Device, system, and method for identifying cyber assets and identifying cyber risk mitigation measures based on a democratic matching algorithm

By employing a democratic matching algorithm to execute multiple cyber asset identification algorithms and determine true match probabilities, the method improves the accuracy and efficiency of cyber asset identification and risk mitigation, addressing the complexities and inaccuracies of current approaches.

JP2025518016APending Publication Date: 2025-06-12BLUEVOYANT LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024569369
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-25
Filing Date
2023-05-17
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Current methods for identifying cyber assets and mitigating cyber risks are complex, resource-intensive, and often inaccurate, due to difficulties in distinguishing between entities and correctly classifying cyber assets.

Method used

The implementation of a democratic matching algorithm that executes multiple cyber asset identification algorithms to identify candidate match pairs, determines true match probabilities, and adds verified cyber assets to an entity-specific database, enabling the generation of accurate cyber risk mitigation measures.

Benefits of technology

This approach enhances the accuracy and efficiency of cyber asset identification and risk mitigation, reducing the resources required and enabling automated execution of mitigation measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025518016000001_ABST
    Figure 2025518016000001_ABST
Patent Text Reader

Abstract

A method for identifying cyber assets and implementing cyber risk mitigation measures based on a democratic matching algorithm is disclosed. In one aspect, the method includes executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, each candidate match pair including two cyber assets identified as potential assets of the same entity by at least one of the cyber asset identification algorithms. The method may further include determining a true match probability for each candidate match pair, the true match probability being the probability that the two cyber assets within the candidate match pair are assets of the same entity, and the true match probability being based on which cyber asset identification algorithm identified the candidate match pair.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] (Cross - Reference to Related Applications) This application relates to U.S. Provisional Patent Application No. 63 / 345,679, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM", filed on May 25, 2022, the disclosure of which is hereby incorporated by reference in its entirety.

[0002] The present disclosure generally relates to network security, and more specifically, to improved devices, systems, and methods for identifying cyber assets and performing cyber risk mitigation measures based on a democratic matching algorithm.

Summary of the Invention

[0003] The following summary is provided to facilitate an understanding of some of the innovative features specific to the aspects disclosed herein and is not intended as a complete description. A complete understanding of the various aspects can be obtained by taking the entire specification, claims, and abstract.

[0004] In various aspects, the present disclosure provides a method for identifying cyber assets and implementing cyber risk mitigation measures. The method may include executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs. Each candidate match pair can include two cyber assets that are identified as potential assets of the same entity by at least one of the cyber asset identification algorithms. The method may further include determining a true match probability for each candidate match pair. The true match probability is the probability that the two cyber assets within the candidate match pair are assets of the same entity. The true match probability may be based on which of the cyber asset identification algorithms identified the candidate match pair. The method may further include determining that, for at least a portion of the candidate match pairs, the true match probability exceeds a predetermined threshold. Further, the method may include adding at least one of the cyber assets from each candidate match pair having a true match probability exceeding the predetermined threshold to a cyber asset database corresponding to the entity used to identify the match pair. In some aspects, the method may include generating cyber risk mitigation measures based on the cyber asset database.

[0005] In various aspects, the present disclosure provides a method for identifying cyber assets and generating cyber risk mitigation measures. The method can include selecting a target entity for evaluation and executing a plurality of domain identification algorithms to identify a plurality of candidate domains. Each candidate domain can be identified as a potential asset of the target entity by at least one of the domain identification algorithms. The method can further include determining a true match probability for each candidate domain. The true match probability is the probability that the candidate domain is an asset of the target entity. The true match probability can be based on which of the domain identification algorithms identified the candidate domain. The method can further include classifying candidate domains having a true match probability that exceeds a predetermined threshold as related domains, where each related domain is considered to be an asset of the target entity. In some aspects, the method can include generating an entity asset database for the target entity based on the associated domains and generating cyber risk mitigation based on the entity asset database.

[0006] In various aspects, the present disclosure provides a server. The server can be configured to identify cyber assets and perform cyber risk mitigation based on a democratic matching algorithm. The server can include a processor and a memory configured to generate a footprint module and a risk mitigation module. The footprint module can include a democratic matching module and a plurality of cyber asset identification modules. The memory can store instructions that, when executed by the processor, cause the processor to execute a plurality of cyber asset identification algorithms via the cyber asset identification module to identify a plurality of candidate match pairs. Each candidate match pair can include two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the same entity. The memory can further store instructions that, when executed by the processor, cause the processor to determine, via the democratic matching module, a true match probability for each candidate match pair. The true match probability is the probability that the two cyber assets within the candidate match pair are assets of the same entity. The true match probability can be based on any of the cyber asset identification algorithms that identified the candidate match pair. The memory can store instructions that, when executed by the processor, cause the processor to determine, via the democratic matching module, that the true match probability is greater than or equal to a predetermined threshold for at least some of the candidate match pairs, and via the footprint module, cause at least one of the cyber assets from each candidate match pair having a true match probability greater than or equal to the predetermined threshold to be added to a cyber asset database corresponding to the entity used to identify the match pair. The memory can further store instructions that, when executed by the processor, cause the processor to generate cyber risk mitigation based on the cyber asset database via the risk mitigation module.

[0007] The objects, functions, and characteristics of the present disclosure, as well as the methods of operation, functions, combinations of components, and manufacturing economies of the related structural elements, will become more apparent by considering the following description and the appended claims, which refer to the accompanying drawings, all of which form a part of this specification, and like reference numerals designate corresponding parts in the various figures. However, it should be explicitly understood that the drawings are for illustrative and explanatory purposes only and are not intended as a definition of the limits of the invention.

Brief Description of the Drawings

[0008] The various features of the aspects described herein are set forth in detail in the appended claims. However, the various aspects regarding both the organization and the method of operation, as well as the advantages thereof, can be understood from the following description in conjunction with the accompanying drawings as follows.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

[0009] Corresponding reference numerals indicate corresponding parts throughout the several views. The embodiments described herein illustrate various aspects of the invention in one form, and such embodiments should not be construed as limiting the scope of the invention in any way.

DETAILED DESCRIPTION OF THE INVENTION

[0010] The applicant of the present application owns the following U.S. provisional patent applications, and the disclosures of each of them are incorporated herein by reference in their entirety. - U.S. Provisional Patent Application No. 63 / 341,264, filed on May 12, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS", - U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS", - U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM", - International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", - International Patent Application No. PCT / US2022 / 072743, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - U.S. Provisional Patent Application No. 63 / 365,819, filed on June 3, 2022, entitled "DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX" - U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS" - U.S. Provisional Patent Application No. 63 / 366,903, filed on June 23, 2022, entitled "DEVICES, SYSTEMS, AND METHOD FOR GENERATING AND USING A QUERYABLE INDEX IN A CYBER DATA MODEL TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 368,567, filed on July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT" - U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES" - International Patent Application No. PCT / US2022 / 082167, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, and MethodS For PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - International Patent Application No. PCT / US2022 / 082173, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS" - International Patent Application No. PCT / US2023 / 061069, filed on January 23, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION’S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE" - International Patent Application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS"

[0011] Numerous specific details are set forth in order to provide a complete understanding of the overall structure, function, manufacture, and use of the aspects described in this disclosure and illustrated in the accompanying drawings. Well-known operations, components, and elements are not described in detail so as not to obscure the aspects described herein. The reader will understand that the aspects described and illustrated herein are non-limiting aspects. Thus, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary. Modifications and variations can be made without departing from the scope of the claims.

[0012] Before explaining in detail various aspects of the systems and methods disclosed herein, it should be noted that the exemplary aspects are not limited to the application or use of the details disclosed in the accompanying drawings and description. Of course, the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications and may be practiced or carried out in various ways. Further, unless otherwise indicated, the terms and expressions used herein are selected for the purpose of describing the exemplary aspects for the convenience of the reader and are not intended for purposes of limitation. For example, any reference herein to a particular manufacturer, software suite, application, or development platform is merely intended to illustrate some of the many aspects of this disclosure. This includes any reference to trademarks. Thus, it should be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any purpose of use and / or user preference.

[0013] As used herein, the term "server" refers to, or may include, one or more computing devices that are operated or facilitated by communication and processing for multiple parties in a network environment, such as the Internet or any public or private network. As used herein, a reference to a "server" or "processor" may refer to the server already mentioned and / or the processor mentioned as performing a process or function, different servers and / or processors, and / or a combination of servers.

[0014] As used herein, the term "entity" refers to, or may include, a corporation, business-related organization, non-profit organization, government agency, charity, educational institution, or any other type of organization or individual that owns or has a relationship with a collection of cyber assets. As used herein, a reference to "cyber assets" may refer to computing devices, networks, hardware, software, data, information, or any other type of information technology-related component, label, or identifier for switching, signaling, or routing, such as, for example, a domain, Internet Protocol (IP) address, or shared and / or dynamic assets.

[0015] As used herein, the terms "domain" and "domain name" refer to, or may include, a string that identifies or otherwise associates with a network, computing device, or other resource that communicates with the Internet, such as a server, personal computer, website, or other service communicated via the Internet. In some aspects, as used herein, "domain" and "domain name" generally refer to that described in Domain Names - Implementation and Specification, Network Working Group (Nov. 1987), the disclosure of which is incorporated herein by reference.

[0016] Entities typically need to understand and manage cyber security risks. More specifically, enterprises need to understand and manage cyber security risks associated with cyber assets. For example, an entity can have an Internet presence, i.e., a large number of cyber assets used for Internet-related communications. One or more of these cyber assets may be configured such that the entity is potentially exposed to cyber threats. Cyber threats can include unwanted or malicious attempts to gain access to an entity's network, data, and / or other information. Cyber threats can also include, for example, maliciously denying the proper owner's use of cyber assets, such as a denial-of-service attack or ransomware. Thus, to identify potential exposure to cyber threats and take measures against such threats, an entity, and / or its risk assessors and auditors, need to identify cyber assets and how they are configured.

[0017] To further improve the management of cyber threats and other security risks, an entity also needs to identify and understand the cyber assets of other entities. This need can arise because communication between entities can lead to the exposure of threats, or perhaps because an entity's cyber security risk can cause catastrophic service disruptions outside the realm of the Internet, potentially affecting partner entities. For example, a first entity can use its cyber assets to communicate with the cyber assets of another entity. If the cyber assets of the other entity are vulnerable to cyber threats, communication with these assets can expose the first entity to risk. Therefore, an entity needs to not only identify and understand its own cyber assets, but also identify and understand the risks posed by the cyber assets of other entities.

[0018] However, the large-scale identification of entities and their cyber assets can be a complex, time-consuming, and resource-intensive process. First, often it can be difficult to distinguish entities from each other simply because they share the same name. For example, an Internet search for the company "Island Realty" can identify businesses with that name in Surf City NJ, Isle of Palms SC, Jamestown RI, Orange Park, FL, Gross Ile MI, Grand Isle LA, and other locations around the world. Further, entities often share similar names. For example, a business called "The Island Realty" in Fisher’s Island Fl can be misconstrued with the various businesses operating under the name "Island Realty" above. Therefore, there is a need for methods, systems, and devices to reliably identify entities and distinguish them from each other so that cyber assets (e.g., the domain name "islandrealty.com") can be classified as belonging to a specific entity.

[0019] Furthermore, once a particular entity is identified, it can be complex and resource-intensive to identify some or all of the cyber assets owned and / or controlled by that entity. For example, the type of cyber asset that may be important to identify when analyzing cyber risk is the domain. Along with IP addresses, domains are generally used as the primary identifiers of networks and other types of assets within an IT system. However, due to the overwhelming number of domains available for investigation, it can be particularly difficult to identify and classify domains, at least in part, as being owned by or otherwise related to an entity. As of the second quarter of 2021, Verisign reported that the Internet contains at least 367,000,000 registered domains. See Verisign, 18 Domain Name Industry Brief 3, 2 (Sept. 2021), the disclosure of which is incorporated herein by reference. Each of these domains may potentially belong to a particular entity under evaluation.

[0020] Analyzing each of these domains to identify potential associations with specific entities is a task of such scope, scale, and complexity that it is not practically executable by human thought. Further, domain registration information is often incomplete, inaccurate, or may be deliberately edited, which can create difficulties when analyzing domains for potential associations with entities. As an example, the registration information for a particular domain may include only a name and a phone number, but no other information that may be used to confirm an association with a specific entity. As another example, the name, phone number, or other information included in the registration information may contain spelling mistakes or misnotations (e.g., “Willims Computing” instead of “Williams Computing” [sic], “123-465-7890” instead of “123-456-7890”). Thus, security analysts tasked with identifying, analyzing, and / or managing the cyber assets of multiple entities tend to misclassify and / or fail to discover associated domain names. Additionally, contracting with security analysts to perform this task can be costly due to the effort and complexity involved.

[0021] To address these issues, various rule-based algorithms can be used to discover cyber assets (e.g., domains) and determine whether the discovered cyber assets are owned by a particular entity or otherwise associated. As an example, a simple algorithm that searches and analyzes internet registration databases for domains registered to a particular entity may be used to identify domains potentially owned by that entity. As another example, a more complex cyber asset identification algorithm such as the domain redirection technology described in the aforementioned international patent application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS, which is hereby incorporated by reference in its entirety, may be used. As expected, different cyber asset identification algorithms may exhibit different levels of accuracy and performance. For example, a first algorithm may be able to identify some of the cyber assets belonging to an entity with a high level of accuracy, but may also fail to identify some of the cyber assets belonging to that entity. A second algorithm may be able to identify more cyber assets belonging to the entity than the first algorithm, but may also misassociate a number of cyber assets with the entity. Therefore, it may be desirable to employ multiple cyber asset identification algorithms to take advantage of the benefits each algorithm may provide. However, when different cyber asset identification algorithms provide different results, it can be difficult to determine which of the identified cyber assets actually belong to a particular entity and which cyber assets have been misclassified by one or more of the algorithms.

[0022] Incorrectly classifying or omitting cyber assets during the investigation of entities can be detrimental to the process of analyzing and mitigating cyber security risks. As explained above, cyber assets may be configured to be potentially exposed to cyber threats. If the cyber assets of a particular entity (e.g., a domain, etc.) are exposed to cyber threats but are not identified as belonging to the entity, the cyber security assessment of that entity may be inaccurate and incomplete. Furthermore, since the exposed cyber assets are never identified, it may be difficult or impossible for the evaluated entity, or other entities that potentially communicate or transact with the evaluated entity in other ways, to implement measures to mitigate potential cyber threats. For example, it may be desirable to execute configuration changes in response to determining that a cyber asset is exposed to a cyber threat. However, if the cyber asset is not identified, the configuration change may not be executed. Accordingly, provided are devices, systems, and methods for reliably identifying entities existing on the Internet, reliably identifying cyber assets associated with a particular entity, and generating cyber risk mitigation measures based on the identified cyber assets. Such enhancements can reduce the resources required to identify cyber assets belonging to a particular entity while also improving accuracy. Furthermore, such enhancements may enable automated execution of cyber risk mitigation measures.

[0023] The present disclosure presents devices, systems, and methods for reliably identifying entities existing on the Internet, identifying cyber assets (e.g., domains) associated with a particular entity, and / or implementing cyber risk mitigation measures based on the identified cyber assets. These devices, systems, and methods include, for example, (1) more accurately identifying cyber assets associated with a particular entity, and using multiple cyber asset identification algorithms in an unusual way to identify a plurality of candidate match pairs including two cyber assets that may each belong to the same entity, and determining a true match probability for each candidate match pair based on which of the cyber asset identification algorithms identified the candidate match pair, and generating an entity-specific cyber asset database by adding the cyber assets of the candidate match pairs to a cyber asset database corresponding to the entity used to identify the match pairs with a true match probability exceeding a predetermined threshold; (2) using machine learning to determine an accuracy coefficient for each of the cyber asset identification algorithms, providing the technical advantage of enabling more accurate cyber asset classification; (3) identifying, by a plurality of different cyber asset (e.g., domain) identification algorithms, which of millions of existing domains are potential assets of a particular entity, thereby identifying cyber assets associated with the entity at a scale and complexity that would not actually be carried out by human thinking, and / or (4) integrating the generation of the database including the cyber assets into a practical application by generating automatic cyber risk mitigation measures based on the database, providing many technical advantages such as this.The devices, systems, and methods described herein can also provide technical benefits by enabling the rapid prototyping and use of various cyber asset identification algorithms, which may not necessarily be fully optimized and / or accurate by incorporating the results of such algorithms into the true match probabilities determined by the democratic matching algorithms described herein.

[0024] Referring now to FIG. 1, there is shown a diagram of a system 1000 configured to identify cyber security assets and generate cyber risk mitigation measures across a plurality of entities, according to at least one non-limiting aspect of the present disclosure. System 1000 may include a cyber risk management provider server 1002 comprising a memory 1004 and a processor 1006. In various aspects, the cyber risk management provider server 1002 may comprise a computer system 9000 and its various components (e.g., the processor 1006 may be similar to the processor 9004 and the memory 1004 may be similar to the main memory 9006), which is described further with reference to FIG. 12. The memory 1004 may be configured to store instructions that, when executed by the processor 1006, perform various aspects of methods 100, 200, 300, 500, 800, and / or 900 as described hereinafter with respect to FIGS. 2 - 3 and FIGS. 5 - 11. For example, the memory 1004 may include instructions executable by the processor 1006 to generate a footprint module 1020 for implementing one or more of methods 100, 300, 500, and 800. The memory 1004 may similarly include instructions executable by the processor 1006 to generate a risk mitigation module 1030 for implementing one or more of methods 200 and 900. The cyber risk management provider server 1002 may be communicatively coupled via a network 1008 to a plurality of entities 1010 1 , 1010 2 , … 1010 n and may be communicatively coupled. Each of the plurality of entities 10101 ,1010 2 ,…1010 n can represent a tenant (e.g., a customer organization) that contracts with a cyber risk management provider for cyber security services and / or an entity that may be evaluated by the cyber risk management provider for cyber threats. According to a non-limiting aspect of FIG. 1, network 1008 may include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, network 1008 may include an internal network, a local area network (LAN), WiFi (registered trademark), a cellular network, near field communication (hereinafter, “NFC”), and the like.

[0025] Referring further to FIG. 1, each of the plurality of entities 1010 1 ,1010 2 ,…1010 n can host and / or associate one or more instances of one or more cyber assets 1012, 1014, 1016 (also referred to herein as clients 1012, 1014, 1016). For example, the first entity 1010 1 can include one or more devices that execute or are otherwise associated with one or more cyber assets 1012 1 ,1012 2 ,…1012 n , and the second entity 1010 2 can include one or more devices that execute or are otherwise associated with one or more cyber assets 1014 1 ,1014 2 , 1014 n , and / or the third entity 1010 n can include one or more devices that execute or are otherwise associated with one or more cyber assets 1016 1 ,1016 2 ,…1016 n . Each entity 1010 1 ,1010 2,…1010 n may include an intranet (i.e., a network) through which each device can communicate. As described above, each entity 1010 1 ,1010 2 ,…1010 n can represent a tenant (e.g., a customer), such as an organization, that contracts with a cyber risk management provider for security services. Thus, the cyber risk management provider server 1002 can be configured to oversee one or more of the plurality of entities, 1010 1 ,1010 2 , and 1010 n and thus be responsible for monitoring, and / or managing, the cyber assets (e.g., 1012, 1014, 1016) of the entities in order to mitigate cyber security threats.

[0026] Referring further to FIG. 1, the memory 1004 of the cyber risk management provider server 1002 can store a cyber asset database 1040. The cyber asset database 1040 can include information correlating various cyber assets 1012, 1014, 1016 with appropriate entities 10101, 10102, and 1010n. The cyber asset database 1040 may be generated by the footprint module 1020. However, as described above, identifying the cyber assets (e.g., 1012, 1014, 1016) of a plurality of entities (e.g., 10101, 10102,... 1010n) by a cyber risk management provider (e.g., using the cyber risk management provider server 1002) can be a complex and resource-intensive process. Further, misclassifying and omitting the cyber assets of a particular entity can be detrimental to the cyber security risk mitigation process. Thus, the present disclosure now turns to various methods for identifying the cyber assets of a plurality of entities and generating cyber risk mitigation measures based on the identified assets.

[0027] Referring now to FIG. 2, a flowchart of a method 100 for identifying cyber assets associated with a plurality of entities is shown, according to at least one non-limiting aspect of the present disclosure. The method 100 for identifying cyber assets associated with a plurality of entities may be referred to herein as the "footprint process 100". In various aspects, the cyber risk management provider server 1002 of FIG. 1 can generate a footprint module 1020 to execute the footprint process 100. Further, in various aspects, any of the footprint process 100 can be executed using algorithms that use machine learning, statistical techniques, and / or logic and expert system-based techniques, as well as search, sort, match, and other data processing techniques and logic.

[0028] The footprint process 100 can proceed by identifying 102 entity-specific characteristics and generating an entity database 108. As described above, due to the ambiguity associated with identifying those characteristics, it can be difficult to distinguish between entities (e.g., entities may conduct transactions under the same or similar names). Thus, identifying 102 entity-specific characteristics may include executing an algorithm that causes a search and analysis of public data 104 that describes the entity and / or proprietary data 106 that describes the entity for identifiers that are particularly unique to a specific entity. These unique identifiers can be used to generate an entity database 108 in correlation with a specific entity. For example, referring again to the above "Island Realty" example, searching public and / or proprietary data (e.g., domain registration data) that describes entities 104, 106 can reveal that the domain "islandrealty.com" is registered to an organization doing business under the name "Island Realty" in South Carolina. Thus, since the domain "islandrealty.com" is unique and may not be shared by other entities, this can be used to reliably distinguish the cyber presence and assets of South Carolina's "Island Realty" from other entities. This domain can be correlated with the reality of the South Carolina island and added to the entity database 108.

[0029] Identifiers used to generate entity database 108 may include identifiers such as, for example, Internet domains, addresses, telephone numbers, business registration numbers, and tax identifiers. Public data 104 describing the entity may include, for example, databases having information such as U.S. Securities and Exchange Commission (SEC) filings, Internal Revenue Service (IRS) disclosures, state-based business and / or charity registrations with the Secretary of State, legal filings, government filings, international entity identifier base identifiers, public key certificates, information found on organizational websites, public Internet registrations, patent applications, and trademark applications. Proprietary data 106 describing the entity may include, for example, databases having information such as firmographic information catalogs regarding entities purchased from Dun & Bradstreet, Moody’s, Standard & Poor’s, Zoominfo, Open Corporates, as well as mailing lists, and / or sales lead suppliers. Public data 104 describing the entity and proprietary data 106 describing the entity are often incomplete and may contain errors. Thus, in various aspects, identifying 102 entity-specific characteristics may include searches, sorts, matches, and logic-driven distinctions such as using machine learning and / or statistical techniques, and expert system evaluations to clarify the entity.

[0030] The footprint process 100 can continue by identifying 110 cyber assets associated with entities within the entity database 108. As described above, a given entity can be associated with several different types of cyber assets, such as, for example, domains, IP addresses, and shared and dynamic assets. However, there is no previous source, or method, that can easily identify and classify the cyber assets of multiple entities. Therefore, to address this need, identifying 110 cyber assets associated with entities within the entity database 108 may include executing an algorithm that causes a search and analysis of public data 112 that describes the entity's cyber assets and / or proprietary data 114 that describes the entity's cyber assets. Based on this search and analysis, identify specific types of cyber assets and correlate them with the identifiers stored in the entity database 108 to the entity domain database 116 1 , the entity IP address database 116 2 , the entity shared and dynamic asset database 116 3 , and / or any number of other cyber asset databases 116 for storing data related to various types of cyber assets n(Collectively, the cyber asset database 116) can be generated. In some embodiments, the cyber asset database 116 may be similar to the cyber asset database 1040 referenced with respect to FIG. 1. The process of identifying 110 the cyber assets associated with each entity in the entity database 108 may include one or more of the steps of method 300 for identifying cyber assets based on a democratic algorithm and / or method 500 for identifying domains based on a democratic matching algorithm for generating cyber risk mitigation measures described in detail below with respect to FIGS. 5-10. In various embodiments, the algorithms used to identify 110 cyber assets can use search, sorting, collation, and / or statistical techniques, logic-driven discrimination such as expert system evaluation, and / or machine learning.

[0031] In one embodiment, the entity domain database 116 1 can include a plurality of domain databases, each domain database including the domains classified as being associated with a particular entity from the entity database 108. In another embodiment, the entity IP address database 116 2 can include a plurality of IP address databases, each IP address database including the IP addresses classified as being associated with a particular entity from the entity database 108. In another embodiment, the entity shared asset database 116 3 can include a plurality of shared asset and dynamic asset databases, each shared asset and dynamic asset database including the shared assets and dynamic assets classified as being associated with a particular entity from the entity database 108. In yet another embodiment, various other types of cyber asset databases 116 ncan each include a plurality of type-specific cyber asset databases, where each type-specific cyber asset database includes cyber assets of a specific type classified as being associated with a particular entity from the entity database 108. The cyber asset database 116 can be used as a basis for generating cyber risk mitigation measures, as discussed below with respect to FIG. 3.

[0032] Referring now to FIG. 3, a flowchart of a method 200 for generating cyber risk mitigation measures across a plurality of entities based on the cyber asset database 116 is shown, in accordance with at least one non-limiting aspect of the present disclosure. The method 200 for generating cyber risk mitigation measures across a plurality of entities may be referred to herein as the "cyber risk mitigation process 200." In various aspects, the cyber risk management provider server 1002 of FIG. 1 can generate a risk mitigation module 1030 for implementing the cyber risk mitigation process 200. Further, in various aspects, any of the steps of the cyber risk mitigation process 200 can be performed using algorithms that use search, sort, match, and / or statistical techniques, logic-driven discrimination such as expert system evaluation, and / or machine learning.

[0033] The cyber risk mitigation process 200 can be initiated by investigating 202 one or more of the cyber asset databases 116 for cyber assets exposed to cyber threats. As described above, any of the entity's cyber assets (e.g., domains, IP addresses, as well as shared assets and dynamic assets) may be configured such that the entity is exposed to cyber threats. Thus, in the investigation 202, the cyber asset database 116 may include executing an algorithm to determine which of the various cyber assets within the cyber asset database 116 are vulnerable to cyber threats or may include configurations that are exploited by cyber threats. In various aspects, investigating 202 the cyber asset database 116 for cyber threats can constitute one or more of the steps of method 900 for generating cyber risk mitigation measures based on the entity domain database, which is described in detail below with respect to FIG. 11.

[0034] Referring further to FIG. 3, in various aspects, the threat exposure of a given cyber asset configuration may be time-dependent and / or may change in response to the occurrence of various cyber events. Thus, investigating 202 the cyber asset database 116 for cyber threats may also include searching and analyzing the Internet for public information 204 related to the presence of exploitation risks or the occurrence of cyber events, and / or searching and analyzing the Internet for proprietary information 206 related to the presence of exploitation risks or the occurrence of cyber events to identify cyber data and events that may indicate that one or more cyber assets within the cyber asset database 116 are exposed to cyber threats. In various aspects, the algorithm for investigating 202 the cyber asset database 116 for cyber threats can use various computer-executed analysis techniques such as, for example, search, sort, collation, and / or statistical techniques, logic-driven discrimination such as by expert system evaluation, and / or machine learning.

[0035] The cyber risk mitigation process 200 can continue by generating 208 one or more cyber risk mitigation measures based on the cyber threats identified at 202 and the risk indicators. Generating 208 cyber risk mitigation measures can include, for example, generating a cyber security risk report 210 for the entity, generating a cyber asset threat, vulnerability, and risk database 212, implementing corrective actions 214, and generating alerts (collectively, "cyber risk mitigation measures 210, 212, 214, 216") 216.

[0036] In various aspects, generating 208 cyber risk mitigation measures may include generating a cyber security risk report 210 for the entity. The entity cyber security risk report 210 can include one or more reports, and each report includes an assessment of the exposure of cyber threats of one or more entities within the entity database 108 based on the investigation performed at 202. The risk report 210 may include a risk level score that a cyber risk management provider can use to determine the relative risk level of a particular entity compared to other entities within the entity database 108.

[0037] In various aspects, generating 208 cyber risk mitigation measures may include generating a threat, vulnerability, and risk database 212 for the entity's cyber assets. The threat, vulnerability, and risk database 212 for cyber assets may include logs for each asset from the cyber asset database 116 that were identified at 202 as being exposed to cyber threats, vulnerabilities, and / or risks. The threat, vulnerability, and risk database 212 for cyber assets, or a portion thereof, may be referenced by a cyber risk management provider when making asset management decisions. For example, the threat, vulnerability, and risk database 212 for cyber assets can be used to identify cyber assets that require configuration updates.

[0038] In various aspects, generating cyber risk mitigation measures 208 may include implementing corrective measures 214. In some aspects, implementing corrective measures 214 may include executing an algorithm at 202 that causes an automatic configuration update to one or more cyber assets identified as being exposed to a cyber threat. For example, implementing corrective measures 214 may include executing a restored configuration 946 based on an e-mail related cyber threat, executing a restored configuration 962 based on a host configuration related cyber threat, and / or executing a restored configuration 974 based on a traffic related cyber threat, as described below with reference to FIG. 11.

[0039] In various aspects, generating cyber risk mitigation measures 208 may include generating an alert 216 in response to identifying at 202 that one or more cyber assets are exposed to a cyber threat. For example, in one aspect, the alert may be sent to a security analyst of a cyber risk management provider and / or other parties billed for the cyber security of a particular entity. In other aspects, the alert may be sent to a cyber asset, or a user of the cyber asset, associated with the identified cyber threat. The generated alert 216 may include instructions for a security analyst, user, or other party to take particular measures in response to the identified cyber threat. In another aspect, the alert may also take the form of an automatic control instruction to a computer system providing a security service. For example, a control message to close a port may be sent to an entity's firewall upon viewing evidence of malicious activity.

[0040] Democratic matching algorithm Although a general implementation of an apparatus, system, and method for identifying entities existing on the Internet, identifying cyber assets related to the identified entities, and generating cyber risk mitigation measures based on the identified cyber assets has been described, the present disclosure now turns to a specific implementation of these apparatuses, systems, and methods related to identifying cyber assets related to a specific entity using a democratic matching algorithm and generating cyber risk mitigation measures based on the identified cyber assets. Any of the aspects described below with respect to FIGS. 4-11 are applicable to the apparatuses, systems, and methods described above with respect to system 1000 of FIG. 1, footprint process 100 of FIG. 2, and cyber risk mitigation process 200 of FIG. 3.

[0041] FIG. 5 shows a flowchart of a method 300 for identifying cyber assets associated with a plurality of entities based on a democratic matching algorithm, and FIG. 6 shows an example of a match table 400 that may be employed by method 300 in accordance with some non-limiting aspects of the present disclosure. As an example of one particular implementation of method 300, FIGS. 7-8 and FIG. 10 show flowcharts illustrating a method 500 for identifying candidate domains 506 associated with a target entity 502 based on a democratic matching algorithm. Further, FIG. 9 shows an example of a match table 700 that may be employed by method 500. A more detailed understanding of the various aspects of method 300 can be obtained based on the various details disclosed with respect to method 500 of FIGS. 7-10 and the accompanying description. Thus, any aspect disclosed with respect to method 500 may be brought to method 300 and vice versa. In various aspects, the cyber risk management provider server 1002 of FIG. 4 can store instructions executable by a processor 1006 on a memory 1004 to execute method 300 and / or method 500, as will be described in detail below.

[0042] Referring now to FIGS. 5 and 6, method 300 includes a plurality of cyber asset identification algorithms (e.g., a 1 ,a2 ,…a n ) is executed 304 1 , 304 2 ,…304 n (collectively referred to as "execution 304") to generate a plurality of candidate match pairs 306 1 , 306 2 ,…306 n (collectively, candidate match pairs 306) can be started by identifying them. Each of the candidate match pairs 306 is a pair of two cyber assets (e.g., CA i and CA j ) identified by at least one of the cyber asset identification algorithms as potential assets of the same entity. FIGS. 5 and 6 show that method 300 executed at 304 includes more than three cyber asset identification algorithms, but method 300 can be implemented by executing any number of cyber asset identification algorithms where n is an integer greater than 1.

[0043] Referring mainly to FIG. 6 here, the results 304 of executing various cyber asset identification algorithms can be organized into a match table 400. Each candidate match pair 306 1 , 306 2 , 306 3 , 306 4 ,…306 n is in a different row of table 400 and each cyber asset identification algorithm a 1 , a 2 ,…a n is organized along a different column of table 400. Along each candidate match pair row, binary values are assigned to each cyber asset identification algorithm, with a "1" assigned to each cyber asset identification algorithm that identifies the candidate match pair 306 and a "0" assigned to each cyber asset algorithm that could not identify the candidate match pair 306. For example, referring to match pair 306 3 , cyber asset identification algorithm a 1 identified that cyber assets CA 520 and CA 139 might belong to the same entity, but cyber asset identification algorithm a 2and a n is the cyber asset CA 520 and CA 139 could not be identified as potentially belonging to the same entity. As another example, referring to the matching pair 306 n the cyber asset identification algorithm a 1 a 2 and a n each identified the cyber assets CA 235 and CA 166 as potentially belonging to the same entity.

[0044] The cyber asset identification algorithm a 1 , a 2 , … a n may be any type of rule-based matching algorithm configured to search for and analyze publicly available information and / or proprietary information to identify cyber assets that are potentially owned or otherwise associated with the same entity. Each of the cyber asset identification algorithms may employ different methods (e.g., different sets of rules, different sets of parameters, and / or different information sources or combinations of information sources, etc.) to identify candidate matching pairs 306.

[0045] In some aspects, the cyber asset identification algorithm may be configured to identify candidate matching pairs 306 of multiple entities during a single execution of the algorithm, and not all of the identified candidate matching pairs 306 need to be associated with the same entity. For example, referring again to Table 400 of FIG. 6, the cyber assets CA 1 of the candidate matching pair 306 42 3 and CA 74 may be identified as potentially belonging to the first entity by the cyber asset identification algorithms a 1 and a 2 while the cyber asset identification algorithm a 3 fails to identify a match. Further, the cyber assets CA 4 of the candidate matching pair 306 389 and CA89 is the cyber asset identification algorithm a 2 and a n may be identified as potentially belonging to a second entity by the cyber asset identification algorithm a 1 fails to identify a match. Even further, the cyber assets CA n of the candidate match pair 306 235 and CA 166 may be identified as potentially belonging to a third entity by the cyber asset identification algorithm a 1 , a 2 , and a n . Thus, in this embodiment, the cyber asset identification algorithms a 1 , a 2 , and a n are configured to identify candidate match pairs 306 across multiple entities.

[0046] In other aspects, the cyber asset identification algorithm may be configured to identify candidate match pairs 306 of a single entity at a time. For example, referring again to Table 400 of FIG. 6, the candidate match pairs 306 1 , 306 2 , 306 3 , 306 4 , … 306 n may be based on the same entity, and the various algorithms a 1 , a 2 , … a n only identify the match pairs of that entity during one execution of the algorithm. In various aspects, the method 500, described in detail below with respect to FIGS. 7 - 10, may employ a cyber asset identification algorithm configured to identify candidate match pairs 306 (e.g., candidate domains) for a single entity at a time.

[0047] Referring again primarily to FIGS. 5 and 6, the method 300 is the true match probability P for each candidate match pair 306 Tcan be continued by determining 308. As used herein, the true match probability can refer to the overall probability or confidence level that two cyber assets within the candidate match pair 306 are assets of the same entity based on the collective result of the cyber asset identification algorithms. The true match probability for a particular candidate match pair 306 can depend on which cyber asset identification algorithm a 1 ,a 2 ,…a n identifies the match pair. For example, referring mainly to FIG. 6, the true match probability P 1 ,306 2 ,306 3 ,306 4 ,…306 n for each of can be calculated based on the binary values assigned to each of the cyber asset identification algorithms a T ,a 1 ,a 2 ,…a n for that particular match pair.

[0048] The true match probability P T for each candidate match pair 306 can be calculated using various different methods or determined in other ways. For example, a precision factor is assigned to each cyber asset identification algorithm, and the true match probability P TIt may be used to calculate. The accuracy coefficient may be determined in advance based on training a cyber asset identification algorithm against one or more ground truth sets of cyber assets, as described in more detail below. In some aspects, the accuracy coefficient for a given cyber asset identification algorithm can include an accuracy coefficient representing the probability that the algorithm returns a true positive result (i.e., the probability that the algorithm correctly identifies a candidate match pair that includes cyber assets belonging to the same entity), and an accuracy coefficient representing the probability that the algorithm returns a true negative result (i.e., the probability that the algorithm correctly omits a candidate match pair that includes cyber assets not belonging to the same entity). In other aspects, the accuracy coefficient for a given cyber asset identification algorithm can include another type of weighting coefficient associated with the algorithm.

[0049] As described above, the accuracy coefficient may be determined in advance based on training a cyber asset identification algorithm against one or more ground truth sets of cyber assets. Specifically, the accuracy coefficient for each cyber asset identification algorithm may be determined in advance based on the accuracy of each algorithm as measured by running the algorithm to identify training match pairs for entities having a known ground truth set of cyber assets (i.e., known entities). As used herein, a "training match pair" can refer to a match pair returned by a cyber asset identification algorithm for comparison against a set of ground truth cyber assets. Each training match pair can include two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of a known entity. Further, each cyber asset identification algorithm identifies at least a subset of the training match pairs. As used herein, a "ground truth cyber asset" can refer to a cyber asset that is known to be associated with a known entity or has otherwise been verified. For example, the ground truth cyber assets of a given entity can be curated by a security analyst or selected in other ways.

[0050] Using various statistical and / or machine learning techniques, the cyber assets in the training match pairs identified by the algorithm can be compared with the ground truth set of cyber assets of known entities to determine the accuracy coefficient of a given cyber asset identification algorithm. In some aspects, a given cyber asset identification algorithm can be run multiple times to identify a set of training match pairs for multiple known entities. Each set of training match pairs can be compared with the known ground truth set of cyber assets of the corresponding known entity to further refine the accuracy coefficient. In other aspects, a support vector machine (SVM) machine learning model can be used to determine the accuracy coefficient for a given cyber asset identification algorithm. Various aspects of method 800 for determining the accuracy coefficient of a domain identification algorithm, as described below with respect to FIG. 10, can be similarly employed to generally determine the accuracy coefficient of the cyber asset identification algorithm described with respect to method 300 of FIG. 5.

[0051] Referring further to FIGS. 5 and 6, in one aspect, the true match probability P for a given candidate match pair 306 can be determined 308 using Equation 1 below. T can be determined 308. [Number]

[0052] In Equation 1 above, p i is the accuracy coefficient and represents the probability that a given cyber identification algorithm returns a true positive result. Further, r j is the accuracy coefficient and represents the probability that a given cyber identification algorithm erroneously returns a negative result. Thus, (1 - r j ) is the probability that a given cyber identification algorithm returns a true negative result. In some aspects, p i and r j are, as described above, the cyber asset identification algorithms a 1 , a 2 , … a nFor each of them, it is based on the accuracy of a specific algorithm compared to ground truth.

[0053] Using Equation 1 above, for a given candidate match pair 306, the true match probability P T To calculate, the product for i is taken over all cyber asset identification algorithms that identify the candidate match pair 306 (i.e., the algorithm assigned a "1" to the corresponding row in the match table 400), and the product for j is taken over all cyber asset identification algorithms that did not identify the candidate match pair 306 (i.e., the algorithm assigned a "0" to the corresponding row in the match table 400). In other words, according to a non - limiting aspect of Equation 1 above, the true match probability P T for a given candidate match pair 306 is equal to the case where all algorithms assign "1" and the case where all algorithms assign "0" are correct, divided by the sum of the case where all algorithms assign "1" and the case where all algorithms assign "0" are correct and the case where all algorithms assign "1" and the case where all algorithms assign "0" are incorrect. As described above, in other aspects, other methods may be used to calculate the true match probability P T for a given candidate match pair 306. For example, different or additional accuracy coefficients may be introduced into Equation 1 above (e.g., different or additional weighting coefficients and / or probability coefficients determined based on a model trained using a given ground truth).

[0054] Referring again mainly to FIGS. 5 and 6, the method 300 determines the true match probability P for each candidate match pair 306 Tcan continue by determining 310 whether it exceeds a predetermined threshold. In some embodiments, the predetermined threshold may be selected by a security analyst or other user tasked with performing the fingerprinting process. In other embodiments, the predetermined threshold may be automatically determined based on machine learning and / or statistical methods based on a trained model using a given ground truth. In yet other embodiments, the predetermined threshold may be 0.50 or greater, e.g., 0.60, 0.70, 0.75, 0.80, 0.85, 0.90, 0.91, 0.92, 0.93, 0.94, 0.95, 0.96, 0.97, 0.98, 0.99, 0.995, 0.996, 0.997, 0.998, or 0.999 or greater.

[0055] The method adds at least one cyber asset 312 from each candidate match pair 306 having a true match probability P above a predetermined threshold T to the cyber asset database 116 corresponding to the entity used to identify the match pair. For example, referring primarily to FIG. 6 and also to FIG. 5, the match table 400 shows that for candidate match pair 306 1 a true match probability P of 0.91 T has been determined 308. The cyber assets CA 1 and CA 423 of candidate match pair 306 74 may be IP addresses identified by cyber asset identification algorithms a 1 and a 2 as potentially both belonging to the first entity. If the predetermined threshold is selected to be 0.90, method 300 determines 310 that candidate match pair 306 T has a true match probability P that exceeds the predetermined threshold 1 and adds 312 at least one of cyber assets CA T and CA 423 to the entity IP address database 116 corresponding to the first entity. 74 2 ​

[0056] As another example, Table 400 shows that a true match probability P of 0.23 has been determined 308 for candidate match pair 306 2 The cyber assets CA T and CA 2 for candidate match pair 306 893 and CA 982 may both be IP addresses identified by cyber asset identification algorithm a as potentially belonging to a second entity n Again, assuming that a predetermined threshold is selected to be 0.90, method 300 would determine 310 that candidate match pair 306 T does not have a true match probability P that exceeds the predetermined threshold 2 Accordingly, no action would be taken to add either cyber asset CA T or CA 2 to entity IP address database 116 corresponding to the second entity 893 and CA 982 In some embodiments, one of cyber assets CA 893 and CA 982 may already exist in entity IP address database 116 corresponding to the second entity, based on a different candidate match pair 306 or previous operation of the fingerprinting process 2 It should be noted that

[0057] For general implementation, devices, systems, and methods for identifying cyber assets belonging to an entity using a democratic matching algorithm have been described. However, the present disclosure moves to specific implementations of these devices, systems, and methods, which relate to identifying domains belonging to a specific entity using a democratic matching algorithm and generating cyber risk mitigation measures based on the identified domains. As described above, any aspect disclosed below with respect to method 500 may be brought to method 300, and vice versa

[0058] 7-8 and 10 show a flowchart of a method 500 for identifying domains associated with a target entity 502 based on a democratic matching algorithm, according to certain non-limiting aspects of the present disclosure, and FIG 11 shows a method 900 for implementing cyber risk mitigation measures based on associated domains. Additionally, FIG 9 shows an example of a match table 700 that may be employed by the method 500.

[0059] 7 and 9, the method 500 may begin by selecting an entity of interest 502 for evaluation. The method may include evaluating multiple domain identification algorithms (e.g., 1 ,a 2 ,…a n )504 1 ,504 2 ,…504 n (collectively “executing 504”) a plurality of candidate domains 506 1 ,506 2 ,…506 n (collectively candidate domains 506). Each candidate domain 506 is identified as a potential asset for the target entity by at least one of the domain identification algorithms. Although Figures 7 and 9 show method 500 executing three or more domain identification algorithms 504, method 500 may be implemented by executing any number of domain identification algorithms, where n is an integer greater than one.

[0060] Domain Identification Algorithm a 1 ,a 2 ,…a n The domain identification algorithm may be any type of rule-based matching algorithm configured to search and analyze public and / or proprietary information to identify domains potentially owned by or otherwise associated with the same entity. 1 ,a 2 ,…a nCandidate domain 506 can be identified by identifying domain matching pairs 702, where one of the domains in the matching pair is always the seed domain (d seed ) of the target entity (the other domain of the matching pair 702 is the candidate domain 506). As used herein, "seed domain" may refer to the primary registered second-level domain of the target entity. For example, the seed domain may be the domain where the target entity's homepage is provided (such as bluevoyant.com, amazon.com, uspto.gov, etc.). In some embodiments, the seed domain of the target entity may be the domain identified as a unique identifier at 102 in FIG. 1 and stored in the entity database 108. Thus, the domain identification algorithms a 1 , a 2 , … a n may be configured to identify candidate domain 506 by searching and analyzing public information and / or proprietary information to identify domains that are potentially owned by or otherwise associated with the same entity as seed domain d seed .

[0061] Each of the domain identification algorithms may employ different methods (e.g., different sets of rules, different sets of parameters, different information sources, or combinations of information sources, etc.). In some embodiments, one or more of the domain identification algorithms may be configured to search and analyze an Internet registration database (e.g., a public database having domain registration data such as a DNS database, a proprietary database having domain registration data such as a WhoisXML API domain database) for domains registered to a particular entity. For example, different algorithms may search and analyze different databases. As another example, a single algorithm may search and analyze multiple databases.

[0062] In various aspects, one or more of the domain identification algorithms may be configured to apply a filter to exclude from the candidate domain 506 a portion of the identified domains having at least some of the same registration information as the seed domain. For example, the domain registration information included in the domain registration database may often include field values such as "REDACTED". Thus, it may result in a large number of identified matches with the seed domain. In some aspects, the applied filter may be configured to exclude matches based on registration fields that include "REDACTED" or similar values. In other aspects, the applied filter may be configured to limit the number of candidate domains 506 to be identified. For example, the domain identification algorithm may be limited to identifying 100,000 or fewer candidate domains 506, such as 10,000, 9,000, 9,000, 7,000, 6,000, 5,000, 4,000, 3,000, 2,000, 1,000, 900, 800, 700, 600, 500, 400, 300, 200, or 100 or fewer candidate domains 506.

[0063] In various aspects, the domain identification algorithm a 1 ,a 2 ,…a n may be configured to employ one or more of the various redirect techniques described in the aforementioned international patent application No. PCT / US2023 / 062894, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS, filed on February 20, 2023, which is hereby incorporated by reference in its entirety.

[0064] Referring mainly to FIG. 9 here, the results 504 of executing various domain identification algorithms may be organized in a match table 700. Each candidate match pair 702 is for a target entity (d seed) includes the seeded domain and candidate domain 506. Each candidate domain (or each matching pair 708 including different candidate domains) 506 1 ,506 2 ,506 3 ,506 4 ,…506 n is sorted along different columns of the matching table 700 and each domain identification algorithm a 1 ,a 2 ,…a n is sorted.

[0065] Referring again mainly to FIG. 7, the method 500 can continue by determining 508 the true match probability P T for each candidate domain 506. Each true match probability P T is the probability that the corresponding candidate domain 506 is a cyber asset of the target entity. The true match probability P T of a particular candidate domain 506 may depend on which of the domain identification algorithms a 1 ,a 2 ,…a n identified the domain. For example, FIG. 8 shows, according to at least one non-limiting aspect of the present disclosure, the true match probability P n of the candidate domain 506 T and a flowchart of a method for determining 508.

[0066] Referring now to FIGS. 8 and 9, the determination 508 of the true match probability P n of the candidate domain 506 T may include a determination 520 of whether each domain identification algorithm a 1 ,a 2 ,…a n identified the candidate domain 506 n (collectively, determination 520). Based on the determination 520, a binary value can be assigned to each domain identification algorithm, and a "1" is assigned to each domain identification algorithm that identified the candidate domain 506 1 ,522 2 ,…502 n (collectively, determination 520) may be included. Based on the determination 520, a binary value can be assigned to each domain identification algorithm, and a "1" is assigned to each domain identification algorithm that identified the candidate domain 506 n and a "0" is assigned to each domain identification algorithm that did not identify the candidate domain 5061 ,522 2 ,…522 n ), candidate domain 506 n For each domain identification algorithm that did not identify, a "0" is assigned (524 1 ,524 2 ,…524 n ). The results of each assignment 522, 524 can be organized in the match table 700. For example, along the row corresponding to the candidate domain 506 n For the domain identification algorithms a 1 , a 2 , and a n to which "1" is assigned, it means that each of these algorithms identified the candidate domain 506 n as a result of their execution 504. As another example, along the row corresponding to the candidate domain 506 2 "0" is assigned 524 to the domain identification algorithms a 1 and a 2 , which means that it was determined that these algorithms did not identify the candidate domain 506 2 .

[0067] Furthermore, referring to FIGS. 8 and 9, to determine the true match probability P T of the candidate domain 506n, for each of the domain identification algorithms a 1 , a 2 ,…a n , a predetermined accuracy coefficient (526 1 ,526 2 ,…526 nmay also include calling (0). As described above, the accuracy coefficient of a given cyber asset identification (e.g., domain identification) algorithm may include an accuracy coefficient representing the probability that the algorithm returns a true positive result (i.e., the probability that the algorithm correctly identifies a candidate domain belonging to the target entity), and / or an accuracy coefficient representing the probability that the algorithm returns a true negative result (i.e., the probability that the algorithm correctly omits a domain that does not belong to the target entity). In other aspects, the accuracy coefficient for a given cyber asset identification (e.g., domain identification) algorithm can include another type of weighting coefficient for the algorithm. The accuracy coefficient may be predetermined based on training a cyber asset identification algorithm (e.g., a domain identification algorithm) against one or more ground truth sets of cyber assets (e.g., ground truth domains). Various machine learning and / or statistical methods may be used to determine the accuracy coefficient for each algorithm. An example of a method 800 for determining the accuracy coefficient of a domain identification algorithm will be described below with respect to FIG. 10.

[0068] Referring further to FIGS. 8 and 9, determining the true match probability P n for candidate domain 506 T may further include calculating the true match probability 528 based on the binary values assigned to each domain identification algorithm and the accuracy coefficient for each domain identification algorithm. As described above, the true match probability P T may be calculated or determined in other ways using various different methods. For example, using Equation 1 above, the true match probability P n for candidate domain 506 T may be calculated. As another example, different or additional accuracy coefficients for the domain identification algorithm are introduced into Equation 1 to perhaps P for the true match of candidate domain 506 n T(For example, different or additional weighting factors and / or probability factors determined based on a model trained using a given ground truth) can be calculated.

[0069] Referring again mainly to FIG. 7 and also to FIG. 9, the true match probability P for each candidate domain 506 T After being determined, method 500 can continue by determining 510 whether the true match probability P for each candidate domain 506 T exceeds a predetermined threshold. In some aspects, the predetermined threshold may be selected by a security analyst or other user tasked with performing the footprinting process. In other aspects, the predetermined threshold may be automatically determined based on machine learning and / or statistical methods by comparing the trained model to a given ground truth. In still other aspects, the predetermined threshold may be 0.70 or greater, for example, 0.75, 0.80, 0.85, 0.90, 0.91, 0.92, 0.93, 0.94, 0.95, 0.96, 0.97, 0.98, 0.99, 0.995, 0.996, 0.997, 0.998 or greater, or 0.999 or greater.

[0070] The method can continue by classifying 512 each candidate domain 506 having a true match probability P that exceeds the predetermined threshold as an associated domain. As used herein, "associated domain" can refer to a domain that is considered an asset of the target entity. For example, referring mainly to FIG. 9 and also to FIG. 7, when a true match probability threshold of 0.90 is applied at 510, candidate domains 506 T (d 1 ) and 506 1 ) and 506 n (d n ) are candidate domains 506 1 (d 1 ) and 506 n having a true match probability P greater than 0.90 TSince it has, 512 is classified as a related domain. In some embodiments, method 500 may also include generating an entity domain database 550 for a target entity based on the associated domains. The entity domain database 550 may be one of the entity domain databases 116 described above with respect to FIG. 3. As will be described in detail below with respect to FIG. 11, various cyber risk mitigation measures may be generated based on the entity domain database 550. 1 It may be one of them. As will be described in detail below with respect to FIG. 11, various cyber risk mitigation measures may be generated based on the entity domain database 550.

[0071] Referring now to FIG. 10, a flowchart of a method 800 for determining an accuracy coefficient for a domain matching algorithm a 1 , a 2 , … a n is illustrated in accordance with at least one non-limiting embodiment of the present disclosure. In one embodiment, the accuracy coefficient determined by method 800 may be a predetermined accuracy coefficient 526 for determining the true match probability P T for each candidate domain 506, as described with reference to FIGS. 7 and 8 above, as part of method 500.

[0072] Method 800 begins by selecting 802 a known entity having a known ground truth domain. As used herein, a "ground truth domain" can refer to a domain that is known or otherwise confirmed for the cyber assets of the selected 802 known entity. For example, the ground truth domain of a given entity may be curated by a security analyst or selected in some other way. In some embodiments, method 800 may include identifying the ground truth domain of the selected 802 known entity.

[0073] Method 800 executes 804 each of the domain matching algorithms a 1 , a 2 , … a n respectively 1 , 804 2 , … 804n (Collectively, execution 804) can be continued by identifying a plurality of training domains 806. The executed 804 algorithm a 1 ,a 2 ,…a n can be the same algorithm as that used to identify the candidate domain 506, as described with respect to FIG. 7. Further, similar to the candidate domain 506, each training domain 806 is identified as a potential asset of a known entity by at least one of the domain identification algorithms a 1 ,a 2 ,…a n and each domain identification algorithm identifies a subset of the training domains 806.

[0074] Method 800 can be continued by comparing the subset of training domains 806 identified by each domain identification algorithm a 1 ,a 2 ,…a n with the known ground truth domain 808 of the known entity. The known ground truth domain 808 may be all or substantially all of the domains owned by the known entity. Thus, by comparing the subsets of training domains 806 identified by a particular domain identification algorithm, the accuracy of the algorithm can be determined. For example, the accuracy of a particular domain identification algorithm may be based on the ground truth domain that the algorithm was unable to identify as part of the training domains 806. Further, the accuracy of a particular domain identification algorithm may be based on the extra training domains 806 identified by an algorithm that are not part of the ground truth domain 808.

[0075] In one aspect, method 800 can continue by selecting 802 different known entities, executing 804 the domain identification algorithm for that entity, and comparing 810 a subset of the training domains 806 identified by each algorithm to the known ground truth domain 808 of that entity. By repeating this process for multiple entities, a more refined accuracy for each domain identification algorithm can be determined.

[0076] Method 800 can continue by determining 814 an accuracy coefficient for each domain identification algorithm based on a comparison 810 of a subset of the training domains 806 identified by the domain identification algorithm to the ground truth domain 808. Various statistical and / or machine learning techniques can be used to determine 814 the accuracy coefficient for a given domain identification algorithm. For example, the training domains 806 and the domain identification algorithm can be organized into a table similar to the match table 700 discussed above with respect to FIG. 9 to generate a binary category feature vector. In some aspects, this binary category feature vector can be used to determine probabilities associated with the performance of each algorithm (e.g., using a naive regression model, a logistic regression model, etc.). In some aspects, machine learning techniques such as a support vector machine (SVM) model can be used to determine the accuracy coefficient for each domain identification algorithm.

[0077] Next, referring to FIG. 4, a diagram of a system 2000 is shown that is configured to identify cyber assets across multiple entities based on a democratic matching algorithm and generate cyber risk mitigation measures, according to at least one non-limiting aspect of the present disclosure. System 2000 may be similar in many respects to system 1000 described above with respect to FIG. 1 (having corresponding reference characters representing corresponding components). For example, system 2000 may include a cyber risk management provider server 1002 comprising a memory 1004 and a processor 1006 for generating a footprint module 1020. The footprint module 1020 includes one or more cyber asset identification (CA ID) modules 1024 1 , 1024 2 , … 1024 n (collectively, the “cyber asset identification modules 1024”), a democratic matching algorithm module 1022 (democratic module 1022), and / or a training module 1026.

[0078] System 2000 further includes a cloud server 2002 communicatively coupled via a network 1008 to the cyber risk management provider server 1002 and various entities 1010 1 , 1010 2 , … 1010 n via the network 1008. Similar to the footprint module 1020, the cloud server 2002 includes one or more cyber asset identification (CA ID) modules 2024 1 , 2024 2 , … 2024 n (collectively the “cyber asset identification modules 2024”), a democratic matching algorithm module 2022 (democratic module 2022), and / or a training module 2026.

[0079] The various cyber asset identification (CA ID) modules 1024, 2024 are the various cyber asset identification algorithms a described above with respect to FIGS. 5 - 10 1 , a 2,…a n (e.g., domain identification algorithm d 1 ,d 2 ,…d n ) can be used to execute (304, 504). In some embodiments, each cyber asset identification module 1024, 2024 may execute a different cyber asset identification algorithm.

[0080] The democratic matching algorithm modules 1022, 2022 can be used to execute various steps of the democratic matching algorithm described above with respect to FIGS. 5-10 (e.g., determining the true match probability P T of candidate match pairs / candidate domains 308, 508, determining whether the true match probability P T exceeds a predetermined threshold 310, 510, determining whether the true match probability P T exceeds a predetermined threshold, adding the cyber assets of 312 to the cyber asset database 116, classifying the candidate domains of 512 as related domains, etc.).

[0081] The training modules 1026, 2026 can be used to execute various steps of method 800 to determine an accuracy coefficient for each of the cyber asset identification algorithms (e.g., domain identification algorithm) as described above with respect to FIGS. 5 and 10.

[0082] In various aspects, the cyber asset identification module 1024, the democratic matching algorithm module 1022, and the training module 1026 can be implemented via on-site based software instances configured to perform the respective functions of the modules. In various other aspects, the cyber asset identification module 2024, the democratic module 2022, and the training module 2026 can be implemented via cloud-based software instances configured to perform the respective functions of the modules. Any combination of the cloud-based modules 1022, 1024, 1026, 2022, 2024, 2026 can be used to implement the methods 300, 500, and 800 described below.

[0083] As described above, various cyber risk mitigation measures can be generated based on the results of the democratic matching algorithm described in method 500 of FIG. 7. For example, FIG. 11 shows a flowchart of a method 900 for generating cyber risk mitigation measures based on an entity domain database 550 generated by method 500, in accordance with at least one non-limiting aspect of the present disclosure.

[0084] Referring to FIG. 11, method 900 can include, for example, investigating the domains included in entity domain database 550 for cyber security threats, such as an investigation 942 of cyber threats related to email, an investigation 958 of cyber threats related to host configuration, an investigation 966 of cyber threats related to traffic, or an investigation of additional types of cyber threats.

[0085] In some aspects, the entity domain database 550 may include a domain associated with the email configuration of the target entity 502. For example, an entity associates an email address with a well-known domain (e.g., the email address "billg@microsoft.com" and the domain "microsoft.com"). Thus, the entity domain database 550 may be investigated 924 for email-related security threats. Email security-related threats may include, for example, the use of an email configuration lacking an email authentication method or an email configuration with an incorrectly configured authentication method. There are various methods of domain-based email authentication, such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and other similar sender domain-based methods (such as DMARC, BIMI, etc.) that enable an email recipient to verify an email.See Kitterman, S., Sender Policy Framework(SPF)for Authorizing Use of Domains in Email, Version 1, RFC 7208, DOI 10.17487 / RFC7208(April 2014), https: / / www.rfc-editor.org / info / rfc7208; Crocker, D., Ed., Hansen, T., Ed., and M. Kucherawy, Ed., DomainKeys Identified Mail(DKIM)Signatures, STD 76, RFC 6376, DOI 10.17487 / RFC6376,(September 2011), https: / / www.rfc-editor.org / info / rfc6376; and Rose et al., Trustworthy Email, NIST Special Publication 800-177 Rev. 1,(Feb. 2019), https: / / nvlpubs.nist.gov / nistpubs / SpecialPublications / NIST.SP.800-177r1.pdf, each of which is incorporated herein by reference in its entirety. Thus, in some aspects, investigating 942 cyber risks associated with email may include analyzing domains within an entity domain database 550 for use of email authentication methods. However, email authentication can be misconfigured such that the authentication method is not secure. Thus, in other aspects, investigating 942 cyber threats associated with email may include analyzing domains within an entity domain database 550 for use of misconfigured email authentication methods. In other aspects, various other email security controls may be investigated 942. For example, investigating 942 cyber threats associated with email may include evaluating an entity's use of spam filters, malware detection, phishing protection, and the like.

[0086] Referring further to FIG. 11, method 900 can continue by generating 944 one or more cyber risk mitigation measures based on the identified cyber threats associated with the electronic mail. Generating 944 one or more cyber risk mitigation measures can include, for example, automatically implementing 946 a modified electronic mail authentication configuration, applying 948 an automatic labeling indicating that the electronic mail may not be authentic, automatically rejecting and / or quarantining 950 an electronic mail that may be exposed to the cyber threat, generating 952 an alert, generating 954 a cyber threat database, and / or generating 956 a cyber security risk report.

[0087] In various aspects, generating 944 one or more cyber risk mitigation measures can include automatically implementing 946 a modified electronic mail authentication configuration based on an investigation 942 of the cyber threats associated with the electronic mail. For example, referring now to FIGS. 1 and 11, the selected entity 502 can be an entity 1010 1 that contracts with a cyber risk management provider (i.e., tenant entity 1010 1 ). The cyber risk management provider server 1002 can have write access to at least some of the cyber assets 1012 1 of the tenant entity 1010 1 , 1012 2 , … 1012 n thereby enabling the cyber risk management provider to cause an update to the electronic mail configuration associated with the domain of the tenant entity 1010 1 . In response to identifying a domain that includes an electronic mail configuration lacking an authentication method or having a misconfigured authentication method, the cyber risk management provider server 1002 can cause the tenant entity 1010 1Instructions can be automatically generated that are sent to the cyber asset 1012 (e.g., via network 1008). The instructions can cause an automatic update of an email configuration associated with a specified domain. The modified email authentication configuration may include a new email authentication configuration and / or a modified email authentication configuration.

[0088] Referring further to FIGS. 1 and 11, in various aspects, generating 944 one or more cyber risk mitigation measures may include applying 948 automatic labeling based on an investigation 942 of email-related cyber threats. For example, tenant entity 1010 1 may contract with a cyber risk management provider to perform a cyber security risk analysis of other entities 1010 2 ,…1010 n The selected entity 502 may be one of the other entities 1010 2 …1010 n and may be analyzed by a cyber risk management provider. The cyber risk management provider server 1002 may have write access to at least some of the cyber assets 1012 1 of tenant entity 1010 1 ,1012 2 ,…1012 n thereby enabling the cyber risk management provider to cause an update of the email configuration associated with the domain of tenant entity 1010 1 In response to identifying a domain (e.g., cyber asset 1014 of other entity 1010 2 ) that includes an email configuration lacking an authentication method or having a misconfigured authentication, the cyber risk management provider server 1002 can automatically generate instructions that are sent (e.g., via network 1008) to the cyber asset 1012 of tenant entity 1010 1 The instructions can be for the tenant entity 1010 1To the cyber asset 1012 of 2 tenant entity 1010 from the exposed domain (e.g., cyber asset 1014) of another entity 1010 1 electronic mails received by can have automatic labeling applied. In some aspects, the automatic labeling can be applied to electronic mails received from all domains (all cyber assets 1014 2 in the entity domain database 550 of another entity 1010 1 , 1014 2 , … 1014 n ). The automatic labeling can be text added to the received electronic mail indicating the likelihood that the mail is not authentic.

[0089] Further referring to FIGS. 1 and 11, in various aspects, generating 944 one or more cyber risk mitigation measures can include rejecting the receipt of an electronic mail and / or quarantining 950 the received electronic mail based on an investigation 942 of cyber threats related to the electronic mail. For example, the cyber risk management provider server 1002 can automatically generate an instruction (e.g., via the network 1008) to be sent to the cyber asset 1012 (e.g., an electronic mail server) of the tenant entity 1010 1 to reject the receipt of electronic mails sent from the exposed domain (e.g., cyber asset 1014) of another entity 1010 2 . In some aspects, the instruction can cause the cyber asset 1012 of the tenant entity 1010 1 to quarantine electronic mails received from the exposed domain (e.g., cyber asset 1014) of the entity 1010 2 . This can enable the quarantined mails to be investigated for authenticity.

[0090] Referring further to FIGS. 1 and 11, in various aspects, generating 944 one or more cyber risk mitigation measures may include generating 952 an alert based on an investigation 942 of cyber threats related to email. The alert may be sent to a cyber risk management provider or another party claimed to manage the cyber assets of a particular tenant entity 1010 1 and may include a message indicating, for example, that an email configuration has been compromised, that a potentially unauthenticated email has been sent, and / or that a potentially unauthenticated email has been received. In some aspects, the alert may include instructions to take specific actions in response to a identified cyber threat related to email.

[0091] Referring further to FIGS. 1 and 11, in various aspects, generating 944 one or more cyber risk mitigation measures may include generating a cyber threat database 954 based on an investigation 942 of cyber threats related to email. The cyber threat database 954 may include a log of each domain from the entity domain database 550 identified as being exposed to cyber threats related to email. The cyber threat database 954 or a portion thereof may be referenced by a security analyst of a cyber risk management provider or another party claimed to manage the cyber assets of a particular tenant entity 1010 1 For example, the cyber threat database can be used to identify domains that require email configuration updates.

[0092] Referring further to FIGS. 1 and 11, in various aspects, generating 944 one or more cyber risk mitigation measures may include generating a cyber security risk report 956 based on an investigation 942 of cyber threats related to email. The cyber security risk report 956 is based on the identified cyber threats related to email and is for a target entity 502 (e.g., tenant entity 10101 or another entity 1010 2 ,…1010 n ) can include an assessment of cyber threat exposure. For example, the use of email authentication by an entity can be an important factor in assessing how well the entity's cyber assets are protected from cyber threats such as malicious email forgery.

[0093] Referring again primarily to FIG. 11, in various aspects, the entity domain database 550 can include domains associated with (e.g., addressed or identified by) a computer that is owned, controlled, or otherwise used by a selected entity 502. Thus, referring to FIG. 11, the domain database 904 can conduct an investigation 958 regarding host configuration-related security threats. Host configuration-related threats can include insecure configurations and / or operations of computers associated with domains within the domain database 550. There are many types of computing services and executions of computing services that can cause insecure configurations or operations of a computer, and the list is constantly growing. Further, there are numerous Internet ports and related services that can be scanned for host-related security threats.

[0094] As an example, conducting an investigation 958 regarding host configuration-related security threats can include accessing one or more servers associated with a selected entity 502 (e.g., "www.example.com") and retrieving information such as server type, software release version, available encryption parameters, or other security-related information presented by the server. This information can be analyzed to identify security threats such as the execution of a server with known security vulnerabilities, the use of deprecated cryptographic services, or a lack of control over access to sensitive information.

[0095] As another example, investigating security threats related to host configurations 958 may include identifying non-web server services that are not inherently secure and are used by host computers associated with domains within the entity domain database 550. These threats may be identified by searching for services, software release versions, available encryption parameters, or other security-related information. Non-secure services may include, for example, old versions of Telnet (addressable by computer, e.g., as "telnet.example.com") that transmit usernames and passwords without encryption of sensitive information or without an open database. See Unprotected elasticsearch Server Leaks 5 Billion Records, CISOMAG (March 20, 2020), which is hereby incorporated by reference in its entirety. Additionally, non-secure services may include, for example, the File Transfer Protocol (FTP) as seen at "ftp.example.com". FTP is known to suffer from a number of security vulnerabilities. See Nate Lord, What is FTP Security▼question mark▲ Securing BMS usage, Digital Stream (Sept. 7, 2018), which is hereby incorporated by reference in its entirety. Thus, investigating security threats related to host configurations 958 may include analyzing host computers associated with domains within the entity domain database 550 for the use of non-secure configurations or operations.

[0096] 11 , the method 900 may continue by generating 960 one or more cyber risk mitigation actions based on the host configuration-related cyber threats identified at 958. Various actions that may be generated 960 include, for example, automatically executing 962 the corrected host configuration, generating 964 an alert, generating 954 a cyber threat database, and / or generating 956 a cyber security risk report.

[0097] 1 and 11 , in various aspects, generating 960 the one or more cyber risk mitigation measures may include automatically executing 962 a modified host configuration based on the investigation 958 of the host configuration-related cyber threats. For example, as described above, the subject entity 502 may communicate with a cyber risk management provider (i.e., a tenant entity 1010) to determine whether the cyber risk management provider is a cyber risk management provider. 1 ) to contract with Entity 1010 1 The cyber risk management provider server 1002 may 1 Cyber ​​Assets 1012 1 ,1012 2 ,…1012 n , whereby the cyber risk management provider may have write access to at least some of the tenant entities 1010. 1 In response to identifying a domain associated with a host computer that uses an insecure configuration, the cyber risk management provider server 1002 may cause an update of the host computer configuration associated with the tenant entity 1010. 1 The domain may automatically generate instructions that are sent (e.g., over the network 1008) to the cyber assets 1012 of the identified domain. The instructions may cause an automatic update of the configuration of the host computers associated with the identified domain. The modified host configuration may include, for example, a new version of the insecure host configuration or a replacement service for the insecure host configuration.

[0098] Referring further to FIGS. 1 and 11, in various aspects, generating 960 one or more cyber risk mitigation measures may include generating 964 an alert based on an investigation 958 of cyber threats related to the host configuration. The alert may be sent to a cyber risk management provider or another party claimed by managing the cyber assets of a particular tenant entity 1010 1 . In some aspects, the alert may include a message indicating, for example, that an insecure host configuration has been detected, that a computer using the insecure host configuration has been used to send or receive information, and / or that a domain associated with a computer using the insecure host configuration has been communicated. In some aspects, the alert may include an instruction to take a particular action in response to a cyber threat associated with the identified host configuration.

[0099] Referring further to FIGS. 1 and 11, in various aspects, generating 960 one or more cyber risk mitigation measures may include generating 954 a cyber threat database based on an investigation 942 of cyber threats related to the host configuration. The cyber threat database 954 may include a log of each domain from the domain database 550 identified as being exposed to cyber threats related to the host configuration. The cyber threat database 954 or a portion thereof may be referenced by a security analyst of the cyber risk management provider or another party claimed by managing the cyber assets of a particular tenant entity 1010 1 . For example, the cyber threat database can be used to identify domains associated with insecure host configurations that need to be updated.

[0100] Referring further to FIGS. 1 and 11, in various aspects, generating one or more cyber risk mitigation measures 960 can include generating a cyber security risk report 956 based on an investigation 942 of host configuration-related cyber threats. The cyber security risk report 956 can include an assessment of the cyber threat exposure of a selected entity 502 (e.g., tenant entity 1010 1 , or another entity 1010 2 ,…1010 n ) based on the identified host configuration-related cyber threats.

[0101] Referring again primarily to FIG. 11, in various aspects, the domain database 550 can include domains associated with (e.g., addressed or identified by) computers that are owned, controlled, or otherwise used by a selected entity 502. These computers can attempt to send or receive data with malicious actors (e.g., groups or individuals with malicious intent such as access to or destruction of data). Thus, referring to FIG. 11, the entity domain database 550 can conduct an investigation 966 of traffic-related security threats. To conduct an investigation 966 of traffic-related security threats, data related to the public discovery of malicious actors 968 and / or data related to the proprietary discovery of malicious actors 970 can be searched to identify domains, IP addresses, modus operandi, or other indicators that can be used to identify malicious actors. Next, the cyber assets of the target entity 502 (e.g., domains within the entity domain database 550, computers associated with the domains within the entity domain database 550) can be monitored for communication with malicious actors.

[0102] To identify traffic-related cyber threats involving malicious intrusion traffic, investigating traffic-related cyber threats 966 may include identifying a domain, or IP address, associated with a malicious actor that attempts to send or is about to send data to a domain within an entity domain database 550. For example, the IP address "1.2.3.4" may be known to be associated with a malicious actor based on data related to the public discovery of the malicious actor 968 and / or data related to the proprietary discovery of the malicious actor 970. The IP address "1.2.3.4" may be observed as attempting to request a DNS lookup or connect to the IP address of the domain "ftp.example.com" of the associated domain 922 within the entity domain database 550. Based on this request, the associated domain 922 "ftp.example.com", and / or the subject entity 502 may be identified with a certain degree of confidence as potential targets of interest to a malicious actor. If more interactions between "ftp.example.com" and the IP address "1.2.3.4" are observed, the likelihood that the domain "ftp.example.com", and / or the target entity 502 is a potential target of interest may increase. As another example, network data such as netflow logs, or packet captures, can be used to observe a long Internet connection between the IP address of a malicious actor and a computer associated with an associated domain 922 such as "payroll.example.com". Based on this network data, the associated domain 922 (payroll.example.com), and / or the target entity 502 may be identified with a certain degree of confidence as potential targets of interest to a malicious actor.

[0103] To identify traffic-related cyber threats with malicious external traffic, investigating traffic-related cyber threats 966 may include identifying computers associated with domains in an entity domain database 550 that attempt to connect to a domain associated with a malicious actor, or an IP address. For example, the IP address of the domain "evilhackercontroller.com" may be known to be associated with a malicious actor based on data related to the public discovery of the malicious actor 968 and / or data related to the proprietary discovery of the malicious actor 970. A computer acting as a boundary DNS resolver linked to an associated domain 922 such as "dns.example.com" is observed and may request the IP address of the domain "evilhackercontroller.com. Based on this request, the associated domain 922 "example.com", and / or the target entity 502 may be identified with a high level of confidence as a target of a malicious actor.

[0104] Referring further to FIG. 11, the method 900 can continue by generating 972 one or more cyber risk mitigation measures based on the identified traffic-related cyber threats. The various measures 972 that may be generated include, for example, automatically executing 974 a modified configuration, generating 976, generating a cyber threat database 954, and / or generating a cybersecurity risk report 956.

[0105] Referring again to FIGS. 1 and 11, in various aspects, generating 972 one or more cyber risk mitigation measures may include automatically executing 974 a modified host configuration based on an investigation 966 of traffic-related cyber threats. For example, as described above, the target entity 502 contracts with a cyber risk management provider (i.e., tenant entity 1010 1 ) entity 10101 It may also be. The cyber risk management provider server 1002 is the tenant entity 1010 1 's cyber assets 1012 1 , 1012 2 , … 1012 n may have write access to at least some of them, whereby the cyber risk management provider causes the tenant entity 1010 1 to be able to cause an update of the computer associated with the domain of. In response to identifying a domain associated with a computer that is the target of a traffic-related cyber threat, the cyber risk management provider server 1002 is the tenant entity 1010 1 may automatically generate an instruction (e.g., via network 1008) to be sent to the cyber assets 1012 of. The instruction may cause an automatic update of the configuration of the computer associated with the target domain. The modified configuration may include, for example, the termination of a connection between the target domain and a malicious actor, or the blocking of an attempted connection.

[0106] Referring further to FIGS. 1 and 11, in various aspects, generating 972 one or more cyber risk mitigation measures may include generating 976 an alert based on an investigation 966 of traffic-related cyber threats. The alert may be sent to the cyber risk management provider or another party claimed to manage the cyber assets of a particular tenant entity 1010 1 .

[0107] Referring further to FIGS. 1 and 11, in various aspects, generating 972 one or more cyber risk mitigation measures may include generating 954 a cyber threat database based on an investigation 966 of traffic-related cyber threats. The cyber threat database 954 may include logs of each domain from the entity domain database 550 that have been identified as being exposed to traffic-related cyber threats. The cyber threat database 954 or a portion thereof may be referred to by a security analyst of a cyber risk management provider or by another party that is claimed to manage the cyber assets of a particular tenant entity 1010 1 For example, the cyber threat database can be used to identify domains associated with insecure host configurations that need to be updated.

[0108] Referring further to FIGS. 1 and 11, in various aspects, generating 972 one or more cyber risk mitigation measures may include generating 956 a cyber security risk report based on an investigation 966 of traffic-related cyber threats. The cyber security risk report 956 may include an assessment of cyber threat exposure of a target entity 502 (e.g., tenant entity 1010 1 , or another entity 1010 2 ,…1010 n ) based on the identified traffic-related cyber threats.

[0109] Referring again to FIG. 5, (i) execute a plurality of cyber asset identification algorithms 304 to identify a plurality of candidate match pairs 306, where each match pair 306 includes two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the same entity, and (ii) the true match probability P T is the probability that the two cyber assets of the candidate match pair 306 are assets of the same entity, and the true match probability P Tis the true match probability P of each candidate match pair 306 based on which cyber asset identification algorithm identified the candidate match pair T is determined 308, and (iii) for at least some of the candidate match pairs 306, it is determined 310 that the true match probability P T is greater than or equal to a predetermined threshold, and (iv) at least one 312 of the cyber assets from each candidate match pair 306 having a true match probability P T greater than or equal to the predetermined threshold is added to the cyber asset database 116 corresponding to the entity used to identify the match pair 306, by a non - stationary method, the cyber assets owned or otherwise managed by a particular entity can be identified more accurately and completely.

[0110] Furthermore, this non - routine method executes tasks on a scale that is not actually feasible in the human mind, and the method 300 executes 304 multiple different cyber asset (e.g., domain) identification algorithms to discover which of millions of existing domains and / or other cyber assets are potential assets of a particular entity. Further, the true match probability P used in this non - routine method TIt may be calculated using one or more accuracy coefficients associated with each cyber asset identification algorithm. In some aspects, using machine learning techniques provides the technical advantage of determining an accuracy coefficient for each of the cyber asset identification algorithms, enabling more accurate cyber asset classification based on training using ground truth cyber assets. Further, referring to FIGS. 3 and 5, the generation of the cyber asset database 116 is integrated into a practical application by generating 208 one or more cyber risk mitigation measures (e.g., implementing corrective measures 214, generating alerts 216, generating a cyber security risk report 210, generating a cyber asset threat, vulnerability, and risk database 212). Similarly, referring to FIG. 11, the generation of the entity domain database 550 is integrated into a practical application by generating one or more automated cyber risk mitigation measures of 944, 960, 972 (e.g., implementing improved configurations 946, 962, 974, generating alerts 952, 964, 976, generating a cyber security risk report 956, generating a cyber threat database 954).

[0111] Referring now to FIG. 12, a diagram of a computing system 9000 is shown in accordance with at least one non-limiting aspect of the present disclosure. As will be described below, the computing system 9000 and the various components included therein can be used to implement the various components of the systems 1000, 2000 described above in connection with FIGS. 1 and 4, and can also be used to store and execute any of the instructions of the various methods described above in connection with FIGS. 2-3 and 5-11.

[0112] According to a non-limiting aspect of FIG. 12, computer system 9000 may include a bus 9002 (i.e., an interconnect), one or more processors 9004, main memory 9006, read-only memory 9008, removable storage media 9010, mass storage 9012, and one or more communication ports 9014. As should be understood, components such as removable storage media are optional and not required in all systems. Communication port 9014 may be connected to one or more networks through which computer system 9000 may receive and / or transmit data.

[0113] As used herein, "processor" can mean one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, graphics processing units (GPUs), or similar devices, or any combination thereof, regardless of architecture. An apparatus for performing a process may include, for example, a processor and those devices such as input devices and output devices appropriate for performing the process.

[0114] The processor 9004 can be any known processor, such as but not limited to processors manufactured and / or sold by INTEL (registered trademark), AMD (registered trademark), or MOTOROLA (registered trademark), which are generally well-known to those skilled in the art and clearly defined in the literature. The communication port 9014 can be any of, for example, an RS-232 port for use in a modem-based dial-up connection, a 10 / 100 Ethernet port, a gigabit port using copper or fiber, or a USB port. The communication port 9014 may be selected according to the network, such as a local area network (LAN), a wide area network (WAN), a CDN, or any network to which the computer system 9000 is connected. The computer system 9000 may communicate with peripheral devices (such as a display screen 9016, an input device 9018) via an input / output (I / O) port 9020.

[0115] The main memory 9006 can be a random access memory (RAM) or any other dynamic storage device commonly known in the art. The read-only memory 9008 can be any static storage device, such as a programmable read-only memory (PROM) chip, for storing static information such as instructions of the processor 9004. Information and instructions can be stored using a mass storage device 9012. For example, a hard disk such as the Adaptec (registered trademark) family of small computer serial interface (SCSI) drives, an optical disk, an array of disks such as a redundant array of independent disks (RAID) such as the Adaptec (registered trademark) family of RAID drives, or any other mass storage device can be used.

[0116] Bus 9002 communicatively couples processor 9004 to other memory, storage, and communication blocks. Bus 9002 can be, for example, a PCI / PCI-X, SCSI, Universal Serial Bus (USB)-based system bus (or others) depending on the storage devices used. Removable storage medium 9010 can be any kind of external hard drive, floppy drive, Iomega® Zip drive, Compact Disc Read Only Memory (CD-ROM), Compact Disc Rewritable (CD-RW), Digital Versatile Disc Read Only Memory (DVD-ROM), and the like.

[0117] Aspects described herein may be provided as one or more computer program products, which may include a machine-readable medium having instructions stored thereon, which may be used to program a computer (or other electronic device) to perform a process. As used herein, the term "machine-readable medium" refers to any medium, multiple media, or combination of different media that participates in providing data (e.g., instructions, data structures) that can be read by a computer, processor, or similar device. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks and other persistent memory. Volatile media includes dynamic random access memory, which typically constitutes a computer's main memory. Transmission media includes coaxial cables, copper wire, and fiber optics, including the wires that make up a system bus coupled to a processor. Transmission media can include acoustic, light, and electromagnetic radiation, such as that generated during radio frequency (RF) and infrared (IR) data communications, or transmitted thereby.

[0118] Machine-readable media can include, but are not limited to, floppy disks, optical disks, CD-ROMs, magneto-optical disks, ROMs, RAMs, erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic or optical cards, flash memories, or other types of media / machine-readable media suitable for storing electronic instructions. Further, the aspects described herein may also be downloaded as a computer program product, and the program may be transferred from a remote computer to a requesting computer by a data signal embodied in a carrier wave or other propagation medium via a communication link (e.g., a modem or network connection).

[0119] Various forms of computer-readable media may be involved in carrying data (e.g., a sequence of instructions) to a processor. For example, the data may be (i) delivered from RAM to the processor, (ii) carried on a wireless transmission medium, (iii) formatted and / or transmitted according to a number of formats, standards, or protocols, and / or (iv) encrypted in any of a variety of ways well known in the art. The computer-readable media can store program elements (in any suitable form) appropriate for performing the methods.

[0120] As shown, main memory 9006 is encoded with an application 9022 that supports the functions discussed herein (the application 9022 may be an application that provides some or all of the functions of the CD service described herein, including client applications). The application 9022 (and / or other resources described herein) may be embodied as software code, such as data, and / or logical instructions (e.g., code stored in memory or on another computer-readable medium such as a disk) that support processing functions according to different aspects described herein.

[0121] During operation of one aspect, processor 9004 accesses main memory 9006 via the use of bus 9002 to start, execute, run, interpret, or otherwise execute the logical instructions of application 9022. Execution of application 9022 generates processing functionality for services related to the application. In other words, process 9024 represents one or more portions of application 9022 that operate within or on processor 9004 within computer system 9000.

[0122] In addition to process 9024 that performs (carries out) operations as discussed herein, it should be noted that other processes described herein may include application 9022 itself (i.e., logical instructions and / or data that are unexecuted or non-executing). Application 9022 may be stored on a computer-readable medium (e.g., a repository) such as a disk, or within an optical medium. According to other aspects, application 9022 may also be stored in a memory-type system such as firmware, read-only memory (ROM), or executable code within main memory 9006 (e.g., within random access memory, or RAM) as in this example of execution. For example, application 9022 may also be stored on removable storage medium 9010, read-only memory 9008, and / or mass storage device 9012.

[0123] Those skilled in the art will understand that computer system 9000 may also include other processes, such as an operating system that controls the allocation and use of hardware resources, and / or software and hardware components.

[0124] The various aspects of the subject matter described herein are set forth in the numbered clauses below.

[0125] Clause 1: A method for identifying cyber assets and implementing cyber risk mitigation measures, comprising: selecting a target entity for evaluation; executing a plurality of domain identification algorithms to identify a plurality of candidate domains, each candidate domain being identified as a potential asset of the target entity by at least one of the domain identification algorithms; determining a true match probability for each candidate domain, the true match probability being the probability that the candidate domain is an asset of the target entity and being based on which of the domain identification algorithms identified the candidate domain; classifying candidate domains having a true match probability equal to or greater than a predetermined threshold as related domains, each related domain being considered an asset of the target entity; generating an entity asset database of the target entity based on the related domains; and generating cyber risk mitigation measures based on the entity asset database.

[0126] Clause 2: The method according to Clause 1, wherein the true match probability is further based on a plurality of accuracy coefficients, each accuracy coefficient corresponding to one of the domain identification algorithms.

[0127] Clause 3: The method according to any one of Clauses 1 to 2, wherein determining the true match probability for each candidate domain comprises: assigning binary values to each domain identification algorithm, one binary value being assigned to each domain identification algorithm that identifies the candidate domain and zero being assigned to each domain identification algorithm that does not identify the candidate domain; and calculating the true match probability based on the binary values assigned to the domain identification algorithms and the accuracy coefficients for the domain identification algorithms.

[0128] Clause 4: Further including determining a precision coefficient, where determining the precision coefficient includes selecting a known entity, identifying the ground truth domain for the known entity, the ground truth domain being a domain known to be an asset of the known entity, executing a plurality of domain identification algorithms to identify a plurality of training domains, each training domain being identified as a potential asset of the known entity by at least one of the domain identification algorithms, each domain identification algorithm identifying a subset of the training domains, and comparing the subset of the training domains identified by each domain identification algorithm with the ground truth domain, the method according to any one of Clauses 1 to 3.

[0129] Clause 5: The method according to any one of Clauses 1 to 4, where determining the precision coefficient further includes using machine learning techniques to determine a precision coefficient for each domain identification algorithm based on the comparison between each subset of the training domains and the ground truth domain.

[0130] Clause 6: The method according to any one of Clauses 1 to 5, where adopting machine learning techniques includes adopting a support vector machine (SVM) model.

[0131] Clause 7: The method according to any one of Clauses 1 to 6, where each of the plurality of domain identification algorithms adopts a different method for identifying candidate domains.

[0132] Clause 8: The method according to any one of Clauses 1 to 7, where executing a plurality of domain identification algorithms to identify a plurality of candidate domains includes identifying a seed domain of the target entity, and identifying, by each of the domain identification algorithms, domains potentially associated with the same entity as the seed domain.

[0133] Clause 9: The method according to any one of Clauses 1 to 8, wherein identifying a plurality of candidate domains by executing a plurality of domain identification algorithms includes identifying the seed domain of the target entity and, by at least one of the domain identification algorithms, searching public data, proprietary data, or a combination thereof to identify a domain having at least a part of the same registration information as the seed domain.

[0134] Clause 10: The method according to any one of Clauses 1 to 9, further including applying a filter so as to exclude, from the identified domains having at least a part of the same registration information as the seed domain, a part of the identified domains that are identified as candidate domains by at least one of the domain identification algorithms.

[0135] Clause 11: The method according to any one of Clauses 1 to 10, wherein applying a filter includes excluding a domain containing edited registration data.

[0136] Clause 12: The method according to any one of Clauses 1 to 11, further including investigating an entity asset database to identify related domains linked to devices constituting an insecure host configuration, and generating cyber risk mitigation measures based on the entity asset database, which includes automatically implementing an improved host configuration when a device constituting an insecure host configuration is identified, generating a security warning when a related domain linked to a device constituting an insecure host configuration is identified, or generating a cybersecurity risk report based on the investigation of the entity asset database, or a combination thereof.

[0137] Clause 13: By a processor, to investigate an entity asset database to identify associated domains linked to devices communicating with malicious actors, and to generate cyber risk mitigation measures based on the entity asset database, to automatically execute a modified device communication configuration when communication with a malicious actor is identified, to generate a security alert when an associated domain linked to a device communicating with a malicious actor is identified, to generate a cybersecurity risk report based on an investigation of the entity asset database, or a combination thereof, at least one of which is included in the method according to any one of Clauses 1 to 12.

[0138] Clause 14: By a processor, to investigate an entity asset database to identify associated domains including security threats related to emails, where security threats related to emails include email configurations lacking an email authentication method and / or email configurations having an incorrectly configured email authentication method, and to generate cyber risk mitigation measures based on the entity asset database, to automatically execute a modified email authentication configuration when an associated domain including a security threat related to emails is identified, to generate an automatic label indicating that an email may not be authentic when received from an associated domain including a security threat related to emails, to quarantine an email when received from an associated domain including a security threat related to emails, to generate a security alert when an associated domain including a security threat related to emails is identified, and to generate a cybersecurity risk report based on an investigation of the entity asset database, or a combination thereof, at least one of which is included in the method according to any one of Clauses 1 to 13.

[0139] Clause 15: A method for identifying cyber assets and implementing cyber risk mitigation measures, the method comprising: executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, each candidate match pair including two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the same entity; determining a true match probability for each candidate match pair, the true match probability being the probability that the two cyber assets within the candidate match pair are assets of the same entity, and determining on which of the cyber asset identification algorithms that identified the candidate match pair the true match probability is based; for at least a portion of the candidate match pairs, determining that the true match probability exceeds a predetermined threshold; adding at least one of the cyber assets from each candidate match pair having a true match probability exceeding the predetermined threshold to a cyber asset database corresponding to the entity used to identify the match pair; and generating cyber risk mitigation measures based on the cyber asset database.

[0140] Clause 16: Determining the true match probability for each match pair includes: assigning binary values to each cyber asset identification algorithm, where 1 is assigned to each cyber asset identification algorithm that identifies a match pair and zero is assigned to each cyber asset identification algorithm that does not identify a match pair, and calculating the true match probability based on the binary values assigned to each cyber asset identification algorithm and the accuracy coefficient of each cyber asset identification algorithm. The method according to Clause 15.

[0141] Clause 17: Determining the true match probability for each matching pair involves assigning binary values to each cyber asset identification algorithm, where 1 is assigned to each cyber asset identification algorithm that identified a matching pair and 0 is assigned to each cyber asset identification algorithm that did not identify a matching pair, and calculating the true match probability based on the binary values assigned to each cyber asset identification algorithm and the accuracy coefficient of each cyber asset identification algorithm. The method according to any one of Clauses 15 to 16.

[0142] Clause 18: Further includes determining the accuracy coefficient of each cyber asset identification algorithm. Determining the accuracy coefficient for each cyber asset identification algorithm involves selecting known entities, identifying the ground truth cyber assets of the known entities, where the ground truth cyber assets are cyber assets known to be the assets of the known entities, executing a plurality of cyber asset identification algorithms to identify a plurality of training matching pairs, each training matching pair including two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the known entity, each cyber asset identification algorithm identifying a subset of the training matching pairs, and comparing the subset of the training matching pairs identified by each cyber asset identification algorithm with the ground truth cyber assets. The method according to any one of Clauses 15 to 17.

[0143] Clause 19: Determining the accuracy coefficient of each cyber asset identification algorithm further includes using machine learning techniques to determine the accuracy coefficient of each cyber asset identification algorithm based on the comparison between each subset of the training matching pairs and the ground truth cyber assets. The method according to any one of Clauses 15 to 18.

[0144] Clause 20: Adopting machine learning techniques includes adopting a support vector machine (SVM) model. The method according to any one of Clauses 15 to 19.

[0145] Clause 21: The method according to any one of Clauses 15 to 20, wherein each of a plurality of cyber asset identification algorithms employs a different method for identifying candidate matching pairs.

[0146] Clause 22: A server configured to identify cyber assets based on a democratic matching algorithm and perform cyber risk mitigation, comprising a processor and a memory configured to generate a footprint module and a risk mitigation module, the footprint module comprising a democratic matching module and a plurality of cyber asset identification modules, the memory, when executed by the processor, causing the processor to execute a plurality of cyber asset identification algorithms via the cyber asset identification module to identify a plurality of candidate matching pairs, each candidate matching pair including two cyber assets identified as potential assets of the same entity by at least one of the cyber asset identification algorithms; determining, via the democratic matching module, a true match probability for each candidate matching pair, the true match probability being the probability that the two cyber assets in the candidate matching pair are assets of the same entity, the true match probability being determined based on which cyber asset identification algorithm identified the candidate matching pair; determining, via the democratic matching module, for at least some of the candidate matching pairs, that the true match probability exceeds a predetermined threshold; adding, via the footprint module, at least one of the cyber assets from each candidate matching pair for which the true match probability exceeds the predetermined threshold to a cyber asset database corresponding to the entity used to identify the matching pair; and generating, via the risk mitigation module, cyber risk mitigation based on the cyber asset database.

[0147] Clause 23: The server according to Clause 22, wherein the true match probability is further based on an accuracy coefficient associated with each cyber asset identification algorithm.

[0148] Clause 24: When an instruction for determining the true match probability for each matching pair is executed by a processor, the processor is caused to assign, via a democratic matching module, a binary value to each cyber asset identification algorithm, with 1 assigned to each cyber asset identification algorithm that identifies a matching pair and zero assigned to each cyber asset identification algorithm that did not identify the matching pair, calculate, based on at least one of the binary values assigned to each cyber asset identification algorithm and the accuracy coefficient for each cyber asset identification algorithm via the democratic matching module, a true match probability, and the server according to any one of Clauses 22 to 23, based on at least one of them.

[0149] Clause 25: The footprint module further includes a training module, and when the memory is executed by a processor, the processor is caused to, via the training module, determine an accuracy coefficient for each cyber asset identification algorithm, cause the processor to execute an instruction for determining the accuracy coefficient for each cyber asset identification algorithm, cause the processor to select a known entity, identify the ground truth cyber asset of the known entity, where the ground truth cyber asset is a cyber asset known to be an asset of the known entity, execute the plurality of cyber asset identification algorithms to identify a plurality of training matching pairs, each training matching pair including two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the known entity, each cyber asset identification algorithm identifying a subset of the training matching pairs, and further configured to compare the subset of the training matching pairs identified by each cyber asset identification algorithm with the ground truth cyber asset, and the server according to any one of Clauses 22 to 25.

[0150] Clause 26: The server according to any of Clauses 22 to 25, further including instructions for determining a precision coefficient for each cyber asset identification algorithm, which are based on a comparison between each subset of training match pairs and ground truth cyber assets using machine learning techniques to determine the precision coefficient for each cyber asset identification algorithm.

[0151] Clause 27: The server according to any of Clauses 22 to 26, including instructions for adopting a support vector machine (SVM) model, which are instructions for adopting machine learning techniques.

[0152] Clause 28: The server according to any of Clauses 22 to 27, where each of the multiple cyber asset identification algorithms adopts a different method for identifying candidate match pairs.

[0153] Clause 29: The system and method for cyber risk mitigation are substantially as disclosed and described herein.

[0154] All patents, patent applications, publications, or other disclosure materials described herein are hereby incorporated by reference in their entirety as if each individual reference were specifically incorporated by reference. All references, and any materials, or portions thereof, said to be incorporated by reference herein are incorporated herein only to the extent that the incorporated materials do not conflict with the existing definitions, descriptions, or other disclosure materials described in this disclosure. Accordingly, and to the extent necessary, the disclosure set forth herein supersedes any conflicting materials incorporated by reference herein, and the disclosure is described explicitly within the scope of this application.

[0155] Various illustrative and exemplary aspects are described. The aspects described herein are to be understood as providing illustrative features of various details of the various aspects of the present disclosure, and thus, unless otherwise specified, without departing from the scope of the present disclosure, as much as possible, one or more features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure may be combined, separated, exchanged, and / or rearranged with one or more other features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the illustrative aspects may be made without departing from the claimed subject matter. Further, those skilled in the art can, by a review of this specification, recognize, or confirm, many equivalents to the various aspects of the present disclosure using only routine experimentation. Accordingly, the present disclosure is not limited by the descriptions of the various aspects, but only by the claims.

[0156] Those skilled in the art will generally recognize that terms used herein, and particularly in the appended claims (e.g., the body of the appended claims), are generally intended to be terms without limitation (e.g., the term "including" should be construed as "including but not limited to", the term "having" should be construed as "having at least", the term "includes" should be construed as "including but not limited to", etc.). It will further be understood by those skilled in the art that where a specific number of recited patent claims is intended, such intent is explicitly recited in the claims, and where there is no such recitation, such intent does not exist. For example, by way of illustration, the following appended claims may include the use of introductory phrases "at least one" and "one or more" to introduce a recitation of claims. However, the use of such phrases should not be construed as implying that the introduction of a claim by the indefinite article "a" or "an" limits any particular claim that includes such introduced recitation of claims to a claim scope that includes only one such recitation, and the same applies to the use of the definite article used to introduce a recitation of claims even when the same claim includes introductory phrases "one or more" or "at least one", and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should generally be construed as meaning "at least one" or "one or more").

[0157] Furthermore, even if a specific number of the recited introduced claims is explicitly recited, one of ordinary skill in the art will recognize that such a recitation should typically be interpreted to mean at least the recited number (e.g., a mere recitation of "two recitations" will typically be understood to mean at least two recitations or two or more recitations without other qualifying language). Further, in these instances where a convention similar to "at least one of A, B, and C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art will understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). In instances where a convention similar to "at least one of A, B, or C, etc." is used, generally, such a construction is intended in the sense that one of ordinary skill in the art will understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). It will be further understood by those of skill in the art that in any of the description, claims, or drawings, disjunctive and / or phrases presenting two or more alternative terms will typically be understood to contemplate the possibility of including one of the terms, any of the terms, or both terms, unless the context indicates otherwise. For example, the phrase "A or B" will typically be understood to include the possibility of "A" or "B" or "A and B".

[0158] Regarding the appended claims, one of ordinary skill in the art will understand that the operations recited therein may generally be performed in any order. Also, although the claims are presented in sequence, it should be understood that the various operations may be performed in other orders than those recited, or may be performed simultaneously. Examples of such alternative orders include, unless the context otherwise indicates, repetition, interleaving, interruption, reordering, incrementing, preparation, supplementation, simultaneity, reversal, or other variant orders. Further, unless the context otherwise indicates, terms such as "responding," "relating," or other past tense adjectives generally are not intended to exclude such variants.

[0159] It should be noted that any reference to "one aspect," "aspect," "exemplification," "an exemplification," and the like means that a particular feature, structure, or characteristic described in relation to the aspect is included in at least one aspect. Thus, the appearances of the phrases "in one aspect," "in an aspect," "in an exemplification," and "in an exemplification" at various places throughout this specification are not necessarily all referring to the same aspect. Further, a particular feature, structure, or characteristic may be combined in any suitable manner in one or more aspects.

[0160] As used herein, unless the context clearly indicates otherwise, the singular forms "a," "an," and "the" include plural references.

[0161] For example, without limitation, directional terms used herein such as up, down, left, right, below, above, front, back, and variations thereof relate to the orientation of the elements shown in the accompanying drawings and are not limiting with respect to the claims unless otherwise explicitly stated.

[0162] As used herein, the terms "about" or "approximately" mean an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the terms "about" or "approximately" mean within 1, 2, 3, or 4 standard deviations. In certain embodiments, the terms "about" or "approximately" mean within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0163] As used herein, unless otherwise indicated, all numerical parameters are to be understood as being preceded by the term "about," which in all instances means that the numerical parameter includes the inherent variations of the underlying measurement technique used to determine the value of the parameter. At a minimum, and not as an attempt to limit the application of the doctrine of equivalents to the claims, each numerical parameter herein is to be construed in light of the reported significant digits and by applying ordinary rounding techniques.

[0164] Any numerical range recited herein includes all sub-ranges subsumed within the recited range. For example, a range of "1 to 100" includes all sub-ranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, that is, all sub-ranges having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the endpoints of the recited range. For example, a range of 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, Applicants reserve the right to amend the specification, including the claims, to expressly recite sub-ranges expressly included within the ranges expressly recited herein. All such ranges are inherently described in this specification.

[0165] Any patent application, patent, non-patent publication, or other disclosure material mentioned in this specification and / or listed in any application data sheet is incorporated herein by reference to the extent that the incorporated material is not inconsistent with this specification. Accordingly, and to the extent necessary, the present disclosure, as explicitly described herein, prevails over any conflicting material incorporated herein by reference. Although said to be incorporated herein by reference, any material or portion thereof that conflicts with an existing definition, statement, or other disclosure material set forth herein is incorporated only to the extent that no conflict arises between the incorporated material and the existing disclosure material.

[0166] The terms "comprise" (and any form of comprise such as "comprises", "comprising", etc.), "have" (and any form of have such as "has", "having", etc.), "include" (and any form of include such as "includes", "including", etc.), and "contain" (and any form of contain such as "contains", "containing", etc.) are open-ended conjunctive verbs. As a result, a system that "comprises", "has", "includes", or "contains" one or more elements possesses those one or more elements but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises", "has", "includes", or "contains" one or more features possesses those one or more features but is not limited to possessing only those one or more features.

[0167] The foregoing detailed description has described various forms of devices and / or processes by use of block diagrams, flowcharts, and / or examples. If such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented individually and / or collectively by a wide variety of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented as one or more computer programs operating on one or more computers (e.g., as one or more programs operating on one or more computer systems), as one or more programs operating on one or more processors (e.g., as one or more programs operating on one or more microprocessors), as firmware, or substantially any combination thereof, and that all or part of the equivalent integrated circuit can be implemented, and the circuit design, and / or the description of the software code, and also the firmware are within the scope of the skills of those skilled in the art in light of the present disclosure. Further, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal carrying medium used to actually carry out the distribution.

[0168] The instructions used to program the logic to implement the various disclosed aspects may be stored in a memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Further, the instructions may be distributed via a network or via other computer-readable media. Thus, a machine-readable medium is any mechanism, but not limited to, for storing or transmitting information in a form readable by a machine (e.g., a computer), such as floppy disks, optical disks, compact disks, read-only memory (CD-ROM), and magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic or optical cards, flash memory, or tangible machine-readable storage devices used to transmit information over the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Thus, a non-transitory computer-readable medium includes any type of tangible machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0169] When used in any aspect of this specification, the term "control circuit" can refer to, for example, a wired circuit, a programmable circuit (e.g., a computer processor with one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA)), a state machine circuit, firmware storing instructions executed by a programmable circuit, and any combination thereof. The control circuit can be embodied, collectively or individually, as part of a larger system, such as an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuit" includes, but is not limited to, an electrical circuit having at least one discrete electrical circuit, an electrical circuit having at least one integrated circuit, an electrical circuit having at least one application specific integrated circuit, an electrical circuit forming a general purpose computing device configured by a computer program (e.g., a general purpose computer configured by a computer program that at least partially executes a process, and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process, and / or a device described herein), an electrical circuit forming a memory device (e.g., in the form of a random access memory), and / or an electrical circuit forming a communication device (e.g., a modem, a communication switch, or an optoelectronic device). One of ordinary skill in the art will recognize that the subject matter described herein can be implemented in analog or digital fashion or some combination thereof.

[0170] When used in any aspect of this specification, the term "logic" may refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software may be embodied as a software package, code, instructions, instruction sets, and / or data recorded in a non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) in a memory device.

[0171] When used in any aspect of this specification, terms such as "component", "system", "module", etc. may refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.

[0172] When used in any aspect of this specification, "algorithm" refers to a self-consistent order of steps that yields a desired result, and "step" refers to an operation on a physical quantity and / or a logical state that can, although not necessarily, take the form of an electrical or magnetic signal capable of being stored, transferred, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms may be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.

Claims

1. A method for identifying cyber assets and implementing cyber risk mitigation measures, comprising: selecting a target entity for evaluation; executing a plurality of domain identification algorithms to identify a plurality of candidate domains, each candidate domain being identified as a potential asset of the target entity by at least one of the domain identification algorithms; determining a true match probability for each candidate domain, the true match probability being the probability that the candidate domain is an asset of the target entity and being determined based on which of the domain identification algorithms identified the candidate domain; classifying the candidate domains having a true match probability exceeding a predetermined threshold as associated domains, each associated domain being regarded as an asset of the target entity; generating an entity asset database of the target entity based on the associated domains; generating cyber risk mitigation based on the entity asset database.

2. The method according to claim 1, wherein the true match probability is further based on a plurality of accuracy coefficients, each accuracy coefficient corresponding to one of the domain identification algorithms.

3. Determining the true match probability for each candidate domain comprises: assigning binary values to each domain identification algorithm, one being assigned to each domain identification algorithm that identifies the candidate domain and zero being assigned to each domain identification algorithm that does not identify the candidate domain; calculating the true match probability based on the binary values assigned to each domain identification algorithm and the accuracy coefficients for each domain identification algorithm.

4. Further comprising determining the accuracy coefficients, wherein determining the accuracy coefficients comprises: selecting a known entity; identifying a ground truth domain for the known entity, the ground truth domain being a domain known to be an asset of the known entity. Executing the plurality of domain identification algorithms to identify a plurality of training domains, wherein each training domain is identified by at least one of the domain identification algorithms as a potential asset of the known entity, and each domain identification algorithm identifies a subset of the training domains, and the identifying; comparing the subset of the training domains identified by each domain identification algorithm with the ground truth domain, the method according to claim 2 comprising.

5. Determining the accuracy coefficient further comprises using machine learning techniques to determine the accuracy coefficient for each domain identification algorithm based on comparing each of the subsets of the training domains with the ground truth domain, the method according to claim 4.

6. Adopting the machine learning technique includes adopting a support vector machine (SVM) model, the method according to claim 5.

7. Each of the plurality of domain identification algorithms adopts a different method for identifying candidate domains, the method according to claim 1.

8. Executing the plurality of domain identification algorithms to identify the plurality of candidate domains, identifying a seed domain of the target entity; identifying, by each of the domain identification algorithms, a domain potentially associated with the same entity as the seed domain, the method according to claim 1.

9. Executing the plurality of domain identification algorithms to identify the plurality of candidate domains, identifying a seed domain of the target entity; further comprising, by at least one of the domain identification algorithms, searching public data, proprietary data, or a combination thereof to identify a domain having at least a portion of the same registration information as the seed domain, the method according to claim 1.

10. Executing the plurality of domain identification algorithms to identify the plurality of candidate domains, Excluding by applying a filter by at least one of the domain identification algorithms to identify a part of the identified domains having at least a part of the same registration information as the seed domain as candidate domains. The method according to claim 9, comprising:

11. The method according to claim 10, wherein applying the filter includes excluding domains including edited registration data.

12. Further comprising investigating the entity asset database to identify related domains linked to devices constituting an insecure host configuration, Generating cyber risk mitigation measures based on the entity asset database, Automatically implementing an improved host configuration when a device constituting an insecure host configuration is identified, Generating a security warning when a related domain linked to a device constituting an insecure host configuration is identified, or Generating a cybersecurity risk report based on the investigation of the entity asset database, or The method according to claim 1, including a combination thereof.

13. Further comprising investigating the entity asset database to identify related domains linked to devices communicating with malicious actors, Generating cyber risk mitigation measures based on the entity asset database, Automatically implementing an improved device communication configuration when it is identified that communication is being made with a malicious actor, Generating a security warning when a related domain linked to a device communicating with a malicious actor is identified, or Generating a cybersecurity risk report based on the investigation of the entity asset database, or The method according to claim 1, including a combination thereof.

14. Further comprising the processor investigating the entity asset database to identify associated domains including security threats related to electronic mail, The security threats related to electronic mail include an electronic mail configuration lacking an electronic mail authentication method and / or an electronic mail configuration having an incorrectly configured electronic mail authentication method. generating cyber risk mitigation measures based on the entity asset database, automatically executing a modified email authentication configuration when an associated domain including an email-related security threat is identified, generating an automatic label indicating that an email may not be authentic when received from an associated domain including an email-related security threat, isolating an email when received from an associated domain including an email-related security threat, generating a security alert when an associated domain including an email-related security threat is identified, and generating a cybersecurity risk report based on an investigation of the entity asset database, or a combination thereof, the method according to claim 1.

15. A method for identifying cyber assets and implementing cyber risk mitigation measures, executing, by a cyber asset identification module, a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, each candidate match pair including two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the same entity, identifying; determining, by a democratic matching module, a true match probability for each candidate match pair, the true match probability being the probability that the two cyber assets within the candidate match pair are assets of the same entity, and the true match probability being based on which of the cyber asset identification algorithms that identified the candidate match pair, determining; determining, by the democratic matching module, that for at least a portion of the candidate match pairs, the true match probability exceeds a predetermined threshold; adding, by a footprint module, at least one of the cyber assets from each candidate match pair having a true match probability exceeding the predetermined threshold to a cyber asset database corresponding to the same entity used to identify the match pair; generating, by a risk mitigation module, cyber risk mitigation based on the cyber asset database, a method comprising.

16. The method according to claim 15, wherein the true matching probability is further based on a precision coefficient associated with each cyber asset identification algorithm.

17. Determining the true matching probability for each matching pair comprises: the democratic matching module assigning binary values to each cyber asset identification algorithm, one being assigned to each cyber asset identification algorithm that identifies the matching pair, and zero being assigned to each cyber asset identification algorithm that did not identify the matching pair; the democratic matching module calculating the true matching probability based on the binary values assigned to each cyber asset identification algorithm and the precision coefficient for each cyber asset identification algorithm. The method according to claim 16.

18. further comprising determining a precision coefficient for each cyber asset identification algorithm, and determining a precision coefficient for each cyber asset identification algorithm comprises: the training module selecting a known entity; the training module identifying the ground truth cyber asset of the known entity, the ground truth cyber asset being a cyber asset known to be an asset of the known entity; the democratic matching module executing the plurality of cyber asset identification algorithms to identify a plurality of training matching pairs, each training matching pair including two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the known entity, and each cyber asset identification algorithm identifying a subset of the training matching pairs; the training module comparing the subset of the training matching pairs identified by each cyber asset identification algorithm with the ground truth cyber asset. The method according to claim 16.

19. Determining the accuracy coefficient for each cyber asset identification algorithm further includes using machine learning techniques to determine the accuracy coefficient for each cyber asset identification algorithm based on comparing each subset of the training match pairs with the ground truth cyber assets. The method according to claim 18.

20. The method according to claim 19, wherein adopting the machine learning technique includes adopting a support vector machine (SVM) model.

21. The method according to claim 15, wherein each of the plurality of cyber asset identification algorithms adopts a different method for identifying candidate match pairs.

22. A server configured to identify cyber assets and perform cyber risk mitigation based on a democratic matching algorithm, the server comprising a processor and a memory configured to generate a footprint module and a risk mitigation module, the footprint module comprising a democratic matching module and a plurality of cyber asset identification modules, and when the memory is executed by the processor, the processor is caused to Execute a plurality of cyber asset identification algorithms via the cyber asset identification module to identify a plurality of candidate match pairs, wherein each candidate match pair includes two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the same entity. Identifying; Determine the true match probability for each candidate match pair via the democratic matching module, wherein the true match probability is the probability that the two cyber assets within the candidate match pair are assets of the same entity, and determine which of the cyber asset identification algorithms that identified the candidate match pair the true match probability is based on. Determine, via the democratic matching module, that the true match probability exceeds a predetermined threshold for at least a portion of the candidate match pairs. Via the footprint module, add at least one of the cyber assets from each candidate match pair having a true match probability exceeding the predetermined threshold to a cyber asset database corresponding to the entity used to identify the match pair. A server configured to generate cyber risk mitigation based on the cyber asset database via the risk mitigation module. **Claim 23** The server according to claim 22, wherein the true match probability is further based on an accuracy coefficient associated with each cyber asset identification algorithm. **Claim 24** When the instructions for determining the true match probability for each match pair are executed by the processor, the processor is caused to: Assign binary values to each cyber asset identification algorithm via the democratic matching module, where one is assigned to each cyber asset identification algorithm that identifies the match pair and zero is assigned to each cyber asset identification algorithm that did not identify the match pair; Calculate the true match probability based on the binary values assigned to each cyber asset identification algorithm and the accuracy coefficient for each cyber asset identification algorithm via the democratic matching module. The system according to claim 23 is configured to perform the above operations. **Claim 25** The footprint module further comprises a training module, and when the memory is executed by the processor, the memory stores instructions for causing the processor to determine the accuracy coefficient of each cyber asset identification algorithm via the training module. When the instructions for causing the processor to determine the accuracy coefficient of each cyber asset identification algorithm are executed by the processor, the processor is caused to: Select a known entity; Identify the ground truth cyber assets of the known entity, where the ground truth cyber assets are cyber assets known to be the assets of the known entity; Execute the plurality of cyber asset identification algorithms to identify a plurality of training match pairs, where each training match pair includes two cyber assets identified by at least one of the cyber asset identification algorithms as potential assets of the known entity, and each cyber asset identification algorithm identifies a subset of the training match pairs; The system according to claim 23 is further configured to compare the subset of training match pairs identified by each cyber asset identification algorithm with the ground truth cyber assets.

26. The instruction for determining the accuracy coefficient for each cyber asset identification algorithm further includes an instruction for determining the accuracy coefficient for each cyber asset identification algorithm based on comparing each of the subsets of the training match pairs with the ground truth cyber assets using machine learning techniques, the server according to claim 25.

27. The instruction for adopting the machine learning technique includes an instruction for adopting a support vector machine (SVM) model, the server according to claim 26.

28. Each of the plurality of cyber asset identification algorithms adopts a different method for identifying candidate match pairs, the server according to claim 22.