Provisional Patent Application No. 63 / 365,819, filed on June 3, 2022, entitled "DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX"; -U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS"; -U.S. Provisional Patent Application No. 63 / 366,903, filed on June 23, 2022, entitled "DEVICES, SYSTEMS, AND METHOD FOR GENERATING AND USING A QUERYABLE INDEX IN A CYBER DATA MODEL TO ENHANCE NETWORK SECURITY"; -U.S. Provisional Patent Application No. 63 / 368,567, filed on July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY"; -U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled “AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT”; -U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES"; -International Patent Application No. PCT / US22 / 82167, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS"; -International Patent Application No. PCT / US22 / 82173, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS."

[0011] Numerous specific details are described to provide a thorough understanding of the overall structure, function, manufacture, and use of the embodiments described in this disclosure and illustrated in the accompanying drawings. Well-known operations, components, and elements have not been described in detail so as not to obscure the embodiments described herein. The reader will understand that the embodiments described and illustrated herein are non-limiting embodiments. Thus, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary. Variations and modifications may be made without departing from the scope of the claims.

[0012] Before describing in detail the various aspects of the systems and methods disclosed herein, it should be noted that the exemplary aspects are not limited in application or use to the details disclosed in the accompanying drawings and description. It should be understood that the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications, and may be practiced or carried out in various ways. Furthermore, unless otherwise indicated, the terms and expressions used herein have been selected for the purpose of describing the exemplary aspects for the convenience of the reader, and are not intended to be limiting thereof. For example, it will be understood that any reference to a particular manufacturer, software suite, application, or development platform disclosed herein is intended merely to illustrate some of the many aspects of the disclosure. This includes any reference to trademarks. It should therefore be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software updates according to any purpose of use and / or user preferences.

[0013] As used herein, the term "server" may refer to or include one or more computing devices that operate or facilitate communication and processing for multiple parties in a network environment, such as the Internet, or any public or private network. As used herein, references to a "server" or "processor" may refer to a server already mentioned, and / or a processor mentioned as performing a process or function, a different server and / or processor, and / or a combination of servers.

[0014] As used herein, the term "entity" may refer to or include a company, business-related organization, non-profit organization, government agency, charity, educational institution, or any other type of organization or individual that owns or has affiliations with a collection of cyber assets. As used herein, references to "cyber assets" may refer to computing devices, networks, hardware, software, data, information, or any other type of information technology related components, labels, or identifiers for switching, signaling, or routing, such as, for example, domains, Internet Protocol (IP) addresses, or shared and / or dynamic assets.

[0015] As used herein, the terms "domain" and "domain name" may refer to or include a character string that identifies or is otherwise associated with a network, computing device, or other resource that communicates with the Internet, such as, for example, a server, personal computer, website, or other service that communicates via the Internet. In some aspects, as used herein, "domain" and "domain name" are generally as described in Domain Names - Implementation and Specification, Network Working Group (Nov.1987), https: / / datatracker.ietf.org / doc / html / rfc1035, the disclosure of which is incorporated herein by reference.

[0016] Entities typically need to understand and manage cybersecurity risks. More specifically, businesses need to understand and manage cybersecurity risks associated with their cyber assets. For example, an entity may have an internet presence, i.e., a large number of cyber assets used for internet-related communications. One or more of these cyber assets may be configured such that the entity may be exposed to cyber threats. Cyber ​​threats may include unwanted or malicious attempts to gain access to the entity's network, data, and / or other information. Cyber ​​threats may also include malicious denial of use of a cyber asset by its appropriate owner, e.g., denial of service attacks and ransomware. Thus, to identify potential exposure to cyber threats and take action against such threats, an entity, and / or its risk assessors and auditors, need to identify its cyber assets and how they are configured.

[0017] To further improve management of cyber threats and other security risks, entities also need to identify and understand the cyber assets of other entities. This need may arise because communications between entities may lead to threat exposure, or perhaps because an entity's cybersecurity risks may cause catastrophic service outages outside the realm of the Internet, adversely affecting partner entities. For example, a first entity may use its cyber assets to communicate with another entity's cyber assets. If the other entity's cyber assets are susceptible to cyber threats, communicating with these assets may expose the first entity to risk. Thus, an entity needs to identify and understand not only its own cyber assets, but also the risks posed by the other entity's cyber assets.

[0018] However, large-scale identification of entities and their cyber assets can be a complex, time-consuming, and resource-intensive process. First, it can be difficult to distinguish entities from one another simply because they often share the same name. For example, an Internet search for the company "Island Realty" can identify businesses with that name in Surf City NJ, Isle of Palms SC, Jamestown RI, Orange Park, FL, Gross Ile MI, Grand Isle LA, and other locations around the world. Furthermore, entities often share similar names. For example, a business called "The Island Realty" in Fisher's Island FL can be mistaken for various businesses doing business under the name "Island Realty" mentioned above. Thus, there is a need for methods, systems, and devices that reliably identify entities and distinguish them from one another so that cyber assets (e.g., domain name "islandrealty.com") can be classified as belonging to a particular entity.

[0019] Furthermore, once a particular entity is identified, identifying some or all of the cyber assets owned and / or controlled by that entity can be complex and resource intensive. For example, a type of cyber asset that may be important to identify when analyzing cyber risk is a domain. Domains, along with IP addresses, are commonly used as primary identifiers of networks and other types of assets within IT systems. However, domains can be particularly difficult to identify and classify as owned or otherwise associated with an entity, in part due to the overwhelming number of domains available for investigation. As of the second quarter of 2021, Verisign reported the Internet contained at least 367,000,000 registered domains, see Verisign, 18 Domain Name Industry Brief 3, 2 (Sept. 2021), https: / / www.verisign.com / assets / domain-name-report-Q22021.pdf, the disclosure of which is incorporated herein by reference. Each of these domains may belong to a particular entity under evaluation.

[0020] Analyzing each of these domains to identify potential associations with entities is a task of scope, scale, and complexity that is practically impractical for the human mind to perform. Furthermore, domain registration information may often be incomplete, inaccurate, or purposely redacted, which can create difficulties in analyzing domains for potential associations with entities. As one example, the registration information for a particular domain may include only a name and phone number, but no other information that may be used to confirm an association with a particular entity. As another example, the name, phone number, or other information included in the registration information may include misspellings or typographical errors (e.g., "Willims Computing" [sic] instead of "Williams Computing"; "123-456-7890" instead of "123-465-7890"). Thus, security analysts tasked with identifying, analyzing, and / or managing the cyber assets of multiple entities are prone to misclassifying and / or not discovering associated domain names. Furthermore, contracting security analysts to perform this task can be costly due to the effort and complexity involved.

[0021] Misclassifying and omitting domain names during an entity investigation can be detrimental to the cybersecurity risk analysis and mitigation process. As explained above, cyber assets can be configured to be potentially exposed to cyber threats. If a particular entity's cyber assets (e.g., domains, etc.) are exposed to cyber threats but are not identified as belonging to the entity, the entity's cybersecurity assessment can be inaccurate and incomplete. Furthermore, because the exposed cyber assets are never identified, it can be difficult or impossible for the assessed entity, or other entities that potentially communicate or otherwise transact with the assessed entity, to implement actions to mitigate the potential cyber threats. For example, it may be desirable to implement a configuration change in response to determining that a cyber asset is exposed to a cyber threat. However, if the cyber asset is not identified, the configuration change may not be implemented. Thus, there is a need for improved devices, systems, and methods for reliably identifying entities that have a presence on the Internet, narrowing down millions of existing domains to a manageable set of domains that can be analyzed for potential associations with the identified entities, and generating cyber risk mitigation actions based on the analyzed domains. Such enhancements may reduce the resources required to identify cyber assets belonging to specific entities while improving accuracy and may enable automated execution of cyber risk mitigation actions.

[0022] The present disclosure presents devices, systems, and methods for reliably identifying entities present on the Internet, identifying cyber assets (e.g., domains) associated with the particular entities, and / or performing cyber risk mitigation actions based on the identified cyber assets. These devices, systems, and methods provide many technical advantages, including: (1) more accurately identifying domains associated with an entity by generating a list of candidate domains in an unconventional manner, fetching the candidate domains, determining routing information, and classifying the candidate domains as associated domains based on the routing information; (2) narrowing down millions of existing registered domains (e.g., millions of known redirecting domains) to a manageable list of known redirecting domains, and classifying the redirecting domains as associated domains by fetching routing information for the redirecting domains, thereby identifying domains associated with an entity at a scale not practically performed by a human brain; and / or (3) integrating the generation of a database including associated domains into practical applications by generating automated cyber risk mitigation actions based on the database.

[0023] Referring now to FIG. 1, a diagram of a system configured to identify cybersecurity assets and generate cyber risk mitigation actions across multiple entities is shown in accordance with at least one non-limiting aspect of the present disclosure. The system 1000 may include a cyber risk management provider server 1002 comprising a memory 1004 and a processor 1006. In various aspects, the cyber risk management provider server 1002 may comprise a computer system 9000 and various components thereof (e.g., the processor 1006 may be similar to the processor(s) 9004 and the memory 1004 may be similar to the main memory 9006), which will be described with further reference to FIG. 6. The memory 1004 may be configured to store instructions that, when executed by the processor 1006, perform various aspects of the methods 100, 200, and / or 300, as described below with respect to FIGS. 2, 3, 4A, and 4B. The cyber risk management provider server 1002 communicates with a number of entities 10101, 10102, . . . 1010 via a network 1008. n Each of the entities 10101, 10102, and the plurality of entities 1010 n may represent a tenant (e.g., a customer organization) that contracts with the cyber risk management provider for cybersecurity services and / or an entity that may be assessed by the cyber risk management provider for cyber threats. According to a non-limiting aspect of FIG. 1, the network 1008 may include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, the network 1008 may include an internal network, a local area network (LAN), WiFi, a cellular network, a near field communication (hereinafter "NFC"), etc.

[0024] With further reference to FIG. 1, each of the entities 10101, 10102, . . . a plurality of 1010 nA first entity 10101 may host and / or associate with one or more instances of one or more cyber assets 1012, 1014, 1016 (also referred to herein as clients 1012, 1014, 1016). For example, a first entity 10101 may host and / or associate with one or more instances of one or more cyber assets 10121, 10122, . . . 1012. n The second tenant 10102 may include one or more devices that execute or are otherwise associated with one or more cyber assets 10141, 10142, 10143, 10144, 10145, 10146, 10147, 10148, 10149, 10150, 10151, 10152, 10153, 10154, 10155, 10156, 10157, 10158, 10159, 10160, 10161, 10162, 10163, 10164, 10165, 10166, 10167, 10168, 10169, 101611, 101692, 101693, n and / or a third tenant 1010. n 10161, 10162, 1016 n Each of the entities 10101, 10102, . . . 1010 may include one or more devices that perform or are otherwise associated with the entities 10101, 10102, . . . 1010. n may include an intranet (i.e., a network) through which each device can communicate. As described above, each entity 10101, 10102, . . . 1010 n may represent a tenant (e.g., a customer), such as an organization, that contracts with the cyber risk management provider for security services. Thus, the cyber risk management provider server 1002 may communicate with one or more of the entities, 10101, 10102, and 10103, of the plurality of entities. n , and thus may be responsible for monitoring and / or managing the entity's cyber assets (e.g., 1012, 1014, 1016) to mitigate cybersecurity threats.

[0025] However, as previously discussed, identifying cyber assets (e.g., 1012, 1014, 1016) of multiple entities (e.g., 10101, 10102, ... 1010) by a cyber risk management provider (e.g., using a cyber risk management provider server 1002) can be a complex and resource-intensive process. Furthermore, misclassifying and omitting cyber assets of certain entities can be detrimental to the cybersecurity risk mitigation process. Accordingly, the present disclosure now turns to various methods for identifying cyber assets of multiple entities and generating cyber risk mitigation measures based on the identified assets.

[0026] Referring now to FIG. 2, a flow chart of a method 100 for identifying cyber assets associated with a plurality of entities is shown in accordance with at least one non-limiting aspect of the present disclosure. The method 100 for identifying cyber assets associated with a plurality of entities may be referred to herein as a “footprinting process 100.” In various aspects, the cyber risk management provider server 1002 of FIG. 1 may store instructions in memory 1004 executable by a processor 1006 to perform the footprinting process 100. Additionally, in various aspects, any of the footprinting process 100 may be performed using algorithms employing machine learning, statistical techniques, and / or logical and expert system-based techniques, as well as searching, sorting, matching, and other data processing techniques and logic.

[0027] The footprinting process 100 may proceed by identifying 102 entity-specific characteristics to generate an entity database 108. As discussed above, it may be difficult to distinguish between entities due to ambiguity associated with identifying those characteristics (e.g., entities may trade under the same or similar names). Thus, identifying 102 entity-specific characteristics may include executing an algorithm that triggers a search and analysis of public data describing the entities 104 and / or proprietary data describing the entities 106 for identifiers that are specifically unique to a particular entity. These unique identifiers may be correlated with a particular entity to generate an entity database 108. For example, referring back to the "Island Realty" implementation example above, searching public and / or proprietary data (e.g., domain registration data) describing the entities 104, 106 may reveal that the domain "islandrealty.com" is registered to an organization in South Carolina doing business under the name "Island Realty." Thus, because the domain "islandrealty.com" is unique and may not be shared by other entities, it can be used to reliably distinguish the cyber presence and assets of "Island Realty" of South Carolina from other entities. This domain can be correlated to the island reality of South Carolina and added to the entity database 108.

[0028] Identifiers used to generate the entity database 108 may include identifiers such as, for example, internet domains, addresses, telephone numbers, business registration numbers, and tax identifiers. Public data describing entities 104 may include databases having information such as, for example, Securities and Exchange Commission (SEC) filings, Internal Rate of Return (IRS) disclosures, state-based business and / or charity registrations with the Secretary of State, legal filings, government filings, International Corporate Identifiers Basic Identifiers, public key certificates, information found on organization websites, public internet registrations, patent applications, and trademark applications. Proprietary data describing entities 106 may include databases having information such as, for example, catalogs of firmographic information about entities purchased from Dun & Bradstreet, Moody's, Standard & Poor's, Zoominfo, Open Corporates, and mailing lists and / or sales lead suppliers. Public data describing entities 104 and proprietary data describing entities 106 are often incomplete and may contain errors. Thus, in various aspects, identifying 102 entity-specific characteristics may include searching, sorting, matching, and logic-driven differentiation using machine learning and / or statistical techniques, such as expert system evaluation to uncover entities.

[0029] The footprinting process 100 may continue by identifying 110 cyber assets associated with the entity in the entity database 108. As discussed above, a given entity may be associated with several different types of cyber assets, such as, for example, domains, IP addresses, and shared and dynamic assets. However, there is no prior source or method by which multiple entities' cyber assets can be easily identified and categorized. Thus, to address this need, identifying 110 cyber assets associated with the entity in the entity database 108 may include executing an algorithm(s) that triggers a search and analysis of public data 112 describing the entity's cyber assets and / or proprietary data 114 describing the entity's cyber assets. Based on this search and analysis, a particular type of cyber asset may be identified and correlated with identifiers stored in the entity database 108 to identify and / or classify the cyber assets in an entity domain database 1161, an entity IP address database 1162, an entity shared and dynamic assets database 1163, and / or any number of other cyber asset databases 116 for storing data related to various types of cyber assets. n (collectively, cyber asset database 116). The process of identifying 110 cyber assets associated with each entity in entity database 108 may include one or more of the method 300 for identifying entity domains and generating cyber risk mitigation actions, detailed in Figures 4A and 4B. In various aspects, the algorithm(s) used to identify 110 the cyber assets may use searching, sorting, matching, and / or statistical techniques, logic-driven distinctions such as expert system evaluation, and / or machine learning.

[0030] In one aspect, the entity domain database 1161 may include multiple domain databases, each including domains classified from the entity database 108 as associated with a particular entity. In another aspect, the entity IP address database 1162 may include multiple IP address databases, each including IP addresses classified from the entity database 108 as associated with a particular entity. In another aspect, the entity shared asset database 1163 may include multiple shared asset and dynamic asset databases, each including shared asset and dynamic asset databases classified from the entity database 108 as associated with a particular entity. In yet another aspect, various other types of cyber asset databases 1166 may include multiple shared asset and dynamic asset databases, each including shared asset and dynamic asset databases classified from the entity database 108 as associated with a particular entity. n may each include multiple type-specific cyber asset databases, each type-specific cyber asset database including a particular type of cyber asset that has been classified as associated with a particular entity from the entity database 108. The cyber asset database 116 may be used as a basis for generating cyber risk mitigation measures, as discussed below with respect to FIG.

[0031] 3, a flowchart of a method 200 for generating cyber risk mitigation actions across multiple entities based on the cyber asset database 116 is shown in accordance with at least one non-limiting aspect of the present disclosure. The method 200 for generating cyber risk mitigation actions across multiple entities may be referred to herein as a “cyber risk mitigation process 200.” In various aspects, the cyber risk management provider server 1002 of FIG. 1 may store instructions in a memory 1004 executable by a processor 1006 to execute the cyber risk mitigation process 200. Additionally, in various aspects, any of the cyber risk mitigation process 200 may be executed using algorithms that employ searching, sorting, matching, and / or logic-driven distinctions such as statistical techniques, expert system evaluations, and / or machine learning.

[0032] The cyber risk mitigation process 200 can begin by investigating 202 one or more of the cyber asset databases 116 for cyber assets exposed to a cyber threat. As described above, any of the entity's cyber assets (e.g., domains, IP addresses, and shared and dynamic assets) may be configured such that the entity is exposed to a cyber threat. Thus, in the investigation 202, the cyber asset database 116 may include executing an algorithm(s) to determine which of the various cyber assets in the cyber asset database 116 may be vulnerable to a cyber threat or include configurations utilized by a cyber threat. In various aspects, investigating 202 the cyber asset database 116 for a cyber threat may include one or more steps of a method 300 for identifying entity domains for generating cyber risk mitigation actions, detailed in FIGS. 4A and 4B.

[0033] 3, in various aspects, the threat exposure of a given cyber asset configuration may be time-dependent and / or may change in response to the occurrence of various cyber events. Thus, investigating 202 the cyber asset database 116 for cyber threats may also include searching and analyzing the Internet for public information 204 related to the presence of utilization risks or the occurrence of cyber events, and / or searching and analyzing the Internet for proprietary information 206 related to the presence of utilization risks or the occurrence of cyber events to identify cyber data and events that may indicate that one or more cyber assets in the cyber asset database 116 are exposed to a cyber threat. In various aspects, the algorithm(s) for investigating 202 the cyber asset database 116 for cyber threats may use various computer-implemented analysis techniques, such as, for example, searching, sorting, matching, and / or statistical techniques, logic-driven distinctions such as by expert system evaluation, and / or machine learning.

[0034] The cyber risk mitigation process 200 may continue by generating 208 one or more cyber risk mitigation actions based on the cyber threats and risk indicators identified in 202. Generating 208 cyber risk mitigation actions may include, for example, generating a cybersecurity risk report 210 for the entity, generating a cyber asset threat, vulnerability, and risk database 212, implementing corrective actions 214, and generating alerts 216 (collectively, “cyber risk mitigation actions 210, 212, 214, 216”).

[0035] In various aspects, generating 208 the cyber risk mitigation measures may include generating an entity cybersecurity risk report 210. The entity cybersecurity risk report 210 may include one or more reports, each report including an assessment of the cyber threat exposure of one or more entities in the entity database 108 based on the investigation performed in 202. The risk report 210 may include a risk level score that the cyber risk management provider may use to determine the relative risk level of a particular entity compared to other entities in the entity database 108.

[0036] In various aspects, generating 208 the cyber risk mitigation measures may include generating a cyber asset threat, vulnerability, and risk database 212 for the entity. The cyber asset threat, vulnerability, and risk database 212 may include a log of each asset from the cyber asset database 116 that was identified in 202 as being exposed to a cyber threat, vulnerability, and / or risk. The cyber asset threat, vulnerability, and risk database 212, or a portion thereof, may be referenced by a cyber risk management provider when making asset management decisions. For example, the cyber asset threat, vulnerability, and risk database 212 may be used to identify cyber assets that require configuration updates.

[0037] In various aspects, generating (208) the cyber risk mitigation actions may include executing (214) the remediation actions. In some aspects, executing (214) the mitigation actions may include executing an algorithm that triggers an automatic configuration update to one or more of the cyber assets identified in 202 as being exposed to the cyber threat. For example, executing (214) the mitigation actions may include executing (346) a remediation configuration based on email-related cyber threats, executing (362) a remediation configuration based on host configuration-related cyber threats, and / or executing (374) a remediation configuration based on traffic-related cyber threats, as described below with reference to FIG.

[0038] In various aspects, generating (208) a cyber risk mitigation measure may include generating (216) an alert in response to identifying one or more cyber assets as exposed to a cyber threat in 202. For example, in one aspect, the alert may be sent to a security analyst at a cyber risk management provider and / or other party charged with managing the cybersecurity of a particular entity. In other aspects, the alert may be sent to a cyber asset, or a user of the cyber asset, associated with the identified cyber threat. The generated (216) alert may include instructions to the security analyst, user, or other party to take a particular action in response to the identified cyber threat. In another aspect, the alert may also take the form of an automated control instruction to a computer system providing security services, e.g., a control message to close a port may be sent to an entity's firewall upon seeing evidence of malicious activity.

[0039] Having described general implementations of devices, systems, and methods for identifying entities present on the Internet, identifying cyber assets associated with the identified entities, and generating cyber risk mitigation actions based on the identified cyber assets, the present disclosure now turns to specific implementations of those devices, systems, and methods related to identifying domains associated with the entities, and generating cyber risk mitigation actions based on the identified domains. Any of the aspects described below with respect to Figures 4A and 4B may be applied to the devices, systems, and methods described above with respect to footprint process 100 of Figure 2 and cyber risk mitigation process 200 of Figure 3.

[0040] 4A and 4B, a flowchart of a method 300 for generating cyber risk mitigation actions based on an entity domain database 340 is shown in accordance with at least one non-limiting aspect of the present disclosure. In various aspects, the cyber risk management provider server 1002 of FIG. 1 can store in memory 1004 instructions executable by a processor 1006 to perform the method 300. Furthermore, in various aspects, any of the things in the method 300 can be performed using algorithms using various computer-implemented analysis techniques, such as searching, sorting, matching, and / or statistical techniques, logic-driven identification approaches such as using expert system evaluation, and / or machine learning.

[0041] With reference to FIG. 4A, the method 300 may begin by selecting (302) an entity ("selected entity 302") for evaluation. The selected entity 302 may be an entity included in the entity database 108 of FIG. 1, for example. The method 300 may continue by identifying (304) one or more seed domains for the selected entity 302. As used herein, a seed domain may generally refer to a domain associated with the selected entity 302. In some aspects, the seed domain may be a primary domain used by the selected entity 302. For example, the seed domain may be a domain from which the entity's home page is served (e.g., bluevoyant.com, amazon.com, uspto.gov, etc.). In some aspects, the one or more seed domains identified at 304 may be a domain identified as a unique identifier at 102 of FIG. 1 and stored in the entity database 108.

[0042] 4A, the method 300 may continue by identifying 310 potential domains 312 that are deemed to be potential cyber assets of the selected entity 302. This list of potential domains 312 may be identified by searching and analyzing public data 306A, proprietary data 306B, or a combination thereof, for information suggesting that one or more of the over 367,000,000 registered domains potentially belong to or are otherwise controlled by the selected entity 302. In various aspects, the public data 306A may include databases such as, for example, Internet registration databases, Internet Domain Name System (DNS), SEC filings, other regulatory filings, public key certificates, websites, Federal Deposit Insurance Corporation, legal filings, government filings, and information found on company websites. The proprietary data 306B may include, for example, bulk DNS data that may be purchased, and / or other domain-related information that may be purchased from companies such as, for example, Domain Tools, Whois XML API, and IPinfo.

[0043] However, as explained above, the public data 306A and / or proprietary data 306B (e.g., registration information) available for a particular domain may be incomplete or inaccurate (e.g., including only a name and / or phone number, including an incorrect name, including an incorrect phone number). Thus, due to the complexities and variations associated with the public data 306A and / or proprietary data 306B, in some aspects the search and analysis of the public data 306A and / or proprietary data 306B performed when identifying 310 potential domains 312 may be performed using statistical and / or machine learning techniques. For example, statistical and / or machine learning techniques may be used to recognize a domain with the name "Willims Computing" (sic) listed in its registration information as potentially belonging to a selected entity 302 called "Williams Computing" and add this domain to the list of potential domains 312. Thus, identifying 310 potential domains 312 can effectively narrow down a list of over 367,000,000 registered domains to a more manageable list of potential domains 312 by searching and analyzing public data 306A and / or proprietary data 306B, a process performed on a scope, scale, and complexity that is practically impractical for human thought. In some aspects, the process for identifying 310 potential domains can be performed using algorithms that employ various computer-implemented analysis techniques, such as searching, sorting, matching, and / or statistical techniques, logic-driven identification approaches such as using expert system evaluation, and / or machine learning. As described in more detail below, the potential domains 312 can be fetched 314 to obtain domain routing information 316 that can be used to infer and / or confirm associations between the potential domains 312 and the selected entity 302.

[0044] 4A , in some aspects, the method 300 may include discovering (328) a redirecting domain (330) (sometimes referred to herein as a known redirecting domain 330) based on public data 326A and / or proprietary data 326B. The known redirecting domain 330 may include a domain that is known to redirect, but the final location of the redirection has not yet been determined. As described in more detail below, the known redirecting domain 330 may be fetched (314) to obtain domain routing information 316 that may be used to infer and / or confirm an association between the known redirecting domain 330 and the selected entity 302.

[0045] Discovering (328) known redirect domains 330, fetching (314) known redirect domains 330, obtaining domain routing information 316, and identifying (318) associations with selected entities 302 may enable a more comprehensive, non-routine method for identifying and classifying domains as associated with a particular entity, as compared to existing methods. For example, as described above, domain registration information and other similar data sources traditionally used to identify associations between domains and entities may be incomplete and unreliable. Thus, it may not be possible to confirm associations between domains and entities simply using registration information and other similar data sources. Thus, by relying solely on domain registration information, or other similar data sources, some domains may be unintentionally omitted from cyber asset identification analysis. As another example, it may be difficult to infer associations between domains and entities based on domain hosting information, because thousands, or even millions, of domains may be associated with a single IP address (e.g., a GoDaddy server may appear to serve millions of domains). Thus, it may not be possible to make an informed conclusion about the association of a domain with a particular entity by analyzing only the DNS-provided hosting information of that domain. However, these domains (e.g., domains with incomplete registration information, domains that share the same IP address as many other domains not associated with the entity of interest) may redirect to known domains of the entity of interest. Thus, the routing information of a domain can be used to infer the relationship between a selected entity and the domain when other search and analysis techniques may fail. Thus, it may be beneficial to analyze the routing information of domains known to redirect, even if the redirection location is unknown prior to analysis.

[0046] Various methods can be implemented to discover (328) known redirection domains 330. In one aspect, and now referring to FIGS. 4A and 5, a method for discovering (328) known redirection domains 330 may include identifying (331) potential uniform resource locators (URLs) 332 based on public data 326A and / or proprietary data 326B. In some aspects, public data 326A and proprietary data 326B may be similar to public data 306A and / or proprietary data 306B, respectively. Additionally, in some aspects, potential URLs 332 may be identified based on URLs associated with seed domain 304. For example, potential URLs 332 may be associated with seed domain 304 by means other than redirection, such as one or more keyword searches of registration data, public key certificates, DNS data, and the like. In some aspects, computers on the Internet that are primarily or exclusively responsible for performing URL redirection may be identified. The redirected domains may be discovered by determining which of the universe of over 300 million domains, by addresses reported by the DNS, are served by computers identified as performing bulk URL redirection.

[0047] The identified (331) potential URLs 332 may be fetched (334) to obtain URL routing information 336. If the URL routing information 336 indicates that one of the potential URLs 332 is associated with a domain that redirects to a different domain (the redirect domain), the redirect domain may be discovered (328) as a known redirect domain 330.

[0048] In various aspects, the URL routing information 336 may include information that may be used to identify (338) additional potential URLs. The additional potential URLs 332 may also be fetched (334). Fetching (334) the additional potential URLs 332 may reveal URL routing information 336 that indicates that one of the additional potential URLs 332 is associated with a redirect domain. Thus, the redirect domain may be discovered 328 as a known redirect domain 330.

[0049] In another aspect, the URL routing information 336 of the additional potential URLs 332 may be used to further identify (338) additional potential URLs 332. This method for discovering (328) known redirect domains 330 continues in an iterative manner to identify (338) and fetch (334) additional potential URLs 332 by looking at all identifiable URLs through recursive identification and subsequent fetching of URLs in the data returned by the server, until a calculated threshold is met or the iterative process terminates. In some aspects, the calculation threshold may be the specification of a particular number of potential URLs 332, such as, for example, 100, 10,000, 100,000, 200,000, 300,000, 400,000, 500,000, 600,000, 700,000, 800,000, 900,000, 1,000,000, 2,000,000, 3,000,000, 4,000,000, 5,000,000, 6,000,000, 7,000,000, 8,000,000, 9,000,000, 10,000,000, 100,000,000, 1,000,000,000 potential URLs 332. In other aspects, the calculation threshold may be based on reaching a calculation time threshold, such as, for example, 10, 20, 30, 40, 50, 60, 70, 80, 100, 1,000, 10,000, or 100,000 seconds of calculation time.

[0050] 4A , in some aspects, the public data 326A and / or the proprietary data 326B may include a database of domains that have already been identified as domains known to redirect, but may not provide the final redirect location. For example, the public data 326A may include data published by Commoncrawl (see, e.g., “Server Responses with HTTP Status Code Other than 200 (404s, Redirects, etc.),” available at https: / / commoncrawl.org / 2016 / 09 / robotstxt-and-404-redirect-data-sets / ). Thus, discovering 328 known redirect domains 330 may include identifying the domains based on a data source, such as Commoncrawl, or other similar database.

[0051] 4A, the method 300 may continue by fetching (314) the candidate domains 312, 330. As used herein, the term “candidate domains 312, 330” may be used to refer to only the potential domains 312, only the known redirect domains 330, or to both the potential domains 312 and the known redirect domains 330. As used herein, “fetching” may generally refer to obtaining data related to a particular cyber asset (e.g., obtaining data related to a particular domain or obtaining data related to a URL). In various aspects, the fetching (314) may be performed using software, such as, for example, a general internet browser (e.g., Chrome, Firefox, Edge, etc.), or a command line interface tool (e.g., curl, wget, etc.), or custom developed software. The data obtained by fetching (314) each of the candidate domains 312, 330 may include domain routing information 316. In some aspects, the domain routing information 316 may include signaling and routing information.

[0052] The domain routing information 316 may include many different types of information that may be used to infer an association between the candidate domains 312, 330 and the selected entity 302. In one aspect, the domain routing information 316 may include information (e.g., signaling and routing information) that indicates that one of the candidate domains 312, 330, when fetched, redirects to one or more of the seed domains identified in 304. The redirection to the seed domain may occur, for example, after a first redirection from the candidate domain 312, 330. The redirection to the seed may also occur after a chain of two or more redirects, initiated, for example, by fetching (314) the candidate domain 312, 330. For example, the candidate domain 312, 330 may be "b.com". When fetching 314 the domain "b.com," the domain routing information 316 may indicate that the candidate domain 312, 330 "b.com" ultimately redirects, after a chain of one or more redirects, to the seed domain "a.com."

[0053] The process of fetching (314) the candidate domains 312, 330 may include multiple processes (e.g., 100) that are separately provisioned and highly parallelized, occurring at a scope and scale that is beyond the ability of human thought to execute. For example, FIG. 4C illustrates a flowchart of an example execution of a process for fetching (314) the candidate domains 312, 330 that may be executed according to the method 300. According to one non-limiting aspect, each of the mains 312, 330 (e.g., known redirect domains 330 and / or potential domains 312) of FIG. 4C may be provided to a job distributor module. The job distributor module may provision (315) the candidate domains 312, 330 to one of a plurality of web page fetchers (e.g., web page fetcher 1, web page fetcher 2, . . . web page fetcher n). Each of the plurality of web page fetchers may be a web page fetcher 3171, 3172, . . . 317. n, and a corresponding one of the candidate domains 312, 330 is provisioned (315) therefor. The job distributor module and / or each of the multiple web page fetchers may be a separately provisioned resource. For example, each web page fetcher may be executed by a separate processor, or group of processors. As another example, each web page fetcher may correspond to a segmented resource provisioned by a distributed network (e.g., a pool of processors). Each of the multiple web page fetchers may be 3171, 3172, ... 317 n , 3171, 3172, . . . 3173, 3174, 3175, 3176, 3177, 3178, 3179, 3180, 3181, 3182, 3183, 3184, 3185, 3186, 3187, 3188, 3189, 3190, 3191, 3192, 3193, 3194, 3195, 3196, 3197, 3198, 3199, 3200, 3201, 3202, 3203, 3204, 3205, 3206, 3207, 3208, 3209, 3210, 3211, n can be fetched, and a corresponding one of the candidate domains 312, 330 can be provisioned 315 thereto in parallel. Thus, the process of fetching 314 the candidate domains 312, 330 may be performed at a scope and scale beyond the reach of human thought.

[0054] Further referring to FIG. 4C, 3171, 3172, . . . 317 n By fetching the candidate domains 312, 330, a fetch result is generated and the candidate domains 312, 330 may be stored in a fetch result storage 319. n , domain routing information 316 corresponding to each of the candidate domains 312 , 330 may be extracted 321 from the fetch storage 319 .

[0055] 4A , the method 300 may continue by determining (318) whether the domain routing information 316 indicates that one of the candidate domains 312, 330 is associated (e.g., owned or otherwise controlled) by the selected entity 302. If the domain routing information 316 includes information indicating that the candidate domain 312, 330 redirects to the identified seed domain 304, an association may be identified between the candidate domain 312, 330 and the selected entity 302. Based on this identified association, the candidate domain 312, 330 may be classified (320) as an associated domain and added to a list of associated domains 322. For example, if the routing information 316 includes information indicating that the candidate domain 312, 330 redirects to the seed domain "a.com" of the selected entity 302, "b.com" may be inferred to be owned or otherwise controlled by the selected entity 302. Therefore, “b.com” may be classified 320 as an associated domain and added to the list of associated domains 322 .

[0056] In various aspects, the domain routing information 316 may include information indicating that one of the candidate domains 312, 330, when fetched, redirects to one of the previously classified associated domains 322. It may be inferred that the candidate domain 312, 330 that redirects to the associated domain 322 is owned or otherwise controlled by the selected entity 302. Thus, identifying 318 an association with the selected entity 302 may include identifying that the candidate domain 312, 330 redirects to the associated domain 322. Further, the candidate domain 312, 330 may be classified 320 as an associated domain and added to the list of associated domains 322. For example, the candidate domain 312, 330 may be "c.com". When fetching 314 the domain "c.com," the domain routing information 316 may indicate that "c.com" redirects to "b.com," a domain that was previously classified as an associated domain 322. Thus, based on the routing information 316, it may be inferred that "c.com" is owned or otherwise associated with the selected entity 302.

[0057] In various aspects, the domain routing information 316 may include information indicating that one of the candidate domains 312, 330, when fetched, redirects to a subdomain of the seed domain identified in 304. It may be inferred that the candidate domain 312, 330 that redirects to a subdomain of the seed domain is owned or otherwise controlled by the selected entity 302. Thus, identifying 318 an association with the selected entity 302 may include identifying that the candidate domain 312, 330 redirects to a subdomain of the seed domain. Further, the candidate domain 312, 330 may be classified 320 as an associated domain and added to a list of associated domains 322. For example, the candidate domain 312, 330 may be "b.com". When fetching 314 the domain "b.com," domain routing information 316 may indicate that "b.com" redirects to "shop.a.com," which is a subdomain of the seed domain "a.com" identified in 304. Thus, based on the routing information 316, it may be inferred that "b.com" is owned or otherwise associated with the selected entity 302.

[0058] In various aspects, the domain routing information 316 may include information indicating that one of the candidate domains 312, 330, when fetched, redirects to a sub-domain of the previously classified associated domain 322. It may be inferred that the candidate domain 312, 330 that redirects to a sub-domain of the associated domain 322 is owned or otherwise controlled by the selected entity 302. Thus, identifying 318 an association with the selected entity 302 may include identifying that the candidate domain 312, 330 redirects to a sub-domain of the associated domain 322. Further, the candidate domain 312, 330 may be classified 320 as a related domain and added to the list of associated domains 322. For example, the candidate domain 312, 330 may be "c.com". When fetching 314 the domain “c.com,” the domain routing information 316 may indicate that “c.com” redirects to “shop.b.com,” which is a subdomain of the associated domain “b.com” that is classified at 320. Thus, based on the routing information 316, it may be inferred that “c.com” is owned or otherwise associated with the selected entity 302.

[0059] In various aspects, the domain routing information 316 may include intermediate and / or final hosting information. The intermediate and / or final hosting information may include, for example, an IP address. In some aspects, the IP address may be a host address of the candidate domain 312, 330. In some aspects, the IP address may be a host address of a domain to which the candidate domain 312, 330 redirects. If the intermediate and / or final hosting information of the candidate domain 312, 330 is identical to the hosting information of the seed domain identified in 304 and / or is identical to the hosting information of the associated domain 322 classified in 320, it may be inferred that the candidate domain 312, 330 is owned or otherwise controlled by the selected entity 302. Thus, identifying 318 an association with the selected entity 302 may include identifying that the intermediate and / or final hosting information of the candidate domain 312, 330 is identical to the hosting information of the seed domain. Further, the candidate domains 312, 330 may be classified 320 as associated domains and added to a list of associated domains 322. For example, the candidate domains 312, 330 may be "b.com". When fetching 314 the domain "b.com", the domain routing information 316 may indicate that "b.com" has hosting information that includes the IP address "123.456.789.100". The seed domain "a.com" identified in 304 may also have hosting information that includes the IP address "123.456.789.100", which is known to be used only by the owner of a.com. Thus, based on the hosting information included in the routing information 316, it may be inferred that "b.com" is owned or otherwise associated with the selected entity 302.

[0060] In various aspects, the domain routing information 316 may be identified (318) as including information (and / or a lack of information) indicating no association between the candidate domains 312, 330 and the selected entity 302. If the candidate domains 312, 330 are identified (318) as not associated with the selected entity 302, the potential domains may be eliminated (324) from further consideration as redirect-equivalent domains belonging to the entity.

[0061] Using various parameters, the candidate domains 312, 330 may be identified (318) as not associated with the selected entity 302. In some aspects, the candidate domains 312, 330 may be identified (318) as not having an identifiable association with the selected entity 302 based on redirect information included in the domain routing information 316. For example, the candidate domains 312, 330 may be excluded (324) from further analysis as redirects if the candidate domains 312, 330 do not redirect to the seed domain identified in 304. As another implementation, the candidate domains 312, 330 may be excluded (324) from further analysis as redirects if the candidate domains 312, 330 do not redirect to a sub-domain of the seed domain 304. As yet another example, the candidate domains 312, 330 may be excluded (324) from further analysis as redirects if the candidate domains 312, 330 do not redirect to the associated domains 322 and / or sub-domains of the associated domains 322.

[0062] In some aspects, if the routing information 316 indicates that the candidate domain 312, 330 is not actively used by the selected entity 302, then an absence of association between the candidate domain 312, 330 and the selected entity 302 may be identified (318). For example, the candidate domain 312, 330 may be removed (324) from further analysis as a redirect-equivalent domain if the routing information 316 indicates that the candidate domain 312, 330 and / or the domain to which the candidate domain 312, 330 redirects are inactive (e.g., down, under construction, available for resale).

[0063] In some aspects, a candidate domain 312, 330 may be identified (318) as not being related to the selected entity 302 based on the URL path of the candidate domain 312, 330 and / or the domains to which the candidate domain 312, 330 routes. In one aspect, a candidate domain 312, 330 may be removed (324) from further analysis if the candidate domain 312, 330 routes to a domain with a URL that exceeds a path segment threshold, such as a path segment threshold of 2, 3, 4, 5, 6, 7, 8, 9, or 10 path segments, or a path segment threshold of more than 10. The use of a path segment threshold to remove potential domains may reduce the risk of misidentifying the candidate domain 312, 330 as an associated domain 322. For example, the candidate domain 312, 330 may be "b.com". The routing information 316 may indicate that "b.com" redirects to a domain with the URL "d.com / en / shopping / men / shirts / cotton / long_sleves / dress_shirts.html," which is greater than three path segments. Based on this routing information, "b.com" may be excluded (324) from further analysis. In one aspect, the candidate domains 312, 330 may be excluded (324) from further analysis based on a statistical identification algorithm, generated using machine learning, that analyzes the URL path segments of the candidate domains 312, 330 and / or the domains to which the candidate domains 312, 330 route. In various aspects, the statistical identification algorithm may be performed to identify candidate domains 312, 330 that have been incorrectly classified as associated domains 322. In various aspects, the statistical identification algorithm may be performed to confirm that the candidate domains 312, 330 have been correctly classified as associated domains 322.

[0064] 4A, the associated domains 322 and one or more seed domains identified in 304 may be used to generate an entity domain database 340. The entity domain database 340 may include each of the domains identified in method 300 that are deemed owned or otherwise controlled by the selected entity 302. Method 300 continues in FIG. 4B.

[0065] Referring to FIG. 4B, method 300 can continue by investigating domains included in domain database 340 for cybersecurity threats, such as investigating (342) for email-related cyber threats, investigating (358) for host configuration-related cyber threats, investigating (366) for traffic-related cyber threats, or investigating for additional types of cyber threats.

[0066] In some aspects, the domain database 340 may include domains associated with the email configuration of the selected entity 302. For example, the entity associates an email address with a well-known domain (e.g., email address "billg@microsoft.com" and domain "microsoft.com"). Thus, the domain database 340 may be examined (342) for email-related security threats. Email security-related threats may include, for example, the use of email configurations that lack an email authentication method or that have a misconfigured authentication method. There are various methods of domain-based email authentication, such as Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM), and other similar sender domain-based methods (DMARC, BIMI, etc.) that allow email recipients to validate emails.KKitterman, S., Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1, RFC 7208, DOI 10.17487 / RFC7208(April 2014), https: / / www.rfc-editor.org / info / rfc7208, Crocker, D., Ed., Hansen, T., Ed., and M. Kucherawy, Ed., DomainKeys Identified Mail (DKIM) Signatures, STD 76, RFC 6376, DOI 10.17487 / RFC6376, (September 2011), https: / / www.rfc-editor.org / info / rfc6376, and Rose et al., Trustworthy Email, NIST Special Publication 800-177 Rev. 1, (Feb. 2019), See, https: / / nvlpubs.nist.gov / nistpubs / SpecialPublications / NIST.SP.800-177r1.pdf, each of which is incorporated herein by reference in its entirety. Thus, in some aspects, researching (342) for email-related cyber risks may include analyzing domains in domain database 340 for use of email authentication methods. However, email authentication can be misconfigured such that the authentication method is insecure. Thus, in other aspects, researching (342) for email-related cyber threats may include analyzing domains in domain database 340 for use of misconfigured email authentication methods. In other aspects, various other email security controls may be investigated (342). For example, researching (342) for email-related cyber threats may include evaluating the use of entities such as spam filters, malware detection, phishing protection, and the like.

[0067] 4B , method 300 may continue by generating (344) one or more cyber risk mitigation actions based on the identified email-related cyber threats. Generating (344) the one or more cyber risk mitigation actions may include, for example, automatically performing (346) a modified email authentication configuration, applying (348) automatic labeling indicating that an email may not be authentic, automatically rejecting (350) and / or quarantining (350) email that may be exposed to a cyber threat, generating (352) an alert, generating a cyber threat database 354, and / or generating a cyber security risk report 356.

[0068] In various aspects, generating (344) one or more cyber risk mitigation actions may include automatically executing (346) a modified email authentication configuration based on the investigation (342) of email-related cyber threats. For example, referring now to FIGS. 1, 4A, and 4B, the selected entity 302 may be an entity 10101 that contracts with a cyber risk management provider (i.e., a tenant entity 10101). The cyber risk management provider server 1002 may store and manage the cyber assets 10121, 10122, ... 1012 of the tenant entity 10101. n, which allows the cyber risk management provider to trigger updates to email configurations associated with the tenant entity's 10101 domains. In response to identifying a domain that includes an email configuration that lacks an authentication method or has a misconfigured authentication method, the cyber risk management provider server 1002 can automatically generate instructions that are sent (e.g., via the network 1008) to the tenant entity's 10101 cyber assets 1012. The instructions can cause an automatic update of the email configurations associated with the identified domains. The modified email authentication configurations may include new and / or modified email authentication configurations.

[0069] 1, 4A, and 4B, in various aspects, generating (344) one or more cyber risk mitigation measures may include applying (348) automated labeling based on the research (342) into the email-related cyber threats. For example, a tenant entity 10101 may contract with a cyber risk management provider to provide automated labeling to other entities 10101, 10102, 10104, 10106, 10108, 10109, 10201, 102011, 102012, 102013, 102014, 102015, 102016, 102017, 102018, 102019, 102020, 102030, 102040, 102050, 102060, 102070, 102080, 102090, 102091, 102092, 103010, 103011, 103012, 103013, 103014, 103015, 103016, 103017, 103018, 103019, 104010, 104010, 104011, 104014, 104015, 104016, 104017, 104018, 104019, 105010, 105010, 105010, 105011, 105011, 105012, 105013, 105014, 1050 2、··· 1010 n The selected entity 302 may perform a cybersecurity risk analysis of the other entities 10102, . . . 1010. n , and may be analyzed by the cyber risk management provider. The cyber risk management provider server 1002 may store the cyber assets 10121, 10122, ... 1012 of the tenant entity 10101. n, thereby allowing the cyber risk management provider to trigger updates to email configurations associated with the tenant entity's 10101 domains. In response to identifying a domain (e.g., the cyber assets 1014 of the other entities 10102) that includes an email configuration that lacks an authentication method or has a misconfigured authentication, the cyber risk management provider server 1002 can automatically generate instructions that are sent (e.g., over the network 1008) to the cyber assets 1012 of the tenant entity 10101. The instructions can cause the cyber assets 1012 of the tenant entity 10101 to apply auto-labeling to emails received by the tenant entity 10101 from the exposed domains (e.g., the cyber assets 1014) of the other entities 10102. In some aspects, the auto-labeling can be applied to all domains (all cyber assets 10141, 10142, ... 1014) in the domain database 340 of the other entities 10102. n ) may be applied to emails received from the phishing email service. The automatic labeling may be text added to the received email to indicate that the email may not be authentic.

[0070] 1, 4A, and 4B, in various aspects, generating (344) one or more cyber risk mitigation actions may include refusing (350) to receive email and / or quarantining (350) received email based on the investigation (342) of the email-related cyber threat. For example, the cyber risk management provider server 1002 may automatically generate instructions (e.g., over the network 1008) to be sent to a cyber asset 1012 (e.g., an email server) of the tenant entity 10101, such that the cyber asset 1012 refuses to receive email sent from an exposed domain (e.g., cyber asset 1014) of another entity 10102. In some aspects, the instructions may cause the cyber asset 1012 of the tenant entity 10101 to quarantine email received from an exposed domain (e.g., cyber asset 1014) of the entity 10102. This may allow the quarantined email to be investigated for authenticity.

[0071] 1, 4A, and 4B, in various aspects, generating (344) one or more cyber risk mitigation measures may include generating (352) an alert based on investigating (342) the email-related cyber threat. The alert may be sent to a cyber risk management provider or another party charged with managing the cyber assets of a particular tenant entity 10101. In some aspects, the alert may include a message indicating, for example, that an email configuration has been compromised, that a potentially unauthenticated email has been sent, and / or that a potentially unauthenticated email has been received. In some aspects, the alert may include instructions to take a particular action in response to the identified email-related cyber threat.

[0072] 1, 4A, and 4B, in various aspects, generating one or more cyber risk mitigation actions (344) may include generating a cyber threat database 354 based on the investigation of email-related cyber threats (342). The cyber threat database 354 may include a log of each of the domains from the domain database 340 that have been identified as being exposed to email-related cyber threats. The cyber threat database 354, or a portion thereof, may be referenced by a security analyst at the cyber risk management provider or another party responsible for managing the cyber assets of a particular tenant entity 10101. For example, the cyber threat database may be used to identify domains that require email configuration updates.

[0073] 1, 4A, and 4B, in various aspects, generating (344) one or more cyber risk mitigation measures may include generating a cybersecurity risk report 356 based on the investigation of (342) the email-related cyber threats. The cybersecurity risk report 356 may include a report of a selected entity 302 (e.g., tenant entity 1010) based on the identified email-related cyber threats. 1、 or another entity 10102, ... 1010 n For example, an entity's use of email authentication may be an important factor in assessing how well the entity's cyber assets are protected from cyber threats such as malicious email forgery.

[0074] 4A and 4B, in various aspects, the domain database 340 may include domains associated with (e.g., address or otherwise identify) computers owned, controlled, or used by the selected entity 302. Thus, with reference to FIG. 4B, the domain database 340 may be examined (358) for host configuration related security threats. Host configuration related threats may include insecure configuration and / or operation of a computer associated with a domain in the domain database 340. There are many types of computing services and execution of computing services that may cause an insecure configuration or operation of a computer, and the list is constantly expanding. Additionally, there are many Internet ports and associated services that may be scanned for host related security threats.

[0075] As an example, investigating 358 for host configuration related security threats may include visiting one or more server(s) associated with a selected entity 302 (e.g., "www.example.com") and retrieving information such as the server type, software release version, available encryption parameters, or other security related information presented by the server. This information may be analyzed to identify security threats, such as, for example, running a server with known security vulnerabilities, using deprecated cryptographic services, or lack of control over access to sensitive information.

[0076] As another example, investigating 358 host configuration related security threats may include identifying inherently insecure non-web server services used by host computers associated with domains in the domain database 340. These threats may be identified by searching the services, software release versions, available encryption parameters, or other security related information. Insecure services may include, for example, outdated versions of telnet (e.g., computer addressable as "telnet.example.com") that transmit usernames and passwords without encryption or an open database of sensitive information. See Unprotected elasticsearch Server leaks 5 Billion Records, CISOMAG (March 20, 2020), https: / / cisomag.eccouncil.org / unprotected-elasticsearch-server-leaks-5-billion-records / , which is incorporated herein by reference in its entirety. Additionally, insecure services may include File Transfer Protocol (FTP), for example, found at "ftp.example.com". FTP is known to suffer from numerous security vulnerabilities. See Nate Lord, What is FTP Security Securing FTP Usage, Digital Guardian (September 7, 2018), https: / / digitalguardian.com / blog / what-ftp-security-securing-ftp-usage, which is incorporated by reference in its entirety. Thus, investigating 358 host configuration-related security threats may include analyzing host computers associated with domains in domain database 340 for the use of insecure configurations or behaviors.

[0077] 4B , method 300 may continue by generating (360) one or more cyber risk mitigation actions based on the host configuration-related cyber threats identified at 358. Various actions that may be generated (360) include, for example, automatically executing (362) the corrected host configuration, generating (364) an alert, generating (354) a cyber threat database, and / or generating (356) a cyber security risk report.

[0078] 1, 4A, and 4B, in various aspects, generating (360) one or more cyber risk mitigation actions may include automatically executing (362) a modified host configuration based on examining (358) the host configuration-associated cyber threats. For example, as described above, the selected entity 302 may be an entity 10101 that contracts with a cyber risk management provider (i.e., a tenant entity 10101). The cyber risk management provider server 1002 may store and manage the cyber assets 10121, 10122, ... 1012 of the tenant entity 10101. n , which allows the cyber risk management provider to trigger an update of the host computer configuration associated with the tenant entity's 10101 domain. In response to identifying a domain associated with a host computer that uses an insecure configuration, the cyber risk management provider server 1002 may automatically generate instructions (e.g., over the network 1008) that are sent to the tenant entity's 10101 cyber assets 1012. The instructions can trigger an automatic update of the host computer configuration associated with the identified domain. The modified host configuration may include, for example, a new version of the insecure host configuration or a replacement service for the insecure host configuration.

[0079] 1, 4A, and 4B, in various aspects, generating (360) one or more cyber risk mitigation measures may include generating (364) an alert based on investigating (358) the host configuration-related cyber threat. The alert may be sent to a cyber risk management provider or another party charged with managing the cyber assets of a particular tenant entity 10101. In some aspects, the alert may include a message indicating, for example, that an insecure host configuration has been detected, that a computer using the insecure host configuration has been used to send or receive information, and / or that a domain associated with a computer using the insecure host configuration has been communicated. In some aspects, the alert may include instructions to take a particular action in response to the identified host configuration-related cyber threat.

[0080] 1, 4A, and 4B, in various aspects, generating (360) one or more cyber risk mitigation measures may include generating (354) a cyber threat database based on the host configuration-related cyber threat investigation (342). The cyber threat database 354 may include a log of each of the domains from the domain database 340 that have been identified as being exposed to the host configuration-related cyber threats. The cyber threat database 354, or a portion thereof, may be viewed by a security analyst at the cyber risk management provider or another party claimed to manage the cyber assets of a particular tenant entity 10101. For example, the cyber threat database may be used to identify domains associated with insecure host configurations that need to be updated.

[0081] 1, 4A, and 4B, in various aspects, generating (360) one or more cyber risk mitigation measures may include generating (356) a cybersecurity risk report based on the host configuration-related cyber threat investigation (342). The cybersecurity risk report 356 may include generating (356) a cybersecurity risk report for a selected entity 302 (e.g., tenant entity 1010, tenant entity 1021, tenant entity 1022, tenant entity 1023, tenant entity 1024, tenant entity 1025, tenant entity 1026, tenant entity 1027, tenant entity 1028, tenant entity 1029, tenant entity 1030, tenant entity 1031, tenant entity 1032, tenant entity 1033, tenant entity 1034, tenant entity 1035, tenant entity 1036, tenant entity 1037, tenant entity 1038, tenant entity 1039, tenant entity 1040, tenant entity 1041, tenant entity 1042, tenant entity 1043, tenant entity 1044, tenant entity 1045, tenant entity 1046, tenant entity 1047, tenant entity 1048, tenant entity 1049, tenant entity 1050, tenant entity 1051, tenant entity 1052, tenant entity 1053, tenant entity 1054, tenant entity 1055, tenant entity 1056, tenant entity 1057, tenant entity 1058, tenant entity 1059, tenant entity 1060, tenant entity 1061, tenant entity 1062, tenant entity 1063, tenant entity 1064, tenant entity 1065, tenant entity 1066, tenant entity 1067, tenant entity 1068, tenant entity 1069, tenant entity 1070, tenant entity 1071 1、 or another entity 10102, . . . 1010 n ), an assessment of cyber threat exposure.

[0082] 4A and 4B, in various aspects, the domain database 340 may include domains associated with (e.g., addresses or identifying) computers owned, controlled, or otherwise used by the selected entity 302. These computers may attempt to send or receive data to or from malicious actors (e.g., groups or individuals with malicious intent, such as accessing or destroying data). Thus, with reference to FIG. 4B, the database 340 may be investigated 366 for traffic-related security threats. To investigate 366 traffic-related security threats, data related to public discoveries of malicious actors 368 and / or data related to proprietary discoveries of malicious actors 370 may be searched to identify domains, IP addresses, modus operandi, or other indicators that may be used to identify malicious actors. The cyber assets of the selected entity 302 (e.g., domains in the domain database 340, computers associated with domains in the domain database 340) may then be monitored for communications with malicious actors.

[0083] To identify traffic-related cyber threats involving malicious intrusion traffic, researching 366 for traffic-related cyber threats may include identifying domains, or IP addresses, associated with malicious actors that send or attempt to send data to domains in domain database 340. For example, IP address "1.2.3.4" may be known to be associated with a malicious actor based on data associated with public discoveries of malicious actor 368 and / or data associated with proprietary discoveries of malicious actor 370. IP address "1.2.3.4" may be observed requesting a DNS lookup or attempting to connect to the IP address of domain "ftp.example.com" of associated domains 322 in domain database 340. Based on this request, associated domain 322 "ftp.example.com" and / or selected entity 302 may be identified with a degree of confidence as a potential target of interest for the malicious actor. If more interactions between "ftp.example.com" and IP address "1.2.3.4" are observed, the likelihood that the domain "ftp.example.com" and / or the selected entity 302 are a potential target of interest may increase. As another example, network data, such as netflow logs or packet captures, can be used to observe Internet connections over time between a malicious actor's IP address and a computer associated with an associated domain 322, such as "payroll.example.com." Based on this network data, the associated domain 322 (payroll.example.com) and / or the selected entity 302 may be identified with a degree of confidence as a potential target of interest for the malicious actor.

[0084] To identify traffic-related cyber threats involving malicious incoming traffic, investigating 366 the traffic-related cyber threats may include identifying computers associated with domains in domain database 340 that attempt to connect with domains or IP addresses associated with the malicious actor. For example, the IP address of the domain "evilhackercontroller.com" may be known to be associated with the malicious actor based on data associated with public discoveries of the malicious actor 368 and / or data associated with proprietary discoveries of the malicious actor 370. A computer acting as a boundary DNS resolver linked to an associated domain 322, such as "dns.example.com", may be observed requesting the IP address of the domain "evilhackercontroller.com". Based on this request, the associated domain 322 "example.com" and / or the selected entity 302 may be identified with a high level of confidence as a target of the malicious actor.

[0085] 4B, method 300 may continue by generating (372) one or more cyber risk mitigation actions based on the identified traffic-related cyber threats. Various actions 372 that may be generated include, for example, automatically executing (374), generating (376) a modified configuration, generating (354) a cyber threat database, and / or generating (356) a cyber security risk report.

[0086] 1, 4A, and 4B, in various aspects, generating (372) one or more cyber risk mitigation actions may include automatically executing (374) a modified host configuration based on the traffic-related cyber threat investigation (366). For example, as described above, the selected entity 302 may be an entity 10101 that contracts with a cyber risk management provider (i.e., a tenant entity 10101). The cyber risk management provider server 1002 may be configured to automatically execute (374) the one or more cyber risk mitigation actions based on the traffic-related cyber threat investigation (366). The cyber risk management provider server 1002 may be configured to automatically execute (374) the one or more cyber risk mitigation actions based on the traffic-related cyber threat investigation (366). n , which may enable the cyber risk management provider to trigger updates to computers associated with the tenant entity's 10101 domain. In response to identifying a domain associated with a computer that is the subject of a traffic-related cyber threat, the cyber risk management provider server 1002 may automatically generate instructions (e.g., over the network 1008) that are sent to the tenant entity's 10101 cyber assets 1012. The instructions may cause an automatic update of the configuration of the computer associated with the target domain. The modified configuration may include, for example, terminating a connection, or blocking an attempted connection, between the target domain and the malicious actor.

[0087] 1, 4A, and 4B, in various aspects, generating (372) one or more cyber risk mitigation actions may include generating (376) an alert based on investigating (366) the traffic-related cyber threats. The alert may be sent to a cyber risk management provider or another party charged with managing the cyber assets of a particular tenant entity 10101.

[0088] 1, 4A, and 4B, in various aspects, generating (372) one or more cyber risk mitigation actions may include generating (354) a cyber threat database based on investigating (366) the traffic-related cyber threats. The cyber threat database 354 may include a log of each of the domains from the domain database 340 that have been identified as being exposed to traffic-related cyber threats. The cyber threat database 354, or a portion thereof, may be viewed by a security analyst at the cyber risk management provider or another party claimed to manage the cyber assets of a particular tenant entity 10101. For example, the cyber threat database may be used to identify domains associated with insecure host configurations that need to be updated.

[0089] 1, 4A, and 4B, in various aspects, generating (372) one or more cyber risk mitigation measures may include generating (356) a cybersecurity risk report based on the investigation (366) of the traffic-related cyber threats. The cybersecurity risk report 356 may include a cybersecurity risk report for a selected entity 302 (e.g., tenant entity 1010) based on the identified traffic-related cyber threats. 1、 or another entity 10102, ... 1010 n ), an assessment of cyber threat exposure.

[0090] 4A and 4B, the ad-hoc method of generating an entity domain database by (i) identifying (310) / discovering (328) candidate domains 312, 330 (i.e., potential domains 312 and / or known redirecting domains) based on public data 306A, 326A, and / or proprietary data 306B, 326B (which may be performed using machine learning and / or other statistical or related computational methods); and (ii) fetching (314) the candidate domains 312, 330, classifying (320) the candidate domains 312, 330 as associated domains 322, 330, and obtaining domain routing information 316, can enable more accurate and complete identification of cyber assets owned or otherwise controlled by the selected entity 302. Moreover, the ad hoc method performs tasks on a scale that is not practically feasible with the human mind, as the method 300 may discover 328 and fetch 314 million known redirect domains 330 and classify 320 some of these domains as associated domains 322 based on the obtained routing information 316. For example, thousands of known redirect domains 330 may be discovered 328 and fetched 314 to classify 320 the domains as associated domains 322 (in one example, 28 million known redirect domains 330 are discovered 328 and fetched 314 as part of the method 300). Moreover, the iterative manner in which some aspects of the method 300 repeatedly identify 338 additional potential URLs 332 until no new known redirect domains 330 are identified or until a computational threshold is met is not practically feasible with the human mind.Furthermore, the generation of the entity domain database 340 is integrated into practical applications by generating (344, 360, 372) one or more automated cyber risk mitigation actions (e.g., executing modified configurations 346, 362, 374, generating alerts 352, 364, 376, generating cybersecurity risk reports 356, and generating a cyber threat database 354).

[0091] 6, a diagram of a computer system 9000 is shown in accordance with at least one non-limiting aspect of the present disclosure. Computer system 9000, and various components included therein, may be used to execute various components of system 1000, as described below, and / or may be used to store and execute instructions for any of the various processes described above in connection with FIGURES 2-4A and 4B.

[0092] 6, computer system 9000 may include a bus 9002 (i.e., interconnect), one or more processors 9004, a main memory 9006, a read-only memory 9008, a removable storage medium 9010, a mass storage 9012, and one or more communication ports 9014. As should be understood, components such as removable storage media are optional and may not be required in all systems. The communication ports 9014 may be connected to one or more networks over which computer system 9000 may receive and / or transmit data.

[0093] As used herein, a processor may mean one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, graphic processing units (GPUs), or similar devices, or any combination thereof, regardless of architecture. An apparatus that executes a process may include, for example, a processor and those devices, such as input and output devices, appropriate for executing the process.

[0094] The processor(s) 9004 may be any known processor, such as, but not limited to, processors manufactured and / or sold by INTEL®, AMD®, or MOTOROLA®, which are generally well known to those skilled in the art and clearly defined in the literature. The communication port(s) 9014 may be any of an RS-232 port for use with a modem-based dial-up connection, a 10 / 100 Ethernet port, a Gigabit port using copper or fiber, or a USB port. The communication port(s) 9014 may be selected depending on the network, such as a local area network (LAN), a wide area network (WAN), a CDN, or any network to which the computer system 9000 connects. The computer system 9000 may communicate with peripheral devices (e.g., a display screen 9016, input device(s) 9018) via input / output (I / O) ports 9020.

[0095] The main memory 9006 may be a random access memory (RAM) or any other dynamic storage device(s) commonly known in the art. The read-only memory 9008 may be any static storage device(s), such as programmable read-only memory (PROM) chips for storing static information, such as instructions for the processor 9004. The mass storage device 9012 may be used to store information and instructions. For example, hard disks such as the Adaptec® family of small computer serial interface (SCSI) drives, optical disks, arrays of disks such as redundant arrays of independent disks (RAID) such as the Adaptec® family of RAID drives, or any other mass storage device may be used.

[0096] The bus 9002 communicatively couples the processor(s) 9004 with other memory, storage, and communication blocks. The bus 9002 may be a PCI / PCI-X, SCSI, Universal Serial Bus (USB) based system bus (or other) depending on the storage device used, etc. The removable storage medium 9010 may be any type of external hard drive, floppy drive, IOMEGA® Zip drive, compact disk read-only memory (CD-ROM), compact disk rewriteable memory (CD-RW), digital versatile disk read-only memory (DVD-ROM), etc.

[0097] Aspects described herein may be provided as one or more computer program products, which may include machine-readable media having instructions stored thereon, which may be used to program a computer (or other electronic device) to execute a process. As used herein, the term "machine-readable medium" refers to any medium, multiple media, or combination of different media that participate in providing data (e.g., instructions, data structures) that may be read by a computer, a processor, or a similar device. Such media may take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks, and other persistent memories. Volatile media include dynamic random access memory, which typically constitutes the main memory of a computer. Transmission media include coaxial cables, copper wire, and optical fibers, including wires that comprise a system bus coupled to a processor. Transmission media may include or convey acoustic waves, light waves, and electromagnetic radiation, such as those generated during wireless radio frequency (RF) and infrared (IR) data communications.

[0098] The machine-readable medium may include, but is not limited to, a floppy disk, an optical disk, a CD-ROM, a magneto-optical disk, a ROM, a RAM, an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic or optical card, a flash memory, or other type of medium / machine-readable medium suitable for storing electronic instructions. Furthermore, the aspects described herein may also be downloaded as a computer program product, and the program may be transferred from a remote computer to a requesting computer by data signals embodied in carrier waves or other propagation medium over a communications link (e.g., a modem or network connection).

[0099] Various forms of computer-readable media may be involved in carrying data (e.g., sequences of instructions) to a processor. For example, data may (i) be delivered to the processor from a RAM, (ii) be carried over a wireless transmission medium, (iii) be formatted and / or transmitted according to a number of formats, standards, or protocols, and / or (iv) be encrypted in any of a variety of manners known in the art.

[0100] The computer readable medium may store (in any suitable format) program elements suitable for carrying out the method.

[0101] As shown, main memory 9006 is encoded with application(s) 9022 supporting functionality discussed herein (application(s) 9022 may be applications that provide some or all of the functionality of the CD service described herein, including client applications). Application(s) 9022 (and / or other resources described herein) may be embodied as software code, such as data and / or logical instructions (e.g., code stored in memory or on another computer-readable medium, such as a disk) that support processing functions according to different aspects described herein.

[0102] During operation of one embodiment, the processor(s) 9004 access the main memory 9006, via use of the bus 9002, to launch, execute, execute, interpret, or otherwise execute logical instructions of the application(s) 9022. The execution of the application(s) 9022 generates processing functions for services associated with the application(s). In other words, the process(es) 9024 represent one or more portions of the application(s) 9022 operating within or on the processor(s) 9004 within the computer system 9000.

[0103] In addition to the process(es) 9024 that execute (perform) the operations as discussed herein, it should be noted that other processes described herein include the application 9022 itself (i.e., unexecuted or non-executed, logical instructions, and / or data). The application 9022 may be stored on a computer-readable medium (e.g., a repository) such as a disk, or in an optical medium. According to other aspects, the application 9022 may also be stored in a memory type system, such as firmware, read-only memory (ROM), or executable code in the main memory 9006 (e.g., in random access memory, or RAM), as in this implementation example. For example, the application 9022 may also be stored in the removable storage medium 9010, the read-only memory 9008, and / or the mass storage device 9012.

[0104] Those skilled in the art will appreciate that computer system 9000 may include other processes and / or software and hardware components, such as an operating system that controls the allocation and use of hardware resources.

[0105] Various aspects of the subject matter described herein are set forth in the following numbered sections.

[0106] Clause 1: A method for identifying cyber assets and performing cyber risk mitigation measures, the method including: selecting, by a processor, an entity for evaluation; identifying, by the processor, one or more seed domains of the entity; identifying, by the processor, candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetching, by the processor, the candidate domains and determining routing information for each of the candidate domains; classifying, by the processor, each candidate domain that redirects to the one or more seed domains as an associated domain based on the routing information, wherein each associated domain is considered to be an asset of the entity; generating, by the processor, an entity asset database based on the one or more seed domains and the associated domains; and generating, by the processor, cyber risk mitigation measures based on the entity asset database.

[0107] Clause 2: The method of clause 1, wherein the processor interrogates the entity asset database to identify associated domains linked to devices having insecure host configurations, and generating cyber risk mitigation measures based on the entity asset database includes at least one of: automatically executing a corrected host configuration when a device having an insecure host configuration is identified; generating a security alert when an associated domain linked to a device including an insecure host configuration is identified; generating a cybersecurity risk report based on the interrogation of the entity asset database; or a combination thereof.

[0108] Clause 3: The method of any of clauses 1-2, wherein the processor interrogates the entity asset database to identify associated domains linked to devices communicating with malicious actors, and generating cyber risk mitigation measures based on the entity asset database includes at least one of: automatically executing a modified device communication configuration when communication with a malicious actor is identified; generating a security alert when an associated domain linked to a device communicating with a malicious actor is identified; generating a cybersecurity risk report based on the interrogation of the entity asset database; or a combination thereof.

[0109] Clause 4: The method of any of clauses 1-3, wherein the processor interrogates the entity asset database to identify associated domains that include email-related security threats, the email-related security threats including email configurations that lack an email authentication method and / or email configurations that have a misconfigured email authentication method, and generating cyber risk mitigation measures based on the entity asset database includes at least one of: automatically executing a corrected email authentication configuration when an associated domain that includes an email-related security threat is identified; generating an automatic label indicating that an email may not be authentic when received from an associated domain that includes an email-related security threat; quarantining email when received from an associated domain that includes an email-related security threat; generating a security alert when an associated domain that includes an email-related security threat is identified; and generating a cybersecurity risk report based on the interrogation of the entity asset database, or a combination thereof.

[0110] Clause 5: The method of any of clauses 1 to 4, further comprising: identifying, by the processor, one or more candidate domains that redirect to one or more of the associated domains based on the routing information; and classifying, as an associated domain, each of the candidate domains that redirect to an associated domain.

[0111] Clause 6: The method of any of clauses 1 to 5, further comprising: identifying, by the processor, one or more candidate domains for redirecting to subdomains of the one or more seed domains based on the routing information; and classifying, by the processor, each of the candidate domains for redirecting to subdomains of the one or more seed domains as an associated domain.

[0112] Clause 7: The method of any of clauses 1 to 6, further comprising: identifying, by the processor, one or more candidate domains for redirecting to one or more subdomains of the associated domain based on the routing information; and classifying, by the processor, each of the candidate domains for redirecting to one or more subdomains of the associated domain as an associated domain.

[0113] Clause 8: The method of any one of clauses 1 to 7, wherein the candidate domains include potential domains, the potential domains being considered to be potential assets of the entity.

[0114] Clause 9: The method of any of clauses 1-8, identifying the candidate domains based on at least one of public data sources, proprietary data sources, or a combination thereof, wherein the public data sources include identifying potential domains based on at least one of Internet registration databases, public Domain Name System (DNS) databases, databases containing private and public DNS information, public key certificates, websites, government filings, or a combination thereof.

[0115] Clause 10: A method as described in any of clauses 1 to 9, wherein fetching the candidate domains to determine routing information for each of the candidate domains includes determining at least one of intermediate hosting information, final hosting information, or a combination thereof.

[0116] Clause 11: A method as described in any of clauses 1 to 10, comprising: fetching, by the processor, the candidate domains to determine whether one or more candidate domains are inactive; and excluding, by the processor, a candidate domain from being classified as an associated domain if the candidate domain is inactive.

[0117] Clause 12: The method of any of clauses 1 to 11, further comprising: excluding, by the processor, a candidate domain from being classified as an associated domain if a uniform resource locator (URL) of a domain to which the candidate domain routes exceeds a path segment threshold.

[0118] Clause 13: The method of any of clauses 1 to 12, further comprising: using machine learning, by the processor, excluding a candidate domain from being classified as an associated domain based on a uniform resource locator (URL) path of the domain to which the candidate domain routes.

[0119] Clause 14: The method of any of clauses 1-13, wherein identifying the candidate domains includes detecting known redirect domains.

[0120] Clause 15: The method of any of clauses 1-14, wherein identifying the candidate domains includes identifying potential uniform resource locators (URLs) based on at least one of a public data source, a proprietary data source, or a combination thereof, fetching the potential URLs to determine routing information for each of the URLs, and identifying one or more of the known redirect domains based on the URL routing information.

[0121] Clause 16: The method of any of clauses 1-15, wherein identifying the candidate domains further includes identifying additional potential URLs based on the URL routing information, fetching the additional potential URLs and determining URL routing information for each of the additional potential URLs, and repeating identifying additional potential URLs and fetching the additional potential URLs until a calculation threshold is met or no new known redirection domains are identified.

[0122] Clause 17: A non-transitory computer-readable storage medium comprising instructions executable by a processor to select an entity for evaluation; identify one or more seed domains for the entity; identify candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetch the candidate domains and determine routing information for each of the candidate domains; classify each candidate domain that redirects to the one or more seed domains based on the routing information as an associated domain, each of which is considered to be an asset of the entity; generate an entity asset database based on the one or more seed domains and the associated domains; and generate cyber risk mitigation measures based on the entity asset database.

[0123] Clause 18: The non-transitory computer-readable storage medium of clause 17, further comprising instructions executable by the processor to interrogate the entity asset database to identify associated domains linked to devices with insecure host configurations, wherein the instructions for generating cyber risk mitigation measures based on the entity asset database include instructions for performing at least one of: automatically executing a corrected host configuration when a device with an insecure host configuration is identified; generating a security alert when an associated domain linked to a device with an insecure host configuration is identified; or generating a cybersecurity risk report based on the interrogation of the entity asset database, or a combination thereof.

[0124] Clause 19: A non-transitory computer-readable storage medium according to any one of clauses 17 to 18, further comprising instructions executable by the processor to interrogate the entity asset database to identify associated domains linked to devices communicating with malicious actors, wherein the instructions for generating cyber risk mitigation measures based on the entity asset database include instructions for performing at least one of: automatically executing a modified device communication configuration when communication with a malicious actor is identified; generating a security alert when an associated domain linked to a device communicating with a malicious actor is identified; or generating a cybersecurity risk report based on the interrogation of the entity asset database, or a combination thereof.

[0125] Clause 20: The non-transitory computer-readable storage medium according to any one of clauses 17 to 19, further comprising instructions executable by the processor to interrogate the entity asset database to identify associated domains containing email-related security threats, including email configurations lacking an email authentication method and / or email configurations having a misconfigured email authentication method, and generating cyber risk mitigation measures based on the entity asset database, the instructions comprising: automatically executing a corrected email authentication configuration when an associated domain containing an email-related security threat is identified; generating an automatic label indicating that an email may not be authentic when received from an associated domain containing an email-related security threat; quarantining an email when received from an associated domain containing an email-related security threat; generating a security alert when an associated domain containing an email-related security threat is identified; or generating a cybersecurity risk report based on the interrogation of the entity asset database, or a combination thereof.

[0126] Clause 21: A non-transitory computer-readable storage medium according to any of clauses 17 to 20, further comprising instructions executable by the processor for identifying one or more candidate domains for redirecting to one or more of the associated domains based on the routing information, and classifying each of the candidate domains for redirecting to an associated domain as an associated domain.

[0127] Clause 22: A non-transitory computer-readable storage medium according to any one of clauses 17 to 21, further comprising instructions executable by the processor for identifying one or more candidate domains for redirecting to sub-domains of the one or more seed domains based on the routing information, and classifying each of the candidate domains for redirecting to sub-domains of the one or more seed domains as an associated domain.

[0128] Clause 23: A non-transitory computer-readable storage medium according to any of clauses 17 to 22, further comprising instructions executable by the processor for identifying, based on the routing information, one or more candidate domains for redirecting to one or more sub-domains of the associated domain, and classifying each of the candidate domains for redirecting to one or more sub-domains of the associated domain as an associated domain.

[0129] Clause 24: A non-transitory computer-readable storage medium according to any one of clauses 17 to 23, wherein the candidate domains include potential domains, and the potential domains are considered to be potential assets of the entity.

[0130] Clause 25: The non-transitory computer-readable storage medium according to any one of clauses 17 to 24, wherein identifying the candidate domains is performed using machine learning; 1. A non-transitory computer-readable storage medium, wherein the public data sources include at least one Internet registration database, a public Domain Name System (DNS) database, a public key certificate, a website, or a government filing, and the proprietary data sources include at least one private database containing DNS transactions.

[0131] Clause 26: A non-transitory computer-readable storage medium according to any one of clauses 17 to 25, wherein the routing information includes at least one of intermediate hosting information, final hosting information, or a combination thereof.

[0132] Clause 27: A non-transitory computer-readable storage medium according to any of clauses 17 to 26, further comprising instructions executable by the processor to fetch the candidate domains, determine whether one or more candidate domains are inactive, and exclude the candidate domain from being classified as an associated domain if the candidate domain is inactive.

[0133] Clause 28: A non-transitory computer-readable storage medium according to any of clauses 17 to 27, further comprising instructions executable by the processor for excluding a candidate domain from being classified as an associated domain if the Uniform Resource Locator (URL) of a domain to which the candidate domain routes exceeds a path segment threshold.

[0134] Clause 29: A non-transitory computer-readable storage medium according to any of clauses 17 to 28, further comprising instructions executable by the processor for excluding a candidate domain from being classified as an associated domain if the Uniform Resource Locator (URL) of a domain to which the candidate domain routes exceeds a path segment threshold.

[0135] Clause 30: A non-transitory computer-readable storage medium according to any one of clauses 17 to 29, wherein identifying the candidate domains includes detecting known redirect domains.

[0136] Clause 31: A non-transitory computer-readable storage medium according to any of clauses 17 to 30, wherein the instructions for identifying the candidate domains include instructions for identifying potential uniform resource locators (URLs) based on at least one of a public data source, a proprietary data source, or a combination thereof, fetching the potential URLs and determining routing information for each of the URLs, and identifying one or more of the known redirect domains based on the URL routing information.

[0137] Clause 32: A non-transitory computer-readable storage medium according to any of clauses 17 to 31, wherein the instructions for identifying the candidate domains further comprise instructions for: identifying additional potential URLs based on the URL routing information; fetching the additional potential URLs; determining URL routing information for each of the additional potential URLs; and repeating the process of identifying additional potential URLs and fetching the additional potential URLs until a calculation threshold is met or no new known redirection domains are identified.

[0138] All patents, patent applications, publications, or other disclosure materials described herein are incorporated herein by reference in their entirety, as if each individual reference were each expressly incorporated by reference. All references and any material, or portions thereof, that are said to be incorporated herein by reference are incorporated herein only to the extent that the incorporated material does not conflict with existing definitions, descriptions, or other disclosed material set forth in this disclosure. For that reason, and to the extent necessary, the present disclosure as set forth herein takes precedence over any conflicting material incorporated herein by reference, and the present disclosure is expressly set forth within the control of this application.

[0139] Various exemplary and illustrative aspects have been described. The aspects described herein are understood to provide illustrative features of various details of the various aspects of the present disclosure, and therefore, unless otherwise specified, it is to be understood that, to the extent possible, one or more features, elements, components, ingredients, structures, modules, and / or aspects of the aspects of the present disclosure may be combined, separated, substituted, and / or rearranged with or relative to one or more other features, elements, components, ingredients, structures, modules, and / or aspects of the aspects of the present disclosure without departing from the scope of the present disclosure. Thus, one of ordinary skill in the art will recognize that various substitutions, modifications, or combinations of any of the exemplary aspects may be made without departing from the claimed subject matter. Moreover, one of ordinary skill in the art will recognize or be able to ascertain, upon review of this specification and using no more than routine experimentation, many equivalents to the various aspects of the present disclosure. Thus, the present disclosure is not limited by the description of the various aspects, but only by the scope of the claims.

[0140] Those skilled in the art will recognize that the terms used herein in general, and in the appended claims in particular (e.g., the body of the appended claims), are generally intended as "open-ended" terms (e.g., the term "including" should be interpreted as "including but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "including but not limited to," etc.). It will be further understood by those skilled in the art that where recitation of a particular number of introduced claims is intended, such intent will be expressly recited in the claims, and in the absence of such recitation, no such intent exists. For example, as an aid to understanding, the following appended claims may include the use of the introductory phrases "at least one" and "one or more" to introduce the recitation of claims. However, the use of such phrases should not be construed as implying that the introduction of a claim recitation with the indefinite article "a" or "an" limits any particular claim that includes such an introduced claim recitation to claims that include only one such recitation, even when the same claim also includes the introductory phrases "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should ordinarily be construed to mean "at least one" or "one or more").

[0141] Moreover, even if a particular number of enumerations in an introduced claim are explicitly recited, one of ordinary skill in the art will recognize that such enumerations should typically be interpreted to mean at least the number recited (e.g., the mere enumeration of "two enumerations," without other modifiers, typically means at least two enumerations, or more than two enumerations). Furthermore, in those cases where a convention similar to "at least one of A, B, and C, etc." is used, such a structure is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). In those instances where a convention similar to "at least one of A, B, or C, etc." is used, such construction is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). It will be further understood by those of ordinary skill in the art that disjunctions and / or phrases, whether in the specification, claims, or drawings, that typically present two or more alternative terms, should be understood to contemplate the possibility of including one of the terms, either of the terms, or both terms, unless the context dictates otherwise. For example, the phrase "A, or B" will typically be understood to include the possibilities of "A" or "B," or "A and B."

[0142] With respect to the appended claims, one of ordinary skill in the art will appreciate that the actions recited therein may generally occur in any order. Also, while the claim recitations are presented in order(s), it should be understood that various actions may occur in other orders than those described, or may occur simultaneously. Examples of such alternative orders include overlapping, interleaved, interrupted, reordered, incremental, preparatory, supplementary, simultaneous, reverse, or other variant orders, unless the context dictates otherwise. Moreover, terms such as "responsive," "related to," or other past tense adjectives are generally not intended to exclude such variants, unless the context dictates otherwise.

[0143] It should be noted that any reference to "one embodiment," "embodiment," "exemplary," "one example," and the like means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, the appearances of the phrases "in one embodiment," "in an embodiment," "in an example," and "in one example" in various places throughout this specification do not necessarily all refer to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0144] As used herein, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise.

[0145] Directional terms used herein, such as, for example, but not limited to, up, down, left, right, below, upward, front, rear, and variations thereof, relate to the orientation of the elements as shown in the accompanying drawings and are not intended to be limiting with respect to the claims, unless expressly stated otherwise.

[0146] The term "about" or "approximately" as used in this disclosure, unless otherwise specified, refers to an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the term "about" or "approximately" refers to within 1, 2, 3, or 4 standard deviations. In certain embodiments, the term "about" or "approximately" refers to within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0147] In this specification, unless otherwise indicated, all numerical parameters are to be understood as being predicated and, in all instances, the numerical parameters should be understood to be modified by the term "about" given the inherent variability characteristic of the underlying measurement technique used to determine the numerical value of the parameter. At the very least, and not as an attempt to limit the application of the doctrine of equivalents to the scope of the claims, each numerical parameter set forth in this specification should at least be construed in light of the number of reported significant digits and by applying ordinary rounding techniques.

[0148] Any numerical range recited herein includes all subranges subsumed within the recited range. For example, a range of "1 to 100" includes all subranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the recited range endpoints. For example, a range of 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, applicants reserve the right to amend this specification, including the claims, to explicitly recite subranges that are subsumed within the explicitly recited ranges. All such ranges are inherently described herein.

[0149] Any patent application, patent, non-patent publication, or other disclosure material mentioned herein and / or listed in any application data sheet is incorporated herein by reference to the extent that the incorporated material does not contradict this specification. Thus, and to the extent necessary, the present disclosure as expressly set forth herein supersedes any conflicting material incorporated herein by reference. Any material, or portion thereof, that is said to be incorporated herein by reference but that contradicts an existing definition, statement, or other disclosure material set forth herein, is incorporated only to the extent that no contradiction arises between the incorporated material and the existing disclosure material.

[0150] The terms "comprise" (and any form of comprise, such as "comprises", "comprising"), "have" (and any form of have, such as "has" and "having"), "include" (and any form of include, such as "includes" and "including"), and "contain" (and any form of contain, such as "contains" and "containing") are open-ended linking verbs. As a result, a system that "comprises", "has", "includes", or "contains" one or more elements possesses those one or more elements, but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises", "has", "includes", or "contains" one or more features possesses those one or more features, but is not limited to possessing only those one or more features.

[0151] The foregoing detailed description describes various aspects of devices and / or processes through the use of block diagrams, flow charts, and / or examples. Where such block diagrams, flow charts, and / or implementation examples include one or more functions and / or operations, those skilled in the art will appreciate that each function and / or operation within such block diagrams, flow charts, and / or implementation examples may be individually and / or collectively implemented by a wide range of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the embodiments disclosed herein may be equivalently implemented in whole or in part in an integrated circuit as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or substantially any combination thereof, and that designing the circuitry and / or writing the code for the software and / or firmware is within the skill of those skilled in the art in light of this disclosure. Further, those skilled in the art will appreciate that the mechanisms of the subject matter described herein can be distributed as one or more program products in a variety of forms, and that the illustrative forms of the subject matter described herein apply regardless of the particular type of signal-bearing medium used to actually effect the distribution.

[0152] The instructions used to program the logic to execute the various disclosed aspects may be stored in memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage device. Additionally, the instructions may be distributed over a network or via other computer readable media. Thus, a machine readable medium is any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), including, but not limited to, floppy diskettes, optical disks, compact disks, read only memories (CD-ROMs), and magneto-optical disks, read only memories (ROMs), random access memories (RAMs), erasable programmable read only memories (EPROMs), electrically erasable programmable read only memories (EEPROMs), magnetic or optical cards, flash memory, or tangible machine readable storage devices used in transmitting information over the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Accordingly, non-transitory computer-readable media includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (eg, a computer).

[0153] The term "control circuitry" as used in any aspect herein may refer to, for example, hardwired circuitry, programmable circuitry (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA)), a state machine circuit, firmware that stores instructions executed by the programmable circuit, and any combination thereof. The control circuitry may be embodied collectively or individually as circuitry that forms part of a larger system, e.g., an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on a chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuitry" includes, but is not limited to, electrical circuitry having at least one discrete electrical circuit, electrical circuitry having at least one integrated circuit, electrical circuitry having at least one application specific integrated circuit, electrical circuitry forming a general purpose computing device configured by a computer program (e.g., a general purpose computer configured by a computer program that at least partially executes a process and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process and / or a device described herein), electrical circuitry forming a memory device (e.g., a form of random access memory), and / or electrical circuitry forming a communication device (e.g., a modem, a communication switch, or an optoelectronic device). Those skilled in the art will recognize that the subject matter described herein may be implemented in an analog or digital fashion, or some combination thereof.

[0154] As used in any aspect herein, the term "logic" may refer to an application, software, firmware, and / or circuitry configured to perform any of the operations described above. Software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) within a memory device.

[0155] As used in any aspect of this specification, the terms "component," "system," "module," etc. may refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.

[0156] As used in any aspect of the present specification, an "algorithm" refers to a self-consistent sequence of things that leads to a desired result, and the "things" refer to the manipulation of physical quantities and / or logical states, which may, but need not, take the form of electrical or magnetic signals that can be stored, moved, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, or the like. These and similar terms may be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

Claims

1. 1. A method for identifying cyber assets and implementing cyber risk mitigation measures, comprising: selecting, by a processor, an entity for evaluation; identifying, by the processor, one or more seed domains for the entity; identifying, by the processor, candidate domains based on at least one of public data sources, proprietary data sources, or a combination thereof; fetching, by the processor, the candidate domains and determining routing information for each of the candidate domains; classifying, by the processor, each candidate domain that redirects to the one or more seed domains as an associated domain based on the routing information, wherein each associated domain is considered to be an asset of an entity; generating, by the processor, an entity asset database based on the one or more seed domains and the associated domains; generating, by the processor, a cyber risk mitigation measure based on the entity asset database.

2. and further comprising: examining, by the processor, the entity asset database to identify associated domains linked to devices with insecure host configurations; generating cyber risk mitigation measures based on the entity asset database; automatically executing a corrected host configuration when a device with an insecure host configuration is identified; generating security alerts when associated domains linked to devices containing insecure host configurations are identified; generating a cybersecurity risk report based on an examination of said entity asset database; or The method of claim 1 , comprising at least one of the above combinations.

3. further comprising examining, by the processor, the entity asset database to identify associated domains linked to devices communicating with malicious actors; generating cyber risk mitigation measures based on the entity asset database; automatically implementing corrected device communication configurations when communications with malicious actors are identified; generating security alerts when associated domains linked to devices communicating with malicious actors are identified; generating a cybersecurity risk report based on the examination of the entity asset database; or a combination thereof.

4. and examining, by the processor, the entity asset database to identify associated domains containing email-related security threats. the email-related security threats include email configurations that lack an email authentication method and / or have a misconfigured email authentication method; generating cyber risk mitigation measures based on the entity asset database; automatically implementing a corrected email authentication configuration when an associated domain containing an email-related security threat is identified; generating an automatic label indicating that an email may not be authentic when received from a domain associated with an email-related security threat; Quarantine email when received from an associated domain that contains an email-related security threat; generating security alerts when associated domains containing email-related security threats are identified; generating a cybersecurity risk report based on the examination of the entity asset database; or a combination thereof.

5. identifying, by the processor, one or more candidate domains for redirecting to one or more of the associated domains based on the routing information; and classifying each of the candidate domains that redirect to an associated domain as an associated domain.

6. identifying, by the processor, one or more candidate domains for redirection to subdomains of the one or more seed domains based on the routing information; The method of claim 1 , further comprising: classifying, by the processor, each of the candidate domains that redirect to a subdomain of the one or more seed domains as an associated domain.

7. identifying, by the processor, one or more candidate domains for redirection to one or more subdomains of the associated domain based on the routing information; 10. The method of claim 1, further comprising: classifying, by the processor, each of the candidate domains that redirect to one or more subdomains of the associated domain as an associated domain.

8. The method of claim 1 , wherein the candidate domains include potential domains, the potential domains being considered potential assets for the entity.

9. identifying the candidate domains based on at least one of public data sources, proprietary data sources, or a combination thereof; 9. The method of claim 8, comprising identifying the potential domains based on at least one of an Internet registration database, a public Domain Name System (DNS) database, a database containing private and public DNS information, a public key certificate, a website, a government filing, or a combination thereof.

10. 2. The method of claim 1, wherein fetching the candidate domains to determine routing information for each of the candidate domains comprises determining at least one of intermediate hosting information, final hosting information, or a combination thereof.

11. fetching, by the processor, the candidate domains to determine whether one or more candidate domains are inactive; The method of claim 1 , further comprising: the processor precluding a candidate domain from being classified as an associated domain if the candidate domain is inactive.

12. 2. The method of claim 1, further comprising: excluding, by the processor, a candidate domain from being classified as an associated domain if a uniform resource locator (URL) of a domain to which the candidate domain routes exceeds a path segment threshold.

13. 10. The method of claim 1, further comprising: using machine learning, by the processor, to exclude a candidate domain from being classified as an associated domain based on a uniform resource locator (URL) path of a domain to which the candidate domain routes.

14. The method of claim 1 , wherein identifying the candidate domains comprises detecting known redirection domains.

15. identifying potential uniform resource locators (URLs) based on at least one of public data sources, proprietary data sources, or a combination thereof; fetching the potential URLs and determining routing information for each of the URLs; and identifying one or more of the known redirect domains based on the URL routing information.

16. identifying said candidate domains, Identifying additional potential URLs based on the URL routing information; and fetching the additional potential URLs and determining URL routing information for each of the additional potential URLs; 16. The method of claim 15, further comprising identifying additional potential URLs and repeating the steps of fetching the additional potential URLs until a calculation threshold is met or until no new known redirection domains are identified.