Software application for continuously determining, processing, and correcting cyber risks in real time

A real-time cyber risk processing SaaS application addresses the inadequacies of traditional cybersecurity protocols by continuously evaluating and improving network security architectures, effectively mitigating the exponential growth of cyber threats.

JP7699061B2Active Publication Date: 2025-06-26CONQUEST TECHNOLOGY SERVICES CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021572839
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-06-10
Filing Date
2020-06-10
Publication Date
2025-06-26
Estimated Expiration
2040-06-10

AI Technical Summary

Technical Problem

Traditional cybersecurity protocols are insufficient as they are reactive, outdated, and not designed to handle the evolving nature of cyber threats, leading to a continuous exponential growth in cyber risks.

Method used

A software-based SaaS application that processes cyber risks in real time by determining, analyzing, evaluating, and implementing corrective measures to continuously improve and mature an organization's network security architecture.

Benefits of technology

Enables organizations to proactively adapt to actual threats in real time, reducing the cost and complexity of technical resources required, and achieving higher levels of compliance, maturity, and effectiveness in cybersecurity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007699061000001
    Figure 0007699061000001
  • Figure 0007699061000002
    Figure 0007699061000002
  • Figure 0007699061000003
    Figure 0007699061000003
Patent Text Reader

Abstract

A software-based application for determining, addressing, and remediating cyber risk in real time may include, but is not limited to, profiling, analysis, assessment, documentation, enforcement, verification, and monitoring components. These components may operate to enable organizations to adaptively adjust their network security to continuously improve and mature their network security. Such components may (1) determine the organization's operational baseline, (2) identify the inherent risks and significance therein, (3) generate corrective controls for such risks and significance and verify their effectiveness, (4) document and audit such decisions, and (5) continuously monitor the organization's network security. In this manner, an organization's network security architecture may be modified based on threat scenario-based control effectiveness and residual risk determinations, based on the agnostic, risk-focused, systems-based approach disclosed herein.
Need to check novelty before this filing date? Find Prior Art

Description

Description of Related Applications

[0001] This application is a Patent Cooperation Treaty application and claims priority under 35 U.S.C. § 119 to U.S. Provisional Patent Application No. 62 / 859,414, filed on June 10, 2019, and is currently pending U.S. Patent Application No. 16 / 897,779, filed on June 10, 2020, the contents of each of which are hereby incorporated by reference in their entirety.

Technical Field

[0002] The present invention relates to software applications and / or systems designed to enable users and / or organizations to continuously evaluate, monitor, and correct cyber risks in real time.

Background Art

[0003] Over the past few years, organizations have been subject to external cyberattacks, resulting in the leakage of confidential data such as personal identification information, organizational trade secrets, and asset data. Ultimately, organizations are spending millions of dollars to respond to such attacks and repair their effects. As a result, management and top information security officers are trying to assess the operating ecosystem, including internal and external contacts, over a long period of time to accurately identify and determine the location of vulnerabilities.

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, traditional cybersecurity protocols are still insufficient for various reasons. First, traditional cyber risk controls are typically deployed reactively to an organization's network security architecture, and as such, are only addressed to prevent or limit the impact of tools, tactics, and malicious adversary procedures used in the past. Thus, such cybersecurity controls and network architectures are often insufficient to cope with the ever-evolving software, tools, techniques, and tactics of cyberattacks used by malicious adversaries. In particular, organizations often have to respond to cyberattacks reactively and, in most cases, rely on historical data to design and implement their control systems. As a result, the control systems are often outdated and insufficient for new threats the control systems may encounter. Thus, the defensive side of the system is often at least one step behind. This is because the defensive side of the system simply responds to already identified attacks and is not prepared to prevent or adequately defend against future attacks. Furthermore, considering that network architectures are constantly becoming more complex and there is too much data of interest to malicious adversaries, it can be understood that the evolution of cyber risk continues to grow at an exponential rate. Therefore, as the number of devices containing microprocessors continues to increase, so do the cyber threats to the system.

[0005] For example, looking back at the history of malware, malware such as computer viruses, worms, Trojan horses, and backdoors has been one of the most frequently used tools in cyberattacks since the 1980s. They have mainly invaded under the same tactic of installing and hiding malicious software on computers, servers, clients, or computer networks. However, the design and functionality of malware have continued to evolve in their own ways. Therefore, new malware is designed to avoid detection, so malware countermeasure programs a few years ago often provided insufficient protection for users. Also, as the development of devices corresponding to the Internet-of-Things progresses, the paths through which malware can invade are expanding.

[0006] Furthermore, in the aforementioned reality where cyber security networks are in operation, the current approach of risk management platforms to cyber risk compliance further exacerbates the situation. Specifically, the current integrated risk management platforms and traditional approaches to cyber risk compliance operate under a static point-in-time evaluation strategy. Generally, such an approach involves examining the maturity of an organization's cyber risks at a specific point in time. However, since such an evaluation strategy does not consider the constantly changing nature of cyber threats, it gives users a false sense of security. Additionally, since such an evaluation strategy is operated through static point-in-time procedures, valuable time and resources are often spent preparing for such evaluations, thus hindering the time and resources that should be allocated for the implementation and testing of valuable new controls, plans, training, and execution.

[0007] Therefore, it is necessary to constantly update and proactively deploy the cybersecurity network. Solutions to such problems include, for example, systems, applications, and / or platforms designed to apply real-world changes to the maturity of network cyber risks, and organizations should be able to manage the constantly evolving cyber risk management network and protocols in real time. Such solutions should also be carried out to reduce the amount and cost of technical resources required for such operations, and should be carried out to achieve a higher level of compliance, maturity, and effectiveness.

[0008] Specifically, such systems, applications, and / or platforms should be constructed to facilitate the process of enterprise-wide cyber risk management. This includes, but is not limited to, internal and external stakeholders, third-party vendors, third-party partnerships, internal and external users, data, physical hardware systems, software-based virtual systems, platforms, and applications. Therefore, enterprises incorporating such systems, applications, and / or platforms can predict and prevent risk scenarios through adaptation to the organization's operating environment, enabling such organizations to adapt to actual threats almost in real time.

Means for Solving the Problem

[0009] The present invention is directed to a software-based SaaS (software-as-a-service) application executable on the web for processing cyber risks in real time. In this sense, as used herein, processing cyber risks in real time can, based on the disclosure of the present invention, include, for example, but not limited to, determining, analyzing, evaluating, correcting, implementing the corrective measures, repairing, changing, modifying, improving, or taking other actions directed thereto, of the cyber security of a user and / or an organization. Such an application can be built on-premises or in the cloud and can focus on a framework-independent, risk-focused, and system-based approach and can include software coding and a graphical user interface. As used herein, the terms "user," "organization," and their equivalents are intended to be used interchangeably, thereby indicating that a user can be an organization that includes multiple users or vice versa.

[0010] Components of such applications generally consist of data feeds, technical controls, management policies, and physical access controls supplied to a software-based data collection engine. Such applications are further constructed to support algorithms that use multiple matrices and methods to modify and / or change operational controls and incorporate the changes into set thresholds for comparison, thereby enabling real-time approximation or real-time cyber fitness, maturity, and effectiveness facilitated by such modification functions. Such matrices are constructed to index controls to determine the monitoring regime and implementation requirements specific to the relevant organization. Further, such applications are constructed to aggregate data feeds from multiple sources, including third-party vendor integration. In particular, such data feeds are supplied to a collector and normalized before being sent to a staging database based on a common schema. Further, such data feeds are tailored to controls and provided to users and / or organizations via widgets that may include, but are not limited to, direct data feed products, multiple data feeds, data feed products, and / or other widgets.

[0011] In this way, an application according to at least one embodiment of the present invention can provide the ability to adaptively adjust to continuously improve and mature an organization's network security architecture. For example, the application of the present invention may be configured to automatically apply controls or other risk responses to an organization's network security architecture by, but not limited to, physical modification of documents, configuration changes, blocking of access and ports, and involvement of physical controls.

[0012] More specifically, the application or system of the present invention, in general terms: (1) determines the compliance, maturity, and effectiveness of the user's operational baseline network security at a control-based level; (2) identifies the risks and importance specific to such operational baseline network security based on a developed threat framework; (3) generates corrective controls for such risks and importance at the individual control-based levels, similar to those of an integrated cybersecurity network architecture, and verifies their effectiveness; (4) documents and audits the aforementioned components and procedures; and (5) continuously monitors, evaluates, and improves the user's network security by continuously, periodically, or optionally reapplying at least a portion of the components constructed within the scope of the present invention. Such components can include, for example, but are not limited to, profiling components, analysis components, evaluation components, documentation components, implementation components, verification components, and monitoring components. Each of these components will be described in detail hereinafter.

[0013] As described above, the application or system of the present invention can include a profiling component. Specifically, the profiling component of the system according to the present invention may be constructed to effectively evaluate the user's physical and virtual network security environment at a control-based level. Alternatively, the profiling component of the present invention may evaluate the compliance, maturity, and effectiveness of the user's network security at a control level. Based on such an evaluation, the system of the present invention may then determine the operational baseline of the user's network security architecture.

[0014] The profiling component of the present invention can evaluate a user's network security architecture based on various methods. For example, the profiling component can use an automated self-assessment provided based on one or more questionnaires or similar procedures intended to elicit network security information from the user and / or organization. Additionally, the profiling component can alternatively utilize an assessment performed by a qualified third party.

[0015] In this regard, the profiling component may be constructed in relation to an end-user's profile framework, which is derived from sectors related to industry, scale, region, site, system, and organization, and is configured such that the end-user can consider and revise the end-user's profile framework. For example, the end-user can provide additional information regarding the organization's systems, networks, data, and applications that support the organization's mission and business processes, and can choose to detail how individuals act within the organization.

[0016] Furthermore, the profiling component according to at least one embodiment of the present invention can include various different tasks constructed to identify the compliance, maturity, and effectiveness of each control built within the user's cybersecurity network. For example, the profiling component can be constructed to perform asset discovery and inventory tasks, conduct system profiling, determine requirements dependent on the user's organizational operations, and select and analyze individual controls. This can be done as individual parts or as part of the entire network architecture. Thus, the profiling component can generate a complete inventory and assessment of importance while prioritizing all systems, subsystems, data, networks, endpoints, and users.

[0017] According to at least one embodiment of the present invention, an analysis component may be constructed in relation to the aforementioned profiling component. The analysis component may generally be constructed to constitute, determine, or otherwise generate at least one, or in some instances, a plurality of variables of interest. The variables of interest can be made available via key data collected from a baseline rendered by the profiling component and can include, but are not limited to, (a) threat agents, (b) persons of interest, (c) tactics, techniques, and procedures, (d) assets and their importance, and (e) the importance and volatility of controls already implemented in the user's network security environment. Further, using such variables of interest, the analysis component can develop a threat framework that constitutes the complete theoretical threats that may be issued against the user's baseline.

[0018] In this sense, the analysis component can be constructed to determine the target state of a user or organization. The target state may, for example, include target levels of compliance, maturity, and effectiveness of the organization's cyber security network and may be determined automatically by the system of the present invention. Conversely, the target state may also be constructed based on the organization's risk tolerance. Thus, the analysis component is aimed at determining the variables of interest related to impeding the security effectiveness of a particular network architecture while developing a target state in line with the organization's intentions.

[0019] As can be understood, by analyzing the user's baseline and developing variables to be considered, the application and / or system of the present invention can effectively perform dynamic risk analysis, in which threats, vulnerabilities, and assets are the main variables to be considered, and further, based on the importance and volatility of the controls already implemented, determine the amount of monitoring given to each control, response, and / or process, and the level of implementation priority.

[0020] For example, in at least one embodiment of the present invention, together with such profiling and analysis components, an evaluation component can further be included. The evaluation component can include, for example, a risk engine constructed to evaluate the established baselines for asset importance, threats, and vulnerabilities based on the threat framework developed by the analysis component.

[0021] Specifically, the evaluation component can, for example, utilize the threat framework to organize and coordinate the theoretical threats to the determined baseline network security of the organization. In such a manner, specific threat agents, tactics, techniques, and procedures can be analyzed using various models. For example, in at least one embodiment of the present invention, the risk engine component may be constructed to utilize an adversary-defense model to identify specific vulnerabilities and remediation steps present in the organization's baseline.

[0022] By applying a threat framework that can include variables of specific considerations that constitute a complete theoretical threat, it can be understood that the evaluation component can then, in at least one embodiment of the present invention, designate a specific threat framework as a specified threat. The specified threat can include, for example, design-based threats, which are considered unacceptable due to their relationship to the level of risk associated with the threat and the current baseline of the cybersecurity network, and are actionable in that there are specific corrective measures that can be implemented. Thus, when a given threat framework generates threats that fall within such a threshold and a reasonable user develops a response to the scenario, such a threat framework is designated as a specified threat, and thus variables of specific considerations can be identified based on the threat so specified.

[0023] Using the threat so specified, the evaluation component can then, in at least one embodiment of the present invention, determine the baseline risk of the current cybersecurity network. The evaluation component can further generate theoretical controls designed to correct the risk specified by the specified threat.

[0024] Furthermore, the evaluation of theoretical control by the aforementioned evaluation component may generate specific data such as the importance and volatility of the theoretical control. As can be understood, the importance of the theoretical control may indicate the effectiveness of that control in modifying the identified threats. Furthermore, the volatility of the theoretical control may indicate the frequency of that control when modifying the identified threats. In this way, each theoretical control can be effectively evaluated. Here, the product of the importance and volatility evaluations may provide the implementation priority. As can be understood, the implementation priority is set to indicate the implementation of that theoretical control by showing the overall effectiveness of the theoretical control applied to the baseline cybersecurity network in light of the identified threats. Thus, considering effectiveness and frequency, it is determined that a particular theoretical control has a higher level of necessity, and it can be understood that that particular theoretical control can modify a predetermined identified threat.

[0025] Furthermore, in at least one embodiment of the present invention, a documentation component is utilized together with the aforementioned components to record additional relevant data such as the identified threats and implementation priorities, and the decisions made regarding them, the applied exceptions, and the developed mitigation plans. In this way, the system according to at least one embodiment of the present invention enables an organization to maintain sufficient documentation related to its cybersecurity compliance, maturity, and effectiveness. Such documentation is used, for example, in decisions on whether to implement specific corrective controls, determination of appropriate values for residual risks, creation of risk management strategies at the organizational level, training of employees, and determination of appropriate corrective strategies when threat scenarios are realized in the physical environment.

[0026] In connection with the foregoing components, in at least one embodiment of the present invention, there can also be provided an implementation component configured to direct, adjust, or implement the corrective controls collected from the foregoing evaluation component. In doing so, the implementation component can utilize, for example, the foregoing identified threats, theoretical controls, and implementation priorities collected from the evaluation component to direct the technical implementation of specific corrective controls.

[0027] For example, when the evaluation component identifies a specific threat, the system according to the present invention can subsequently identify at least one, and in some cases multiple, theoretical controls that can correct the identified threat. Based on the importance value and volatility value of such theoretical controls, the implementation priority of each control is determined, and using that implementation priority, it is possible to determine which theoretical control should be implemented and the technical aspects by which that theoretical control should be implemented.

[0028] In other words, the implementation component of at least one embodiment of the present invention is configured to direct, adjust, or implement corrective controls and is configured to execute such controls only if such controls and their technical implementations are generated via the evaluation component. For example, as can be understood, because cyber security networks are complex, a certain theoretical control may be ideal in defending an organization from a specific threat. However, that theoretical control may also simultaneously expose the organization to many other threats. Thus, the evaluation component aims to determine the appropriate theoretical control that is most beneficial to the organization's interests with respect to both the acceptable level of risk and the organization's goals. In this way, in the system of the present invention, at the implementation component stage, the appropriate corrective controls have already been determined by the evaluation component.

[0029] In addition, the implementation component of the present invention can further include a notification component designed to notify and report to users and / or organizations appropriate change control and data related to appropriate change control (e.g., analysis options, risk handling options, and data related to the impact of risk dynamics on identified threats). The notification component can notify users and / or organizations via multiple appropriate notification means such as, but not limited to, an email or text message system. As can be understood, the notification component is further constructed in an input / output relationship with the system of the present invention, thereby enabling a user to permit the implementation of change control. Thus, in this way, the implementation component of the present invention may be designed to automatically implement change control or, alternatively, to request approval prior to implementation.

[0030] In implementing such change control, in at least one embodiment of the present invention, it can further include a verification component constructed to test and verify the effectiveness of the change control. For example, the verification component can, when implementing change control, reapply the aforementioned evaluation component to determine whether the same or alternative identified threats exist within the modified network architecture. By doing so, the effectiveness of the change control can be evaluated at both the discrete individual control - based level and as part of the overall network architecture. In this way, the compliance, maturity, and effectiveness of the organization's network security architecture can be enhanced and continuously tested. This enables the organization to continuously monitor and conform to the cyber - security network in real - time.

[0031] Furthermore, in at least one embodiment of the present invention, the monitoring component may be constructed to be connected to the aforementioned components. As can be understood, the monitoring component may monitor the organization's cybersecurity network in order to identify both real-world threats and ineffective controls. Based thereon, the monitoring component may further be constructed to provide certain documentation and auditing procedures, thereby continuously monitoring and modifying the organization's cybersecurity compliance, maturity, and effectiveness. For example, the monitoring component may be constructed to perform certain risk assessment, impact analysis, and reporting tasks designed to identify areas where the organization's network security may be improved.

[0032] In connection with the aforementioned components of the present invention, the system of the present disclosure may further include additional components designed to further improve the cybersecurity of users and / or organizations in real time. For example, in at least one embodiment of the present disclosure, the system of the present invention may further include a machine learning component constructed in connection with the system of the present invention, and an interconnected data warehouse. In this way, the machine learning component may be constructed to improve certain components of the present invention, such as the evaluation component and the implementation component, based on training provided by the organization and / or end users.

[0033] For example, the machine learning component can determine appropriate situations for improving notifications, assignments, and decision-making based on both training provided in the real world and virtual scenarios executed through the system of the present invention. In this way, for example, by continuously tracking real-world threat scenarios, end-user decision-making and inputs, and the effectiveness of remediation controls, machine learning can develop, for example, a more appropriate threat framework that is applied to the user's baseline network. By doing so, the machine learning component is used to ensure that the threat framework provided through the system of the present invention is up-to-date, thereby enabling the user and / or organization's security network to be constructed at the current time rather than being fixed at some past point in time.

[0034] These and other objects, features, and advantages of the present invention will become more apparent when considered in conjunction with the drawings and the detailed description.

Brief Description of the Drawings

[0035] To more fully understand the essence of the present invention, reference should be made to the following detailed description in conjunction with the accompanying drawings.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 4A

Figure 5

Figure 5A

Figure 6

Figure 7

Figure 8

Figure 9

DETAILED DESCRIPTION OF THE INVENTION

[0036] As detailed above, the present invention is directed to a software-based web-executable SaaS (software-as-a-service) application for processing cyber risks in real time. As described above, the real-time processing of cyber risks can include, based on the disclosure of the present invention, for example, but not limited to, determining, analyzing, evaluating, modifying, implementing the modification measures, repairing, changing, altering, improving, or taking other actions directed thereto for the cyber security of users and / or organizations. Such an application can be built on-premises or in the cloud and can be built using at least one memory and at least one processor for its implementation. Generally speaking, such an application can focus on a framework-independent, risk-focused, and system-based approach and can generally include software coding and a graphical user interface.

[0037] More specifically, referring particularly to the embodiment of the present invention shown in FIG. 1, the application 10 can include a system 100 that can typically be composed of a plurality of interconnected individual components. Such components can include, for example, a profiling component 110, an analysis component 120, an evaluation component 130, a documentation component 140, an implementation component 150, a verification component 160, and a monitoring component 170. Further, as shown in FIG. 1, the system 100 may be constructed to be connected to a data feed 20, a data warehouse 30, and a machine learning component 40. The interconnection with each system 100 will be described in more detail hereinafter.

[0038] As shown in FIGS. 1 to 3 and as described above, at least one embodiment of the present invention can include a system 100 that includes a profiling component 110. The profiling component 110 may be constructed to evaluate a user's network security architecture at a control level using various methods. For example, the profiling component 110 can automatically evaluate an organization's compliance, maturity, and effectiveness at a control level based on at least one questionnaire or, alternatively, based on an evaluation presented by a qualified third party.

[0039] Such profiling component 110 may be further constructed to perform various tasks in relation to data collected based on an evaluation, whether automated, provided independently by an accredited third party, or otherwise. For example, asset discovery and inventory tasks 111 may be utilized to provide network visibility, identify hardware devices, and identify connections to hardware devices. Further, profiling component 110 may be constructed to perform system profiling tasks 112 designed to identify details regarding the hardware and software present in an organization's network architecture. Further, profiling component 110 may be constructed to identify an organization's security requirements 113. As can be understood, security requirements 113 vary depending on the applicable organization and thus, an acceptable risk threshold for a given threat can be set. Further, a particular data source, such as data feed 20, may be connected to system 100 to provide indicators and enable connection to the required information ingestion engine.

[0040] Furthermore, the profiling component 110 can also execute a control selection task 114. Specifically, the profiling component 110 can index the controls already implemented within the organization's network architecture. By doing so, the profiling component 110 can develop a baseline for the user and / or the organization. Thus, such a baseline can include, for example, controls, requirements, and hardware and software-based details regarding the current network security of the organization. In this way, the profiling component 110 develops a baseline from which threat and remediation controls 151 are developed, tested, and verified to ensure that the remediation controls 151 are effective in enhancing the compliance, maturity, and effectiveness of the user and / or organization's cybersecurity network. As can be understood, such a baseline can indicate the organization's priorities, mission and / or business processes, and the importance of the system from both the perspectives of the organization and any end-user profile.

[0041] In at least one embodiment of the present invention, as shown in FIGS. 1-4, the analysis component 120 may be constructed in relation to the profiling component 110. As described above, the analysis component 120 may generally be constructed to identify at least one, and in some cases a plurality, of variables of interest. The variables of interest can include, for example, threat agents, stakeholders, tactics, techniques and procedures, assets, and their importance, as well as the importance and volatility of the controls already implemented by the organization. As can be understood, the variables of interest may be at least partially determined based on key data collected from the baseline rendered by the profiling component 110.

[0042] Specifically, the analysis component 120 may be constructed to perform various tasks and evaluations to determine the threat framework 129 using such variables of interest. For example, the analysis component 120 may perform various tasks including, but not limited to, threat identification 121, vulnerability identification 122, likelihood determination 123, impact magnitude determination 124, risk determination 125, result communication 126, evaluation 127, and facility involvement determination 128. As can be understood, such tasks may be constructed to assist in the development of the threat framework 129, where a complete threat scenario is developed based on applicable variables of interest and the organization's baseline. In this way, the analysis component 120 may develop a complete threat framework 129, and then the threat framework 129 may be evaluated against the user's baseline to determine whether the threat framework 129 is a problem for the organization in its current state. Further, in at least one embodiment of the present invention, the user and / or organization may be able to adjust or develop the threat framework 129 to the extent that it is deemed appropriate.

[0043] One way to determine the threat framework 129, which can be used in at least one embodiment of the present invention, is shown in FIG. 4A. As shown, the analysis component 120 can include an analysis routine 200 constructed to determine at least one threat framework 129. Specifically, such an analysis method 200 can include a plurality of steps constructed to determine the threat framework 129. For example, the analysis method 200 can iterate through a plurality of threats 201, determine the capabilities 202 of the iterated threats, and thereby determine whether the iterated threats 201 are sufficient with respect to both the ability and intent to compromise the organization's baseline network security as determined by the aforementioned profiling component 110. If the iterated threats 201 are considered sufficient, the analysis method 200 can then consider the motives and intentions 204 behind the iterated threats 201. If the motives and intentions are considered to correspond to the organization's business, related data, and security requirements 205, the analysis method 200 can build a profile of the iterated threats 201 by classifying 210 the iterated threats 201 based on specific related data. For example, this classification task 210 can be constructed to determine, but is not limited to, the number of adversarial actions 211, adversarial devices 212, adversarial knowledge 213, adversarial skills 214, and adversarial tools 215 present in the iterated threats 201. It can be understood that a complete threat framework 129 can be obtained therefrom using the related data collected by this analysis method 200.

[0044] Based on this analysis component 120, in at least one embodiment of the present invention, an evaluation component 130 can be further arranged to be coupled thereto. As can be specifically seen by referring to FIGS. 5 and 5A, the evaluation component 130 can include, for example, but not limited to, a risk engine constructed to evaluate an established baseline and threat framework 129 in order to determine the importance, threats, and vulnerabilities of assets. For example, but not limited to, the evaluation component 130 can utilize a golden image in a sandbox environment to evaluate the threat framework 129 against the baseline of the user and / or organization. Conversely, the evaluation component 130 can access a subset of approved nodes and execute the corresponding threat framework 129 therein, thereby determining the threat framework 129 regarding its associated real-world impact. Such real-world impact can then be extrapolated across the user's entire network security architecture in order to obtain a broader evaluation regarding the risks presented by the threat framework 129, which will be understood.

[0045] In this way, the evaluation component 130 is generally constructed to identify a specific threat framework 129 that includes the organization's baseline against a certain threshold, thereby indicating that the specific threat framework 129 should constitute the identified threats 135. Specifically, the identified threats 135 may constitute a threat framework 129 that is considered unacceptable but also treatable regarding the level of risk indicated by the threat framework 129, which means that the responsible party will develop a response to such a scenario. Thus, for subsequent measures, a designated threshold remains such that any given threat framework 129 can be considered an identified threat 135.

[0046] More specifically, the evaluation component 130 according to at least one embodiment of the present invention can execute a plurality of evaluation tasks configured to determine whether a threat 135 identified by the threat framework 129 should be regarded as such. In this way, specific threats, agents, tactics, procedures, etc. against the determined baseline of the organization can be tested and analyzed based on various models. For example, at least in the embodiment of the present invention, in order to identify specific vulnerabilities and corrective steps existing in the organization's baseline, the adversary-defender model may be used to analyze the threat framework 129.

[0047] For example, the evaluation tasks executed by the evaluation component 130 of at least one embodiment of the present invention can specifically refer to FIG. 5. As can be understood, the evaluation component 130 may be configured to analyze the relevant threat framework 129 based on a specific decision-making process. For example, the evaluation component 130 may determine (1) whether the threat framework presents an acceptable level of risk 131, (2) whether the threat framework 129 is avoided 132 by alternative means, (3) whether the risk presented by the threat framework 129 is transferred 133 elsewhere, and (4) whether the risk presented by the threat framework 129 is reduced 134 by means already existing in the network security architecture of the user and / or organization's baseline. As can be understood, if the threat framework 129 is any of acceptable, avoidable, transferable, or reducible, the evaluation component 130 ends with respect to that specific threat framework 129 and starts evaluating another different threat framework 129. Further, if the threat framework 129 is not acceptable, avoidable, transferable, or reducible, the evaluation component 130 proceeds to the classification of the identified threat 135, the determination of at least one theoretical control 136 for correcting such an identified threat 135, and the calculation of an implementation priority 137 constructed to demonstrate the superiority of the theoretical control 136.

[0048] One way to determine a specific threat 135 is shown in FIG. 5A. Shown in FIG. 5A is an evaluation routine 300 that can be used according to at least one embodiment of the present invention. As can be understood, the evaluation method 300 can first identify a threat 310 presented by a threat framework 129. Following such identification 310, the evaluation method 300 can then analyze the threat to determine a plurality of data 320 related to the threat. For example, the evaluation method 300 may be constructed to determine, but is not limited to, the complexity 321 of the event, the likelihood of specific system, application, and data utilization for users and / or organizations in the threat event 322, the spread of adversarial behavior 323, the level of ideology related to the threat 324, the capabilities of the organization facing the threat 325, the intent behind the threat 326, the historical frequency of the threat 327, and the organization's facility involvement in the threat event 328. Further, the evaluation method 300 may further determine specific data useful for providing additional variables 330 for the threat, such as the historical basis 331 of the threat, the capabilities of the adversarial behavior behind the threat 332, and the variations the threat can take 333.

[0049] Using the data thus collected, the evaluation routine 300 can then perform a specific evaluation task 340 constructed to determine, for example, the risks and vulnerabilities specific to the threat 310. For example, the evaluation task 340 can include an asset determination 341 and / or an identification task designed to uniquely identify an asset based on known identifiers and / or known information related to the asset. Further, the evaluation task 340 can include a diagnostic evaluation designed to identify and rank the targets of the threat to determine the risks and vulnerabilities specific to the targets. For example, as one of the diagnostic evaluations, it can include the application of a CARVER analysis 342 and the determination of a CARVER score 343 by the CARVER analysis 342. Alternative analytical evaluation methods can similarly be used and devised in alternative embodiments of the present invention herein.

[0050] Specifically, under the CARVER analysis 342, the evaluation method 300 can determine a plurality of scores related to the criticality, accessibility, recuperability, vulnerability, effect, and recognizability of the threat 310, and the impact of the threat 310 on the user's baseline network architecture such as the determined asset 341 described above. Then, the evaluation method 300 can use the CARVER matrix to determine the CARVER score 343 associated with each of the determined assets 341. Thus, it can be understood that if the CARVER score 343 is considered to be within the specified threshold described above, the threat 310 can be designated as a specific threat 135 for which corrective measures should be executed.

[0051] Once the specific threat 135 is determined, the evaluation component 130 according to at least one embodiment of the present invention may subsequently determine at least one theoretical control 136 that can be applied to correct the specific threat 135, as shown in FIG. 5. Specifically, the evaluation component 130 may be constructed to generate at least one theoretical control 136 designed to correct the risks and vulnerabilities present in the specific threat 135. For example, in an embodiment that utilizes the evaluation method 300 shown in FIG. 5A, the data collected through the threat data task 320 and the additional variable task 330, which is embodied in the scores obtained from the evaluation task 340, can help identify problems related to a specific asset 341, user, and / or the current baseline network architecture of the organization for which the risk has been determined, and the theoretical control 136 that can be implemented for it. As can be understood, the theoretical control 136 is generated, for example, based on the tendency to reduce the probability or severity of the specific threat 135.

[0052] Once theoretical control 136 is generated, the evaluation component 130 can then perform a task designed to evaluate the theoretical control 136 based on (1) the control importance indicating the effectiveness of the theoretical control 136 when modifying the identified threat 135, and (2) the volatility of the theoretical control 136 indicating the frequency of the theoretical control 136 for modifying the identified threat 135. Thus, once the importance score and the volatility score are determined, the evaluation component 130 can determine an implementation priority 137 for each theoretical control 136 that includes the product of the importance score and the volatility score. As can be understood, the implementation priority 137 may be used to indicate the technical implementation requirements of the theoretical control 136. Further, at least one further embodiment of the present invention can provide greater variability for the analysis of the theoretical control 136 by making the importance score and the volatility score configurable or otherwise changeable by the user and / or the organization.

[0053] After utilizing the evaluation component 130, in at least one embodiment of the present invention, a documentation component 140 constructed to record the identified threat 135, the theoretical control 136, and the implementation priority 137 can be utilized. As shown in FIG. 6, the documentation component 140 can record, for example, a risk determination 141 related to the identified threat 135, an exception 142 applied to the identified threat 135, and a mitigation plan 143 created based on the identified threat 135 (e.g., the previously developed theoretical control 136 and the associated implementation priority 137, etc.). Thus, a system according to at least one embodiment of the present invention enables an organization to maintain sufficient documentation related to the compliance, maturity, and effectiveness of its cybersecurity. Such documentation is used, for example, to determine whether to implement specific corrective controls when an identified threat 135 occurs in a physical environment, to determine an appropriate value for the residual risk, to create a risk management strategy at the organizational level, to train employees, and to determine an appropriate corrective strategy.

[0054] Furthermore, in at least one embodiment of the present invention, an implementation component 150 may be constructed in relation to the aforementioned components of the system 100. Specifically, the implementation component 150 may be constructed to direct, adjust, or implement the corrective control 151 collected from the evaluation component 130. For example, based on the applicable identified threat 135, the developed theoretical control 136, and the determined implementation priority 137 therefrom, the implementation component 150 may be constructed to apply the appropriate corrective control 151 to the user and / or organizational network security architecture and / or an already determined baseline.

[0055] Based on the implementation of the corrective control 151, the implementation component 150 may further include a notification component, which is constructed to explain the implemented corrective control 151. For example, the explanation of the corrective control 151 has the function of notifying and reporting the corrective control 151 and related data thereto to the user and / or organization, and examples include analysis options regarding the relevant identified threat 135, risk handling options, and data regarding the impact of risk dynamics. The notification component can notify the user and / or organization via a plurality of appropriate notification means, such as, but not limited to, an email or text message system. As can be understood, the notification component is further constructed in the input / output relationship with the system of the present invention, thereby enabling the user to permit the implementation of the corrective control. Thus, in this way, the implementation component 150 of the present invention may be designed to automatically implement the corrective control, or alternatively, may be designed to request approval before implementation. Furthermore, the implementation component 150 constructs a predetermined configuration to perform such as whether the corrective control 151 is automatically implemented, postponed based on specified criteria, or delegated to additional responsible persons for approval or rejection.

[0056] In implementing such a remediation control, in at least one embodiment of the present invention, as shown in FIG. 8, a verification component 160 can be further included that is constructed to test and verify the effectiveness of the remediation control 151. Specifically, the verification component 160 can be constructed to reapply the aforementioned evaluation component 130 when implementing the remediation control 151 to determine whether the same or other specified threats 135 exist within the remediated network architecture. In this way, real-world data such as asset disposition, threats, and vulnerabilities may be evaluated in scenarios focused on the specified threats 135. Further, the verification component 160 may operate to ensure that the security and privacy requirements 162 existing in the organization are sufficiently achieved by the implementation of the remediation control 151. Thus, such a process may be utilized to verify 163 the remediation control 151. By doing so, the effectiveness of the remediation control 151 may be evaluated at the discrete individual control-based level and as part of the overall network architecture. In this way, the compliance, maturity, and effectiveness of the organization's network security architecture may be enhanced and continuously tested. Thereby, it is ensured that the organization continuously monitors and conforms its cybersecurity network in real time and that the residual risk is maintained within the organization's determined risk tolerance.

[0057] Furthermore, in at least one embodiment of the present invention, the monitoring component 170 may be constructed in relation to the aforementioned components of the system 100, as shown in FIG. 9. As can be understood, the monitoring component 170 can monitor an organization's cybersecurity network to identify both real-world threats and ineffective controls. Based thereon, the monitoring component is further constructed to provide specific documentation and auditing procedures, whereby the organization's cybersecurity compliance, maturity, and effectiveness can be continuously monitored and revised. For example, the monitoring component may be constructed to perform specific monitoring and auditing tasks such as, but not limited to, the task of approval of change control 171, the task of effectiveness of change control 172, the monitoring task of document change 173, the task of risk assessment 174, the task of impact analysis 175, and the task of general reporting 176. For example, the risk assessment 174 may be determined based on the stratification of threat and vulnerability data, in contrast to the importance and volatility of the controls determined by the aforementioned components of the system 100.

[0058] Based on the aforementioned components of the present invention, the system of the present disclosure can further include additional components designed to further improve the cybersecurity of users and / or organizations in real time. For example, as shown in FIG. 1, in at least one embodiment of the present invention, the system of the present disclosure can further include a machine learning component 40 constructed in relation to the system 100 of the present invention and an interconnected data warehouse 30. In this way, the machine learning component 40 may be constructed to improve specific components of the present invention, such as, for example, the evaluation component 130 and the implementation component 150, based on training provided by an organization and / or an end user.

[0059] For example, the machine learning component 40 can determine appropriate situations for improving notifications, assignments, and decision-making based on training provided through both real-world and virtual scenarios developed through the system of the present invention. In such a manner, for example, by continuously tracking real-world threat scenarios, end-user decision-making and inputs, and the effectiveness of remediation controls, machine learning can develop, for example, a more appropriate threat framework that is applied to the user's baseline network. By doing so, the machine learning component is used to ensure that the threat framework 129 provided through the system of the present invention is up-to-date, thereby enabling the user's and / or organization's security network to be constructed at the current time rather than being fixed at some past point in time.

[0060] Furthermore, the system 100 may be constructed in relation to a plurality of data feeds 20, regardless of whether it is part of a predetermined organization's network architecture, or may be constructed in relation to other data feeds such as data feeds collected from interconnected third-party systems, applications, and networks. For example, the third-party data feeds 20 may be used to determine a risk layer based on services provided by third parties, and the risk layer may include, for example, the product of (1) the impact on the organization's mission and / or business, and (2) an amount related to the detection sensitivity of critical data. Thus, using the risk layer, the third-party data feeds 20 can be evaluated with respect to their risk profiles, thereby affecting the baseline generated by the profiling component 110.

[0061] As can be understood, the application of the present invention can be continuously executed at a certain predetermined interval or at the discretion of the user, thereby enabling the user and / or organization to continuously adjust the network security architecture and prevent real-world threat scenarios. For example, the system 100 can adapt or repeat certain components such as, but not limited to, the evaluation component 130, the implementation component 150, and the verification component 160, to enable real-time changes to the organization's network security architecture. Further, such an application can also be used in a reactive manner, such as when a critical system loses its backup and is at risk, when threat agents, tactics, techniques or procedures have evolved, or when a vulnerability has been discovered, i.e., when the importance of assets changes in the real world. In such situations, it can be understood that such changes can be incorporated into the organization's baseline for subsequent processing via the components of the system 100, for change control or for determining acceptable risks.

[0062] Thus, the present invention can provide specific recommendations for improving the cyber security compliance, maturity, and effectiveness of an organization based on a continuous cycle of adjusting the organization's network security architecture based on real-world operation and evaluation of theoretical risk variables. Thus, in this way, an application according to at least one embodiment of the present invention can provide the ability to process and thereby adaptively adjust the organization's network security architecture in real time based on the effectiveness of scenario-based controls and residual risks. By doing so, ineffective controls can be identified and corrected, thereby enabling the organization to evaluate, implement, and adapt to network security changes when they occur.

[0063] Since the details of the described preferred embodiments of the present invention can be subject to various modifications, variations, and changes, all matters shown in the above description and the accompanying drawings are intended to be construed in an illustrative rather than a limiting sense. Therefore, the scope of the present invention should be determined based on the appended claims and their legal equivalents.

Explanation of Signs

[0064] 20 Data Feed 30 Data Warehouse 40 Machine Learning Component 110 Profiling Component 120 Analysis Component 130 Evaluation Component 140 Documentation Component 150 Implementation Component 160 Verification Component 170 Monitoring Component

Claims

1. In a system for real-time processing of cyber risks, a profiling component configured to determine at least one baseline for a user, the baseline including an operation expected for network security compliance, maturity, and effectiveness in at least one control, the profiling component determining the at least one baseline of at least one framework derived from an industry for at least one user network; an analysis component configured to generate at least one threat framework; an evaluation component configured to apply the at least one threat framework to the at least one baseline to determine at least one identified threat, the evaluation component further configured to determine at least one identified threat from the at least one threat framework applied to the at least one baseline using a golden image representing an operation expected for the network security compliance in a sandbox environment, further configured to determine at least one theoretical control based on the at least one identified threat, and further configured to determine at least one implementation priority based on the at least one theoretical control; a documentation component configured to record data; an implementation component configured to implement at least one corrective control based on the at least one theoretical control and the at least one implementation priority; a verification component configured to verify the at least one corrective control; a monitoring component configured to monitor and audit a user's cyber security architecture; A system for real-time processing of cyber risks, including.

2. The system according to claim 1, wherein the at least one implementation priority is determined based on the importance of the at least one theoretical control.

3. The system according to claim 1, wherein the at least one implementation priority is determined based on the volatility of the at least one theoretical control.

4. The system of claim 1, wherein the profiling component is configured to determine the at least one baseline of a user based on at least two data feeds. **Claim 5** The system of claim 1, wherein the at least one threat framework is determined based on an analysis routine. **Claim 6** The system of claim 1, wherein the at least one identified threat is determined based on at least one evaluation routine. **Claim 7** The system of claim 1, wherein the enforcement component further includes a notification component configured to notify the user of the at least one remediation control. **Claim 8** The system of claim 1, wherein the enforcement component is configured to automatically enforce the at least one remediation control. **Claim 9** In a system for processing cyber risk in real time, a profiling component configured to determine at least one baseline of a user, including at least one control, the at least one baseline including the compliance, maturity, and effectiveness of network security, based on at least two data feeds, namely a framework derived from an industry and a user network; an analysis component configured to generate at least one threat framework based on a plurality of variables to be considered; an evaluation component configured to apply the at least one threat framework to the at least one baseline to determine at least one identified threat, further configured to determine at least one identified threat from the at least one threat framework applied to the at least one baseline using a golden image representing the expected operation for the compliance of the network security in a sandbox environment, further configured to determine at least one theoretical control based on the at least one identified threat, and further configured to determine at least one enforcement priority based on the at least one theoretical control; a documentation component configured to record data An implementation component configured to implement at least one corrective control based on the at least one theoretical control and the at least one implementation priority, the implementation component further including a notification component configured to notify the user of the at least one corrective control. A verification component configured to verify the at least one corrective control and determine whether there are other identified threats during the implementation by reapplying the evaluation component. A monitoring component configured to monitor and audit the user's cybersecurity architecture. A system for real-time processing of cyber risks, including the above.

10. The system according to claim 9, wherein the at least one threat framework is determined based on an analysis routine.

11. The system according to claim 9, wherein the at least one identified threat is determined based on at least one evaluation routine.

12. The system according to claim 9, wherein the at least one implementation priority is determined based on the importance of the at least one theoretical control.

13. The system according to claim 9, wherein the at least one implementation priority is determined based on the volatility of the at least one theoretical control.

14. The system according to claim 9, further including a machine learning component constructed by connecting to at least one data warehouse, the machine learning component being configured to be trained based on user input.

15. The system according to claim 9, wherein the at least one threat framework is changeable by the user.

16. The system according to claim 9, wherein the notification component is constructed in an input / output relationship with a graphical user interface.

17. The system according to claim 16, wherein the notification is configured to obtain permission from the user prior to the implementation of the at least one corrective control.

Citation Information

Patent Citations

  • Enterprise Cyber ​​Security Risk Management and Resource Planning

    JP2020524870A

  • Systems and methods for using reputation scores in network services and transactions to calculate security risks to computer systems and platforms

    US20130298192A1

  • Mitigation of Anti-sandbox malware techniques

    US20170109529A1

  • Enterprise cyber security risk management and resource planning

    US20180375892A1

  • Enterprise cyber security risk management and resource planning

    WO2018234867A1