Devices, Systems, and Methods for Classifying, Prioritizing, and Mitigating Cyber Security Risks
The method and system address the challenge of managing cybersecurity risks across multiple entities by identifying cyber asset footprints and classifying risks, enabling efficient and timely mitigation of vulnerabilities through machine learning and data analysis, thus improving cybersecurity management for MSSPs.
Patent Information
- Application Number
- JP2024575337
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-21
- Filing Date
- 2023-06-16
- Publication Date
- 2025-07-23
AI Technical Summary
Existing systems struggle to efficiently identify and manage cybersecurity risks across a large number of interconnected entities, particularly for managed security service providers (MSSPs) managing multiple client networks, due to the complexity and resource-intensiveness of identifying and monitoring cyber assets and vulnerabilities, and lack the ability to scale SIEM implementations effectively.
A method and system for identifying cyber asset footprints, classifying cybersecurity risks based on IT hygiene, vulnerabilities, threat activities, and malicious activities, and generating alerts and reports to mitigate risks, using machine learning and statistical techniques to monitor and analyze data sources for relevant observations and initiate corrective actions.
Enables systematic and targeted assessment of cybersecurity risks across multiple entities, allowing for efficient identification of vulnerabilities and timely implementation of corrective measures, thereby enhancing the overall cybersecurity posture of client entities.
Smart Images

Figure 2025523497000001_ABST
Abstract
Description
Technical Field
[0001] (Cross - Reference to Related Applications) This application relates to U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS, the disclosure of which is incorporated herein by reference in its entirety.
[0002] This disclosure generally relates to computer security, and more specifically, to improved devices, systems, and methods for categorizing, prioritizing, and mitigating cybersecurity risks for a client entity that communicates with a plurality of target entities.
Summary of the Invention
Means for Solving the Problems
[0003] The following summary is provided to facilitate an understanding of some of the innovative features specific to the aspects disclosed herein and is not intended to be a complete description. A complete understanding of the various aspects can be obtained by taking the entire specification, claims, and abstract.
[0004] In various aspects, a method for managing the cybersecurity risk of a client entity that communicates with a plurality of target entities is disclosed. In one aspect, the method includes identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities. In another aspect, the method includes monitoring a plurality of data sources that include cybersecurity risk information to generate source data, the source data being organized based on a plurality of cybersecurity risk factors, the risk factors being classified according to classification branches including information technology (IT) hygiene, vulnerabilities, threat activities, and malicious activities. In yet another aspect, the method includes identifying relevant observations in the source data, each relevant observation including information related to one of the risk factors, each relevant observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints, determining that one of the relevant observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the risk factors, issuing a finding based on determining that the relevant observation does not comply with the predetermined measurement criterion, and transmitting an alert to the client entity based on the classification branch of the risk factor associated with the finding.
[0005] In various aspects, a method for managing the cybersecurity risk of a client entity that communicates with a plurality of target entities is disclosed. In one aspect, the method includes identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities. In another aspect, the method includes monitoring a plurality of data sources that include cyber risk information to generate source data, the source data being organized based on a plurality of risk factors, the risk factors being classified according to a risk factor classification. In yet another aspect, the method includes identifying relevant observations within the source data, each relevant observation including information related to one of the risk factors, each relevant observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints, determining that one of the relevant observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the risk factors, and issuing a finding based on determining that the relevant observation does not comply with the predetermined measurement criterion.
[0006] These and other objects, features, and characteristics of the present disclosure, as well as the methods of operation, functions, combinations of parts, and economies of manufacture of the related structural elements, will become more apparent upon consideration of the following description, the appended claims, and the accompanying drawings, which form a part of this specification, and wherein like reference numerals designate corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for the purpose of illustration and description only and are not intended as a definition of the limits of the invention.
[0007] The various features of the aspects described herein are set forth in detail in the appended claims. However, the various aspects regarding both the organization and method of operation can be understood, along with their advantages, from the following description taken in conjunction with the accompanying drawings below.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6A
Figure 6B
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
[0009] Corresponding reference numerals indicate corresponding parts throughout the several views. The embodiments described herein illustrate various aspects of the invention in one form, and such embodiments should not be construed as limiting the scope of the invention in any way.
BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The applicant of the present application owns the following U.S. provisional patent applications, the entire disclosures of each of which are incorporated herein by reference. - U.S. Provisional Patent Application No. 63 / 341,264, filed on May 12, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS", - U.S. Provisional Patent Application No. 63 / 344,305, filed on May 20, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS", - U.S. Provisional Patent Application No. 63 / 345,679, filed on May 25, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM" - International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS" - International Patent Application No. PCT / US2022 / 072743, filed on June 3, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - U.S. Provisional Patent Application No. 63 / 365,819, filed on June 3, 2022, entitled "DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX" - U.S. Provisional Patent Application No. 63 / 353,992, filed on June 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS" - U.S. Provisional Patent Application No. 63 / 366,903, filed on June 23, 2022, entitled "DEVICES, SYSTEMS, AND METHOD FOR GENERATING AND USING A QUERYABLE INDEX IN A CYBER DATA MODEL TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 368,567, filed on July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY" - U.S. Provisional Patent Application No. 63 / 369,582, filed on July 27, 2022, entitled "AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT" - U.S. Provisional Patent Application No. 63 / 377,304, filed on September 27, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES" - International Patent Application No. PCT / US2022 / 082167, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, and MethodS For PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS" - International Patent Application No. PCT / US2022 / 082173, filed on December 21, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS" - International Patent Application No. PCT / US2023 / 061069, filed on January 23, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION’S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE" - International Patent Application PCT / US2023 / 062894, filed on February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS - International Patent Application No. PCT / US2023 / 021736, filed on May 10, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS" - International Patent Application No. PCT / US2023 / 022535, filed on May 15, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM - International Patent Application No. PCT / US2023 / 022858, filed on May 19, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS.
[0011] Numerous specific details are set forth in this disclosure and are described to provide a complete understanding of the overall structure, function, manufacture, and use of the aspects illustrated in the accompanying drawings. Well-known operations, components, and elements are not described in detail so as not to obscure the aspects described herein. The reader will understand that the aspects described and illustrated herein are non-limiting. Thus, it will be understood that the specific structural and functional details disclosed herein may be representative and exemplary and that variations and modifications may be made without departing from the scope of the claims.
[0012] Before detailing various aspects of the systems and methods disclosed herein, it should be noted that the exemplary aspects are not limited to the applications or uses disclosed in the accompanying drawings and description. Of course, the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications, and they may be practiced or carried out in various ways. Further, unless otherwise indicated, the terms and expressions used herein are selected for the purpose of describing the exemplary aspects for the convenience of the reader and are not intended for purposes of limitation. For example, any reference herein to a particular manufacturer, software suite, application, or development platform is merely intended to illustrate some of the many aspects of this disclosure. This includes any reference to trademarks. Thus, it should be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any use purpose and / or user preference.
[0013] As used herein, the term "server" refers to, or may include, one or more computing devices that are operated by, or facilitate, communication and processing for multiple parties in a network environment such as the Internet or any public or private network. References herein to a "server" or "processor" may refer to the server and / or processor previously mentioned as performing steps or functions, different servers and / or processors, and / or combinations of servers and / or processors.
[0014] As used herein, the term "entity" refers to, or may include, a corporation, business-related organization, non-profit organization, government agency, charity, educational institution, or any other type of organization or individual that owns or has a relationship with a collection of cyber assets.
[0015] References herein to "cyber assets" may refer to computing devices, networks, hardware, software, data, information, or any other type of information technology-related component, label, or identifier for switching, signaling, or routing, such as, for example, a domain, Internet Protocol (IP) address, or shared or dynamic assets.
[0016] As used herein, the terms "domain" and "domain name" refer to, or may include, a string that identifies, or is otherwise associated with, a network, computing device, or other resource that communicates with the Internet, such as, for example, a server, personal computer, website, or other service communicated via the Internet. In some aspects, as used herein, "domain" and "domain name" generally are as described in Domain Names - Implementation and Specification, Network Working Group (Nov. 1987), the disclosure of which is incorporated herein by reference.
[0017] Entities typically need to understand and manage cyber security risks. More specifically, enterprises need to understand and manage cyber security risks associated with cyber assets. For example, an entity can have an Internet presence, i.e., a large number of cyber assets used for Internet-related communications. One or more of these cyber assets may be configured such that the enterprise is potentially exposed to cyber security risks. Cyber security risks can include unwanted or malicious attempts to gain access to an entity's network, data, and / or other information. Cyber security risks can also include, for example, maliciously denying the use of cyber assets by their rightful owners, such as a denial-of-service attack or ransomware. Thus, in order to identify potential exposure to cyber security risks and take measures against such risks, the entity, and / or its risk assessors and auditors, need to identify the cyber assets and how they are configured.
[0018] To further improve the management of cyber threats and other security risks, an entity also needs to identify and understand the cyber assets of other entities (hereinafter sometimes referred to as "target entities"). This need can arise because communication between entities can lead to the exposure of threats, or perhaps because the entity's cyber security risks can cause catastrophic service disruptions outside the realm of the Internet, potentially affecting partner entities. For example, a first entity (e.g., a "client entity") can use its cyber assets to communicate with the cyber assets of many target entities, such as various suppliers, vendors, partners, and third parties. If any of the target entities' cyber assets are vulnerable to cyber security risks, the client entity may also be exposed to risks by communicating with these assets. Therefore, an entity needs to not only identify and understand its own cyber assets, but also identify and understand the risks posed by the target entities' cyber assets.
[0019] However, the large-scale identification of target entities and their cyber assets can be a complex, time-consuming, and resource-intensive process. This can be particularly challenging for a managed security service provider ("MSSP") that deploys cloud-based security information and event management (SIEM) on a large scale, iteratively, and consistently for an extremely large number of concurrent client networks, as disclosed in International Patent Application No. PCT / US2022 / 072739, filed on June 3, 2022, and titled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS", the disclosure of which is hereby incorporated by reference in its entirety.
[0020] For example, an MSSP not only has to manage each specific SIEM implementation for each specific client, but also has to manage the exposure of each client's target entities to risk, which results in what appears to be an unlimited amount of network activity for continuous monitoring and can make it impractical for an MSSP to achieve efficiently and reliably. Known SIEM tools only go so far as to efficiently manage exposure to external entities and lack the technical ability to scale SIEM implementations across multiple client networks. Further, it can be difficult to reliably identify and distinguish target entities from each other. Further, once target entities are identified, it can be difficult to identify most or all of the thousands or even millions of cyber assets belonging to each of the target entities. The aforementioned international patent application No. PCT / US2023 / 062894, filed on February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS, which is hereby incorporated by reference in its entirety, provides additional details regarding the difficulties associated with large-scale identification of cyber entities.
[0021] Even if there is a comprehensive list of target entities and their cyber assets, it can be complex, time-consuming, and resource-intensive to determine which cyber assets are vulnerable to cybersecurity risks. For example, malicious actors are constantly attempting to identify and exploit vulnerabilities associated with cyber assets. At the same time, cyber asset configurations can become outdated and more susceptible to attacks (e.g., new security protocols, software version updates, evolution of industry standards related to cybersecurity, etc.). Therefore, it may be necessary to continuously monitor millions of cyber assets across thousands of target entities for potential cybersecurity risks in order to identify these vulnerabilities and help protect client entities in a meaningful way.
[0022] Furthermore, simply identifying cybersecurity vulnerabilities associated with the cyber assets of a target entity may not be sufficient to meaningfully protect a client entity. A client entity is likely to not realize the benefits of identifying and monitoring the cyber assets of a target entity unless measures are implemented to address the discovered cybersecurity vulnerabilities. However, considering the magnitude and diversity of cybersecurity risks that may exist in the cyber asset footprint of a particular target entity, it can be difficult to determine the order and urgency in which risks need to be addressed. For example, some cybersecurity risks may need to be addressed immediately to prevent potential attacks, while other risks may be of low urgency or low priority. Therefore, there is a need for improved devices, systems, and methods for organizing and reporting identified cybersecurity risks so that the target entity and its cyber asset footprint can be reliably identified, the cybersecurity risks associated with the target entity's cyber assets can be identified, and appropriate corrective measures can be implemented before the target entity's cyber assets are utilized.
[0023] The present disclosure presents an apparatus, system, and method for identifying a cyber asset footprint for a plurality of target entities, identifying cyber security risks associated with the cyber asset footprint, organizing risks identified according to risk factor classification, and reporting information related to the risks identified based on the risk factor classification. These devices, systems, and methods are, for example, (a) identifying and organizing cyber security risk information related to the cyber asset footprint of a target entity, in an unusual way, (i) monitoring a plurality of data sources including cyber risk information to generate source data organized based on risk factors, where the risk factors are classified according to a classification branch including IT hygiene, vulnerability, threat, malicious activity; (ii) associating the cyber risk information with the cyber asset footprint of the target entity to identify relevant observations in the source data; (b) issuing investigation results related to the identified cyber security risk information and sending alerts and / or reports based on the classification branch of the risk factors related to the findings, thereby providing specific improvements to conventional cyber security risk management systems and integrating the organization of the cyber risk information according to risk factors and classification branches into a practical application; (c) (i) managing, at a scale that humans would not actually implement in thought, the cyber security risks of a client entity communicating with a plurality of target entities by identifying the cyber asset footprint of the target entity; (ii) monitoring a plurality of data sources including cyber security risk information to generate source data; (iii) identifying relevant observations of the source data by correlating the cyber security risk information of the source data with one of the cyber asset footprints.
[0024] Furthermore, the apparatuses, systems, and methods described herein can provide technical benefits by initiating corrective actions based on classification branches related to the issued findings, thereby providing certain improvements over previous cyber security risk management systems and integrating the organization of cyber risk information according to risk factors and classification branches into a practical application.
[0025] Referring now to FIG. 1, there is shown a diagram of a system 1000 configured to identify cyber assets and generate cyber risk mitigation measures for a plurality of entities, in accordance with at least one non-limiting aspect of the present disclosure. System 1000 may include a cyber security risk management provider server 1002 having a memory 1004 and a processor 1006. As described above, server 1002 may be operated by a plurality of parties in a network environment, or may refer to or include one or more computing devices that facilitate communication and processing for a plurality of parties. For example, cyber security risk management provider server 1002 may be implemented in accordance with cloud architecture 8000, as further described with reference to FIG. 10. In various aspects, cyber security risk management provider server 1002 may be composed of computer system 9000 and its various components, as further described with reference to FIG. 11. Memory 1004 may be configured to store instructions that, when executed by processor 1006, execute various aspects of processes 100, 200, and / or 300, as described hereinafter with respect to FIGS. 2-3 and 5-9.
[0026] Cyber security risk management provider server 1002 may be communicatively coupled via network 1008 to a plurality of entities 10101, 10102,... 1010 n and. Each of the plurality of entities 10101, 10102,... 1010 ncan represent a tenant (e.g., a client entity) that has contracted with a cybersecurity risk management provider for cybersecurity services and / or an entity (e.g., a target entity) that may be evaluated by the cybersecurity risk management provider for cybersecurity-related deficiencies. According to a non-limiting aspect of FIG. 1, network 1008 can include any variety of wired (e.g., fiber optic cable wiring), long-range wireless, and / or short-range wireless networks. For example, network 1008 can include an internal network, a local area network (LAN), Wi-Fi, a cellular network, or near-field communication, etc.
[0027] Referring further to FIG. 1, each of the plurality of entities 10101, 10102, … 1010 n can host and / or be associated with one or more instances of one or more cyber assets 1012, 1014, 1016. For example, the first entity 10101 can include one or more cyber assets 10121, 10122, … 1012 n implemented or otherwise associated with one or more machines, the second entity tenant 10102 can include one or more cyber assets 10141, 10142 … 1014n implemented or otherwise associated with one or more machines, and / or the third entity 1010 n can include one or more cyber assets 10161, 10162 … 1016 n implemented or otherwise associated with one or more machines. Each entity 10101, 10102, … 1010 n can include an intranet (i.e., a network) through which each device can communicate. As described above, entities 10101, 10102, … 1010 nIt can represent a tenant (e.g., a client entity), such as an organization, that contracts with a cybersecurity risk management provider for security management services. Thus, the cybersecurity risk management provider server 1002 can be configured to monitor one or more entities, 10101, 10102, and 1010 n and thus can be responsible for monitoring and / or managing the cyber assets (e.g., 1012, 1014, 1016) of the entity to mitigate cybersecurity threats.
[0028] However, as described above, identifying the cyber assets (e.g., 1012, 1014, 1016) of multiple entities (e.g., 10101, 10102,... 1010 n ) and which cyber assets (e.g., 1012, 1014, 1016) are vulnerable to cybersecurity risks can be a complex and resource-intensive process. Further, an entity (e.g., 10101, 10102,... 1010 n ) is likely not to realize the advantage of identifying cyber assets vulnerable to cybersecurity risks unless measures are implemented to address the discovered cybersecurity flaws. Thus, the present disclosure now turns to various methods for identifying the cyber assets of multiple entities and generating cybersecurity risk remediation measures based on the identified assets.
[0029] Referring now to FIG. 2, a flowchart of process 100 for identifying cyber assets associated with a plurality of entities is shown, in accordance with at least one non-limiting aspect of the present disclosure. The method 100 for identifying cyber assets associated with a plurality of entities may be referred to herein as the "footprint process 100." In various aspects, any of the footprint process 100 may be performed using algorithms that use machine learning, statistical techniques, and / or logic and expert system-based techniques, as well as search, sort, matching, and other data processing techniques and logic.
[0030] The footprint process 100 can proceed by identifying 102 characteristics specific to the target entity and generating an entity database 108. Due to the ambiguity associated with identifying those characteristics, it can be difficult to distinguish between entities (e.g., entities may conduct transactions under the same or similar names). Thus, identifying 102 characteristics specific to an entity may involve running an algorithm that causes a search and analysis of public data 104 that describes the entity and / or proprietary data 106 that describes the entity for identifiers that are particularly unique to a specific entity. These unique identifiers can be used to generate an entity database 108 in correlation with a specific entity. For example, referring again to the above “Island Realty” example, searching public and / or proprietary data (e.g., domain registration data) that describes entities 104, 106 can reveal that the domain “islandrealty.com” is registered to an organization operating under the name “Island Realty” in South Carolina. Thus, since the domain “islandrealty.com” is unique and may not be shared by other entities, this can be used to reliably distinguish the cyber presence and assets of “Island Realty” in South Carolina from other entities. This domain can be correlated with the reality of the islands in South Carolina and added to the entity database 108.
[0031] The identifiers used to generate the entity database 108 may include identifiers such as, for example, Internet domains, addresses, telephone numbers, business registration numbers, and tax identifiers. The public data 104 that describes the entity may include, for example, databases having information such as U.S. Securities and Exchange Commission (SEC) filings, Internal Revenue Service (IRS) disclosures, state-based business registrations and / or charity registrations with the Secretary of State, legal filings, government filings, international legal entity identifier base identifiers, public key certificates, information found on organizational websites, public Internet registrations, patent applications, and trademark applications. The proprietary data 106 that describes the entity may include, for example, databases having information such as catalogs of firmographic information about entities purchased from Dun & Bradstreet, Moody’s, Standard & Poor’s, Zoominfo, Open Corporates, as well as mailing lists, and / or sales lead providers. The public data 104 that describes the entity and the proprietary data 106 that describes the entity are often incomplete and may contain errors. Thus, in various aspects, identifying 102 entity-specific characteristics may include search, sort, match, and logic-driven discrimination such as using machine learning and / or statistical techniques, and expert system evaluation to clarify the entity.
[0032] The footprint process 100 can continue by identifying 110 cyber assets associated with the target entity within the entity database 108. As described above, a given entity can be associated with several different types of cyber assets, such as domains, IP addresses, and shared and dynamic assets. However, there is no previous source, or method, that can easily identify and classify the cyber assets of multiple entities. Thus, to address this need, identifying 110 cyber assets associated with the entities within the entity database 108 may include executing an algorithm that causes a search and analysis of public data 112 that describes the entity's cyber assets and / or proprietary data 114 that describes the entity's cyber assets. Based on this search and analysis, specific types of cyber assets are identified and correlated with the identifiers stored in the entity database 108 to generate an entity domain database 1161, an entity IP address database 1162, an entity shared and dynamic asset database 1163, and / or any number of other cyber asset databases 116 for storing data related to various types of cyber assets. n (Collectively, the cyber asset databases 116). In various aspects, the algorithms used to identify 110 cyber assets can use search, sort, match, and / or statistical techniques, logic-driven discrimination such as expert system evaluation, and / or machine learning.
[0033] In one aspect, the entity domain database 1161 can include a plurality of domain databases, and each domain database includes domains classified as being associated with a particular entity from the entity database 108. In another aspect, the entity IP address database 1162 can include a plurality of IP address databases, and each IP address database includes IP addresses classified as being associated with a particular entity from the entity database 108. In another aspect, the entity shared asset database 1163 can include a plurality of shared asset and dynamic asset databases, and each shared asset and dynamic asset database includes shared assets and dynamic assets classified as being associated with a particular entity from the entity database 108. In yet another aspect, various other types of cyber asset databases 116 n can each include a plurality of type-specific cyber asset databases, and each type-specific cyber asset database includes cyber assets of a particular type classified as being associated with a particular entity from the entity database 108. The cyber asset database 116 can be used as a basis for generating cyber risk mitigation measures, as discussed below with respect to FIG. 3.
[0034] Referring now to FIG. 3, a flowchart of a process 200 for generating cyber security risk mitigation measures across a plurality of entities based on the cyber asset database 116 is shown, in accordance with at least one non-limiting aspect of the present disclosure. A method 200 for generating cyber security risk mitigation measures across a plurality of entities may be referred to herein as the "cyber risk mitigation process 200." In various aspects, any of the steps of the cyber risk mitigation process 200 can be performed using algorithms that employ search, sort, match, and / or statistical techniques, logic-driven discrimination such as expert system evaluation, and / or machine learning.
[0035] The cyber risk reduction process 200 can begin by investigating risk indicators and / or exposure to cyber threats for the cyber assets 202 of one or more cyber asset databases 116. As described above, any of the entity's cyber assets (e.g., domains, IP addresses, and shared and dynamic assets) may be configured such that the entity is exposed to cyber security risks. Thus, in the investigation 202, the cyber asset database 116 may include executing an algorithm to determine which of the various cyber assets within the cyber asset database 116 are vulnerable to cyber threats or may include configurations that are exploited by cyber threats.
[0036] Referring further to FIG. 3, in various aspects, the risk indicators and threat exposures associated with a given cyber asset configuration are time-dependent and / or may change in response to the occurrence of various cyber events. Thus, investigating the cyber asset database 116 for risk indicators and / or exposure to cyber threats 202 can also include searching and analyzing the Internet for public information 204 related to the existence of exploitation risks or the occurrence of cyber events, and / or searching and analyzing the Internet for proprietary information 206 related to the existence of exploitation risks or the occurrence of cyber events. In various embodiments, investigating the cyber asset database 116, the public information 204, and / or the proprietary information 206 for risk indicators and / or exposure to cyber threats 202 can include one or more of the steps of a process 300 for managing cyber risk based on a risk factor classification described in detail below with respect to FIGS. 5-9.
[0037] Referring further to FIG. 3, the cyber security risk mitigation process 200 can continue by generating (208) one or more cyber security risk mitigation measures based on the cyber threats and risk indicators identified at 202. Generating 208 cyber security risk mitigation measures can include, for example, generating an entity cyber security risk report 210, generating a cyber asset threat, vulnerability, and risk database 212, implementing corrective actions 214, and generating alerts 216.
[0038] In various aspects, generating 208 cyber security risk corrective measures can include generating an entity's cyber security risk report 210. The entity cyber security risk report 210 can include one or more reports, and each report can include an assessment of the cyber threat exposure of one or more entities within the entity database 108 (FIG. 2) based on the investigation performed at 202. The entity cyber security risk report 210 can include a risk level score and / or other types of risk assessments that can be used by a cyber risk management provider to determine the relative risk level of a particular entity compared to other entities within the entity database 108. In some aspects, the entity cyber security risk report 210 can be similar to the entity cyber security risk report 324 described below with reference to FIG. 5.
[0039] In various aspects, generating cyber security risk mitigation measures 208 can include generating a threat, vulnerability, and risk database 212 of an entity's cyber assets. The threat, vulnerability, and risk database 212 of cyber assets may, at 202, include logs of each asset from the cyber asset database 116 that have been identified as being exposed to cyber threats, vulnerabilities, and / or risks. The threat, vulnerability, and risk database 212 of cyber assets, or a portion thereof, may be referenced by a cyber risk management provider when making asset management decisions. For example, the threat, vulnerability, and risk database 212 of cyber assets can be used to identify cyber assets that require configuration updates.
[0040] In various ways, generating cyber risk mitigation measures 208 may include implementing corrective actions 214. In some ways, implementing corrective actions 214 may, at 202, include running an algorithm that causes an automatic configuration update to one or more cyber assets identified as being exposed to a cyber threat. In some embodiments, implementing corrective actions 214 is similar to and / or can include initiating corrective action 326, described below with reference to FIG. 5.
[0041] In various aspects, generating 208 cyber risk mitigation measures can include generating 216 alerts in response to identifying risk metrics and / or threat exposures associated with one or more cyber assets at 202. For example, in one aspect, the alerts may be sent to a security analyst of a cyber risk management provider and / or other parties billed for the cyber security management of a particular entity. In other aspects, alerts may be sent to entities, cyber assets, and / or users of cyber assets associated with the identified cyber threats. The generated 216 alerts may include instructions for a security analyst, user, or other party to take particular actions in response to the identified cyber threats. In another aspect, the alerts may also take the form of automated control instructions to a computer system providing a security service. For example, a control message to close a port may be sent to the entity's firewall upon seeing evidence of malicious activity. In some aspects, generating the alerts at 216 is similar to and / or can include generating the alerts at 322, as described below with reference to FIG. 5.
[0042] Classification, Prioritization, and Mitigation of Cybersecurity Risks An apparatus, system, and method for identifying entities existing on the Internet, identifying cyber assets associated with a target entity, and generating cyber security risk mitigation measures based on the identified cyber assets have been described generally. The present disclosure will next turn to specific implementations of these apparatuses, systems, and methods related to managing cyber security risks based on cyber security risk classifications. Any of the aspects described below with respect to FIGS. 4-9 can be applied to the apparatuses, systems, and methods described above with respect to the system 1000 of FIG. 1, the footprint process 100 of FIG. 2, and the cyber risk mitigation process 200 of FIG. 3.
[0043] FIG. 4 is a diagram of a system 2000 configured to identify cyber assets and generate cyber risk mitigation measures for a plurality of entities based on cyber security risk classification, according to at least one non-limiting aspect of the present disclosure. FIG. 5 shows a flowchart of a process 300 for managing cyber risks based on cyber security risk classification, and FIGS. 6A-6B show examples of cyber security risk classifications 400 that may be employed by process 300, according to some non-limiting aspects of the present disclosure. The process 300 of FIG. 5 may be executed by the system 2000 of FIG. 4.
[0044] Referring now to FIG. 5, process 300 can begin by monitoring 302 a data source 304 that includes cyber security risk information and generating organized source data 308. The data source 304 can include a plurality of different publicly available and / or proprietary data sources that contain information related to cyber security risks. For example, the data source 304 can include public information 204 related to risk exposure and / or cyber events, and / or proprietary information 206 related to risk exposure and / or cyber events as described above with respect to FIG. 3. The following paragraphs provide various non-limiting examples of types of information related to cyber risks that can be monitored 302 at the data source 304. Further, the cyber security risk classification 400 described below with reference to FIGS. 6A-6B can provide a more complete understanding of the various data sources 304 that can be monitored 302.
[0045] In one aspect, monitoring 302 the data source 304 can include scanning Internet Protocol (IP) addresses for information related to services, security certificates, and / or configurations associated with various cyber assets. Information obtained from the IP address scan can be used to determine the level of exposure of these cyber assets to various cyber threats.
[0046] In one aspect, monitoring 302 the data source 304 may include monitoring a security certificate repository. Information obtained from monitoring the security certificate repository can be used to identify vulnerabilities related to certificate-based attack techniques.
[0047] In one aspect, monitoring 302 the data source 304 may include monitoring / collecting domain name system (DNS) records for various domains. For example, monitoring 302 the data source 304 may include monitoring DNS records (e.g., including mail exchange (MX) records) for the domains 310 identified in the cyber asset footprint 312 of the target entity, as discussed in more detail below. The monitored DNS records can be used to identify technology vendors (e.g., support for third-party analysis), security technologies (e.g., use of email scanners, multi-factor identification), IP ranges, extended network infrastructure, and / or security configurations (e.g., email DNS protection) that can be used to detect cyber risk-related information for assessing an entity's protection against cyber security risks and / or exposure to risks.
[0048] In one aspect, monitoring 302 the data source 304 may include monitoring passive DNS transactions. The monitored information related to DNS transactions can be used, for example, to scan for received activities related to cyber assets that indicate the interest of threat actors in extended network infrastructure (e.g., cloud / host-based assets related to cyber assets and the target entity), external connections of cyber assets to malicious infrastructure that indicate active malware and / or hacking activities in the infrastructure of the target entity, click on links to websites of phishing actors for dangerous applications (e.g., Tor software).
[0049] In one aspect, monitoring 302 the data source 304 may include monitoring the darknet and / or dark web sites. The monitored information related to the darknet / dark web sites can be used to identify infringements, threats, attack modalities, exposed authentication information, other personally identifiable information (PII), zero-day attacks (such as newly emerging vulnerabilities), etc.
[0050] Referring further to FIG. 5, the organized source data 308 generated by monitoring 302 the data source 304 that includes cyber risk information can be organized based on a cyber security risk classification 306. The cyber security risk classification 306 is an organizational structure used to classify and evaluate various cyber risk-related information. At the lowest level, the cyber security risk classification 306 classifies cyber security risk-related information according to risk factors. As discussed in more detail below, information regarding specific risk factors can be analyzed according to one or more metrics 318 to assist in the evaluation of the cyber security risk of the target entity. At the next higher level, each risk factor in the cyber security risk classification 306 is classified according to risk categories. Risk categories can be used to group risk factors based on the type of cyber risk captured by each risk factor. At the highest level, each of the risk categories of the cyber security risk classification 306 is classified according to classification branches. FIGS. 6A-6B show an example of a cyber security risk classification 400 that can be adopted as the cyber security risk classification 306 of the process 300.
[0051] Referring now to FIGS. 6A-6B, the cyber security risk classification 400 can include classification branches 402, risk categories 404, and risk factors 406. As shown in FIGS. 6A-6B, the classification branches 402 can include information technology (IT) hygiene, vulnerabilities, threats, and malicious activities. In other aspects, the classification branches can include email, IT hygiene, vulnerabilities, threats, and malicious activities.
[0052] The risk categories 404 and risk factors 406 classified in the IT hygiene classification branch 402 are related to decisions regarding how the target entity conducts the construction and management of IT. For example, the risk category 404 classified in the IT hygiene classification branch 402 may include email security. Configuration information (e.g., patching level, versioning), application security (e.g., security incorporated into applications connected to the Internet), DNS security (e.g., security related to preventing the manipulation or poisoning of responses to DNS requests by authenticating responses), non-business applications (e.g., use of Tor, social media, other risk-inducing applications, etc.), vendor dependency (e.g., focusing on technology, vendor discovery, and analysis), surface-related vulnerabilities (e.g., vulnerabilities related to the domain / IP and hosting strategy of the target entity). As discussed in more detail below, information regarding the risk factors 406 in the IT hygiene classification branch 402 can determine the actual state of the target entity's IT infrastructure related to cybersecurity compared to industry best practices.
[0053] The risk factors 406 for the email security category 404 may include risk factors related to sender policy framework (SPF) implementation, domain-based message authentication reporting and compliance (DMARC) implementation, domain keys identified mail (DKIM) implementation, secure hosting of emails, and / or phishing protection implementation.
[0054] The risk factors 406 in the configuration and version category 404 may include device classification, browser information, operating system (OS) information, mobile OS information, and / or ports (e.g., misconfigured and / or open ports).
[0055] The risk factors 406 in the application security category 404 may include risk factors related to content security policy configuration and / or application security implementation.
[0056] The risk factors 406 in the DNS security category 404 may include risk factors related to the implementation of the Domain Name System Security Extensions (DNSSEC).
[0057] The risk factors 406 in the non-business application risk category 404 may include risk factors related to peer-to-peer file sharing.
[0058] The risk factors 406 in the vendor-dependency risk category 404 may include risk factors related to the discovery and analysis of a fourth party (and / or an Nth party from a fifth party), and / or the stratification of vendor dependencies.
[0059] The risk factors 406 in the attack surface category 404 may include risk factors related to the cyber asset footprint of the target entity and / or the evaluation of network characteristics.
[0060] The risk categories 404 and risk factors 406 classified in the vulnerability classification branch 402 are related to various combinations of software, hardware, and configurations that are vulnerable to cyberattacks. Thus, the vulnerability classification branch 402 can be related to various scan and transaction-based information that can be analyzed to identify active vulnerabilities in the IT of the target entity. For example, the risk categories 404 classified in the vulnerability branch 402 can include software vulnerabilities (e.g., known vulnerabilities based on software versions) and data encryption (e.g., data protection during operation). As discussed in more detail below, information regarding the risk factors 406 in the vulnerability classification branch can be used as a basis to notify the target entity of active vulnerabilities in the infrastructure of the client entity and / or the target entity, and those vulnerabilities can be fixed before they are exploited.
[0061] The risk factors 406 of the software vulnerability category 404 can include software Common Vulnerabilities and Exposures (CVE) and / or new CVEs. Software CVE and / or new CVEs can refer to, for example, CVEs within the CVE database maintained by The MITRE Corporation.
[0062] The risk factors 406 of the data encryption category 404 can include risk factors related to unencrypted web services and / or the security of SSL / TLS certificates.
[0063] The risk categories 404 and risk factors 406 classified in threat activity classification branch 402 are related to potential threats posed by various cybercriminals and other malicious actors. These cybercriminals and malicious actors typically work to capture information about the cybersecurity vulnerabilities of entities of interest in order to exploit these entities. For example, cybercriminals may scan infrastructure, search for authentication information on dark web sites, create attack code to exploit new vulnerabilities, introduce malware, send phishing emails to users seeking to obtain more information, and cooperate with other criminal groups to share information. Each group of cybercriminals can adopt its own working methods and attack methods (e.g., tactics, techniques, and procedures (TTPs)) and focus on various benefits and goals. Thus, threat activity classification branch 402 may include information related to tracking the activities and / or personalities of these various cybercriminals and malicious acts in order to understand the level of threat to a given target entity. Thus, the risk categories 404 classified in threat branch 402 may include information related to intrusive adversarial probes (e.g., traffic from the infrastructure of known malicious actors to the target entity), phishing targeting (e.g., traffic from known phishing infrastructure to the target entity), authentication information targeting, and / or dark web information (e.g., traffic on dark web sites showing interest in the target entity). As will be discussed in more detail below, the information related to risk factor 406 in the threat activity classification branch can be used as a basis for notifying client entities and / or target entities of potential threats based on the activities and / or personalities of various cybercriminals and malicious actors.
[0064] The risk factors 406 of the intrusive adversarial probe category 404 may include risk factors related to scanning and / or botnet activities.
[0065] The risk factors 406 of the phishing targeting category 404 may include risk factors related to received emails from phishing sources, domain analogs, mail exchange (MX) analogs, and / or social media analogs.
[0066] The risk factors 406 of the authentication information targeting category 404 may include risk factors related to authentication information, brute force attack attempts, and / or dark web requests for criminal targeting.
[0067] The risk factors 406 of the dark web information category 404 may include risk factors related to mentions of the dark web by various cybercriminals or other malicious actors (e.g., of the target entity).
[0068] The risk categories 404 and risk factors 406 classified into the malicious activity classification branch 402 are related to various measurement criteria that suggest the target entity has been successfully attacked. These indicators can be found across the Internet and the dark web. For example, malware reaching a destination known to be malicious within the infrastructure of the target entity may indicate a successful attack. As another example, clicking on a link in a phishing email may indicate a successful attack. As yet another example, discovering a sales certificate on the dark web may indicate a successful attack. Thus, the risk categories 404 classified into the malicious activity branch 402 include overseas adversarial interactions (e.g., traffic from the target entity to known malicious infrastructure), phishing exploitation (e.g., traffic from the target entity to known phishing infrastructure), assets listed on blacklists, external traffic anomalies (e.g., measurement criteria for malicious play for routing), violations (e.g., information related to the infringement of the target entity), and utilization of authentication information (e.g., information suggesting that authentication information related to the target entity has been obtained and / or used). As will be discussed in more detail below, the information regarding the risk factors 406 in the malicious activity classification branch 402 can be used as a basis for alerting the client entity and / or the target entity of a successful violation.
[0069] Returning to FIG. 5, process 300 may also include identifying a cyber asset footprint 312 of the 310 entities. The cyber asset footprint 312 of the entity can include a plurality of different cyber asset footprints, and each cyber asset footprint includes cyber assets associated with (e.g., owned or otherwise controlled by) different target entities. For example, the cyber asset footprint 312 of the entity may be similar to the cyber asset database 116 of the entity generated by the footprint process 100 described above with respect to FIG. 1A. 2. Thus, identifying 310 the cyber asset footprint of the entity may include one or more of the steps of the footprint process 100 described above. In some aspects, identifying (310) the cyber asset footprint of the entity may include employing various systems and methods described in International Patent Application No. PCT / US2023 / 062894, filed Feb. 20, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS", and / or International Patent Application No. PCT / US2023 / 022535, filed May 15, 2023, entitled "DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM".
[0070] Referring further to FIG. 5, process 300 can continue by associating the information in source data 308 with cyber assets within the cyber asset footprint 312 of the entity, by identifying relevant observations 314 within the organized source data 308. Relevant observations are information from source data 308 that applies to or is otherwise relevant to one or more of the cyber assets of one or more of the target entities. Thus, identifying relevant observations 314 in the organized source data 308 correlates information explaining various risk factors to the target entity.
[0071] Process 300 can further include determining 316 whether the relevant observations meet one or more predetermined criteria 318. Each of the predetermined criteria 318 is associated with a specific risk factor from the cyber security risk classification 306 and can be used to evaluate information related to that risk factor. As described above, each relevant observation includes information related to one of the risk factors that correlates to at least one of the target entities. Thus, the cyber risk assessment for multiple target entities can be performed by analyzing each relevant observation according to one or more predetermined criteria 318. In some aspects, findings can be issued 320 based on determining 312 that the relevant observations do not comply with one or more predetermined criteria 318. In other aspects, findings can be issued 320 based on determining that the relevant observations comply with one or more predetermined criteria 318.
[0072] For example, one of the risk factors from the cyber security risk classification 306 can be an email security sender policy framework (SPF) risk factor classified based on the IT hygiene classification branch. According to process 300, monitoring 302 the data source 304 can include monitoring various DNS records and MX records. These records can indicate the use of a specific mail server. The SPF record for this specific mail server can be obtained, and thus, monitoring 302 the data source 304 can result in the generation of organized source data 308 including the SPF record (which is organized according to the cyber security risk classification 306 as information related to the email security SPF risk factor). This information can be identified (314) as relevant findings by correlating the use of the mail server (e.g., via MX records) with the cyber assets within the cyber asset footprint 312 of the entity, thereby correlating the SPF record with a specific target entity. The measurement criteria 318 for the email security SPF risk factor can be defined to evaluate the email-related aspect of the IT hygiene of the target entity. As an example, the measurement criteria 318 for the email security SPF risk factor can include measurement criteria (e.g., binary "present" measurement criteria) for determining whether an SPF exists. Based on the presence of the SPF record in the source data 308, in this case, it can be determined 316 that the target entity complies with the "present" email security SPF metric 318. On the other hand, for the mail server, if no relevant observations are identified because no correlation with the cyber assets of a specific target entity is detected, i.e., neither of them is detected, the SPF metric 318 of "present" email security will be violated for the target entity. This process 300 can be performed for many observations related to various risk factors across the cyber security risk classification 306, identifying the relevant observations of 314 and determining 316 whether the relevant observations comply with the predetermined measurement criteria 318.Therefore, evaluating relevant observations within the framework of cyber security risk classification 306 can ultimately enable a systematic and targeted assessment of the cyber risks imposed by various target entities on the client entity.
[0073] Referring further to FIG. 5, process 300 can continue by issuing one or more findings 320 based on determining 316 whether the relevant observations conform to one or more of the predetermined measurement criteria 318. As discussed in detail below, the issued findings 320 can be used to generate alerts 322 sent to the client entity and / or the target entity, generate entity cyber security risk reports 324 that can be used to assist the client entity in evaluating the target entity, and / or initiate corrective actions 326 for the client entity and / or the target entity.
[0074] Each issued finding 320 can include a severity level (e.g., low, medium, high, critical, immediate action, etc.). The severity level assigned to each finding may be based on the urgency of addressing the finding and / or the importance of the finding. Thus, the severity level can be used to determine the type of alert 322 generated and / or the type of corrective action 326 initiated in response to the issued finding 320. Additionally, the cyber security risk classification 306 can be useful in determining the severity level of the findings.
[0075] For example, findings related to IT hygiene risk factors may include a lower level of importance compared to risk factors under other classification branches. In some aspects, this is because the IT hygiene classification branch generally relates to decisions regarding how the target entity conducts the construction and management of IT. Using various risk factors and associated metrics 318, the IT hygiene of the target entity can be evaluated in an objective manner (e.g., industry best practices are defined by organizations such as the National Institute of Standards and Technology (NIST), the Internet Security Center (CIS), and the SANS Institute). Thus, generally, there are clearly defined measures that the target entity can implement to correct findings issued in relation to IT hygiene risk factors. However, the urgency to implement these measures is generally lower than the urgency to implement corrective measures for findings based on other classification branches.
[0076] As another example, findings related to vulnerability risk factors may include a higher level of importance (e.g., a level of importance related to a higher sense of urgency) compared to risk factors under other classification branches. In some aspects, this is because the vulnerability classification branch generally relates to various combinations of software, hardware, and configurations that are known to be vulnerable to cyberattacks. Thus, if it is discovered that a particular software, hardware, or configuration is susceptible to the impact of an attack, it may be important to correct the defect as quickly as possible to prevent exploitation (e.g., by upgrading the application to a patched version, by removing the application, etc.).
[0077] As yet another example, findings related to threat activity risk factors may include a lower level of importance compared to risk factors under other classification branches. In some aspects, this is because the threat activity classification branch is generally related to potential threats posed by various cybercriminals and other malicious actors. These threats can be identified based on monitoring the activities of cybercriminals and other malicious actors and determining their interests (and thus potential targets). For example, the findings may include information indicating that a provider of SPAM or phishing is sending targeted emails to the target entity. As another example, the findings may include information indicating that a known ransomware actor is scanning the infrastructure of the target entity. By combining the typical attack modalities of malicious actors (e.g., ransomware, phishing, etc.) with the volume of activity of the malicious actors, the level of interest of the malicious actors in the target entity can be determined. Thus, somewhat different from the IT hygiene branch, there may not be clearly defined measures available for the target entity to implement in order to correct findings issued in relation to threat activity risk factors. Further, if the target entity is determined to have relatively good IT hygiene, findings related to threat activity risk factors may include the lowest level of importance compared to risk factors under other classification branches.
[0078] As yet another example, findings related to malicious activities may include a higher (or even the highest) level of importance compared to risk factors under other classification branches. In some aspects, this is because the malicious activity classification branch is generally related to various metrics that suggest that the target entity has been successfully attacked. For example, findings related to the malicious activity classification branch may indicate that a user of the target entity has clicked on a link in a phishing email, or that malware (including, for example, ransomware) has been installed somewhere within the target entity's enterprise. Findings of active malicious activities (as opposed to more outlandish attacks, such as observing authentication information for sale on a dark web site) may include the highest level of importance compared to risk factors under other classification branches.
[0079] Referring further to FIG. 5, process 300 can continue by generating an alert (322) based on the issued findings 320. Generating the alert 322 can include sending the alert to a client entity and / or sending the alert to the target entity in response to the issued findings 320. In some aspects, by generating the alert 322, the alert can be sent to a cyber asset and / or a user of the cyber asset associated with the findings. In some aspects, the alert can be generated 322 based on the importance level of the findings. Thus, in some aspects, the alert can be generated 322 based on the classification branch of the risk factors associated with the findings.
[0080] For example, an alert generated 322 in response to findings of IT hygiene risk factors for a particular target entity may be sent to a client entity and / or the target entity, including information related to an aspect of the target entity's IT that should be addressed / fixed.
[0081] As another example, alerts generated 322 in response to findings of vulnerability risk factors for a particular target entity may be sent to a client entity and / or the target entity and include instructions to take corrective action immediately in response to the findings. Alerts to the target entity may include information related to the detected vulnerability and instructions on how to correct the vulnerability (e.g., upgrade to a patched version, remove the exposed version, etc.).
[0082] As yet another example, alerts generated 322 in response to findings of threat activity risk factors for a particular target entity may be sent to a client entity and / or the target entity and include information related to the findings (e.g., describing the activities of malicious actors and the types of attack attempts that may follow).
[0083] As yet another example, alerts generated 322 in response to findings of malicious activity risk factors for a particular target entity may be sent to a client entity and / or the particular target entity and include instructions to take corrective action immediately in response to the findings. Alerts to the target entity may include information related to the malicious activity and instructions for the investigation, stopping, and / or removal of the attack. Alerts to the client entity may include information related to the malicious activity and instructions for ensuring that the communication channels through which the attack was shared with the target entity cannot be crossed.
[0084] Referring further to FIG. 5, process 300 may include generating one or more entity cyber security risk reports 324 based on the findings issued at 320. For each target entity under investigation, a cyber security risk report 324 for a different entity may be generated. Various information related to the findings for a particular target entity can be included in that entity's cyber security risk report 324, which helps the client entity to evaluate the cyber security risks posed by the target entity. Thus, in some aspects, each of the entity cyber security risk reports 324 may include an overall risk assessment of the target entity. As used herein, the term "risk assessment" can refer to a score and / or another type of label or designation used to quantify cyber security risk. For example, a risk assessment may include a score (e.g., a score based on a scale of 0 to 100) for explaining the cyber security risk, a grade (e.g., a letter grade from A to F), a pass / fail designation, and / or another type of bucketed assessment.
[0085] In addition to, or instead of, an overall cybersecurity risk assessment, each of the cybersecurity risk reports 324 may include a classification branch risk assessment for each of the classification branches included in the cybersecurity risk classification 306. The classification branch risk assessment may be calculated and / or determined based on findings related to risk factors classified based on the classification branch of the classification branch risk assessment. For example, an IT hygiene assessment (e.g., score) of the target entity may be based on the issued findings related to the IT hygiene branch of that entity. Calculating and / or determining a risk assessment based on the cybersecurity risk classification 306 can enable findings related to various risk factors to correlate with the impact that each finding has on the cybersecurity risk of a particular target entity for a client entity. Further, by calculating and / or determining a risk assessment based on the cybersecurity risk classification 306, it becomes possible to control the impact that each classification branch assessment has on the overall risk assessment (e.g., if the overall risk assessment is based on 100 points, each classification branch may be assigned a portion of the 100 points to measure the impact that each branch has on the overall score).
[0086] The entity cybersecurity risk report 324 for the target entity may be sent to the client entity or otherwise made accessible. For example, referring again to FIGS. 1 and 5, the cybersecurity risk management provider server 1002 generates an application programming interface (API) and / or a web portal for a client entity (e.g., entity 10101) to interact with the cybersecurity risk report 324 and various target entities (e.g., 10102…1010 n) can enable understanding of the cybersecurity risks brought about by. Based on a request from a client entity (e.g., entity 10101), the cybersecurity risk management provider server 1002 can generate a graphical user interface and configure it to display a cybersecurity risk report 324 on a display screen (e.g., a display screen related to cyber asset 10121).
[0087] Figures 7 and 8 show examples of graphical user interfaces for displaying an entity cybersecurity risk report for a specific target entity according to some non-limiting aspects of the present disclosure. Referring to Figure 7, the graphical user interface 500 includes a breakdown 502 of risk category scores. Further, the breakdown 502 of risk category scores includes an overall score 504 of the target entity (i.e., the company score) and a classification branch score 506 for each branch of the risk factor classification. The breakdown 502 of risk category scores including the overall score 504 and the classification branch score 506 is only an example of the type of risk assessment that can be performed. In this example, the risk factor classification used for the evaluation of the target entity includes branches of email security, IT hygiene, threat activities (hostile threats), vulnerabilities, and malicious activities. In some aspects, the graphical user interface 500 can also display the performance of the target entity compared to other target entities (i.e., peer performance visualization 510).
[0088] Figure 8 shows a detailed view of the peer performance visualization 510 as displayed by the graphical user interface 500 of FIG. 7. The peer performance visualization 510 includes a bar graph showing the classification branch score performance of a particular target entity (i.e., a company) compared to the performance of other target entities (i.e., peers). For example, the email security bar graph 512 and the adversarial threat bar graph 518 indicate that the performance of the target entity regarding email security and threats is below the average performance of other target entities, whereas the IT hygiene bar graph 514, the vulnerability bar graph 516, and the malicious activity bar graph 520 indicate that the performance of the target entity regarding email, IT hygiene, and malicious activity is above the average performance of other target entities. In some aspects, the performance comparison shown in the peer performance visualization 510 can be calculated based on the findings issued as part of process 300 of FIG. 5.
[0089] Referring again to FIG. 5, process 300 can include initiating corrective action 326 based on the issued findings, the generated alerts 322, and / or the entity cyber security risk report 324. Initiating corrective action 326 can include instructing the client entity and / or the target entity to take measures to address the defects associated with one of the issued findings. In some aspects, the initiation of corrective action 326 is based on the cyber security risk classification 306. In other words, the initiation of corrective action 326 can be based on the classification of the risk factors associated with the issued findings and / or the generated alerts that caused the initiation of corrective action 326. For example, different corrective actions can be initiated 326 depending on whether the findings and / or alerts that caused the initiation of corrective action are based on risk factors classified in the IT hygiene, vulnerability, threat, or malicious activity classification branches.
[0090] Figure 9 shows a flowchart of a process for initiating a corrective action 326 based on a cyber security risk classification that can be implemented as part of the process 300 of FIG. 5. Referring now to FIGS. 5 and 9, in one aspect, initiating a corrective action 326 can include determining 328 a classification branch of risk factors associated with the findings and / or alerts that triggered the initiation of the corrective action 326. If the classification branch of risk factors associated with the findings and / or alerts is IT hygiene, initiating a corrective action 326 can include instructing 330 the target entity associated with the findings to update its IT infrastructure. If the classification branch of risk factors associated with the findings and / or alerts is a vulnerability, initiating a corrective action 326 can include instructing 332 the target entity associated with the findings to upgrade the exposed application to a patched version and / or instructing the target entity associated with the findings to remove the exposed application. If the classification branch of risk factors associated with the findings and / or alerts is a threat, initiating a corrective action 326 can include instructing 334 the client entity and / or the target entity associated with the finding that the target entity is being subjected to malicious activity. If the classification branch of risk factors associated with the findings and / or alerts is malicious activity, then initiating a corrective action 326 can include instructing 336 the target entity associated with the findings to investigate the attack, instructing 336 the target entity associated with the findings to stop the attack, and / or instructing the client entity to adjust its communication with the target entity associated with the findings to prevent the client entity from being exposed to the attack.
[0091] Next, referring to FIG. 4, there is shown a diagram of a system 2000 configured to identify cyber security assets based on risk factor classification and generate cyber risk mitigation measures for a plurality of entities, according to at least one non-limiting aspect of the present disclosure. System 2000 may be similar in many respects to system 1000 described above with respect to FIG. 1 (having corresponding reference characters representing corresponding components). System 2000 may include a cyber security risk management provider server 1002 comprising a memory 1004 and a processor 1006. Server 1002 may be configured to generate a footprint module 1020 and a risk mitigation module 1030.
[0092] The footprint module 1020 may be configured to perform various steps of the footprint process 100 described above with respect to FIG. 5 and / or the step of identifying the cyber asset footprint of the 310 entities described above with respect to FIG. 2. In some aspects, the footprint module 1020 may include a cyber asset database 1040. The cyber asset database 1040 may store the entity database 108 and / or the cyber asset database 116 described above with respect to FIG. 5 and / or the entity cyber asset footprint 312 described above with respect to FIG. 2.
[0093] The risk reduction module 1030 may be configured to execute various steps of the cyber risk reduction process 200 described above with respect to FIG. 5, and / or various steps of the process 300 for managing cyber risk based on the risk factor classification described above with respect to FIG. 3. In some aspects, the risk reduction module 1030 may include one or more analysis modules 1032 and a remediation module 1041. The analysis module 1032 is configured to monitor 302 a cyber risk information data source, generate source data, identify 314 relevant observations of the source data based on a correlation with the cyber asset footprint of the entity, determine 316 whether the relevant observations comply with one or more criteria, generate findings 320, alerts 322, and / or generate a cyber security risk report 324 for the entity, as described above with respect to FIG. 5. The remediation module 1041 may be configured to perform the steps of generating an alert 322, generating an entity cyber security risk report 324, and / or initiating a remediation action 326, as described above with respect to FIGS. 5 and 9.
[0094] In some aspects, the risk reduction module 1030 may include source data 1034, a classification 1036, and a criterion 1038. The source data 1034 may store the source data 308 described above with respect to FIG. 5. The classification 1036 may store information related to the cyber security risk classification 306 described above with respect to FIGS. 6A-6B, and / or the cyber security risk classification 400 described above with respect to FIG. 5. The criterion 1038 may store information related to the predetermined criterion 318 described above with respect to FIG. 5.
[0095] Referring again to FIG. 5, a process 300 for managing cyber risks based on a cyber security risk classification 306 can provide many technical benefits. As described in detail above, by organizing risk factors and findings based on the cyber security risk classification 306, the process 300 can prioritize the generation 322 of alerts and the initiation 326 of remediation activities based on different branches and / or categories of the cyber security risk classification 306. Further, by organizing the source data 308 based on the cyber security risk classification, the process 300 can be optimized to identify the most valuable 314 relevant observations for evaluating cyber risks associated with multiple target entities. Still further, a client entity that receives the generated 322 alerts, a cyber risk report 324 of the entity, and / or an order to initiate 326 corrective measures can better understand how different investigation results affect cyber security and what measures need to be implemented to address those investigation results.
[0096] Referring further to FIG. 5, a process 300 for managing cyber risks based on a cyber security risk classification 306 can provide technical benefits for identifying and organizing cyber risk information related to the cyber asset footprint of a target entity, including (i) monitoring 302 a plurality of data sources 304 containing cyber risk information to generate source data 308 organized based on the cyber security risk classification 306, such that the risk factors are classified according to classification branches including information technology (IT) hygiene, vulnerabilities, threats, malicious activities; and (ii) correlating the cyber risk information to the cyber asset footprint of the target entity to identify 314 relevant observations in the source data.
[0097] Referring further to FIG. 5, process 300 issues 320 findings related to the identified 314 relevant observations, generates 322 an alert and / or a cybersecurity risk report 324 based on a classification branch of risk factors associated with the findings, thereby providing certain improvements over previous cybersecurity risk management systems and potentially including integrating the organization of cybersecurity information according to risk factors and classification branches into a practical application.
[0098] Referring further to FIG. 5, process 300 can manage the cybersecurity risk of a client entity that communicates with multiple target entities at a scale that is not realistically executable in a human head by (i) identifying 310 a cyber asset footprint 312 of a target entity, (ii) monitoring 302 a plurality of data sources 304 including cyber risk information to generate source data 308, and (iii) associating the cyber risk information in the source data with one of the cyber asset footprints 312 to identify 314 relevant observations in the source data 308.
[0099] Referring to FIGS. 5 and 6, process 300 can provide a technical benefit by initiating corrective action 326 based on the classification branches of cybersecurity risk classifications 306, 400 associated with the issued findings, thereby providing certain improvements over previous cybersecurity risk management systems and integrating the organization of cyber risk information according to risk factors and classification branches into a practical application. For example, various "risk assessment solutions" exist for assessing cyber risks associated with a target entity, such as those described in U.S. Patent No. 9,294,498, entitled ONLINE PORTAL FOR IMPROVING CYBERSECURITY RISK SCORES, issued March 22, 2016, which is incorporated herein by reference in a manner not inconsistent with the present disclosure. However, these risk assessment solutions generally do not provide corrective means in response to the identification of cyber-related risks. This can make it difficult to determine what corrective actions should be taken in response to a specified risk, as the various categories of cyber risks used by the risk assessment solutions may not be clear. In contrast, the classification branches and risk categories of cybersecurity risk classifications 306, 400 can enable the implementation of specific corrective actions in response to a specified risk.
[0100] As an example, a risk assessment solution may adopt the "social engineering" category to determine an entity's potential susceptibility to targeted social engineering attacks. However, this social engineering category may not be able to distinguish between successful attacks and attempted attacks. Therefore, an entity that receives a score related to "social engineering" may find it difficult to understand how to address the cyber risk associated with this score. Conversely, cyber security risk classifications 306, 400 may include separate branches for threat activities and malicious activities. Therefore, cyber security risk classifications 306, 400 can enable the initiation 326 of different types of corrective actions depending on whether the identified cyber risk is related to threat activities or malicious activities (e.g., in the case of malicious activities, initiate immediate measures to correct the attack, while in the case of just a threat, alert the entity that an attack has been attempted).
[0101] As another example, a risk assessment solution can use the "malware and botnet infection" category to detect malware and botnet "events". However, this malware and botnet infection category may not be able to distinguish between attempted and successful botnet "events". Conversely, cyber security risk classifications 306, 400 may include separate risk categories 404 for attack success (e.g., hostile external infection under the malicious activity branch 402) and attack attempt (e.g., hostile intrusion under the threat activity branch 402). Therefore, as above, cyber security risk classifications 306, 400 can enable the initiation 326 of different types of corrective actions depending on whether the identified cyber risk is related to threat activities or malicious activities (e.g., initiate immediate measures to correct the attack in the case of malicious activities, while simply alert the entity that an attack has been attempted in the case of threat activities).
[0102] As yet another example, a risk assessment solution may adopt a "DNS health" category to measure the health and configuration of an entity's DNS settings and verify that no malicious events have occurred in the entity's network's passive DNS history. However, this DNS health category score may not be able to distinguish between configurations that do not conform to industry cyber security standards and successful attacks. Conversely, cyber security risk classifications 306, 400 may include separate risk categories 404 for IT hygiene-related configuration defects (e.g., DNS security based on email, IT hygiene branch 402) and successful attacks (e.g., overseas adversarial interactions, external traffic anomalies based on malicious activity branch 402). Thus, cyber security risk classifications 306, 400 can enable the initiation of different types of corrective actions 326 depending on whether the identified cyber risk is related to the success of malicious activity (e.g., initiating immediate action to remedy an attack) or a defect in IT hygiene (e.g., instructing the entity to perform a configuration update with a low sense of urgency).
[0103] Referring now to FIG. 10, a diagram of an exemplary cloud architecture 8000 is shown in accordance with at least one non-limiting aspect of the present disclosure. As will be described below, the cloud architecture 8000 and the various components configured therein can be used to implement the server 1002 described hereinabove in connection with FIGS. 1 and 4 and / or to store and execute any of the various processes described hereinabove in connection with FIGS. 2-3 and FIGS. 5-9. The definition provided in "The NIST Definition of Cloud Computing" by Peter Mell and Tim Grance, published in September 2011, which is hereby incorporated by reference in its entirety, is applicable to the discussion accompanying FIG. 10.
[0104] According to a non-limiting aspect of FIG. 10, the cloud architecture 8000 is configured to enable on-demand network access to a shared pool of computing resources. In this regard, the cloud architecture 8000 can be deployed as a private cloud provisioned for exclusive use by a single organization (e.g., a cyber risk management provider), a community cloud provisioned for use by a specific community of users (e.g., including cyber risk management providers, client entities, etc.), a public cloud, or a hybrid cloud.
[0105] The cloud architecture 8000 may include an infrastructure 8100. The infrastructure may include physical hardware such as a computing pool 8110 and / or a storage pool 8120. The computing pool 8110 and the storage pool 8120 comprise a series of servers (e.g., similar to the computer system 9000 of FIG. 11) that provide computing and storage resources to the cloud architecture 8000. The infrastructure 8100 may also include an abstraction layer 8130 and an orchestration layer 8140. The abstraction layer 8130 is provided to abstract the resources of the physical hardware (e.g., via virtualization), and the orchestration layer 8140 is provided to pool the abstracted resources. The pooled resources can be provisioned by the orchestration layer 8140 to execute various functions required by various users of the cloud architecture 8000. For example, the pooled resources of the cloud architecture 8000 and / or the infrastructure 8100 can be provisioned to execute the processes 100, 200, 300 described herein.
[0106] In some aspects, the cloud architecture 8000 includes any number of applications 82101, 82102, 82103…8210 nIt may include an application platform 8200 including. Provision the pooled resources of the underlying infrastructure 8100 to the application platform 8200 to generate executable applications 82101, 82102, 82103…8210 n can be generated. In some embodiments, applications 82101, 82102, 82103…8210 n can be used to implement the processes 100, 200, 300 described herein. For example, applications 82101, 82102, 82103…8210 n can be employed as the footprint module 1020, risk mitigation module 1030, analysis module 1032, and / or repair module 1041 described above with respect to FIG. 4.
[0107] Referring now to FIG. 11, a diagram of a computer system 9000 is shown in accordance with at least one non-limiting aspect of the present disclosure. The computer system 9000, and various components included therein, may be used to execute the various components of the systems 1000, 2000 and cloud architecture 8000 described above in connection with FIGS. 1, 4 and 10, as described below, and / or may be used to store and execute instructions for any of the various processes described above in connection with FIGS. 2-3 and 5-9.
[0108] According to a non-limiting aspect of FIG. 11, the computer system 9000 may include a bus 9002 (i.e., an interconnect), one or more processors 9004, main memory 9006, read-only memory 9008, removable storage media 9010, mass storage 9012, and one or more communication ports 9014. As should be understood, components such as removable storage media are optional and not required in all systems. The communication port 9014 may be connected to one or more networks through which the computer system 9000 can receive and / or transmit data.
[0109] As used herein, "processor" can mean one or more microprocessors, central processing units (CPUs), computing devices, microcontrollers, digital signal processors, graphics processing units (GPUs), or similar devices, or any combination thereof, regardless of architecture. The apparatus for implementing a process may include, for example, a processor and those devices such as input devices and output devices suitable for implementing the process.
[0110] Processor 9004 may be any known processor, such as, but not limited to, a processor manufactured and / or sold by INTEL®, AMD®, or MOTOROLA®, which are generally well-known to those skilled in the art and clearly defined in the literature. Communication port 9014 may be any of, for example, an RS-232 port for use in a modem-based dial-up connection, a 10 / 100 Ethernet port, a gigabit port using copper or fiber, or a USB port. Communication port 9014 may be selected according to the network, such as a local area network (LAN), a wide area network (WAN), a CDN, or any network to which computer system 9000 is connected. Computer system 9000 may communicate with peripheral devices (e.g., display screen 9016, input device 9018) via input / output (I / O) port 9020.
[0111] The main memory 9006 can be a random access memory (RAM) or any other dynamic storage device commonly known in the art. The read-only memory 9008 can be any static storage device, such as a programmable read-only memory (PROM) chip, for storing static information, such as instructions for the processor 9004. A mass storage device 9012 can be used to store information and instructions. For example, a hard disk, such as the Adaptec® family of Small Computer System Interface (SCSI) drives, an optical disk, an array of disks such as a redundant array of independent disks (RAID) of the Adaptec® family of RAID drives, or any other mass storage device can be used.
[0112] The bus 9002 communicatively couples the processor 9004 to other memory, storage, and communication blocks. The bus 9002 can be, for example, a PCI / PCI-X, SCSI, Universal Serial Bus (USB)-based system bus (or others) depending on the storage device used. The removable storage medium 9010 can be any kind of external hard drive, floppy drive, IOMEGA® Zip drive, compact disc read-only memory (CD-ROM), compact disc rewritable (CD-RW), digital versatile disc read-only memory (DVD-ROM), and the like.
[0113] Aspects described herein may be provided as one or more computer program products, which may include a machine-readable medium having instructions stored thereon, which may be used to program a computer (or other electronic device) to perform a process. As used herein, the term "machine-readable medium" refers to any medium, plural media, or combination of different media involved in providing data (e.g., instructions, data structures) that can be read by a computer, processor, or similar device. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media includes, for example, optical or magnetic disks, and other persistent memory. Volatile media may include dynamic random access memory, which typically constitutes a computer's main memory. Transmission media includes coaxial cables, copper wire, and fiber optics, including the wires that make up a system bus coupled to a processor. Transmission media may include acoustic waves, light waves, and electromagnetic radiation, such as those generated during radio frequency (RF) and infrared (IR) data communications, or may transmit them.
[0114] Machine-readable media may include, but are not limited to, floppy disks, optical disks, CD-ROMs, magneto-optical disks, ROMs, RAMs, erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic or optical cards, flash memory, or other types of media / devices suitable for storing electronic instructions. Further, aspects described herein may also be downloaded as a computer program product, where the program may be transferred from a remote computer to a requesting computer by a data signal embodied in a carrier wave or other propagation medium via a communication link (e.g., a modem or network connection).
[0115] Various forms of computer-readable media may be involved in carrying data (e.g., a sequence of instructions) to a processor. For example, the data may be (i) delivered from RAM to the processor, (ii) carried on a wireless transmission medium, (iii) formatted and / or transmitted according to a number of formats, standards, or protocols, and / or (iv) encrypted in any of a variety of ways well known in the art. The computer-readable media can store program elements (in any suitable format) appropriate to execute the methods.
[0116] As shown, main memory 9006 is encoded with application 9022 that supports the functions discussed herein (application 9022 may be an application that provides some or all of the functions of the CD services described herein, including client applications). Application 9022 (and / or other resources described herein) may be embodied as software code, such as data, and / or logical instructions (e.g., code stored in memory or on another computer-readable medium such as a disk) that support processing functions in different manners described herein.
[0117] During operation of one aspect, processor 9004 accesses main memory 9006 via the use of bus 9002 to start, execute, run, interpret, or otherwise execute the logical instructions of application 9022. Execution of application 9022 generates processing functions for services associated with the application. In other words, process 9024 represents one or more portions of application 9022 that operate within or on processor 9004 within computer system 9000.
[0118] In addition to process 9024 that performs operations as discussed herein, note that other processes described herein may include application 9022 itself (i.e., unexecuted or non-executing, logical instructions, and / or data). Application 9022 may be stored on a computer-readable medium, such as a disk (e.g., a repository), or within an optical medium. According to other aspects, application 9022 may also be stored in a memory-type system, such as firmware, read-only memory (ROM), or executable code within main memory 9006 (e.g., within random access memory, or RAM), as in this example. For example, application 9022 may also be stored on removable storage medium 9010, read-only memory 9008, and / or mass storage device 9012.
[0119] One of ordinary skill in the art will understand that computer system 9000 may also include other processes, such as an OS that controls the allocation and use of hardware resources, and / or software and hardware components.
[0120] The various aspects of the subject matter described herein are set forth in the following numbered clauses.
[0121] Clause 1: A method for managing the cybersecurity risks of a client entity that communicates with a plurality of target entities, the method comprising: identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities; monitoring a plurality of data sources including cybersecurity risk information to generate source data, the source data being organized based on a plurality of risk factors, the risk factors being classified according to a classification branch, the classification branch identifying related observations in information technology (IT) hygiene, vulnerabilities, threat activities, malicious activities, the source data; each related observation including information related to one of the risk factors, each related observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints; determining that one of the related observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the cybersecurity risk factors; issuing a finding based on determining that the related observation does not comply with the predetermined measurement criterion, the finding including a severity level, the severity level being based on the classification branch of the risk factor associated with the finding; and sending an alert to the client entity based on the severity level of the finding.
[0122] Clause 2: The method according to clause 1, further comprising initiating a corrective action with respect to the target entity associated with the finding in response to the issuance of the finding.
[0123] Clause 3: For each of the related observations, determining whether the related observation does not comply with at least one of a plurality of predetermined measurement criteria; issuing a finding based on determining whether the related observation does not comply with at least one of the plurality of predetermined measurement criteria; and generating a risk report for each of the target entities based on the finding. The method according to any one of clauses 1 to 2 further includes.
[0124] Clause 4: Based on the findings, generating the risk report for each of the target entities involves determining which of the findings are associated with the target entity, and determining, for the target entity, a classification branch risk assessment for each of the classification branches, each taxonomic risk assessment being based on findings related to a cybersecurity risk factor classified based on the taxonomic branch of the taxonomic branch risk assessment, the method according to any one of Clauses 1 to 3.
[0125] Clause 5: Generating the risk report for each target entity further includes determining an overall risk assessment for the target entity based on the classification branch risk assessment, the method according to any one of Clauses 1 to 4.
[0126] Clause 6: Based on the generated risk report, initiating corrective measures for at least one of the target entities, the method according to any one of Clauses 1 to 5.
[0127] Clause 7: Further including classifying risk factors according to risk categories and classifying risk categories according to classification branches, the method according to any one of Clauses 1 to 6.
[0128] Clause 8: The risk categories classified into the IT hygiene classification branch include at least one of a risk factor related to the attack surface, a risk factor related to email security, a risk factor related to configuration, a risk factor related to application security, a risk factor related to DNS security, a risk factor related to non-business applications, and a risk factor related to vendor dependency, the method according to any one of Clauses 1 to 7.
[0129] Clause 9: The risk categories classified into the vulnerability classification branch include at least one of a risk factor related to software vulnerability and a risk factor related to data encryption, the method according to any one of Clauses 1 to 8.
[0130] Article 10: The method according to any one of Articles 1 to 9, wherein the risk category classified into the threat activity classification branch includes at least one of a risk factor related to received adversarial probing, a risk factor related to phishing targeting, a risk factor related to authentication information targeting, and a risk factor related to the dark web.
[0131] Article 11: The method according to any one of Articles 1 to 10, wherein the risk category classified into the malicious activity classification branch includes at least one of a risk factor related to sent adversarial communication, a risk factor related to phishing exploitation, a risk factor related to blacklisted assets, a risk factor related to abnormal external traffic, a risk factor related to violations, and a risk factor related to authentication information exploitation.
[0132] Article 12: An alert is sent based on the risk factor associated with the finding classified into the vulnerability classification branch, and the method includes, based on the alert, starting a corrective action for the target entity associated with the finding, and starting a corrective action for the target entity includes at least one of instructing the target entity to upgrade the application to a patched version and instructing the target entity to delete the application. The method according to any one of Articles 1 to 11.
[0133] Article 13: An alert is sent based on the risk factor associated with the finding classified into the threat activity classification branch, and the alert includes an instruction to the client entity that the target entity is potentially being used for malicious activities. The method according to any one of Articles 1 to 12.
[0134] Clause 14: An alert is sent based on the risk factor associated with a finding classified into the malicious activity classification branch, and the method includes starting, based on the alert, a corrective action for the target entity associated with the finding, and starting the corrective action for the target entity includes at least one of instructing to investigate an attack on the target entity and instructing to stop an attack on the target entity, the method according to any one of Clauses 1 to 13.
[0135] Clause 15: An alert is sent based on the risk factor associated with a finding classified into the IT hygiene classification branch, and the method further includes starting, based on the alert, a corrective action for the target entity associated with the finding, and starting the corrective action for the target entity includes instructing the target entity to update or otherwise modify its infrastructure, the method according to any one of Clauses 1 to 14.
[0136] Clause 16: A method for managing the cybersecurity risk of a client entity that communicates with a plurality of target entities, the method comprising: identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities; monitoring a plurality of data sources including cyber risk information to generate source data, the source data being organized based on a plurality of risk factors, the risk factors being classified according to a cybersecurity risk classification; identifying relevant observations within the source data, each relevant observation including information related to one of the risk factors, each relevant observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints; determining that one of the relevant observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the risk factors; issuing a finding based on determining that the relevant observation does not comply with the predetermined measurement criterion, the finding including a severity, the severity being based on the classification of the risk factor associated with the finding.
[0137] Clause 17: The method according to clause 16, wherein the cybersecurity risk classification includes classification branches, and the classification branches include at least one of email, information technology (IT) hygiene, vulnerabilities, threatening activities, and malicious activities.
[0138] Clause 18: The method according to any one of clauses 16 to 17, wherein corrective actions are initiated based on the severity of the finding.
[0139] Clause 19: The method according to any one of clauses 16 to 18, further comprising generating an alert based on the finding.
[0140] Clause 20: The method according to any one of Clauses 16 to 19, further comprising at least one of: sending an alert to a target entity associated with a finding; and sending an alert to a client entity.
[0141] Clause 21: The system and method for cyber security risk mitigation are substantially as disclosed and described herein.
[0142] All patents, patent applications, publications, or other disclosure materials described herein are hereby incorporated by reference in their entirety as if each individual reference were explicitly incorporated by reference. All references, and any materials or portions thereof, said to be incorporated by reference herein are incorporated by reference only to the extent that the incorporated material does not conflict with the existing definitions, descriptions, or other disclosure materials set forth in this disclosure. Accordingly, and to the extent necessary, the disclosure set forth herein supersedes any conflicting material incorporated by reference herein, and the disclosure is stated explicitly within the context of this application.
[0143] Various illustrative and exemplary aspects are described. The aspects described herein are to be understood as providing illustrative features of various details of various aspects of the present disclosure, and thus, unless otherwise specified, it is of course possible, without departing from the scope of the present disclosure, to combine, separate, exchange, and / or re-arrange one or more features, elements, components, ingredients, materials, structures, modules, and / or aspects of the aspects of the present disclosure as much as possible. Accordingly, those skilled in the art will recognize that various substitutions, modifications, or combinations of any of the illustrative aspects can be made without departing from the claimed subject matter. Further, those skilled in the art can, by a review of this specification, recognize or confirm many equivalents to the various aspects of the present disclosure using only routine experimentation. Accordingly, the present disclosure is not limited by the description of the various aspects, but only by the claims.
[0144] Those skilled in the art will generally recognize that terms used herein, and particularly in the appended claims (e.g., the body of the appended claims), are generally intended as terms without limitation (e.g., the term "including" should be construed as "including but not limited to", the term "having" should be construed as "having at least", the term "includes" should be construed as "including but not limited to", etc.). Those skilled in the art will further understand that where a specific number of introduced claim listings is intended, such intent is explicitly recited in the claims, and where there is no such listing, such intent does not exist. For example, by way of illustration, the following appended claims may include the use of introductory phrases "at least one" and "one or more" to introduce claim listings. However, the use of such phrases should not be construed as implying that the introduction of a claim listing by the indefinite article "a" or "an" limits any particular claim that includes such introduced claim listing to a claim scope that includes only one such listing, and the same is true for the use of definite articles used to introduce claim listings even when the same claim includes introductory phrases "one or more" or "at least one" and indefinite articles such as "a" or "an" (e.g., "a" and / or "an" should generally be construed as meaning "at least one" or "one or more").
[0145] Furthermore, even if a specific number of the recited claims introduced is explicitly recited, one of ordinary skill in the art will recognize that such a recitation should typically be interpreted to mean at least the recited number (e.g., a mere recitation of “two recitations” would typically mean at least two recitations or more than two recitations without other modifying phrases). Further, in these instances where a convention similar to “at least one of A, B, and C” is used, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., “a system having at least one of A, B, and C” includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). In instances where a convention similar to “at least one of A, B, or C” is applied, generally, such a construction is intended in the sense that one of ordinary skill in the art would understand the convention (e.g., “a system having at least one of A, B, or C” includes, but is not limited to, a system having A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together). It will be further understood by those of skill in the art that in any of the description, claims, or drawings, disjunctive and / or phrases presenting two or more alternative terms will typically be understood to contemplate the possibility of including one of the terms, any of the terms, or both terms, unless the context indicates otherwise. For example, the phrase “A or B” would typically be understood to include the possibilities of “A” or “B” or “A and B”.
[0146] Regarding the appended claims, one of ordinary skill in the art will understand that the operations recited therein may generally be performed in any order. Also, although the claims are presented in sequence, it should be understood that the various operations may be performed in other orders than those recited, or simultaneously. Examples of such alternative orders include, without limitation, repetition, interleaving, interruption, reordering, incrementing, preparation, supplementation, simultaneity, reversal, or other variant orders, unless the context otherwise indicates. Further, unless the context otherwise dictates, terms such as "responding," "relating," or other past tense adjectives generally are not intended to exclude such variants.
[0147] It should be noted that any reference to "one aspect," "aspect," "exemplification," "an exemplification," and the like means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, the appearances of the phrases "in one aspect," "in an aspect," "in an exemplification," and "in an exemplification" at various places throughout this specification are not necessarily all referring to the same aspect. Further, a particular feature, structure, or characteristic may be combined in any suitable manner in one or more aspects.
[0148] As used herein, unless the context clearly dictates otherwise, the singular forms "a," "an," and "the" include plural references.
[0149] For example, without limitation, directional terms used herein such as up, down, left, right, below, above, front, back, and variations thereof relate to the orientation of elements shown in the accompanying drawings and are not limiting with respect to the claims unless otherwise explicitly stated.
[0150] As used herein, the term "about" or "approximately" means, unless otherwise specified, an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the term "about" or "approximately" means within 1, 2, 3, or 4 standard deviations. In certain embodiments, the term "about" or "approximately" means within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.
[0151] As used herein, unless otherwise indicated, all numerical parameters are to be understood as being preceded by the term "about," which in all cases means that the numerical parameter has the inherent variability of the measurement technique used to determine the value of the parameter. At a minimum, and not as an attempt to limit the application of the doctrine of equivalents to the claims, each numerical parameter herein is to be construed in light of the reported number of significant digits and by applying ordinary rounding techniques.
[0152] Any numerical range recited herein includes all sub-ranges subsumed within the recited range. For example, the range "1 to 100" includes all sub-ranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., all sub-ranges having a minimum value of 1 or more and a maximum value of 100 or less. Also, all ranges recited herein include the endpoints of the recited range. For example, the range "1 to 100" includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, Applicants reserve the right to amend this specification, including the claims, to expressly recite sub-ranges expressly within the ranges expressly recited herein. All such ranges are inherently described herein.
[0153] Any patent application, patent, non-patent publication, or other disclosure material mentioned in this specification and / or listed in any application data sheet is incorporated herein by reference to the extent that the incorporated material does not conflict with this specification. Accordingly, and to the extent necessary, the present disclosure as explicitly described herein prevails over any conflicting material incorporated herein by reference. Although said to be incorporated herein by reference, any material or portion thereof that conflicts with an existing definition, statement, or other disclosure material specified herein is incorporated only to the extent that no conflict arises between the incorporated material and the existing disclosure material.
[0154] The terms “comprise” (and any form of comprise such as “comprises,” “comprising,” etc.), “have” (and any form of have such as “has,” and “having,” etc.), “include” (and any form of include such as “includes” and “including,” etc.), and “contain” (and any form of contain such as “contains” and “containing,” etc.) are open-ended conjunctive verbs. As a result, a system that “comprises,” “has,” “includes,” or “contains” one or more elements possesses those one or more elements but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that “comprises,” “has,” “includes,” or “contains” one or more features possesses those one or more features but is not limited to possessing only those one or more features.
[0155] The foregoing detailed description has described various forms of devices and / or processes by use of block diagrams, flowcharts, and / or examples. If such block diagrams, flowcharts, and / or examples include one or more functions and / or operations, those skilled in the art will understand that each function and / or operation within such block diagrams, flowcharts, and / or examples can be implemented individually and / or collectively by a wide variety of hardware, software, firmware, or substantially any combination thereof. Those skilled in the art will recognize that some aspects of the forms disclosed herein can be implemented as one or more computer programs operating on one or more computers (e.g., as one or more programs operating on one or more computer systems), as one or more programs operating on one or more processors (e.g., as one or more programs operating on one or more microprocessors), as firmware, or substantially any combination thereof, and that all or part of the equivalent integrated circuit can be implemented by circuit design and / or the description of the code for software and / or firmware, which is within the scope of the skills of those skilled in the art in light of this disclosure. Further, those skilled in the art will understand that the mechanisms of the subject matter described herein can be distributed in various forms as one or more program products, and that the exemplary forms of the subject matter described herein apply regardless of the particular type of signal-bearing medium used to actually carry out the distribution.
[0156] The instructions used to program the logic to execute the various disclosed aspects may be stored in memory within the system, such as dynamic random access memory (DRAM), cache, flash memory, or other storage devices. Further, the instructions may be distributed via a network or via other computer-readable media. Thus, a machine-readable medium is any mechanism, but not limited to, a floppy disk, optical disk, CD-ROM, and magneto-optical disk, read only memory (ROM), random access memory (RAM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), magnetic or optical card, flash memory, or tangible machine-readable storage devices used to transmit information over the Internet via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.). Thus, a non-transitory computer-readable medium includes any type of tangible device-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a device (e.g., a computer).
[0157] When used in any aspect of this specification, the term "control circuit" can refer to, for example, a wired circuit, a programmable circuit (such as a computer processor having one or more individual instruction processing cores, a processing unit, a processor, a microcontroller, a microcontroller unit, a controller, a digital signal processor (DSP), a programmable logic device (PLD), a programmable logic array (PLA), or a field programmable gate array (FPGA)), a state machine circuit, firmware storing instructions executed by a programmable circuit, and any combination thereof. The control circuit can be embodied, collectively or individually, as part of a larger system, such as an integrated circuit (IC), an application specific integrated circuit (ASIC), a system on chip (SoC), a desktop computer, a laptop computer, a tablet computer, a server, a smartphone, etc. Thus, as used herein, "control circuit" includes, but is not limited to, an electrical circuit having at least one discrete electrical circuit, an electrical circuit having at least one integrated circuit, an electrical circuit having at least one application specific integrated circuit, an electrical circuit forming a general purpose computing device configured by a computer program (such as a general purpose computer configured by a computer program that at least partially executes a process, and / or a device described herein, or a microprocessor configured by a computer program that at least partially executes a process, and / or a device described herein), an electrical circuit forming a memory device (such as in the form of a random access memory), and / or an electrical circuit forming a communication device (such as a modem, a communication switch, or an optoelectronic device). One of ordinary skill in the art will recognize that the subject matter described herein may be implemented in analog, digital, or some combination thereof.
[0158] When used in any aspect of this specification, the term "logic" can refer to an application, software, firmware, and / or circuitry configured to perform any of the foregoing operations. Software can be embodied as a software package, code, instructions, instruction sets, and / or data recorded on a non-transitory computer-readable storage medium. Firmware can be embodied as code, instructions, or instruction sets, and / or data hard-coded (e.g., non-volatile) within a memory device.
[0159] When used in any aspect of this specification, terms such as "component", "system", "module", etc. can refer to a computer-related entity, hardware, a combination of hardware and software, software, or software in execution.
[0160] When used in any aspect of this specification, "algorithm" refers to a self-consistent order of steps that yields a desired result, and "step" refers to an operation on physical quantities and / or a logical state that can take the form of an electrical or magnetic signal that need not necessarily be so but can be stored, moved, combined, compared, and otherwise manipulated. These signals are commonly referred to as bits, values, elements, symbols, characters, terms, numbers, etc. These and similar terms may be associated with appropriate physical quantities and are merely convenient labels applied to these quantities and / or states.
Claims
1. A method for managing the cybersecurity risk of a client entity that communicates with a plurality of target entities, the method comprising: identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities; monitoring a plurality of data sources including cyber risk information to generate source data, the source data being organized based on a plurality of risk factors, the risk factors being information technology (IT) hygiene, vulnerabilities, threat activities, and malicious activities, and being classified according to a classification branch including the same; identifying relevant observations within the source data, each relevant observation including information related to one of the risk factors, each relevant observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints; determining that one of the relevant observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the risk factors; issuing a finding based on the determination that the relevant observation does not comply with the predetermined measurement criterion, the finding including a severity, the severity being based on the classification branch of the risk factor associated with the finding; sending an alert to the client entity based on the severity of the finding.
2. The method according to claim 1, further comprising initiating a corrective action for the target entity associated with the finding in response to the issuance of the finding.
3. The method according to claim 1, for each of the relevant observations, determining whether the relevant observation does not comply with at least one of the predetermined measurement criteria; issuing a finding based on the determination of whether each of the relevant observations does not comply with at least one of the predetermined measurement criteria; The method according to claim 1, further comprising generating a risk report for each of the target entities based on the finding.
4. Based on the findings, generating the risk report for each of the target entities, determining which of the findings are associated with the target entity, for the target entity, determining a classification branch risk assessment for each of the classification branches, each classification branch risk assessment being based on the findings associated with the risk factors classified based on the classification branch of the classification branch risk assessment, the method according to claim 3, comprising:
5. generating the risk report for each of the target entities, further comprising determining an overall risk assessment of the target entity based on the classification branch risk assessment, the method according to claim 4.
6. The method according to claim 5, further comprising initiating a corrective action for at least one of the target entities based on the generated risk report, the method according to claim 5.
7. classifying the risk factors according to risk categories, further comprising classifying the risk categories according to the classification branches, the method according to claim 1.
8. the risk categories classified into the IT hygiene classification branch are attack surface related risk factors, email security related risk factors, configuration related risk factors, application security related risk factors, DNS security related risk factors, non-business application related risk factors, or at least one of vendor dependency related risk factors, the method according to claim 7.
9. the risk categories classified into the vulnerability classification branch are software vulnerability related risk factors, or at least one of data encryption related risk factors, the method according to claim 7.
10. the risk categories classified into the threat activity classification branch are incoming adversarial probing related risk factors phishing targeting related risk factors, authentication information targeting related risk factors, or at least one of dark web related risk factors, the method according to claim 7.
11. the risk categories classified into the malicious activity classification branch are outgoing adversarial communication related risk factors, phishing exploitation related risk factors, blacklist asset related risk factors, external traffic anomaly related risk factors, A method according to claim 7, comprising at least one of a violation-related risk factor or a risk factor related to the utilization of authentication information. A method according to claim 12, wherein the alert is sent based on the risk factor associated with the finding classified into the vulnerability classification branch, and the method comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises at least one of instructing the target entity to upgrade the application to a patched version and instructing the target entity to delete the application. Claim 12 A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the threat activity classification branch, and the alert includes an instruction to the client entity that the target entity is being used for malicious activities. A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the malicious activity classification branch, and the method comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises at least one of instructing the target entity to investigate the attack and instructing the target entity to stop the attack. A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the IT hygiene classification branch, and the method further comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises instructing the target entity to update its infrastructure. A method for managing the cyber security risk of a client entity communicating with a plurality of target entities Claim 13 A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the vulnerability classification branch, and the method comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises at least one of instructing the target entity to upgrade the application to a patched version and instructing the target entity to delete the application. Claim 14 A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the threat activity classification branch, and the alert includes an instruction to the client entity that the target entity is being used for malicious activities. A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the malicious activity classification branch, and the method comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises at least one of instructing the target entity to investigate the attack and instructing the target entity to stop the attack. A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the IT hygiene classification branch, and the method further comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises instructing the target entity to update its infrastructure. A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the vulnerability classification branch, and the method comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises at least one of instructing the target entity to upgrade the application to a patched version and instructing the target entity to delete the application. Claim 15 A method according to claim 1, wherein the alert is sent based on the risk factor associated with the finding classified into the IT hygiene classification branch, and the method further comprises starting a corrective action for the target entity associated with the finding based on the alert, and starting the corrective action for the target entity comprises instructing the target entity to update its infrastructure. A method for managing the cyber security risk of a client entity communicating with a plurality of target entities Claim 16 A method for managing the cyber security risk of a client entity communicating with a plurality of target entities Identifying a plurality of cyber asset footprints, each cyber asset footprint including cyber assets associated with a different one of the target entities Monitoring a plurality of data sources including cyber risk information to generate source data, the source data being organized based on a plurality of risk factors, the risk factors being classified according to a cyber security risk classification Identifying relevant observations within the source data, each relevant observation including information related to one of the risk factors, each relevant observation being identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints Determining that one of the relevant observations does not comply with a predetermined measurement criterion of a plurality of predetermined measurement criteria, each of the predetermined measurement criteria being associated with one of the risk factors Issuing a finding based on determining that the relevant observation does not comply with the predetermined measurement criterion, the finding including a severity level, the severity level being based on the classification of the risk factor associated with the finding
17. The cyber security risk classification includes classification branches, the classification branches including email information technology (IT) hygiene vulnerabilities threat activities, or at least one of malicious activities, the method according to claim 16
18. The method according to claim 16, further comprising initiating a corrective action based on the severity level of the finding
19. The method according to claim 16, further comprising generating an alert based on the finding
20. The method according to claim 19, further comprising at least one of transmitting the alert to the target entity associated with the finding and transmitting the alert to a client entity The method according to claim 19, further comprising at least one of transmitting the alert to the target entity associated with the finding and transmitting the alert to a client entity