Security event analysis with cyber-model context

The security event analysis method addresses the limitations of existing methods by matching security events with cyber-model contexts, leading to enhanced risk assessments and improved security measures.

WO2025134112A1PCT designated stage expired Publication Date: 2025-06-26C2A SEC LTD

Patent Information

Application Number
PCT/IL2024/051190
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-17
Filing Date
2024-12-17
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing security analysis methods lack the ability to effectively analyze security events within the context of a cyber-model, leading to incomplete risk assessments and inadequate security measures.

Method used

A security event analysis method that involves receiving information about a security event, matching it to relevant contents within a cyber-model, analyzing additional context, determining risk information, and outputting an indication of the determined risk.

Benefits of technology

This method enables more comprehensive and accurate risk assessments by integrating security events with cyber-model context, thereby improving the effectiveness of security measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IL2024051190_26062025_PF_FP_ABST
    Figure IL2024051190_26062025_PF_FP_ABST
Patent Text Reader

Abstract

A security event analysis method, the method constituted of: receiving information regarding a security event; matching the security event to one or more contents of a cyber model representing a system; analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model; based at least in part on the analyzed additional context, determining risk information regarding the security event; and outputting an indication of the determined risk information.
Need to check novelty before this filing date? Find Prior Art

Description

SECURITY EVENT ANALYSIS WITH CYBER-MODEL CONTEXTTECHNICAL FIELD

[0001] The present disclosure relates substantially to the field of software and hardware testing, and in particular to security analysis.BACKGROUND

[0002] In programming and software development and in hardware design and development, security experts perform threat analysis and risk assessment (“TARA”) to the software and hardware high level components. In this process, security experts analyze the risk and impact of cyber-attacks on a given component and its functionality. This process usually starts with item definition, identifying the threats, attack trees which describing how attacker performs his attack, risks and suggest optional security controls to reduce the risk. Software and hardware are used as implementation for the functionality of the components.SUMMARY

[0003] Accordingly, it is a principal object of the present invention to overcome at least some of the disadvantages of prior art systems and methods. This is provided in one embodiment by a security event analysis method, the method comprising: receiving information regarding a security event; and matching the security event to one or more contents of a cyber model representing a system. In some examples, the method comprises analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model. In some examples, based at least in part on the analyzed additional context, the method comprises determining risk information regarding the security event. In some examples, the method comprises outputting an indication of the determined risk information.

[0004] Additional features and advantages of the invention will become apparent from the following drawings and description.

[0005] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which thisinvention pertains. In case of conflict, the patent specification, including definitions, governs. As used herein, the articles "a" and "an" mean "at least one" or "one or more" unless the context clearly dictates otherwise. As utilized herein, “and / or” means any one or more of the items in the list joined by “and / or”. As an example, “x and / or y” means any element of the three-element set {(x), (y), (x, y) } . In other words, “x and / or y” means “x, y or both of x and y”. As some examples, “x, y, and / or z” means any element of the seven-element set {(x), (y), (z), (x, y), (x, z), (y, z), (x, y, z)}.

[0006] Further, unless expressly stated to the contrary, “or” refers to an inclusive or and not to an exclusive or. For example, a condition A or B is satisfied by anyone of the following: A is true (or present) and B is false (or not present), A is false (or not present) and B is true (or present), and both A and B are true (or present).

[0007] In addition, use of the “a” or “an” are employed to describe elements and components of embodiments of the instant inventive concepts. This is done merely for convenience and to give a general sense of the inventive concepts, and “a” and “an” are intended to include one or at least one and the singular also includes the plural unless it is obvious that it is meant otherwise.

[0008] As used herein, the term "about", when referring to a measurable value such as an amount, a temporal duration, and the like, is meant to encompass variations of + / -10%, more preferably + / -5%, even more preferably + / -1%, and still more preferably + / -0.1% from the specified value, as such variations are appropriate to perform the disclosed devices and / or methods.

[0009] The term "fine-tuning", as used herein, means a method where weights of a pretrained model are trained on new data, as known to those skilled in the art. In some examples, as known to those skilled in the art, fine-tuning comprises inputting data into the LLM and the LLM is prompted to fine-tune a predetermined sub-set of weights thereof based on a lossfunction. In some examples, the output of the LLM is input into a second LLM which generates an input for the loss-function, as known to those skilled in the art. It is noted that this is merely one method for performing fine-tuning, and is not meant to be limiting in any way.

[0010] The following embodiments and aspects thereof are described and illustrated in conjunction with systems, tools and methods which are meant to be exemplary and illustrative, but not limiting in scope. In various embodiments, one or more of the above-describedproblems have been reduced or eliminated, while other embodiments are directed to other advantages or improvements.BRIEF DESCRIPTION OF DRAWINGS

[0011] For a better understanding of the invention and to show how the same may be carried into effect, reference will now be made, purely by way of example, to the accompanying drawings in which like numerals designate corresponding sections or elements throughout.

[0012] With specific reference now to the drawings in detail, it is stressed that the particulars shown are by way of example and for purposes of illustrative discussion of the preferred embodiments of the present invention only and are presented in the cause of providing what is believed to be the most useful and readily understood description of the principles and conceptual aspects of the invention. In this regard, no attempt is made to show structural details of the invention in more detail than is necessary for a fundamental understanding of the invention, the description taken with the drawings making apparent to those skilled in the art how several forms of the invention may be embodied in practice. In the accompanying drawings:

[0013] FIG. 1A illustrates a high-level block diagram of an attack path adjustment system, in accordance with some examples of the present disclosure;

[0014] FIG. IB illustrates an example of risk analysis information;

[0015] FIG. 1C illustrates a high-level block diagram of an exemplary connectivity for the system of FIG. 1A;

[0016] FIGs. 2A - 2B illustrate various diagrams of attack trees, in accordance with some examples of the present disclosure;

[0017] FIG. 3 A illustrates a first example of an attack tree generated by the system of FIG. 1A;

[0018] FIG. 3B illustrates a second example of an attack tree generated by the system of FIG. 1A;

[0019] FIG. 4 illustrates a high-level block diagram of a security event analysis system, in accordance with some examples of the present disclosure.DETAILED DESCRIPTION OF CERTAIN EXAMPLES

[0020] In the following description, various aspects of the disclosure will be described. For the purpose of explanation, specific configurations and details are set forth in order to provide a thorough understanding of the different aspects of the disclosure. However, it will also be apparent to one skilled in the art that the disclosure may be practiced without specific details being presented herein. Furthermore, well-known features may be omitted or simplified in order not to obscure the disclosure. In the figures, like reference numerals refer to like parts throughout. In order to avoid undue clutter from having too many reference numbers and lead lines on a particular drawing, some components will be introduced via one or more drawings and not explicitly identified in every subsequent drawing that contains that component.

[0021] The term "cyber-model associated with an asset", as used herein, means a model of the asset, or of a larger system containing the asset, such as a vehicle. In some examples, the cyber-model comprises data regarding connectivity within the system. In some examples, the connectivity is between components within the system, such as ECUs. In some examples, the connectivity is between assets within the system. In some examples, the data regarding connectivity comprises data regarding connectivity between software elements within the system, optionally without hardware data associated with the software elements. In some examples, the data regarding connectivity comprises data regarding communication protocols between assets in the system.

[0022] In some examples, the cyber-model comprises any, or a combination, of: risk analysis data of the asset / system, such as TARA data; information regarding configuration data of the asset / system; specifications of the asset / system; and / or the operational state of the asset / system. In some examples, the cyber-model is received from the supplier of the asset, such as a vehicle manufacturer.

[0023] FIG. 1A illustrates a high-level block diagram of an attack path adjustment system 10. In some examples, system 10 comprises: a management subsystem 11, optionally comprising a user interface and / or a command line interface; a memory 20; and an attack pathsubsystem 30. In some examples, system 10 further comprises: an input subsystem 40; and an output subsystem 50. In some examples, management subsystem 11, and attack path subsystem 30 are each implemented on a dedicated processor, or set of processors, however this is not meant to be limiting in any way. In some examples, a processor 12, or set of processors 12, can be used to jointly run more than one of management subsystem 11 and attack path subsystem 30.

[0024] In some examples, management subsystem 11 and attack path subsystem 30 are each implemented by a respective set of instructions stored on memory 20, that when run by one or more processors 12 cause the respective processors 12 to perform the function of the respective one of management subsystem 11 and attack path subsystem 30.

[0025] In some examples, memory 20 comprises: an attack path database 21; and a category database 22, as will be described below. In some examples, memory 20 further comprises a connectivity database, as will be described below.

[0026] In some examples, attack path subsystem 30 comprises: a construction subsystem 32; and an adjustment subsystem 34. In some examples, construction subsystem 32 and adjustment subsystem 34 are each implemented by a respective set of instructions stored on memory 20, that when run by one or more processors 12 cause the respective processors 12 to perform the function of the respective one of construction subsystem 32 and adjustment subsystem 34.

[0027] In some examples, input subsystem 40 and output subsystem 50 each comprise a communication port. In some examples, input subsystem 40 and output subsystem 50 are each in communication with an external server and / or an external software program. Although input subsystem 40 and output subsystem 50 are illustrated herein as separate units, this is not meant to be limiting in any way, and a single hardware apparatus and / or software program can be utilized to implement input subsystem 40 and output subsystem 50.

[0028] In some examples, input subsystem 40 is in communication with a data source 45. In some examples, data source 45 can be a network; a predetermined sender within a cloud server containing system 10, such as an original equipment manufacturer (OEM); or a predetermined sender within a network containing system 10. Although input subsystem 40 is illustrated as being in communication with only a single data source 45 this is not meant to belimiting in any way, and input subsystem 40 may be in communication with any number of data sources 45.

[0029] In some examples, system 10 further comprises a language analysis subsystem 55. In some examples, language analysis subsystem 55 is implemented as a large language model (LLM) 55, and will be described as such unless otherwise stated. In some examples, as will be described below, language analysis subsystem 55 can be implemented as a natural language processor. One illustrative example of LLM 55, without any limitation, is from the LLaMa-2 large language model family, commercially available from Meta AL

[0030] In some examples, LLM 55 is fine-tuned on predefined data. Although the below is described in relation to fine-tuning of a trained LLM 55, this is not meant to be limiting in any way. In some examples, the below described steps of fine-tuning LLM 55 are performed in the process of training of LLM 55, with the appropriate changes, as known to those skilled in the art.

[0031] In some examples, a list of libraries associated with the asset are input to LLM 55, such that the data output by LLM 55 is relevant to these libraries. The term "associated with the asset", as used herein in relation to libraries means libraries that are accessed by the asset and / or accessed libraries that the asset uses data affected by the accessed library. For example, a first process accesses a library and utilizing the accessed library gets certain data, and stores the data in a queue. A second process, which is part of the asset, retrieves the data from the queue. Thus, in such an example, the library is associated with the asset since the asset retrieves data that is associated with the library.

[0032] The term "asset", as used herein, means a feature performing a functionality or a resource used for performing a functionality. Such a resource can include, for example, a key, a configuration file, or any other appropriate resource.

[0033] The term "signal asset", as used herein, means a message that can be sent from a source to a destination. In some examples, the signal asset comprises configuration information associated with the message that can be sent.

[0034] The term "software asset", as used herein, means a feature that is implemented with software which performs at least one functionality. The term "functionality", as used herein,means any function that is performed, such as "send a signal", "raise alarm", "activate sensor", etc. In some examples, these functionalities are implemented in software by developers.

[0035] An example of a software asset is a “Software Update”, which is a functionality that updates software, and is implemented by software in an item or a system. An example of a data asset is the data associated with an “Authentication key” which is used by the software asset to perform the functionality. An example of a system is an in-vehicle infotainment (IVI) system, which is a collection of hardware and software in automobiles that provides audio or video entertainment. An example of an item can be one of the hardware components of IVI system which runs at least on software.

[0036] In some examples, when prompting LLM 55 to output data based on the list of libraries, the list of libraries is input to LLM 55 as a soft prompt. The term "soft prompt", as used herein, means learnable tensors concatenated with the input embeddings.

[0037] In some examples, a specification sheet of the asset is input to LLM 55 such that the data output by LLM 55 is relevant to the specification sheet. In some examples, when prompting LLM 55 to output data based on the specification sheet, the data in the specification sheet is input to LLM 55 as a soft prompt. In some examples, TARA data, such as TARA information, of the asset, is input to LLM 55 such that the data output by LLM 55 is relevant to the TARA data, as will be described below. In some examples, when prompting LLM 55 to output data based on the TARA data, the TARA data, or predetermined parameters thereof, is input to LLM 55 as a soft prompt.

[0038] In some examples, a cyber-model is input to LLM 55 such that the data output by LLM 55 is relevant to the cyber-model. In some examples, when prompting LLM 55 to output data based on the cyber-model, the cyber-model, or predetermined portions thereof, is input to LLM 55 as a soft prompt.

[0039] In some examples, a list of libraries associated with the asset is input into LLM 55, such that the generated keywords are associated with the list of libraries. In one non-limiting example, LLM 55 can be prompted to generate keywords from the received information by requesting a list of keywords, optionally associated with the list of libraries. For example, if the received information contains information regarding vulnerabilities associated with a plurality of libraries, LLM 55 may generate only keywords relating to the vulnerabilitiesassociated with libraries that are in the list of libraries associated with the asset. In some examples, processor 12 inputs the list of libraries into LLM 55

[0040] In some examples, as described above, a specification sheet of the asset is input into LLM 55, such that the generated keywords are associated with the specification sheet. In some examples, as described above, TARA data (e.g., TARA) associated with the asset is input into LLM 55, such that the generated keywords are associated with the TARA data. In some examples, as described above, a cyber-model of the asset, or system containing the asset, is input into LLM 55, such that the generated keywords are associated with the cyber-model.

[0041] In some examples, LLM 55 generates keywords by: extracting words from a textual description of the received information; and providing terms associated with the received information. For example, LLM 55 can be fine-tuned to provide keywords related to the context of the received information. This can include known terms, or attack steps, that are related to the terms contained within the received information. For example, if the received information comprises a description of a vulnerability to a first type of attack aimed at a first functionality, LLM 55 can provide keywords related to other types of attack aimed at the first functionality. Additionally, LLM 55 can provide keywords related to the first type of attack, but that is aimed at different functionalities that are in communication with the first functionality.

[0042] Although the above has been described in relation to examples where the keywords are generated by LLM 55, or a separate LLM, this is not meant to be limiting in any way, and processor 30 can initiate any suitable algorithm for generating keywords from the received information. As described above in relation to LLM 55, such an algorithm can generate keywords that are associated with a list of libraries, specification sheet and / or TARA data associated with the asset.

[0043] In some examples, a plurality of keywords are generated by LLM 55, or a respective algorithm of processor 30, and processor 30 further filters the generated keywords based at least in part on the list of libraries, specification sheet, TARA data and / or cyber model.

[0044] In some examples, where LLM 55 is configured to summarize threat intelligence data, LLM 55 generates a summary of the identified threat intelligence data. In some examples, adjustment subsystem 34 inputs a request to LLM 55 to generate the summary. In some examples, LLM 55 ranks the identified threat intelligence data and / or the summary of the threat intelligence data. In some examples, adjustment subsystem 34 inputs a request to LLM 55 toperform the ranking. In some examples, LLM 55 is fine-tuned for ranking threat intelligence data. In some examples, rank values are assigned to each portion of the threat intelligence data indicating the rank thereof. In some examples, the rank values are assigned by LLM 55 or adjustment subsystem 34.

[0045] In some examples, LLM 55 determines the relevance of the threat intelligence data, and / or the summary of the threat intelligence data. In some examples, the determined relevance is the relevance to the anomalous behavior and / or event data. For example, LLM 55 can determine how relevant the threat intelligence data is to any of, without limitation: the component; the system / sub-system containing the component; the signals exhibiting the anomalous behavior; or the type of anomalous behavior or event. In some examples, LLM 55 is fine-tuned for determining the relevance of the threat intelligence data. In some examples, relevance values are assigned to each portion of the threat intelligence data indicating the relevance thereof. In some examples, the relevance values are assigned by LLM 55 or adjustment subsystem 34.

[0046] In some examples, where language analysis subsystem 55 is implemented as a natural language processor, the ranking and / or relevance can be determined based on predetermined criteria, such as: the general credibility and / or reliability of the source of the threat intelligence data; the credibility and / or reliability of the source of the threat intelligence data in relation to the respective component, system, sub-system, type of anomalous behavior and / or event; and / or the number of generated keywords that appear within the threat intelligence data.

[0047] In some examples, system 10 further comprises a security issue subsystem 57. In some examples, security issue subsystem 57 is implemented by a respective set of instructions stored on memory 20, that when run by one or more processors 12 cause the respective processors 12 to perform the function of security issue subsystem 57.

[0048] In some examples, as illustrated in FIG. 1A, system 10 receives risk analysis information at input subsystem 40, as will be described below. An example for such a risk analysis information file can be an Excel document, commercially available from Microsoft Ltd., containing the risk analysis information. In some examples, risk analysis information can be entered manually to system 10 using user interface subsystem 11. It is noted that the use of Excel as an input document is just an example and not limiting, since the same information canbe stored in other data formats such as a “comma- separated values” (CSV) file or table of values from a database.

[0049] In some examples, risk analysis information contains a description of the results of an analysis of the risk of predetermined security threats associated with one or more functionalities. In some examples, risk analysis information comprises Threat Analysis and Risk Assessment (TARA) information, such as defined in ISO / SAE 21434. Associating risk analysis information with a functionality is just an example and not to be construed as limiting. In some examples, risk analysis information is associated with a software asset, signal asset or data asset; an item which is a container of at least one software asset, signal asset or data asset; a system which is a container of at least one item; and / or a system which is a container for at least one software asset, signal asset or data asset. In some examples, a collection of systems or items can be defined as a “Model”.

[0050] FIG. IB illustrates an example of risk analysis information. As illustrated, a model is defined, the model denoted “Model 1”. Model 1 describes at least one system which comprises at least one item comprising at least one asset. A non-limiting example for such a model is a car program of a specific vehicle containing a plurality of systems, one of the systems being the IVI system. The IVI system comprises items such as an application microcontroller and an in-vehicle communication Microcontroller. For example, “Item 1” illustrated in FIG. IB may represent the application microcontroller and “Asset 1” may represents a software asset being run on the application microcontroller.

[0051] FIG. IB illustrates a pair of systems, denoted System 1 and System 2 (System 2 not detailed for simplicity). Although a pair of systems are illustrated, this is not meant to be limiting in any way, and any number of systems can be included in risk analysis information.

[0052] In the example of FIG. IB, System 1 comprises a pair of items, denoted Item 1 and Item 2. In the example of FIG. IB, Item 1 has associated therewith an asset, denoted Asset 1, and Item 2 has associated therewith an asset, denoted Asset 2_1. Although Item 1 and Item 2 are each illustrated as having associated therewith a single asset, this is not meant to be limiting in any way, and each asset can have associated therewith any number of assets.

[0053] Risk analysis information of Fig. IB also describes the threat that is associated with the asset. As described above, part of the Threat Analysis and Risk Assessment is to perform analysis and suggest different threats that can occur when the asset is compromised. In someexamples, threats can be labeled by the STRIDE model, which is a model for identifying computer security threats developed by Praerit Garg and Loren Kohnfelder at Microsoft. The STRIDE model provides a mnemonic for security threats in six categories. In some examples, the threats of an asset can be labeled by the EVITA model of the Evita project, as known to those skilled in the art. In some examples, each threat contains a description of the method that can make the threat happen. Such a description is commonly defined by an attack tree which contains attack steps that are necessary to perform the attack that will lead to the threat, as will be described further below.

[0054] Asset 1 is associated with a pair of threats, denoted Threat 1 and Threat 2. Each of Threat 1 and Threat 2 has an associated attack tree, denoted herein Attack Tree 1 and Attack Tree 2, respectively. Although each threat is illustrated herein as having a single attack tree, this is not meant to be limiting in any way, and a plurality of attack trees can be provided for a single threat. Each of Attack Tree 1 and Attack Tree 2 is illustrated as comprising two attack steps, denoted Attack Step 1 and Attack Step 2, however this is not meant to be limiting in any way, and each attack tree can comprise any number of attack steps.

[0055] Similarly, Asset 2_1 is associated with a pair of threats, denoted Threat 2_1_1 and Threat 2_1_2. Each of Threat 2_1_1 and Threat 2_1_2 has an associated attack tree, denoted herein Attack Tree 2_1_1 and Attack Tree 2_1_2, respectively. Although each threat is illustrated herein as having a single attack tree, this is not meant to be limiting in any way, and a plurality of attack trees can be provided for a single threat. Each of Attack Tree 2_1_1 and Attack Tree 2_1_2 is illustrated as comprising two attack steps, denoted Attack Step 1 and Attack Step 2; however this is not meant to be limiting in any way, and each attack tree can comprise any number of attack steps.

[0056] FIG. 1C illustrates an exemplary configuration and method for the use of system 10.

[0057] In some examples, as illustrated in FIG. 1C, system 10 is in communication with a Product Lifecycle Management (PLM) or an Application Lifecycle Management (ALM) system 70. PLM / ALM is the process of managing the entire lifecycle of a product / application from its inception through the engineering, design and manufacture stage. The Polarion® ALM system is an example of an ALM system 70, and is commercially available from Polarion Software, a Siemens AG Company from Munich, Germany.

[0058] In some examples, PLM / ALM system 70 provides risk analysis information. Particularly, in some examples, risk analysis information is received by PLM / ALM system 70 from an external source, and the received risk analysis information is transmitted to input subsystem 40.

[0059] In some examples, PLM / ALM system 70 further provides additional information regarding the information stored in a software repository 80 and / or a hardware repository 90. Particularly, in some examples, information supplied by software repository 80 and / or hardware repository 90 are transmitted to input subsystem 40 by PLM / ALM system 70. In some examples, the information is output from PLM / ALM system 70 using the application programming interface (API) of PLM / ALM system 70, as known to those skilled in the art.

[0060] In some examples, system 10 receives PLM / ALM information from PLM / ALM system 70. PLM / ALM information may include, for example: software implementation task status (e.g., new, in-progress, complete); software implementation task effort; the software implementation task owner; and / or a reference (“link”) to software implementation of the task. For example, an ALM system 70 may have list of functionalities that require implementation, and each functionality can be divided into “user-stories”. In software development and product management, a user story is an informal, natural language description of features of a software. The task effort of implementing the feature can be described by story points which are a metric used in agile project management and development to estimate the difficulty of implementing a given user story, as known to those skilled in the art. In some examples, system 10 receives information regarding the task effort as user story points. In some examples, the task effort can be the time it takes to implement, the cost of the implementation and / or any other suitable metrics.

[0061] In some examples, the PLM / ALM information is analyzed to extract risk analysis information (e.g., TARA data). In some examples, the PLM / ALM information is analyzed by language analysis subsystem 55. In some examples, the risk analysis information is extracted by identifying keywords within the PLM / ALM information that are associated with risk analysis (e.g., TARA).

[0062] In some examples, user-stories are identified and mapped by language analysis subsystem 55 to implementation features of one or more assets. For example, if anyimplementation features in the user-story can be identified and used to determine which asset implementation is associated with the information.

[0063] In some examples, system 10 receives risk analysis information directly from input subsystem 40. In some examples, a user can perform risk analysis using a graphical user interface of management subsystem 11 of system 10.

[0064] As described above, one of the steps in risk analysis (e.g., TARA) is to define security threats to assets. For example, a software asset defined as a “signal router”, which routes signals, can have a threat defined as “compromise the integrity of the signal router software”. Another example for a threat associated with a signal router can be “spoofing the identity of the signal”. It is noted that these examples are not meant to be limiting, and are described to help with understanding the term "threat" with regards to software assets and threat analysis.

[0065] There are different ways to describe how an attacker will be able to achieve the threat, for example by describing the attack path. For example, for the threat defined as “compromise the integrity of the signal router software”, the attack path description can be “Using malicious software update, attacker will modify the software of the signal router”.

[0066] One way to describe how an attacker will be able to achieve the threat is by using an attack tree or attack path. The term "attack tree", or "attack path", as defined herein, is a branching, hierarchical data structure that represents a set of potential approaches to achieving an event in which system security is penetrated or compromised in a specified way. An "attack step", as defined herein, is any node of the attack tree or attack path. It is noted that although the disclosure references TARA, this is not meant to be limiting in any way, and any other risk assessment methodology can be used, such as risk management framework (RMF), Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE), or other methodologies.

[0067] Each node of an attack tree may be satisfied by its direct leaf nodes. FIG. 2A illustrates a diagram of an attack tree. The attack tree of FIG. 2A comprises: a root node 1000; a pair of leaf nodes 1001 and 1002 branching from root; a pair of leaf nodes 1001_l and 1001_2 branching from leaf node 1001; and a leaf node 1002_l branching from leaf node 1002. It is noted that the particular configuration of the attack tree of FIG. 2A is illustrative only and any number of leaf nodes can be provided in an attack tree.

[0068] In the example of FIG. 2A, the attack tree comprises an OR condition between leaf nodes 1001 and 1002, which means that one attack path is sufficient to perform the attack. In contrast, the attack tree comprises an AND condition between leaf nodes 1001_ and 1001_2, which means both nodes are needed in order to continue with the attack. Thus, the attack tree of FIG. 2A comprises two attack vectors: a first attack vector comprising nodes 1001, 1001_1 and 1002; and a second attack vector comprising nodes 1002 and 1002_2.

[0069] FIG. 2B illustrates an example of attack steps of an attack tree, in a human readable description. In some examples, an attack step can comprise an action that is performed on a resource. Particularly, FIG. 2B illustrates a first attack step 1010, which is to perform an action A on a resource X. Also illustrated is the feasibility value of this attack step; in this case a high feasibility value. The term "feasibility value", as used herein, is a value that represents the chances of this attack actually happening in the real world, as known to those skilled in the art. The result of attack step 1010, in step 1010_l, is that resource Y can be accessed.

[0070] Attack step 1010_l_l comprises accessing resource Y, with a high feasibility value. Attack step 1010_l_2 comprises performing an action B on resource Y, with a low feasibility value. In the example of FIG. 2B steps 1010_l_l and 1010_l_2 comprise an AND condition therebetween, thus the combined attack step comprises getting resource Y and performing an action B on resource Y. An example for such a condition can be where resource Y is "kernel vulnerability", thus the attack step comprises two sub steps (1010_l_l and 1010_l_2), which is finding the kernel vulnerability (sub step 1010_l_l) and exploiting the kernel vulnerability (1010_l_2). In other words, the term "resource", as used herein, means anything that is being used to perform the attack. The attack step might include information regarding the feasibility to perform this step, as known to whom skills in the art, the feasibility of performing the attack step can is based on different parameters such as: expertise that are needed to perform the step, resources that are needed to perform the attack step, time it takes to perform the attack steps and other parameters.

[0071] Table 1 describes examples of format types for attack steps, as follows:Table 1

[0072] The syntax of the attack step can be described by one of the types that are in the table. For example, the attack step “Exploit Kernel Vulnerability” (described in FIG. 2B as sub steps 1010_l_l and 1010_l_2) has a format of “Verb, Subject, Object”, i.e., the verb is "exploit", the subject is "kernel" and the object is "vulnerability".

[0073] In some examples, the format of the attack steps includes more formats than described in table 1. In some examples, the attack step is defined using the simplest sentence possible. In some examples, utilizing management subsystem 11 of system 10, the user can define additional attack step formats. The use of attack step formats is further described below

[0074] In some examples, attack path database 21 comprises a plurality of attack trees, each with a respective plurality of attack steps.

[0075] In some examples, management subsystem 11 is configured to output the attack tree, and / or a list of attack steps, on a user display, such as the graphical user interface.

[0076] In some examples, each attack tree, or attack path, has a respective risk level associated therewith. In some examples, the term "risk level", as used herein, is defined as a predetermined function of the respective feasibility value and the respective impact value. In some examples, the impact value is a numerical indication of the impact that a particular threat will have on the respective asset (or on the item itself) if the respective threat is realized. In some examples, impact values are assigned numerical values, as known to those skilled in the art.

[0077] In some examples, the feasibility value of an attack tree, or attack path, is a predetermined function of the feasibility values of each of the attack steps therewithin. Thus, in some examples, the feasibility value of each attack step affects the feasibility value of the overall attack tree, or attack path. For example, if one of the attack steps has a low feasibility value, this can reduce the feasibility value of the respective attack path, or attack tree.

[0078] FIG. 3A illustrates a high-level block diagram of one non-limiting example of an attack tree Tl, comprising a plurality of attack steps: 1100; 1100_l; 1100_2; 1100_l_l; and 1100_l_2. In some examples, each of the plurality of attack steps comprises a respective feasibility value. Additionally, attack tree Tl comprises a risk level T1R. As illustrated, attack tree Tl comprises a plurality of attack paths for implementing the threat of the attack tree: attack steps 1100, 1100_l and 1100_l_l; attack steps 1100, 1100_l and 1100_l_2; and attack steps 1100 and 1100_2. In some examples, as described above, risk level T1R is determined as a respective function of: an impact value associated with the threat; and a respective function of the feasibility values of the plurality of attack steps 1100, 1100_l, 1100_2, 1100_l_l and 1100_l_2.

[0079] It is noted that although FIG. 3A is illustrated in relation to an example where each attack step has associated therewith a respective feasibility value, this is not meant to be limiting in any way. In some examples, each attack step has associated therewith a respective risk level. In some examples, each attack step has associated therewith both a respective feasibility value and a respective risk level.

[0080] FIG. 3B illustrates a high-level block diagram of one non-limiting example of an attack tree Tl', comprising a plurality of attack steps: 1100'; 1100_l '; 1100_2'; 1100_l_l '; and 1100_l_2'. In some examples, each of attack steps 1100', 1100_l', 1100_2', 1100_l_l* and 1100_l_2' are in all respects similar to respective attack steps 1100, 1100_l, 1100_2, 1100_l_l and 1100_l_2 of FIG. 3A, with the exception that each of attack steps 1100', 1100_l ', 1100_2', 1100_l_l' and 1100_l_2' has associated therewith a respective category.

[0081] Particularly, in some examples, construction subsystem 32 is configured to assign a respective category to each of the attack steps within attack path database 21. In some examples, information regarding a plurality of categories are stored in category database 22. In some examples, each category indicates a respective category of security events. One such example of a category can be "unauthorized access" to a particular asset. In some examples, such a category is assigned to any attack step which includes unauthorized access to some point.

[0082] In some examples, a category can include a name, or designation, of a component, asset, or system that the attack step is associated therewith. In some examples, the categoriescan include, without limitation: "Linux"; "WIFI"; "Bluetooth" (BT); "Application"; "Control Area Network" (CAN); and "Onboard Diagnostics II" (OBD-II).

[0083] In some examples, each category is assigned to the respective attack steps by assigning a respective data tag to the respective attack steps. In some examples, each data tag comprises a textual description of the respective category.

[0084] In some examples, attack tree Tl' comprises a risk level T1R, as described above.

[0085] In some examples, connectivity database 23 comprises information regarding connections between assets. For example, the connections between assets can include information regarding which assets communicate with each other. In some examples, an asset can be considered connected to another asset if there is direct communication therebetween. In some examples, an asset can be considered connected to another asset if there is communication between each of the assets and one or more intermediary assets. For example, asset A may be considered connected to asset C if both assets A and C communicate with asset B.

[0086] FIG. 3C illustrates a high-level flow chart of a method of adjusting an attack path. In some examples, in stage 2000, security event is received at system 10. In some examples, the security event is associated with one or more assets. It is noted that the security event may, or may not, contain a direct indication of which assets it is associated with. In some examples, the security event comprises information regarding an attack in the asset, information regarding a threat to the asset, information regarding a vulnerability in the asset or information regarding a potential vulnerability in the asset.

[0087] In some examples, an attack in the asset comprises a detected attack. The detected attack may be from a previous time period, or from a currently detected attack.

[0088] In some examples, an attack vulnerability is a known vulnerability of the respective asset to a particular attack. In some examples, the information regarding the attack vulnerability is given in a predetermined format, such as a Common Vulnerabilities and Exposures (CVE) format.

[0089] In some examples, a potential vulnerability is determined based on predetermined vulnerability rules. In some examples, a potential vulnerability is identified based on an identified vulnerability in another asset that is similar to the present asset, in accordance withthe predetermined vulnerabilities. In some examples, a potential vulnerability is identified based on received data from the asset that comprise certain unexplained anomalies, in accordance with the predetermined vulnerabilities.

[0090] In some examples, adjustment subsystem 34 identifies one or more of the attack steps that are associated with the security event. In some examples, in stage 2010, a respective category is identified based at least in part on the received security event. In some examples, the security event comprises a textual description, and adjustment subsystem 34 compares the textual description of the security event to a textual description of each of the plurality of categories, and the identification of the respective category is based at least in part on an outcome of the comparison. In some examples, the comparison is performed by LLM 55.

[0091] In some examples, LLM 55 summaries and / or ranks the received textual description of the security event. In some examples, LLM 55 and / or adjustment subsystem 34 compares the summarized description to the textual descriptions of the plurality of categories in order to identify the respective category.

[0092] In some examples, where the security event contains a description of a threat described in one of the categories (e.g., unauthorized access to a respective asset), adjustment subsystem 34 and / or LLM 55 identifies this category, and further identifies all attack steps containing this category. In some examples, where the security event contains a description of a threat to a respective asset / component / system described in one of the categories, adjustment subsystem 34 and / or LLM 55 identifies this asset / component / system, and further identifies all attack steps containing the category that describes the respective asset / component / system.

[0093] In some examples, by identifying the appropriate category, attack steps from a variety of attack paths, for a variety of assets, can be adjusted based on the received security event.

[0094] In some examples, the feasibility values of the identified one or more of the attack steps are adjusted based at least in part on the security event. In some examples, where the security event comprises adjusted values for the respective feasibility values, adjustment subsystem 34 replaces the respective feasibility values with the adjusted values.

[0095] In some examples, in stage 2020, adjustment subsystem 34 adjusts the respective feasibility values based at least in part on one or more predetermined rules. In some examples,the one or more predetermined rules comprises a respective value for each type of security event. For example, if the security event comprises an indication of an attack in the asset, the updated feasibility value is a first value. If the security event comprises an indication of a discovered threat, the updated feasibility value is a second value. If the security event comprises an indication of a potential vulnerability, the updated feasibility value is a third value.

[0096] In some examples, the feasibility values of the identified one or more of the attack steps are adjusted based at least in part on the received security event. In some examples, where the security event comprises adjusted values for the respective feasibility values, adjustment subsystem 34 replaces the respective feasibility values with the adjusted values contained in the security event.

[0097] In some examples, in stage 2030, based at least in part on the updated feasibility values, adjustment subsystem 34 adjusts the overall feasibility value and / or risk level for the attack tree, or attack path, comprising one or more attack steps whose feasibility value was updated. In some examples, where the overall feasibility value and / or risk level for the attack tree, or attack path, is based at least in part on a predetermined function of the feasibility values of the respective attack steps, adjustment subsystem 34 adjusts the overall feasibility value and / or risk level (e.g., risk level T1R) based at least in part the predetermined function, utilizing the updated feasibility values.

[0098] In some examples, in stage 2040, the adjusted overall feasibility value and / or risk level is compared to a predetermined threshold value. In the event that the adjusted overall feasibility value and / or risk level is greater than the predetermined threshold value, an indication of the adjusted feasibility value and / or risk level is output. In some examples, the comparison, and generation of the respective indication, is performed by rules device 57.

[0099] In some examples, in stage 2050, security issue subsystem 57 analyzes the adjusted values of the attack steps of stage 2020. In some examples, security issue subsystem 57 analyzes the adjusted risk and / or feasibility values of the attack paths of stage 2030. In some examples, based at least in part on one or more predetermined rules, security issue subsystem 57 identifies whether a security issue exists due to the adjustments of stages 2020 and / or 2030.

[0100] In some examples, security issue subsystem 57 identifies whether one or more of the attack steps whose feasibility value has been adjusted violates any of the predeterminedrules. In an illustrative example, such a rule can be that two adjacent attack steps have the same risk level (or feasibility value). In another illustrative example, such a rule can be that within a group of at least a predetermined number of adjacent attack steps, no more than 1 attack step can have a feasibility value greater than a predetermined threshold.

[0101] In some examples, upon identifying a violation of one of the rules, security issue subsystem 57 determines that a security issue is present and generates an indication of the presence of such a security issue. In some examples, the indication is output by output subsystem 50.

[0102] In some examples, security issue subsystem 57 identifies whether one or more of the attack steps of an attack path / attack tree whose risk level was adjusted violates any of the predetermined rules. In an illustrative example, such a rule can be that in an attack path (or attack tree) with a risk level greater than a predetermined number there can be no more than a predetermined number of attack steps with a feasibility value greater than a respective threshold.

[0103] In some examples, upon identifying a violation of one of the rules, security issue subsystem 57 determines that a security issue is present and generates an indication of the presence of such a security issue. In some examples, the indication is output by output subsystem 50.

[0104] In some examples, in stage 2060, where the risk level of an attack tree associated with a first asset is adjusted, adjustment subsystem 34 generates an indication for each of the assets that are connected to the first asset, the indication comprising the adjusted risk level of the attack tree. In some examples, the indication is generated based at least in part on one or more predetermined rules. In some examples, for each asset, an indication is generated for each case where a risk level of an attack tree associated with a connected asset is adjusted. As described above, in some examples, information regarding connectivity of assets is stored in connectivity database 23.

[0105] In some examples, for a group of connected assets, adjustment subsystem 34 generates an indication of the highest risk level within the group of connected assets.

[0106] In some examples, in stage 2070, based at least in part on one or more predetermined rules, security issue subsystem 57 determines whether the risk levels of attacktrees (or attack paths) associated with a group of connected assets violates one of the rules. In one illustrative example, such a rule can be that one of the group of connected assets has an attack tree with a risk level greater than a first predetermined number, and each of the other connected assets has one or more attack trees with risk levels greater than a second predetermined number. In some examples, based at least in part on the determination that one of the rules is violated, security issue subsystem 57 determines that a security issue is present and generates an indication of the presence of such a security issue. In some examples, the indication is output by output subsystem 50.

[0107] In some examples, a method is provided, wherein one or more of the following steps are performed:

[0108] 1. Security event is received.

[0109] 2. Keywords are extracted from the received security event. In some examples, the keywords are extracted using an LLM or any natural language processor.

[0110] 3. Attack steps of attack trees are identified based at least in part on the extracted keywords and the categories of the attack steps.

[0111] 4. The feasibility values of the identified attack steps are adjusted based at least in part on the received security event.

[0112] 5. The risk level of one or more attack paths, or attack trees, is adjusted based at least in part on the adjusted feasibility of the respective attack steps.

[0113] 6. The implications of the adjustment of feasibility values and / or risk levels are analyzed to determine whether a security issue is present.

[0114] It is noted that the terms "label" and "category" are used herein interchangeably and have the same meaning. Thus a label gives a description, optionally in one or two words, of an attack step, component and / or asset.

[0115] FIG. 4 illustrates a high-level block diagram of a security event analysis system 200. In some examples, system 200 comprises one or more processors 210 and a memory 220. In some examples, memory 220 has stored therein a plurality of instructions that when read by the one or more processors 210 cause the one or more processors to perform a plurality of steps.In some examples, memory 220 further has stored therein a cyber-model of one or more systems. In some examples, processors 210 and / or memory 220 are stored on one or more cloud servers.

[0116] In some examples, as described above in relation to system 10, system 200 further comprises an input subsystem 40 and an output subsystem 50. In some examples, input subsystem 40 and output subsystem 50 each comprise a communication port. In some examples, input subsystem 40 and output subsystem 50 are each in communication with an external server and / or an external software program. Although input subsystem 40 and output subsystem 50 are illustrated herein as separate units, this is not meant to be limiting in any way, and a single hardware apparatus and / or software program can be utilized to implement input subsystem 40 and output subsystem 50.

[0117] In some examples, input subsystem 40 is in communication with a data source 45. In some examples, data source 45 can be a network; a predetermined sender within a cloud server containing system 10, such as an original equipment manufacturer (OEM); or a predetermined sender within a network containing system 10. Although input subsystem 40 is illustrated as being in communication with only a single data source 45 this is not meant to be limiting in any way, and input subsystem 40 may be in communication with any number of data sources 45.

[0118] In some examples, system 200 is configured to perform any, or all, of the steps described above in relation to system 10, without exceeding the scope of the disclosure.

[0119] In some examples, the steps of one or more processors 210 comprise: receiving information regarding a security event. In some examples, the security event information is received via input subsystem 40. It is noted that the information regarding security events can be received from any of a plurality of sources, as described above in relation to system 10, such as a performed search or an input from an external source, such as a security operations center.

[0120] As described above, in some examples, the information regarding the security event comprises information regarding any of: an attack; a threat; a vulnerability; or a potential vulnerability.

[0121] In some examples, the steps of one or more processors 210 comprises matching the security event to one or more contents of a cyber model representing a system. The one or morecontents can be: an asset; a component, such as an application programming interface, log files, or other data or interface within the system.

[0122] In some examples, each component and / or asset within the cyber-model of the system has assigned thereto one or more respective labels. In some examples, each component / asset of the cyber-model has assigned thereto a plurality of labels, each label representing a portion of the information associated with that component / asset. In some examples, the cyber-model comprises, for each component / asset thereof, one or more attack paths. As described above, in some examples, each attack step of each attack path has assigned thereto a respective label. In some examples, each attack path has assigned thereto the labels of all the attack steps thereof, such that identifying the attack path can be done by looking at the group of labels associated therewith. In some examples, the respective component / asset has assigned thereto all of the labels of the attack paths associated therewith.

[0123] In one illustrative example, a database could have the following labels: "compromised credential"; "buffer overflow"; and "cryptography bug".

[0124] Thus, in some examples, the contents of the cyber-model can be matched by comparing the security event information with the respective labels, as described above in relation to system 10. In some examples, a tag is generated for the respective security event and the matching is performed by comparing the generated tag, or tags, of the security event with the tags of the cyber-model. In some examples, if the security event comprises a set of vulnerabilities, there may be a tag generated from the entire set.

[0125] In some examples, in the event that no match is found, such as no relevant attack paths are found, the one or more processors 210 update the cyber-model, optionally by generating attack paths relevant to the security event and adding the generated attack paths to the cyber-model.

[0126] In some examples, in the event that no relevant label is found, the one or more processors 210, optionally utilizing a respective LLM, generates one or more new labels and assigns the generated tag / s to a respective portion of the cyber-model. In some examples, the one or more processors 210 determine whether the generated tags are relevant to the cybermodel or whether the security event itself is not relevant to the cyber-model. Thus, in such examples, the tags can be assigned in the event that a relevant content is identified.

[0127] In some examples, as described above, matching can be performed using an LLM that compares the security event information to textual information of the various contents of the cyber-model. In some examples, matching can be performed by comparing the security event to one or more catalogs associated with the cyber-model.

[0128] In some examples, the steps of one or more processors 210 comprise: analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model. In some examples, the additional context is any information that is in the cybermodel. In some examples, the additional context is associated with a component / asset that is connected to the matched component / asset, either directly or indirectly.

[0129] In some examples, the context includes information regarding the feasibility and / or impact of the vulnerability. In some examples, the context can include information regarding a connected component in order to provide information about the connected component. For example, in the event that the connected component / asset has a high impact, the context includes information regarding the likelihood that the security event in the matched component / asset would affect the connected component / asset. For example, the context can include: a distance of the connected component / asset to the matched component / asset (i.e., the vulnerable component / asset); difficulty of attack due to additional requirements or configurations; difficulties in lateral movement between the matched component / asset and the connected component / asset; and / or security controls associated with the matched component / asset or the connected component / asset.

[0130] In some examples, based at least in part on the analyzed additional context, the one or more processors 210 determine risk information regarding the security event. In some examples, the risk information is determined for each connected component / asset. In some examples, the risk information indicates a risk level of the security event. In some examples, the risk level is determined based at least in part on the feasibility and impact of an attack in the respective asset / component.

[0131] In some examples, the risk information is output via output subsystem 50. In some examples, one or more processors 210 utilize the determined risk information to determine a priority of the security event. For example, if the risk of the security event within the cybermodel is low, a low priority can be indicated. Conversely, if the risk of the security event within the cyber-model is high, a high priority can be indicated. In some examples, the riskinformation can be determined for each component / asset of the cyber-model in relation to the respective security event, thus achieving a comprehensive risk analysis of the effect of the received security event on the cyber-model. In some examples, the risk information is output together with the security event information, thus outputting the security event information together with its priority information, for effective filtering / prioritization.Some Examples of the Disclosed Technology

[0132] Some examples of above-described implementations are enumerated below. It should be noted that one feature of an example in isolation or more than one feature of the example taken in combination and, optionally, in combination with one or more features of one or more examples below are examples also falling within the disclosure of this application.

[0133] Example 1. A security event analysis method, the method comprising: receiving information regarding a security event; matching the security event to one or more contents of a cyber model representing a system; analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model; based at least in part on the analyzed additional context, determining risk information regarding the security event; and outputting an indication of the determined risk information.

[0134] Example 2. The method of any example herein, particularly example 1, wherein the determined risk information indicates a risk level of the security event.

[0135] Example 3. The method of any example herein, particularly example 1 or 2, wherein the matched one or more plurality of contents of the cyber model comprises one or more components of the cyber model, and wherein the additional context associated with the matched one or more of the plurality of contents of the cyber model comprises an additional component connected to the matched one or more components.

[0136] Example 4. The method of any example herein, particularly example 3, wherein the additional context comprises: a priority of each component; and a distance between the matched component and the additional component.

[0137] Example 5. The method of any example herein, particularly example 3 or 4, wherein the additional context comprises information regarding a feasibility of an attack in the additional component.

[0138] Example 6. The method of any example herein, particularly any one of examples 1 - 5, wherein each of the contents of the cyber model has assigned thereto one or more respective labels, the matching based at least in part on the one or more respective labels assigned to the matched one or more contents of the cyber model.

[0139] Example 7. The method of any example herein, particularly example 6, wherein each of the contents of the cyber model has assigned thereto a plurality of respective labels, each of the plurality of labels assigned to a portion of the respective content of the cyber model.

[0140] Example 8. The method of any example herein, particularly example 7, wherein the matched content of the cyber model comprises one or more attack paths, each of the one or more attack paths comprises a plurality of attack steps, wherein each of the plurality of labels is assigned to a respective one of the plurality of attack steps of each of the one or more attack paths.

[0141] Example 9. The method of any example herein, particularly example 8, wherein the matching comprises identifying a respective one of the plurality of attack steps, and wherein the method further comprises, based at least in part on the received security event, adjusting a respective feasibility value of the identified attack step.

[0142] Example 10. The method of any example herein, particularly any one of examples 6 - 9, wherein each of the labels comprises a textual description.

[0143] Example 11. The method of any example herein, particularly any one of examples 1 - 10, wherein the information regarding the security event comprises information regarding an attack, a threat, a vulnerability or a potential vulnerability.

[0144] Example 12. A security event analysis system, the system comprising one or more processors and a memory, wherein the memory has stored therein a plurality of instructions that when read by the one or more processors cause the one or more processors to perform a plurality of steps, the steps comprising: receiving information regarding a security event; matching the security event to one or more contents of a cyber model representing a system; analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model; based at least in part on the analyzed additional context, determining risk information regarding the security event; and outputting an indication of the determined risk information.

[0145] Example 13. The system of any example herein, particularly example 12, wherein the determined risk information indicates a risk level of the security event.

[0146] Example 14. The system of any example herein, particularly example 12 or 13, wherein the matched one or more plurality of contents of the cyber model comprises one or more components of the cyber model, and wherein the additional context associated with the matched one or more of the plurality of contents of the cyber model comprises an additional component connected to the matched one or more components.

[0147] Example 15. The system of any example herein, particularly example 14, wherein the additional context comprises: a priority of each component; and a distance between the matched component and the additional component.

[0148] Example 16. The system of any example herein, particularly example 14 or 15, wherein the additional context comprises information regarding a feasibility of an attack in the additional component.

[0149] Example 17. The system of any example herein, particularly any one of examples 12 - 16, wherein each of the contents of the cyber model has assigned thereto one or more respective labels, the matching based at least in part on the one or more respective labels assigned to the matched one or more contents of the cyber model.

[0150] Example 18. The system of any example herein, particularly example 17, wherein each of the contents of the cyber model has assigned thereto a plurality of respective labels, each of the plurality of labels assigned to a portion of the respective content of the cyber model.

[0151] Example 19. The system of any example herein, particularly example 18, wherein the matched content of the cyber model comprises one or more attack paths, each of the one or more attack paths comprises a plurality of attack steps, wherein each of the plurality of labels is assigned to a respective one of the plurality of attack steps of each of the one or more attack paths.

[0152] Example 20. The system of any example herein, particularly example 19, wherein the matching comprises identifying a respective one of the plurality of attack steps, and wherein the steps further comprise, based at least in part on the received security event, adjusting a respective feasibility value of the identified attack step.

[0153] Example 21. The system of any example herein, particularly any one of examples 17 - 20, wherein each of the labels comprises a textual description.

[0154] Example 22. The system of any example herein, particularly any one of examples 12 - 21, wherein the information regarding the security event comprises information regarding an attack, a threat, a vulnerability or a potential vulnerability.

[0155] It is appreciated that certain features of the invention, which are, for clarity, described in the context of separate embodiments, may also be provided in combination in a single embodiment. Conversely, various features of the invention which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable subcombination.

[0156] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as are commonly understood by one of ordinary skill in the art to which this invention belongs. Although methods similar or equivalent to those described herein can be used in the practice or testing of the present invention, suitable methods are described herein.

[0157] All publications, patent applications, patents, and other references mentioned herein are incorporated by reference in their entirety. In case of conflict, the patent specification, including definitions, will prevail. In addition, the materials, methods, and examples are illustrative only and not intended to be limiting.

[0158] It will be appreciated by persons skilled in the art that the present invention is not limited to what has been particularly shown and described hereinabove. Rather the scope of the present invention is defined by the appended claims and includes both combinations and subcombinations of the various features described hereinabove as well as variations and modifications thereof which would occur to persons skilled in the art upon reading the foregoing description.

Claims

CLAIMS1. A security event analysis method, the method comprising: receiving information regarding a security event; matching the security event to one or more contents of a cyber model representing a system; analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model; based at least in part on the analyzed additional context, determining risk information regarding the security event; and outputting an indication of the determined risk information.

2. The method of claim 1, wherein the determined risk information indicates a risk level of the security event.

3. The method of claim 1 or 2, wherein the matched one or more plurality of contents of the cyber model comprises one or more components of the cyber model, and wherein the additional context associated with the matched one or more of the plurality of contents of the cyber model comprises an additional component connected to the matched one or more components.

4. The method of claim 3, wherein the additional context comprises: a priority of each component; and a distance between the matched component and the additional component.

5. The method of claim 3 or 4, wherein the additional context comprises information regarding a feasibility of an attack in the additional component.

6. The method of any one of claims 1 - 5, wherein each of the contents of the cyber model has assigned thereto one or more respective labels, the matching based at least in part on the one or more respective labels assigned to the matched one or more contents of the cyber model.

7. The method of claim 6, wherein each of the contents of the cyber model has assigned thereto a plurality of respective labels, each of the plurality of labels assigned to a portion of the respective content of the cyber model.

8. The method of claim 7, wherein the matched content of the cyber model comprises one or more attack paths, each of the one or more attack paths comprises a plurality of attack steps, wherein each of the plurality of labels is assigned to a respective one of the plurality of attack steps of each of the one or more attack paths.

9. The method of claim 8, wherein the matching comprises identifying a respective one of the plurality of attack steps, and wherein the method further comprises, based at least in part on the received security event, adjusting a respective feasibility value of the identified attack step.

10. The method of any one of claims 6 - 9, wherein each of the labels comprises a textual description.

11. The method of any one of claims 1 - 10, wherein the information regarding the security event comprises information regarding an attack, a threat, a vulnerability or a potential vulnerability.

12. A security event analysis system, the system comprising one or more processors and a memory, wherein the memory has stored therein a plurality of instructions that when read by the one or more processors cause the one or more processors to perform a plurality of steps, the steps comprising: receiving information regarding a security event; matching the security event to one or more contents of a cyber model representing a system; analyzing additional context associated with the matched one or more of a plurality of contents of the cyber model; based at least in part on the analyzed additional context, determining risk information regarding the security event; and outputting an indication of the determined risk information.

13. The system of claim 12, wherein the determined risk information indicates a risk level of the security event.

14. The system of claim 12 or 13, wherein the matched one or more plurality of contents of the cyber model comprises one or more components of the cyber model, and wherein the additional context associated with the matched one or more of the plurality of contents of the cyber model comprises an additional component connected to the matched one or more components.

15. The system of claim 14, wherein the additional context comprises: a priority of each component; and a distance between the matched component and the additional component.

16. The system of claim 14 or 15, wherein the additional context comprises information regarding a feasibility of an attack in the additional component.

17. The system of any one of claims 12 - 16, wherein each of the contents of the cyber model has assigned thereto one or more respective labels, the matching based at least in part on the one or more respective labels assigned to the matched one or more contents of the cyber model.

18. The system of claim 17, wherein each of the contents of the cyber model has assigned thereto a plurality of respective labels, each of the plurality of labels assigned to a portion of the respective content of the cyber model.

19. The system of claim 18, wherein the matched content of the cyber model comprises one or more attack paths, each of the one or more attack paths comprises a plurality of attack steps, wherein each of the plurality of labels is assigned to a respective one of the plurality of attack steps of each of the one or more attack paths.

20. The system of claim 19, wherein the matching comprises identifying a respective one of the plurality of attack steps, and wherein the steps further comprise, based at least in part on the received security event, adjusting a respective feasibility value of the identified attack step.

21. The system of any one of claims 17 - 20, wherein each of the labels comprises a textual description.

22. The system of any one of claims 12 - 21, wherein the information regarding the security event comprises information regarding an attack, a threat, a vulnerability or a potential vulnerability.

Citation Information

Patent Citations

  • Systems and methods for prioritizing security findings using machine learning models

    US20230205891A1

  • Adaptive system for network and security management

    US20230396632A1

Cited By

  • Generation of TARA-based IDPS rules utilizing generative artificial intelligence

    US12500915B1