Framework providing security predictions for network assets in cyber-security network and method thereof

The framework addresses the challenge of measuring and predicting security metrics for network assets by modeling bidirectional relationships between assets and security tags, enabling comprehensive security assessments and informed risk mitigation.

WO2025136159A1PCT designated stage expired Publication Date: 2025-06-26TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2023/051281
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing cybersecurity frameworks struggle to effectively measure and predict security metrics for network assets in complex industrial environments, where multiple security standards and unique business vertical requirements complicate security assessments.

Method used

A framework and method that utilize a bidirectional relationship model between network assets and security tags, incorporating assign and correlation modules, score and computation modules, and latent factor computation to predict security scores and provide comprehensive security predictions.

Benefits of technology

The framework effectively models bidirectional relationships between network assets and security tags, providing principled analysis of diverse security assessments and capturing heterogeneous dependencies, thus aiding security professionals in informed risk mitigation decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2023051281_26062025_PF_FP_ABST
    Figure SE2023051281_26062025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of present disclosure provide framework (200) and method (800) providing security predictions for network assets (202) in cyber-security network (2000). Framework 800 comprises first model (206), second model (208), second computation module (210) and trained score prediction model (212), trained using first latent factors and the second latent factors for predicting security score (234) assigned by security tag (104) to network asset (202). Second computation module computes: first latent factors (220) by using security metrics data (218) and correlation data (220) from the first model (206), and second latent factors (222) by using security score (226) and asset network graph data (228) from the second model (208). Trained score prediction model (212) predicts security score (234) by using the first latent factors (230) and the second latent factors (232).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] FRAMEWORK PROVIDING SECURITY PREDICTIONS FOR NETWORK ASSETS IN CYBERSECURITY NETWORK AND METHOD THEREOF

[0002] TECHNICAL FIELD

[0003] The present disclosure relates generally to a field of cyber security. More particularly, it relates to a framework and a method providing security predictions for network assets in the cyber-security network.

[0004] BACKGROUND

[0005] The convergence of Telco emerging networks towards Information Technology, IT networks and the virtualization of 5G networks are creating new opportunities for businesses to integrate diverse applications and managed services. However, this may also introduce new security challenges across various industries, as different verticals may have different security requirements and with that a multitude of security standards may need to be considered.

[0006] One of the key challenges is how to intrinsically measure security in a complex industrial environment. Traditional security metrics, such as a number of vulnerabilities or number of attacks, are no longer sufficient. To effectively measure security in a particular industrial environment, a comprehensive approach may be needed that may consider multiple perspectives such as various technology standards. Adherence to relevant technology standards, such as 3GPP, European Telecommunications Standards Institute, ETSI, and Customer Service Assurance, CSA, may provide a baseline level of security assurance. These standards may define specific security requirements for different components of the network, ensuring interoperability and consistency.

[0007] Further, from business vertical requirements perspective, each business vertical may have its own unique security requirements, dictated by industry regulations and the sensitivity of the data being handled. For instance, healthcare must adhere to Health Insurance Portability and Accountability Act, HIPAA, while finance is governed by Payment Card Industry Data Security Standard, PCI DSS.

[0008] Furthermore, guidelines from organizations like National Institute of Standards and Technology, NIST and CIS Critical Security Controls , CIS, may provide best practices for implementing security controls across various aspects of the network, including infrastructure, applications, and data. Furthermore, vulnerability scanners and databases may help identify and prioritize potential security weaknesses in the network's software and hardware components.

[0009] By addressing the challenges of measuring security in the presence of a high number of security standards, businesses may ensure that their 5G virtualized networks are secure and reliable.

[0010] SUMMARY

[0011] There is a need for an improved method for providing information about relation between network assets and security tags, security tags and security tags, and network assets and network assets, which alleviates at least some of the above-cited problems.

[0012] It is therefore an object of the present disclosure to provide a framework and a method for providing security predictions for one or more network assets from a plurality of network assets in a cyber-security network to mitigate, alleviate, or eliminate all or at least some of the above-discussed drawbacks of presently known solutions.

[0013] This and other objects are achieved by means of a framework, and a method defined in the appended claims. The term exemplary is in the present context to be understood as serving as an instance, example or illustration.

[0014] According to a first aspect of the present disclosure, a framework is provided. The framework is providing security predictions for one or more network assets from a plurality of network assets in a cyber-security network. The cyber-security network comprises one or more security tags from a plurality of security tags to be assigned to the one or more network assets to assess security metrics of the one or more network assets. The framework comprises at least one first model. The at least one first model comprises an assign module and a correlation module. The assign module is arranged for assigning security metrics data to at least one network asset from the one or more network assets through at least one security tag from the one or more security tags. The correlation module is arranged for computing correlation data to provide information about a relation between the at least one security tag and other security tags from the one or more security tags. The framework further comprises at least one second model. The at least one second model comprises a score module and a first computation module. The score module is arranged for determining at least one security score assigned to each network asset in a set of network assets obtained from the plurality of network assets through each security tag from a set of security tags. The first computation module is arranged for computing asset network graph data to provide information about connectivity of the at least network asset with other network assets from the one or more network assets. The framework further comprises at least one second computation module, arranged for computing, first latent factors for the at least one first model by using the at least security metrics data and the correlation data from the first model and computing, second latent factors for the at least one second model by using the asset security score data and the asset network graph data from the second model. The framework further comprises a trained score prediction model trained by using the first latent factors and the second latent factors, and arranged for predicting at least one security score assigned by the at least one security tag to the at least one network asset.

[0015] Optionally, the at least one security metrics data provides a ground truth score assigned by the at least one security tag to the at least one network asset.

[0016] Optionally, the correlation data comprises weights representing a dependency between the at least one security tag and the other security tags.

[0017] Optionally, the at least one first latent factor comprises an aggregate of the at least one security metrics data and the correlation data.

[0018] Optionally, the second latent factors comprises an aggregate of the asset security score data and the asset network graph data.

[0019] Optionally, the updated score prediction model is arranged for predicting a plurality of security scores for a plurality of network assets assigned by a plurality of security tags and generating, a corresponding rating for each security score in the plurality of security scores.

[0020] Optionally, the one or more network assets are selected from a group comprising at least one of software network assets, hardware network assets, Internet of Things, loT devices, virtual native applications, and virtual appliances. Optional ly, the at least one security metrics data is selected from a group comprising at least one of: trustworthiness data about the at least one network asset, security properties of the at least one network asset, security controls associated with the at least one network asset, security standards associated with the at least one network asset, weaknesses associated with the at least one network asset, and cyber-attacks over the at least one network asset.

[0021] Optionally, both the at least one first latent factor and the at least one second latent factor are computed by using a Machine Learning, ML, model.

[0022] Optionally, the ML model comprises a Graph attention based Neural Network model, GANN. Optionally, aggregation within the GANN may be performed with averaging, convolution, max pooling, mean pooling, Long short-term memory, LSTM shuffles of neighbors. According to a second aspect of the present disclosure, a computer implemented method performed through a framework providing security predictions for one or more network assets from a plurality of network assets in a cyber-security network is provided. The cyber-security network comprises one or more security tags from a plurality of security tags to be assigned to the one or more network assets to assess security metrics of the one or more network assets. The method comprises assigning, through an assign module in at least one first model, security metrics data (108) to at least one network asset from the one or more network assets through at least one security tag from the one or more security tags, and computing, through a correlation module in the at least one first model, correlation data to provide information about a relation between the at least one security tag and other security tags from the one or more security tags. The method further comprises determining the at least one security score assigned to each network asset in the set of network assets obtained from the plurality of network assets through each security tag from a set of security tags. The security score is determined through a score module in at least one second model. The method further comprises computing asset network graph data to provide information about connectivity of the at least one network asset 202 with other network assets from the one or more network assets. The computing is performed through the first computation module in the at least second model. The method further comprises computing the first latent factors for the at least one first model by using the at least security metrics data and the correlation data from the first model and computing the second latent factors for the at least one second model by using the asset security score data and the asset network graph data from the second model. The computing is performed through the at least one second computation module. The computing is performed through the at least one second computation module. The method further comprises predicting at least one security score assigned by the at least one security tag to the at least one network asset. The prediction is performed through the trained score prediction model trained by using the first latent factors and the second latent factors.

[0023] Some embodiments disclosed herein have one or more of the following advantages:

[0024] Effectively modelling a bidirectional relationship between network assets and security tags within complex and heterogeneous Information Technology, IT environments such as industrial systems, telco networks, cloud, etc.

[0025] Providing a principled approach to jointly analyze interactions of diverse security assessments within a security tags-assets graph.

[0026] Capturing heterogeneous dependencies that exist between network assets and security tags.

[0027] Providing an attention graph neural model as the Machine Learning model which serves as a valuable tool for decision support in security posture management.

[0028] By providing insights about relationship between network assets and security tags, the framework helps security professionals make informed decisions about risk mitigation strategies.

[0029] Incorporating an intelligent component that captures security metrics from various security perspectives and diverse types of assets.

[0030] Other advantages may be readily apparent to one having skill in the art. Certain embodiments may have none, some, or all of the recited advantages.

[0031] BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The foregoing will be apparent from the following more particular description of the example embodiments, as illustrated in the accompanying drawings in which like reference characters refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating the example embodiments.

[0033] FIG. 1 discloses a wireless communication system according to some examples; FIG. 2 is a schematic block diagram illustrating an example framework for providing security predictions for one or more network assets in a cyber-security network;

[0034] FIG. 3 is an example schematic diagram illustrating mapping between network assets and security tags;

[0035] FIG. 4(a) and 4(b) are example schematic diagrams of security tags modelling (First Model);

[0036] FIG. 5(a) and 5(b) are example schematic diagrams of asset modelling (second model);

[0037] FIG. 6 is an example dependency graph illustrating dependency between network assets;

[0038] FIG. 7 is an example dependency graph illustrating dependency between network security tags;

[0039] FIG. 8 is a flowchart illustrating example steps for a method implemented in a framework providing security predictions for one or more network assets in a cyber-security network;

[0040] FIG. 9 is a schematic block diagram illustrating security tags-assets graph and aggregation of security tags;

[0041] FIG. 10 is a schematic block diagram illustrating security tags dependencies graph by showing dependencies between security tags;

[0042] FIG. 11 is a schematic block diagram illustrating security tags-assets graph and aggregation of assets;

[0043] FIG. 12 is a schematic block diagram illustrating dependencies between network assets;

[0044] FIG. 13 illustrates an example graph showing loss value convergence according to some embodiments;

[0045] FIG. 14 illustrates an example graph showing trend of Mean Absolute Error (MAE) and Root Mean Square Error (RMSE) according to some embodiments;

[0046] FIG. 15 shows an example graph illustrating a scatter of different data points representing asset and tag tuples according to some embodiments;

[0047] FIG. 16 and 17 shows example graphs illustrating use case of two assets according to some embodiments; FIG. 18 shows an example graph illustrating the use case of another asset according to some embodiments;

[0048] FIG. 19 shows an example graph illustrating Assets' Scores Averaging vs. Corrections according to some embodiments;

[0049] FIG. 20 shows an example graph illustrating security Tag' Scores Averaging vs. Corrections according to some embodiments;

[0050] FIG. 21 shows example graph illustrating a first experiment (PoDs use case) and a second experiment (packages use case) on assets;

[0051] FIG. 22 shows another example graph illustrating a first experiment (packages use case) and a second experiment (packages use case) on assets;

[0052] FIG. 23(a) and (b) shows example graph illustrating Mean Absolute Error (MAE) and Root Mean Square Error (RMSE);

[0053] FIG. 24 shows example experimental graph considering 122 assets as containers;

[0054] FIG. 25 shows example graph illustrating considering 1693 assets as Packages (namespaces);

[0055] FIG. 26 shows example table illustrating ranking value of assets;

[0056] FIG. 27 shows example table illustrating average prediction score of security tags;

[0057] FIG. 28A shows example table illustrating asset dependencies use case;

[0058] FIG. 28B shows example table illustrating asset dependencies use case;FIG. 29 shows example graph illustrating security score of predictions for network assets assigned by the security tags;

[0059] FIG. 30 shows example schematic block diagram showing decision support based on an attention graph Neural Network Model;

[0060] FIG. 31 is an example functional diagram for security posture assessment; and

[0061] FIG. 32 discloses an example computing environment according to some embodiments. DETAILED DESCRIPTION

[0062] Aspects of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. The framework and methods disclosed herein can, however, be realized in many different forms and should not be construed as being limited to the aspects set forth herein. Like numbers in the drawings refer to like elements throughout.

[0063] The terminology used herein is for the purpose of describing particular aspects of the disclosure only and is not intended to limit the invention. It should be emphasized that the term "comprises / comprising" when used in this specification is taken to specify the presence of stated features, integers, steps, or components, but does not preclude the presence or addition of one or more other features, integers, steps, components, or groups thereof. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0064] Embodiments of the present disclosure will be described and exemplified more fully hereinafter with reference tothe accompanying drawings. The solutions disclosed herein can, however, be realized in many different forms and should not be construed as being limited to the embodiments set forth herein.

[0065] It will be appreciated that when the present disclosure is described in terms of a framework and a method, it may also be embodied in one or more processors and one or more memories coupled to the one or more processors, wherein the one or more memories store one or more programs that perform the steps, services and functions disclosed herein when executed by the one or more processors.

[0066] FIG. 1 discloses an example wireless communication system 100. Although the subject matter described herein may be implemented in any appropriate type of system using any suitable components, the examples disclosed herein are described in related to a wireless communication system / wireless network, such as the example wireless communication system 100 described in FIG. 1.

[0067] The wireless communication system 100 may comprise and / or interface with any type of communication, telecommunication, data, cellular, and / or radio network or other similar type of system. The wireless communication system 100 may be configured to operate according to specific standards or other types of predefined rules of procedures. Thus, the wireless communication system 100 may implement communication standards, such as, but are not limited to, global system for mobile communications, GSM, universal mobile telecommunications system, UMTS, long term evolution, LTE, and / or other suitable 2G, 3G, 4G, or 5G standards, wireless local area network, WLAN, standards such as, IEEE 802.11 standards, and / or any other appropriate wireless communication standards, such as, worldwide interoperability for microwave access, WiMax, Bluetooth, Z-Wave and / or ZigBee standards.

[0068] For simplicity, as depicted in FIG. 1, the wireless communication system 100 comprises a framework 200, a network node 104, and a network 106. The framework 200 and the network node 104 operate together in order to provide wireless connections in the wireless communication system 100. The network 106 may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks, PSTNs, packet data networks, optical networks, wide-area networks, WANs, local area networks, LANs, wireless local area networks, WLANs, wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices (for example, wireless devices and network node).

[0069] In an example, the network node 104 refer to equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with the framework 200 and / or with other network nodes or equipment in the wireless communication system 100 to enable and / or provide wireless access to the framework 200 and / or to perform other functions (for example, administration) in the wireless communication system 100. Examples of the network node 104 may include, but are not limited to, access points, APs (for example, radio access points), base stations, BSs (for example, radio base stations, nodeBs, evolved NodeBs, eNBs, new radio, NR, nodes (gNBs), or the like). The BSs may be categorized based on an amount of coverage the BSs provide (or, stated different, their transmit power level) and may then also be referred to as femto BSs, pico BSs, micro BSs, macro BSs. The BS may be a relay node or a relay donor node controlling a relay.

[0070] The framework 200 refers to a device capable, configured, arranged and / or operable to communicate wirelessly with the network node 104 and / or other wireless devices. In some examples, the framework 200 may include one or more of: computing devices, wireless devices, ultra-low power wireless devices, Internet of Things, loT, devices, and so on.

[0071] Examples of the computing devices may include, but are not limited to, a smart phone, a mobile phone, a cell phone, a voice over Internet Protocol, IP, VoIP, phone, a wireless local loop phone, a desktop computer, a personal digital assistant, PDA, a wireless camera, a gaming console or device, a wearable terminal device, a wireless endpoint, a mobile station, a tablet, a laptop, a laptop-embedded equipment, LEE, a laptop-mounted equipment, LME, a smart device, a wireless customer-premise equipment, CPE, a vehicle- mounted wireless terminal device, and so on.

[0072] It should be understood that the framework 200 may not be limited to the above-described wireless devices. The framework 200 may be extended to other wireless devices of different classes or categories providing different services while supporting, for example, Enhanced Mobile Broadband, eMBB, massive Machine-Type Communication, MTC, Ultra-Reliable Low Latency Communication, URLLC, Time Sensitive Networking, TSN, or the like.

[0073] In the wireless communication system 100, the network node 104 and the framework 200 are connected through 3GPP 5G core network where specific network services and operations are provided through software components called network functions (NFs). The wireless communication system 100 hosts large scale applications.

[0074] One of the key challenges is how to intrinsically measure security in a complex industrial environment. Traditional security metrics, such as a number of vulnerabilities or number of attacks, are no longer sufficient. To effectively measure security in a particular industrial environment, a comprehensive approach may be needed that may consider multiple perspectives such as various technology standards. Adherence to relevant technology standards, such as 3GPP, European Telecommunications Standards Institute, ETSI, and Customer Service Assurance, CSA, may provide a baseline level of security assurance. These standards may define specific security requirements for different components of the network, ensuring interoperability and consistency.

[0075] Further, from business vertical requirements perspective, each business vertical may have its own unique security requirements, dictated by industry regulations and the sensitivity of the data being handled. For instance, healthcare must adhere to Health Insurance Portability and Accountability Act, HIPAA, while finance is governed by Payment Card Industry Data Security Standard, PCI DSS.

[0076] Thus, the present disclosure enables the wireless communication network 100, the network node 104 and the framework 200 provides security predictions for one or more network assets from a plurality of network assets in a cyber-security network effectively modelling a bidirectional relationship between network assets and security tags within complex and heterogeneous Information Technology, IT environments such as industrial systems, telco networks, cloud

[0077] FIG. 2 is a schematic block diagram illustrating an example framework 200 for providing security predictions for one or more network assets 202 from a plurality of network assets 202 in a cyber-security network 2000. The cyber-security network 2000 comprises one or more security tags 204, also referred as asset security tags 202 or tags 204, from a plurality of security tags 204, to be assigned to the one or more network assets 202 to assess security metrics of the one or more network assets 202. The framework 200 comprises at least one first model 206, at least one second model 208, at least one second computation module 210a, 210b and a trained score prediction model 212.

[0078] The first model 206 comprises an assign module 214 and a correlation module 216. The assign module 214 is arranged for assigning security metrics data 218 also referred as tag latent factor, to at least one network asset 202 from the one or more network assets 202 through at least one security tag 204 from the one or more security tags 204. The correlation module 216 is arranged for computing correlation data 220 also referred as security space, to provide information about a relation between the at least one security tag 204 and other security tags 204 from the one or more security tags 204.

[0079] The at least one second model 208 comprises a score module 222 and a first computation module 224. The score module 222 is arranged for determining at least one security score 226, also referred as assets latent factor, assigned to each network asset 202 in a set of network assets 202 obtained from the plurality of network assets 202 through each security tag 204 from a set of security tags 204 obtained from the plurality of security tags 204. The first computation module 224 is arranged for computing asset network graph data 228, also referred as asset space, to provide information about connectivity of the at least network asset 202 with other network assets 202 from the one or more network assets 202.

[0080] The framework 200 further comprises the at least one second computation module 210a. The at least one second computation module 210a is arranged for computing first latent factors 230, also referred as security model latent factors, for the at least one first model 206 by using the security metrics data 218 and the correlation data 220 from the first model 206. The at least second computation module 210b is further arranged for computing second latent factors 232 also referred as asset model latent factor, for the at least one second model 208 by using the at least one security score 226 (asset security score data) and the asset network graph data 228 from the second model 208.

[0081] The trained score prediction model 212 is trained by using the first latent factors 230 and the second latent factors 232. The trained score prediction model 212 is arranged for predicting at least one security score 234 assigned by the at least one security tag 204 to the at least one network asset 202.

[0082] Optionally, the one or more network assets 202 are selected from a group comprising at least one of software network assets, hardware network assets, Internet of Things, loT devices, virtual native applications, and virtual appliances.

[0083] Optionally, the at least one security metrics data 218 is selected from a group comprising at least one of: trustworthiness data about the at least one network asset, security properties of the at least one network asset, security controls associated with the at least one network asset, security standards associated with the at least one network asset, weaknesses associated with the at least one network asset, and cyber-attacks over the at least one network asset.

[0084] Optionally, the at least one security metrics data 218 provides a ground truth score assigned by the at least one security tag 204 to the at least one network asset 202.

[0085] Optionally, the correlation data 220 comprises weights representing a dependency between the at least one security tag 204 and the other security tags 204. Optional ly, the at least one first latent factor 230 comprises an aggregate of the at least one security metrics data 218 and the correlation data 220.

[0086] Optionally, the second latent factors 232 comprises an aggregate of the asset security score data 226 and the asset network graph data 228.

[0087] Optionally, a trained score prediction model 212 is arranged for predicting a plurality of security scores 234 for the plurality of network assets 202 assigned by the plurality of security tags 204 and generating, a corresponding rating for each security score 234 in the plurality of security scores 234.

[0088] Optionally, the at least first model 206 may comprise a Machine learning model which may be trained by using an attention graph based Neural network algorithm 214a.

[0089] The at least second model 208 may comprise the above mentioned Machine learning model which may be trained by using an attention graph based Neural network algorithm 216a.

[0090] Optionally, the trained score prediction model 212 comprises the Machine Learning, ML, model trained by using the Graph attention based Neural Network model.

[0091] FIG. 3 is an example schematic diagram illustrating mapping between the plurality of network assets 202 and the plurality of security tags 204 as shown above in FIG. 2. The plurality of network 202 assets and / or the plurality of security tags 204 may have some or all of the features mentioned in relation to FIG. 2. The framework 200 is designed for aggregating security metrics data 218 from various perspectives, including the one or more network assets 202 and the one or more security tags 204, and thus framework 200 offers a comprehensive approach for evaluating an organization's overall security posture.

[0092] In an example, as shown in FIG. 3, the at least one network asset 202 is selected from a group comprising at least one of: networking assets 302 selected from a group comprising at least one of: gateways, switches radio stations, satellites, etc.; software assets 304 selected from a group comprising at least one of operating systems, open-source software, licensed software, third-party software including cloud native applications, etc.; virtualization assets 306 selected from a group comprising at least one of: management, orchestration, virtual machines, containers, etc, and devices 308 selected from a group comprising at least one of: servers, host, Laptop, loT devices, storage devices, etc, hardware, hosts, servers, gateways, and so on.

[0093] In an example, as shown in FIG. 3, the at least one security tag 204 assesses the security metrics data selected from a group comprising at least one of: security control 310, security properties 312, security standards 314, vulnerability weaknesses 316, cyber-attacks 318 and / or trustworthiness 320.

[0094] In an example, the framework 200 addresses a problem of assessing security of the one or more network assets 202 considering different characterizing verticals' deployments of the plurality of network assets 202 as well as the use of different security standards through the one or more security tags 204 for security assessment. The framework 200 not only takes into account an individual security metrics data 218 for each network asset 202 and the one or more security tags 204, but also the relationships between the security metrics data 218 by considering dependencies between: the plurality of network assets 202 to the plurality of security tags 204, the at least one network asset 202 to other network asset 202, the at least one security tag 204 to other security tag 204. The score module 222 calibrate diverse security scores of different network assets 202 from the plurality of network assets 202 based on pre- established and diverse security metrics data 218, and the security metrics data 218 provides insightful inputs for recommendation security systems, which may then be implemented in an organization for outlining priorities in addressing security issues.

[0095] In an example, FIG. 4a and FIG. 4b illustrates example schematic diagrams illustrating modelling of the at least one first model 206 which in turn provides modelling of the plurality security tags 204. The modelling of the plurality of security tags 204 is two-fold, and comprises mapping of each security tag 204 from the plurality if security tags 204 with the one or more network assets 202 and also mapping the at least one security tag 204 with other security tags 202 for identifying dependencies between the security tags 204, based on knowledge of a security expert or professional.

[0096] As shown in FIG. 4a, mapping of two security tags 204 (STI, NIST and STI CIS) with the plurality of network assets 202 is shown. First security tag 204 from the two security tags 204 comprises, security guidelines from NIST (STI) and second security tag 204 form the two security tags 204 comprise security guidelines from Center of Internet Security (CIS) (ST2). The guidelines NIST and CIS may be applied on the plurality of network assets 202 (Al, A2, . Ai,

[0097] An) selected from the group comprising at least one of: operating systems, legacy software, and loT devices, etc.

[0098] As shown in FIG. 4b, dependency of the at least one security tag 204 with the other security tags 204 is shown. Two security tags 204, comprising, security guidelines from NIST and the security guidelines from Center of Internet Security (CIS), are considered, and overlap in terms of security assessment, i.e., assigning the security score to the at least one network asset 202 may be observed between the two security tags 204. The overlap comprises the correlation data 216 which may be defined by a security expert as a binary relationship between the two security tags 204 or a weighted relationship based on a level of correlation (mapping of security assessment).

[0099] In an example, FIG. 5a shows the modelling of the at least second model 208 which in turn provides modelling of the one or more network assets 202. The modelling of the one or more network assets 202 is also two fold, encompassing both: mapping of the at least one network asset 202 with the at least one security tag 204 and computing dependency of at the at least network asset 202 with other network assets 202 from the plurality of network assets 204. The mapping comprises identifying a relationship on how the at least one network asset 204 is given the at least one security score 226 by the at least one security tag 204. Whereas the computation of dependency captures a dependency between different network assets 202 from the plurality of network assets 202 selected from the group comprising at least one of: network topologies, software / hardware relationship, etc.

[0100] In an example, FIG. 5a shows the mapping the plurality of network assets 204 (Al, A2.... An) with two security tags 204, STI (CIS) and STI (NIST). The mapping captures how a set of "n" network assets 202 obtained from the plurality of network assets 202 are assigned the security scores 226 as a set (or group) from the two different security tags 204 namely, NIST (STI) and CIS (ST2).

[0101] In an example, FIG. 5b shows dependency of at least one network assets 202 (for example, Al) over the other network assets 204 (A2, A2, , An). The dependency is computed in as the asset network graph data 228 to identify data about a connectivity of the at least one network asset 202 selected as at least one of: one hardware asset with another hardware asset, or if a software network asset may be deployed on a hardware asset. In another example, the asset network graph data may also be collected from cloud observability artifacts by considering deployment of management layer, orchestration layer and production layer (not shown in Figures).

[0102] FIG. 6 shows an example of a dependency graph 600 illustrating dependency of the at least one network asset 204 over the plurality of network assets 204.

[0103] FIG. 7 shows an example illustration 700 showing dependency between the at least one security tag 204 and the other security tags 204.

[0104] In an example, as shown in FIG. 6 and FIG. 7, 114 vulnerability reports were collected, where weaknesses were considered as one of the security metrics data 218 assigned by the at least security tag 204 and an IP address may be considered as the at least network asset 202. The plurality of security tags 204 considered comprises 73, whereas the plurality of network assets 202 considered comprises 817. A total number of entries comprises 59,005. The example assumes that each network asset 202 in the plurality of network assets 202 have full mesh dependencies over the other network assets 204 for building the dependency graph and each network asset 202 belong to a same / 24 subnet, where the dependencies between the security tags 204 may be randomly generated.

[0105] FIG. 8 is an exemplary flowchart illustrating example steps for a method 800 implemented in the framework 200 providing security predictions for the one or more network assets 202 from the plurality of network assets 202 in the cyber-security network 2000. The cybersecurity network 2000 comprises the one or more security tags 204 from the plurality of security tags 204 to be assigned to the one or more network assets 202 to assess security metrics of the one or more network assets 202.

[0106] The order in which the method 800 is described is not intended to be construed as a limitation, and any number of the described method blocks may be combined in any order to implement the method 800 or alternate methods. Additionally, individual blocks may be deleted from the method 800 without departing from the spirit and scope of the embodiments described herein. At step 802, the method 800 comprises assigning the security metrics data 218 to the at least one network asset 202 from the one or more network assets 202 through at least one security tag 204 from the one or more security tags 204. The assigning is performed through the assign module 214 in the at least first model 206.

[0107] At step 804, the method 800 comprises computing correlation data 220 to provide information about the relation between the at least one security tag 204 and other security tags 204 from the one or more security tags 204. The computing is performed through the correlation module 216 in the at least one first model 206.

[0108] At step 806, the method 800 determines the at least one security score 222 assigned to each network asset 202 in the set of network assets 202 obtained from the plurality of network assets 202 through each security tag 204 from a set of security tags 204. The security score 222 is determined through the score module 222 in at least one second model 212.

[0109] At step 808, the method 800 comprises computing the asset network graph data 216 to provide information about connectivity of the at least one network asset 202 with other network assets 202 from the one or more network assets 202. The computing is performed through the first computation module 224 in the at least one second model 208.

[0110] At step 810, the method 800 comprises computing the first latent factors 230 for the at least one first model 206 by using the at least security metrics data 218 and the correlation data 216 from the at least one first model 206. The computing is performed through the at least one second computation module 210a.

[0111] At step 812, the method 800 comprises computing the second latent factors 222 for the at least one second model 208 by using the asset security score 226 and the asset network graph data 228 from the at least one second model 208. The computing is performed through the at least one second computation module 210b.

[0112] At step 814, the method 800 predicts at least one security score 324 assigned by the at least one security tag 204 to the at least one network asset 202. The prediction is performed through the trained score prediction model 212 trained by using the first latent factors 230 and the second latent factors 232. In an example, FIG. 9 is a schematic block diagram 900 illustrating a security tags 204-network asset 202 graph and an aggregation of the one or more security tags 204. Since the security tag-network asset graph contains interactions between the at least one network asset 202 and the at least one security tag 204 and interaction with the one or more network assets 202 having the security score 226 assigned through the at least one security tag 204, the interactions and the security scores 226 in the security tag-network graph is captured to learn hf, tags latent factor 902 from the security tag- network asset graph. The one or more security tags 204 are aggregated is to provide security tag-space asset latent factor h , i.e. the second latent factor 902 by considering the one or more security tags 204 that the network asset ct] has been assessed by and the network assets 202 having the security scores 226 assigned through the different security tags 204. The aggregation of the security tags 204 may be represented in equations 1, 2, 3, 4, 5 and 6:

[0113] In an example, B(j) is a set of security tags 204 obtained from the plurality of security tags 204 that scored security on the network asset aj, fjtis a vector to denote a scoring interaction between the network asset aj and a security tag st. Aggretagsis the security tags aggregation function. <J is a non-linear activation function, W and b are the learning weight and bias of a neural network. The network asset 204 is a subject to a security evaluation done through the security tag 202 assigning the scoring score denoted as r.

[0114] The network assets 202 are assigned with the security score 226 through the one or more security tags 204, which contribute to model the first latent factors 230 (also referred as security tags space latent factors). As such, for each rating r, a rating embedding vector eris introduced which denotes scoring r as a dense vector. For a relation between the network asset aj and a security tag stwith a scoring r, the representation fjtis modelled by combining a security tag embedding ptand rating embedding erwith Multi-Layer Perceptron (MLP). The latter is meant to capture the dependency between the at least one security tag and the other security tags 204 (also referred as security tag interaction or dependencies) along with the security scores 226 assigned through the one or more security tags 204. As such, the MLP concatenates security tag embedding ptand scoring embedding eras input and its output is a scoring-aware representation between the network asset aj and the security tag (as shown in equation 2), where ® denotes concatenation between vectors.

[0115] The aggregation function Aggretagsillustrated in equation 1, may be replaced by the element-wise mean operator of vectors in { / )t, V s G B( / )} (as shown in equation 3). If it is assumed that all interactions contribute equally to capture assessments on an asset aj, py is assigned (factor with respect to the cardinality of security tags). This approach is not optimal since the dependencies between the network assets 202 may vary in a non-uniform way. Hence, the dependencies between the security tags 204 may contribute differently to the second latent factor 902 (referred as asset's latent factor) by learning the weight of each dependency. An attention mechanism through an attention network 904 is used to tweak p;to catch a target network asset aj assigning individualized weight for the security tags 204 (as shown in equation 4). p / tis the attention weight of the interaction with a security tag 204 from asset security tag-space latent factor 902 captured from the network asset aj with respect to security tags set B j). Specifically, the security tag attention p / tis parameterized with a two-layer network (attention network 904). The input is the score-aware interaction representation fjt. The attention network 904 is defined in equation 5. The final weight is obtained by normalizing attentive scores using Softmax function, which is the contribution of the security tag attention of the tag stto the asset aj.

[0116] In an example, FIG. 10 is a schematic block diagram 10000 illustrating dependencies between the at least one security tag 204 with the other security tags 204. The one or more security tags 204 are meant to provide a certain security assessment in terms of the security metrics 218 by considering at least one a security approach, property, cyber-attacks, cyber weaknesses, etc. in an example, security experts may define heuristically the dependencies between the one or more security tags 204 by assigning an existence of a dependency or not, or providing weights to represent the level of dependencies between the one or more security tags 204. The learning of dependency between the security tags 204 considers the level of dependency between the security tags 204. The security tag dependencies latent factor h_iAS 1002 is learned by considering a security tag and its security tags dependencies (i.e. the dependency with the other security tags 204. The aggregation is represented in equations 7, 8, 9, 10 and 11:

[0117] S(i) is a set of security tags 204 obtained from the plurality of security tags 204 associated with a security tag Aggretags neighbOrhood is a security tags neighborhood aggregation function. <J is a non-linear activation function (i.e., sigmoid or ReLU), 147 and b are the learning weight and bias of the neural network. To compute the security tag space latent factor 1002 of a security tag st, h is used to aggregate the asset network graph data 228 (also referred as asset space latent factors) of the security tags 204 having dependencies with si rnamely S(i) (as shown in equation 7). Like asset dependencies, in another embodiment, the element- wise mean of the vectors in {h , V I E S(T)} may be used (please refer to function 9), where Pi is assigned to — — (factor with respect to the cardinality of security tags depending on a 1^(01 security tag s . However, as mentioned before, this may not be optimal since finding of a certain level of dependencies between the security tags 204 to be learned (as shown in equation 9). Hence, in an example, an attention mechanism with two-layers neural network 1004 is used to capture the level of dependencies between the network assets 202 and model the dependency between the network assets 202 by learning the attention fin considering the asset-space security latent factor h and a target security tag embedding pt(equation 10 and 11). In an example, a final weight is obtained by normalizing attentive scores using Softmax function, which is the contribution of the security tags attention of the neighborhood of the security tag Sj.

[0118] FIG. 11 is a schematic block diagram 1100 illustrating an aggregation of the one or more network assets 202. Since a security tag-asset graph contains interactions between the security tags 204 and the network assets 202 as well as tags ratings on the network assets 202, interactions and ratings in the security tag-asset graph are captured to learn h_iAA, which is used to model security tag latent factor 1102 from the security tag-asset graph. The purpose of asset aggregation is to learn asset-space security tag latent factor h_iAA by considering assets that a security tag s_i has assessed and security tags ratings on these assets. The assets aggregation is represented in equations 12, 13, 14, 15, 16 and 17 as below: h = a(W . Aggreassets( xik, k G A(i)}) + h) (12)

[0119] A(i) is the set of assets, a security tag Sj with which a security rating is provided, xikis a vector to denote a scoring interaction between and an asset ak. Aggreassetsis the assets aggregation function. <J is a non-linear activation function (i.e., sigmoid or ReLU), 14 / and b are the learning weight and bias of the neural network. The security tag 204 is meant to assess the network asset 202 through a certain scoring denoted as r. The scorings capture a certain security posture on assets, which may contribute to model the assets space latent factors 1102. As such, for each rating r, we introduce a rating embedding vector erwhich denotes rating r as a dense vector. For a relation between a security tag and an asset akwith rating r, representation xikis modeled by combining asset embedding qkand rating embedding erwith Multi-Layer Perceptron, MLP. The modeling is meant to capture the assets interaction (dependencies) along with the scoring information i.e., the security score 226. As such, MLP concatenates asset embedding qkand scoring embedding eras input. Its output is the scoring-aware representation between and an asset (as shown in equation 2), where ® denotes concatenation between vectors.

[0120] In some embodiments, the aggregation function Aggreassetsillustrated in equation 12, may be replaced by the element-wise mean operator of vectors in xik, V a G l(i)} (as illustrated in equation 14). If it is assumed that all interactions contribute equally to capture security tag assessment st, c is assigned to (factor with respect to the cardinality of assets), this approach may not be optimal since the dependencies between security tags may vary in a non-uniform way. Hence, the dependencies may contribute differently to security tag's latent factor by learning the weight of each dependency. To do so, attention mechanisms through an attention network 1104 allow to tweak atto catch a target security tag stassigning individualized weight for assets (please refer to equation 15). aikis the attention weight of the interaction with an asset from security tag asset-space latent factor captured from stwith respect to assets set A(i). Specifically, the asset attention aikis parameterized with a two- layer network (attention network). The input is the score-aware interaction representation^. The attention network 1104 is defined in equation 5. The final weight is obtained by normalizing attentive scores using Softmax function, which is the contribution of the asset attention of the asset akto the security tag Sj.

[0121] FIG. 12 is a schematic block diagram 1200 illustrating dependencies between the network assets 202 according to some embodiments. Network assets 202 are meant to be part of an ecosystem, where security may needed to be rated (e.g., hosts, operating systems, etc.). Accordingly, dependencies between diverse assets (e.g., host connects to hosts, operating software installed on hosts) can be defined. As such, the network asset information may need to be incorporated to model assets latent factors (second latent factor). Assets dependencies latent factor h is learned by considering an asset cq and its assets dependencies. The aggregation is represented in equations 18, 19, 20, 21 and 22, as shown below:

[0122] T(j) is the set of assets associated with an asset aj. Ag greassetseighborhood is the assets neighborhood aggregation function. o’ is a non-linear activation function, W and b are the learning weight and bias of the neural network. To compute asset space latent factor 1202 of an asset aj, h is used to aggregate the security tag space latent factors of assets having dependencies with cq, namely T(f) (as shown in equation 21). The element-wise mean of the vectors in { / i , V I E T(j)} can be used (please refer to function 19), where 8j is assigned to

[0123] (factor with respect to the cardinality of assets depending on an asset a;). However, as mentioned before, this may not be optimal since finding a certain level of dependencies between the network assets 202 may need to be learned (as illustrated in equation 20). Hence, the attention mechanism 1204 through an attention network 1204 with two-layers neural network is used to capture the level of dependencies between the security tags 204 and model their ties by learning the attention 8jtconsidering the security tag-space asset factor h and the target asset embedding qj (equation 21 and 22). In an example, the final weight is obtained by normalizing attentive scores using Softmax function, which is the contribution of the assets' attention of the neighborhood of the asset cq.

[0124] FIG. 13 illustrates an example graph 1300 showing loss value convergence for the trained score prediction model 212. A loss function is used to quantify the difference between the ground truth scores and the security scores 234 predicted and generated by the the trained score prediction model 212 also referred as the Graph Attention based Neural Network model 212. From the loss function, derived gradients are used to update the weights of the correlation data 220. An average overall loss values constitutes the cost. The loss convergence towards an optimum may provide valuable insights into the effectiveness of the the trained score prediction model 212 in capturing the bidirectional relationships between the network assets 202, the security tags 204 and the ground truth scoring considering dependencies constraints. The graph network dependencies for both, the network assets 202 and security tags 204 are added as constraints to train on.

[0125] FIG. 14 illustrates an example graph 1400 showing trend of Mean Absolute Error (MAE) and Root Mean Square Error (RMSE) for evaluating the the trained score prediction model 212. To evaluate the the trained score prediction model 212, MAE and RMSE are metrics used to gauge the differences (deltas) between observed score values (e.g., CVSS) and estimated predicted score values 234. For each epoch, MAE and RMSE values are used to evaluate the gap between the observed score values and the predicted score values 234. If the gap between MAE and RMSE values is not too high, it means there is no presence of large samples generating errors in predictions values. For the set of epochs MAE and RMSE, the security expert may choose a certain round by considering the most optimal solution (0.18535, 0.46689) if the security expert wants to be conservative on predictions, or another solution if the security expert wants to be less conservative (more tolerance to prediction errors).

[0126] FIG. 15 shows an example graph 1500 illustrating a scatter of different data points representing the network asset 202 and the security tag 204 tuples. It is observed from the scatter that a big number of data points located in the delta range [-1,1], where predictions (the predicted security scores 234) are not too far from ground truth scores. In an example, asset / tag tuples (107,41), (406,41), (783,41) predictions are not two far from ground truth. In addition, in all the tuples, a common security tag 204 is present. So, for a security analyst, such security tag 204 may be considered risky since the CVSS scores associated with assets 107, 406, 783 are not drastically corrected through predictions. One of the choices for the security expert is to have a ranking report based on predictions. The report generated through the framework 200 may be used therefore to take security actions accordingly. Another interesting group of data points to consider, is the one having high scores and low predictions (e.g., asset / tag tuple (489,43)). In such case, the security expert may compare predictions in terms of the security scores 234 generated through the framework 200 by considering the security tag 204 or the network asset 202 and neighbourhood (surrounding security tags 202 or the network assets 202).

[0127] FIG. 16 shows an example graph illustrating use case of an example network asset 489, shown as 1600 in FIG. 16. By considering the network asset 489, it has 70 neighbours and is associated with 5 security tags 204. As shown in table 1604, the average of all CVSS scores on the asset 489 is higher than the predictions. Tag 43 is the security tag "NVD-CWE-Other", which is associated with miscellaneous vulnerabilities, which indicates variations in the ground truth scores (10 for asset 489 and 5.90 by averaging all vulnerabilities labelled with this security tag). For the security expert, it is better to consider aggregates on the asset and its neighbourhood. The score and the prediction for the latter are almost the same and lower than the average of scores and predictions on the asset. Despite the fact, there is a risk on the neighbourhood, the prediction is lower (drop correction by comparing average scores and average predictions). As such, the security expert may assign less priority to act on since the neighbourhood is less risky. In another use case, the group of data points that have high score and high predictions with a low correction (delta) (e.g., asset / tag tuple (406,41)). In such use case, the average for both the ground truth scores and the predictions are maintained with respect to the asset itself, to the security tag 204 and the neighbours and in such case, the security expert may prioritize to act on the vulnerabilities associated with security tag 41 (NVD-CWE-noinfo) since the averaging of scores and predictions are high and maintained to the same level in comparison with asset averaging and neighbourhood, average score per network asset 204 is depicted in FIG. 17.

[0128] FIG. 18 shows an example graph 1800 illustrating use case of another network asset 107. Fundamentally, from the use cases as described above, the security expert may generate ranking on the security scores 234, predictions, averaging with respect to the security tags 204 or the network assets 202 or neighbourhood. Each of the raking may be used as an input to take security actions accordingly. In an example, the security actions may include and not limited to priorities on assets, priorities on security tags, priorities on neighbourhood and so on.

[0129] In an example, FIG. 19 shows scatter of data points 1900 considering average scores per network asset 202 in the trained score prediction model 212.

[0130] In an example, FIG. 20 shows another scatter of data points 20000 considering average scores per security tag 204 the trained score prediction model 212. With these scattered data points 1900, and the data points 20000, this may be observed that corrections (deltas) may group different averages scores into clusters. For the sake of illustration, in FIG. 19, the data points 1900 in group 1 may be at the same level of group 2 as the predictions are considered based on the assessment of the security for the plurality of security tags 204 aggregates as well as network assets' 202 neighbourhood. The use of ranking or clustering on the network assets 202 or the security tags 204 aggregates can help to define groups of priorities to act on.

[0131] In an example, FIG. 21 shows graphs 2100, 2102 illustrating a first experiment (PoDs use case 2102) and graphs 2104, 2106 illustrating a second experiment (packages use case 2106) on 122 assets (containers) and 1693 assets (packages) respectively. In the first experiment, there are 122 assets (containers) and namespaces are considered as dependencies as shown in 2100 and 2102. The applications are deployed on 8 namespaces orchestrated through Kubernetes and there are 5 security tags (full mesh dependencies). In the example as shown in FIG. 21, the 5 security tags are: severity, criticality, threat count, CVE count, VAP count. It is observed that each instantiation depends on another instantiation if they are deployed in the same namespace. In the second experiment, there are 1693 assets (packages) and namespaces are considered as dependencies as shown in 2104 and 2106. The applications are deployed on 8 namespaces orchestrated 2108 through Kubernetes using 122 PoD Types and there are 6 security tags (full mesh dependencies). It is observed that each package depends on another package if they are deployed in containers within same namespace and PoD type.

[0132] In an example, FIG. 22 shows another example graph illustrating a first experiment, shown in 2200 and 2202 and a second experiment, shown in 2204 and 2206 on the network assets 202. In the first experiment (packages use case), there are 1693 assets and namespaces are considered as dependencies. The applications are deployed on 9 namespaces orchestrated 2204 through Kubernetes and there are 6 security tags (full mesh dependencies). In the example as shown in FIG. 22, the 6 security tags are: severity, criticality, threat count, CVE count, VAP count and Patch existence. In the second experiment, there are 1693 assets (packages) and PoD Types are considered as dependencies. The applications are deployed on 9 namespaces orchestrated 2208 through Kubernetes using 1693 PoD Types and there are 6 security tags (full mesh dependencies). Hence, the latent factors reflect the customer needs and the underlying security experts design.

[0133] In an example, FIG. 23a and FIG. 23b shows example graph illustrating Mean Absolute Error (MAE) 2300 and example graph illustrating Root Mean Square Error (RMSE) 2302, respectively. In FIG. 23a, packages are considered, and PoD types are as dependencies. In FIG. 23b, packages are considered, and Namespaces are considered as dependencies. For the set of epochs MAE and RMSE, the security expert may choose a certain round by considering the most optimal solution if the security expert wants to be conservative on predictions, or another solution if the security expert may want to be less conservative (more tolerance to prediction errors).

[0134] FIG 24 shows an example experimental graph 2402 considering 122 assets as containers. Table 2400 shows description and occurrences and predicted unique values (security score 234) along with ground truth data. FIG. 25 shows an example graph 2502 considering 1693 assets as Packages (namespaces). Table 2500 shows description and occurrences and predicted unique values (security score 234) along with ground truth data.

[0135] FIG. 26 shows example table 2600 illustrating ranking value of the network asset 204 predicted through the trained score prediction model 212 through the framework 1000. Table 2600 shows description and occurrences and predicted unique values, security scores 234 along with ground truth data.

[0136] FIG. 27 shows example table 2700 and 2702 illustrating average prediction security score through the security tags 204 predicted through the trained score prediction model 212 of the framework 200.

[0137] FIG. 28A and FIG. 28B shows example table 2800, 2802 illustrating dependencies of the network asset 202 use case and showing predictions and scores 234 by considering packages as Namespace and PoD types. The predictions are done through the trained score prediction model 212 of the framework 200.

[0138] FIG. 29 shows example graph 2900, 2902, and 2903 illustrating security score predictions 234, as 57.56%, 60.33% and 61.67% respectively, for the network assets 202 assigned through the different security tags 202.

[0139] FIG. 30 shows example schematic block diagram 3000 showing decision support based on the trained score prediction model 212. The prediction scores, the security score 234, are meant to capture security posture considering dependencies from different perspectives such as asset, security tag, asset to security tag or asset to security tag dependencies. An affinity graph neural network aggregates predictions based on diverse mappings and dependencies. As such, a security expert may use rankings in diverse indexes such as asset / tag ranking 3012, asset ranking 2014 security tag ranking 3016 and / or averaging in asset dependencies and / or security tags dependencies 3018. As shown in FIG. 30, the interaction between the framework 200 and the security operating center, where security experts may take the security actions accordingly or design the security orchestrator to trigger the security actions. In an example, different decision strategies are now described. The different decisions may include and not limited to predictions ranking (alternatively may refer as ranking), averaging predictions per asset, averaging predictions per security tag. In predictions ranking, the security expert may establish a ranking mechanism by sorting highest prediction down to the lowest one. The highest predictions may be considered as the most critical to tackle from security standpoint. The ranking is indexed per tuple (asset / tag) in the decision inputs as illustrated in FIG. 30. The security fixes may be applied with security support or a security orchestration mechanism if security playbooks are associated with the security tag on a certain asset.

[0140] In an example, in an averaging predictions per network asset strategy, the security expert may average predictions by indexing them on different assets. This approach is meant to act based on assets' focus, where the importance is more attributed to assets rather than security tags. The ranking is indexed per asset in the decision inputs illustrated in FIG. 30. The security fixes can be applied with security support or a security orchestration mechanism considering a set of security playbooks on each asset.

[0141] In the averaging predictions per security tag strategy, the security expert may average predictions by indexing them on the different security tags. This approach is meant to act based on tags' focus, where the importance is more attributed to security tags rather than assets. The ranking is indexed per security tag in the decision inputs 3010 illustrated in FIG. 30. The security fixes may be applied with security support or the security orchestration mechanism considering a security playbook on a set of assets.

[0142] In an example, FIG. 31 shows a security posture assessment functional diagram 3100. The security posture is firmly related to customers' needs 3102. As such, there is a keen interest to provide the security posture assessment as a service, which is provided through the proposed framework 200. Therefore, the service in question may need to be holistic considering the different security perspectives (expressed as security tags) and diverse assets present on customer's premises. The customers' needs may be designed as a configuration file enumerating different security tag (e.g., security standards, best security practices, security weaknesses, security properties, etc.) and the assets of interest such as devices, software and so on. In addition, dependencies between the assets as well as the security tags may be expressed through the customer needs. Once the customer needs are expressed, at step 1, the needs are interpreted and collection of data (i.e. through the at least first model 206 and the at least second model 208) is triggered at step 2. The collectors 3106 push data step 3, to a data normalizer 3108 to map different assets, security tags, dependencies as well as corresponding security metrics (e.g., security impact, risk, trust levels, etc.). The data normalizer 3108 links diverse assets and security tags and build assets dependencies and security tags dependencies. The normalized data is represented as mappings, which are pushed to an intelligent agent 3110 modeled through the graph attention neural network technique, at step 4.

[0143] At step 5, a reporter 3112 generate predictions by using the framework 200. At step 6, prediction reports (reports on security score assigned to the one or more network assets 202 through the one or more security tags 204 and corresponding rank of each security score) is then saved into a database layer 3114. At step 7, the report may be again pulled by the orchestrator 3104 and at step 8, actions 3116 may be produced by the orchestrator.

[0144] In an example, the report may be pushed as a timestamped ranking report into the database layer 3114 and the ranking report may be used by the orchestrator 3104 to trigger security actions accordingly.

[0145] FIG. 32 illustrates an example-computing environment 3200 implementing a framework 200 and the method 800 as shown in FIGS. 2, and 8 for providing security predictions for the one or more network assets 202 from the plurality of network assets in the cyber-security network 2000. As depicted in FIG. 32, the computing environment 3200 comprises at least one data processing module 3206 that is equipped with a control module 3202 and an Arithmetic Logic Unit (ALU) 3204, a plurality of networking devices 3208 and a plurality Input output, I / O devices 3210, a memory 3212, a storage 3214. The data processing module 3206 may be responsible for implementing the platform and method described in FIGS. 2 and 8 respectively. For example, the data processing module 3206 in some embodiments be equivalent to the controlling circuitry of the platform described above in conjunction with FIGS. 2 and 8. The data processing module 3206 is capable of executing software instructions stored in memory 3212. The data processing module 3206 receives commands from the control module 3202 in order to perform its processing. Further, any logical and arithmetic operations involved in the execution of the instructions are computed with the help of the

[0146] ALU 3204. The computer program is loadable into the data processing module 3206, which may, for example, be comprised in an electronic apparatus (such as the platform). When loaded into the data processing module 3206, the computer program may be stored in the memory 3212 associated with or comprised in the data processing module 3206. According to some embodiments, the computer program may, when loaded into and run by the data processing module 3206, cause execution of method steps according to, for example, any of the methods illustrated in FIGS. 2 and 8, or otherwise described herein.

[0147] The overall computing environment 3200 may be composed of multiple homogeneous and / or heterogeneous cores, multiple CPUs of different kinds, special media and other accelerators. Further, the plurality of data processing modules 1206 may be located on a single chip or over multiple chips.

[0148] The algorithm comprising of instructions and codes required for the implementation are stored in either the memory 3212 or the storage 3214 or both. At the time of execution, the instructions may be fetched from the corresponding memory 3212 and / or storage 3214, and executed by the data processing module 3206.

[0149] In case of any hardware implementations various networking devices 3208 or external I / O devices 3210 may be connected to the computing environment to support the implementation through the networking devices 3208 and the I / O devices 3210.

[0150] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the elements. The elements shown in FIG. 3200 include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0151] Definitions:

[0152] In some examples as shown in the description, let A = {a1, a2, ... , an} and §={si,s2, be sets of the plurality of network assets and the plurality of security tags respectively, where n is the number of the network assets assets and m is the number of security tags. R G IRnxmis the network assets-security tags rating matrix, also may refer as asset-security tags graph. Let A(i) be the set of network assets assessed by a security tag Sj, S(i) is the set of dependent security tags associated with security tag T(j) is the set of dependent assets associated with network asset aj, B j) is the set of security tags which assessed asset aj. Accordingly, S is the security tags dependency graph, T is the network asset dependency graph. Given the network assets-security tags graph R, security tags dependency graph S, and network asset dependency graph T, we aim to infer new rating prediction considering the impact of dependency graphs on initial rating R. The essence of this approach is to introduce a new rating prediction R', which uses neural networks to consider dependency between the security tags as well as the network assets. A rating of a network asset may be impacted by its neighborhood, same wise, the security tags may subjectively assess the network assets if they are considered independent. By creating a level of dependency between the network assets and the security tags, neural networks may be used to capture the level of dependency to assess diverse network assets. The mathematical notations are listed in Table 1 as shown below.

Claims

CLAIMS1. A framework (200) providing security predictions for one or more network assets (202) from a plurality of network assets (202) in a cyber-security network (2000), wherein the cyber-security network (2000) comprises one or more security tags (204) from a plurality of security tags (204) to be assigned to the one or more network assets (202) to assess security metrics of the one or more network assets (202), wherein the framework (200) comprising: at least one first model (206), comprising: an assign module (214) arranged for assigning security metrics data (218) to at least one network asset (202) from the one or more network assets (202) through at least one security tag (204) from the one or more security tags (204); and a correlation module (216) arranged for computing correlation data (220) to provide information about a relation between the at least one security tag (204) and other security tags (204) from the one or more security tags (204); at least one second model (208), comprising: a score module (222) arranged for determining at least one security score (226) assigned to each network asset (202) in a set of network assets (202) obtained from the plurality of network assets (202), through each security tag (204) from a set of security tags (204) obtained from the plurality of security tags (204); and a first computation module (224) arranged for computing asset network graph data (228) to provide information about connectivity of the at least network asset (202) with other network assets (202) from the one or more network assets (202); at least one second computation module (210a, 210b) arranged for: computing, first latent factors (230) for the at least one first model (206) by using the at least security metrics data (218) and the correlation data from the first model (220); andcomputing, second latent factors (232) for the at least one second model (208) by using the asset security score data (226) and the asset network graph data (228) from the second model (208); a trained score prediction model (212) trained by using the first latent factors (230) and the second latent factors (232), and arranged for: predicting at least one security score (234) assigned by the at least one security tag (204) to the at least one network asset (202).

2. The framework (200) according claim 1, wherein the at least one security metrics data provides a ground truth score assigned by the at least one security tag (204) to the at least one network asset (202).

3. The framework (200) according to any of the preceding claims, wherein the correlation data comprises weights representing a dependency between the at least one security tag (204) and the other security tags (204).

4. The framework (200) according to any of the preceding claims, wherein the at least one first latent factor comprises an aggregate of the security metrics data and the correlation data.

5. The framework (200) according to any of the preceding claims, wherein the second latent factors comprises an aggregate of the asset security score data and the asset network graph data.

6. The framework (200) according to any of the preceding claims, wherein the trained score prediction model (212) is arranged for: predicting a plurality of security scores for a plurality of network assets (202) assigned by a plurality of security tags (204); and generate, a corresponding rating for each security score in the plurality of security scores.

7. The framework (200) according to claim 1, wherein the one or more network assets (202) are selected from a group comprising at least one of: software network assets, hardware network assets, Internet of Things, loT devices, virtual native applications, and virtual appliances.

8. The framework (200) according to any of the preceding claims, wherein the at least one security metrics data is selected from a group comprising at least one of: trustworthiness data about the at least one network asset, security properties of the at least one network asset (202), security controls associated with the at least one network asset (202), security standards associated with the at least one network asset (202), weaknesses associated with the at least one network asset (202), and cyberattacks over the at least one network asset (202).

9. The framework (200) according to any of the preceding claims, wherein both the at least one first latent factor and the at least one second latent factor are computed by using a Machine Learning, ML, model; and10. The framework (200) according to claim 9, wherein the ML model comprises a Graph attention based Neural Network model, GANN and wherein an aggregation within the GANN is performed with at least one of averaging, convolution, max pooling, mean pooling and Long short-term memory, LSTM shuffles of neighbor.

11. A computer implemented method (800) implemented in a framework (200) providing security predictions for one or more network assets (202) from a plurality of network assets (202) in a cyber-security network (2000), wherein the cyber-security network (2000) comprises one or more security tags (204) from a plurality of security tags (204) to be assigned to the one or more network assets (202) to assess security metrics of the one or more network assets (202), wherein the method (800) comprising: assigning, through an assign module (214) in at least one first model (206), security metrics data (218) to at least one network asset (202) from the one or more network assets (202) through at least one security tag (204) from the one or more security tags (204); computing, through a correlation module (216) in the at least one first model (206), correlation data (220) to provide information about a relation between the at least one security tag (204) and other security tags (204) from the one or more security tags (204); determining, through a score module (222) in at least one second model (208), at least one security score (226) assigned to each network asset (202) in a set of network assets (202) obtained from the plurality of network assets (202)through each security tag (204) from a set of security tags (204);computing, through a first computation module (224) in the at least second model (208), asset network graph data (228) to provide information about connectivity of the at least one network asset (202) with other network assets (202) from the one or more network assets (202); computing, through at least one second computation module (110a, 110b), first latent factors (230) for the at least one first model (206) by using the at least security metrics data (218) and the correlation data (220) from the first model (206); computing, through the at least one second computation module (110a, 110b), second latent factors (232) for the at least one second model (208) by using the asset security score data (226) and the asset network graph data (228) from the second model (208); and predicting, through a trained score prediction model (212) trained by using the first latent factors (230) and the second latent factors (232), at least one security score (234) assigned by the at least one security tag (204) to the at least one network asset (202).

12. The method according to claim 11, wherein the at least one security metrics data provides a ground truth score assigned by the at least one security tag (204) to the at least one network asset (202).

13. The method according to any of the claims 11-12, wherein the correlation data comprises weights representing a dependency between the at least one security tag (204) and the other security tags (204).

14. The method according to any of the claims 11-13, wherein the at least one first latent factor (230) comprises an aggregate of the at least one security metrics data and the correlation data.

15. The method according to any of the claims 11-14, wherein the second latent factors (232) comprises an aggregate of the asset security score data and the asset network graph data.

16. The method according to any of the claims 11-15, comprising: predicting a plurality of security scores for a plurality of network assets (202) assigned by a plurality of security tags (204); and generate, a corresponding rating for each security score in the plurality of security scores.

17. The method according to any of the claims 11-16, wherein the one or more network assets (202) are selected from a group comprising at least one of software network assets, hardware network assets, Internet of Things, loT devices, virtual native applications, and virtual appliances.

18. The method according to any of the claims 11-17, wherein the at least one security metrics data is selected from a group comprising at least one of: trustworthiness data about the at least one network asset, security properties of the at least one network asset, security controls associated with the at least one network asset, security standards associated with the at least one network asset (202), weaknesses associated with the at least one network asset (202), and cyber-attacks over the at least one network asset (202).

19. The method according to any of the claims 11-18, wherein both the at least one first latent factor (230) and the at least one second latent factor (232) are computed by using a Machine Learning, ML, model;20. The method according to claims 19, wherein the ML model comprises a Graph attention based Neural Network model, GANN and wherein an aggregation within the GANN is performed with at least one of averaging, convolution, max pooling, mean pooling and Long short-term memory, LSTM shuffles of neighbor.

Citation Information

Patent Citations

  • Cyber threat monitor and control apparatuses, methods and systems

    EP3029596B1

  • Cybersecurity threat modeling and analysis

    US20220038489A1

  • Cyber security restoration engine

    US20230403294A1

  • Identification, prediction, and assessment of cyber security risk

    WO2020142245A1