US2016110819A1PendingUtilityA1

Dynamic security rating for cyber insurance products

Assignee: ABRAMOWITZ MARC LAURENPriority: Oct 21, 2014Filed: Oct 20, 2015Published: Apr 21, 2016
Est. expiryOct 21, 2034(~8.2 yrs left)· nominal 20-yr term from priority
H04L 63/1433H04L 63/1466G06Q 40/08H04L 63/1416H04L 63/20H04L 63/1441H04L 63/1425
25
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one or more embodiments, the technology determines one or more cyber insurance policies and/or products based on a company's real-time exposure to a cyber attack on one or more of its computing asset's. The technology performs various security analysis techniques to explore, locate, and evaluate a company's network/assets for creating risk and damage assessments that are used for dynamically determining a cyber insurance that is tailored to that company at that moment of time and, optionally, based on future projections. The technology can continuously or semi-continuously monitor the company's network for any changes and, upon detection of changes that could affect the company's exposure to a cyber attack, provides information associated with the detected changes as feedback to allow determination of new/modified cyber insurance policies/products.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer program product, embodied on one or more non-transitory computer media, comprising:
 program code for receiving real-time data from a computer network at a processor that is implemented at least in-part by electronic circuitry, the real-time data indicative of cyber attacks that are likely to diminish a value of the product or service;   program code for processing by the processor the real-time data to compute real-time damage assessment associated with losses to the product or service due to occurrence of one or more cyber-attacks, the damage assessment computed using at least a likelihood of occurrence of the one or more cyber attacks, a likelihood of success of the one or more cyber attacks, and a measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks; and   program code for determining by the processor an insurability rating for the product or service that is usable for determination of an amount of insurance that sufficiently insures against the occurrence of the one or more cyber attacks, wherein the insurability rating is determined at least in-part based on the real-time damage assessment and is changeable in response to changes in the received real-time data.   
     
     
         2 . The computer program product of  claim 1 , further comprising program code for producing an insurance premium value for the product or service using the insurability rating. 
     
     
         3 . The computer program product of  claim 1 , wherein the real-time damage assessment is computed on an on-going basis based on changes in the real-time data with a time granularity of 1 micro second or less. 
     
     
         4 . The computer program product of  claim 1 , wherein the insurability rating is produced at least in-part by:
 processing the real-time damage assessment over a pre-determined time interval and determining a statistical value associated with a plurality of insurability rating values over the pre-determined time interval.   
     
     
         5 . The computer program product of  claim 4 , wherein the statistical value is an average of the plurality of insurability rating values over the pre-determined time interval. 
     
     
         6 . The computer program product of  claim 4 , wherein the statistical value is a weighted average of the plurality of insurability rating values over the pre-determined time interval, and wherein an insurability rating value that corresponds to a later time instance within the predetermined time interval is assigned a larger weight compared to an insurability rating value that corresponds to an earlier time instance within the predetermined time interval. 
     
     
         7 . The computer program product of  claim 4 , wherein the pre-determined time interval is one of: one hour, one day, one week or one month. 
     
     
         8 . The computer program product of  claim 1 , further comprising program code for determining at least one additional insurability rating based on the real-time data, wherein one of the insurability rating or the additional insurability rating corresponds to a short-term insurability rating, and the other of the insurability rating or the additional insurability rating corresponds to a long-term insurability rating. 
     
     
         9 . The computer program product of  claim 8 , wherein the short-term insurability rating corresponds to a time period ranging from one hour to one day, and wherein the long-term insurability rating corresponds to a time period that is greater than one day and up to one month. 
     
     
         10 . The computer program product of  claim 1 , wherein the real-time damage assessment is computed using a weighted average technique that assigns a first weight to the likelihood of occurrence of the one or more cyber attacks, a second weight to the likelihood of success of the one or more cyber attacks, and a third weight to the measure of severity of damage to the product of service. 
     
     
         11 . The computer program product of  claim 1 , wherein each of the likelihood of occurrence of the one or more cyber attacks, the likelihood of success of the one or more cyber attacks, and the measure of severity of damage to the product of service is determined using historical information associated with previously launched cyber attacks against the product or the service. 
     
     
         12 . The computer program product of  claim 11 , wherein the historical information includes one or more of: a number of previous cyber attacks against the product or service, a rate of success of previous cyber attacks against the product or service, an amount of damage to the service or product caused by a previous cyber attack, or a frequency of occurrence of cyber attacks against other entities that offer products or services that are similar to the product and service. 
     
     
         13 . The computer program product of  claim 1 , wherein the likelihood of occurrence of the one or more cyber attacks is produced by analyzing data associated with patterns of cyber activity over a plurality of data networks in real-time. 
     
     
         14 . The computer program product of  claim 13 , wherein the patterns of cyber activity include indications of cyber attacks on organizations with network connectivity. 
     
     
         15 . The computer program product of  claim 1 , wherein the insurability rating is determined using an inverse proportionality relationship with respect to the real-time damage assessment. 
     
     
         16 . The computer program product of  claim 1 , wherein the insurability rating is determined based in-part on existing cybersecurity countermeasures that are deployed to protect computers, networks or storage units that participate in storage, production or distribution of the product or service. 
     
     
         17 . The computer program product of  claim 16 , wherein the insurability rating is modified based on changes in the cybersecurity countermeasures deployed to protect computers, networks or storage units that participate in storage, production or distribution of the product or service. 
     
     
         18 . The computer program product of  claim 1 , further comprising program code using the computer network for providing one or more of the following to an entity for obtaining or maintaining insurance coverage for the product or service:
 information regarding the real-time damage,   information regarding the likelihood of occurrence of the one or more cyber attacks,   information regarding the likelihood of success of the one or more cyber attacks,   information regarding the measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks,   a recommendation for obtaining additional cybersecurity countermeasures, or   a particular cybersecurity countermeasure.   
     
     
         19 . A method for producing insurability ratings for a product or service, the method comprising:
 receiving, at a processor that is implemented at least in-part by electronic circuitry and coupled to a computer network, real-time data indicative of cyber attacks that are likely to diminish a value of the product or service;   using the processor to process the real-time data to compute a real-time damage assessment associated with losses to the product or service due to occurrence of one or more cyber-attacks, the damage assessment computed using at least a likelihood of the occurrence of the one or more cyber attacks, a likelihood of success of the one or more cyber attacks, and a measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks; and   using the processor to determine an insurability rating for the product or service that is usable for determination of an amount of insurance that sufficiently insures against the occurrence of the one or more cyber attacks, wherein the insurability rating is determined at least in-part based on the real-time damage assessment and is changeable in response to changes in the received real-time data.   
     
     
         20 . The method of  claim 19 , further comprising using the insurability rating to produce an insurance premium value for the product or service. 
     
     
         21 . The method of  claim 19 , wherein the real-time damage assessment is computed on an on-going basis based on changes in the real-time data with a time granularity of 1 micro second or less. 
     
     
         22 . The method of  claim 19 , wherein the insurability rating is produced at least in-part by:
 processing the real-time damage assessment over a pre-determined time interval and determining a statistical value associated with a plurality of insurability rating values over the pre-determined time interval.   
     
     
         23 . The method of  claim 22 , wherein the statistical value is an average of the plurality of insurability rating values over the pre-determined time interval. 
     
     
         24 . The method of  claim 22 , wherein the statistical value is a weighted average of the plurality of insurability rating values over the pre-determined time interval, and wherein insurability rating values that correspond to later time instances within the predetermined time interval are assigned a larger weight compared to insurability rating values that correspond to earlier time instances within the predetermined time interval. 
     
     
         25 . The method of  claim 22 , wherein the pre-determined time interval is one of: one hour, one day, one week or one month. 
     
     
         26 . The method of  claim 19 , further comprising determining at least one additional insurability rating based on the real-time data, wherein one of the insurability rating or the additional insurability rating corresponds to a short-term insurability rating, and the other of the insurability rating or the additional insurability rating corresponds to a long-term insurability rating. 
     
     
         27 . The method of  claim 26 , wherein the short-term insurability rating corresponds to a time period ranging from one hour to one day, and wherein the long-term insurability rating corresponds to a time period that is greater than one day and up to one month. 
     
     
         28 . The method of  claim 19 , wherein the real-time damage assessment is computed using a weighted average technique that assigns a first weight to the likelihood of occurrence of the one or more cyber attacks, a second weight to the likelihood of success of the one or more cyber attacks, and a third weight to the measure of severity of damage to the product of service. 
     
     
         29 . The method of  claim 19 , wherein each of the likelihood of occurrence of the one or more cyber attacks, the likelihood of success of the one or more cyber attacks, and the measure of severity of damage to the product of service is determined using historical information associated with previously launched cyber attacks against the product or the service. 
     
     
         30 . The method of  claim 29 , wherein the historical information includes one or more of: a number of previous cyber attacks against the product or service, a rate of success of previous cyber attacks against the product or service, an amount of damage to the service or product caused by a previous cyber attack, or a frequency of occurrence of cyber attacks against other entities that offer products or services that are similar to the product and service. 
     
     
         31 . The method of  claim 19 , wherein the likelihood of occurrence of the one or more cyber attacks is produced by analyzing data associated with patterns of cyber activity over a plurality of data networks in real-time. 
     
     
         32 . The method of  claim 31 , wherein the patterns of cyber activity are indicative of cyber attacks on other organizations with network connectivity. 
     
     
         33 . The method of  claim 19 , wherein the insurability rating is determined using an inverse proportionality relationship with respect to the real-time damage assessment. 
     
     
         34 . The method of  claim 19 , wherein the insurability rating is determined based in-part on existing cybersecurity countermeasures that are deployed to protect computers, networks or storage units that participate in storage, production or distribution of the product or service. 
     
     
         35 . The method of  claim 34 , wherein the insurability rating is modified based on changes in the cybersecurity countermeasures deployed to protect computers, networks or storage units that participate in storage, production or distribution of the product or service. 
     
     
         36 . The method of  claim 19 , further comprising providing one or more of the following to an entity that is interested in obtaining or maintaining insurance coverage for the product or service:
 information regarding the real-time damage,   information regarding the likelihood of occurrence of the one or more cyber attacks,   information regarding the likelihood of success of the one or more cyber attacks,   information regarding the measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks,   a recommendation for obtaining additional cybersecurity countermeasures, or   a particular cybersecurity countermeasure.   
     
     
         37 . A device, comprising:
 a processor implemented using electronic circuitry; and   a memory comprising processor executable code, the processor executable code, when executed by the processor, causes the device or the components of the device to:   receive real-time data indicative of cyber attacks that are likely to diminish a value of the product or service;   process the real-time data to compute a real-time damage assessment associated with losses to the product or service due to occurrence of one or more cyber-attacks, the damage assessment computed using at least a likelihood of occurrence of one or more cyber attacks, a likelihood of success of the one or more cyber attacks, and a measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks; and   determine an insurability rating for the product or service that is usable for determination of an amount of insurance that sufficiently insures against the occurrence of the one or more cyber attacks, wherein the insurability rating is determined at least in-part based on the real-time damage assessment and is changeable in response to changes in the received real-time data.   
     
     
         38 . A device for generating insurability ratings for a product or service, comprising:
 a first input port coupled to a network communication channel to receive real-time data indicative of cyber attacks that are likely to diminish a value of the product or service;   a damage assessment computation component that is implemented at least in-part using electronic circuits, the damage assessment computation component coupled to the first input port to receive the real-time data and compute a real-time damage assessment measure associated with losses to the product or service due to occurrence of one or more cyber-attacks, the damage assessment computed using at least a likelihood of occurrence of the one or more cyber attacks, a likelihood of success of the one or more cyber attacks, and a measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attack; and   an insurability rating computation component that is implemented at least in-part using electronic circuits and coupled to the damage assessment computation component, the insurability rating computation component to receive the real-time damage indictor computed by the damage assessment computation component and to determine an insurability rating for the product or service that is usable for determination of an amount of insurance that sufficiently insures against the occurrence of the one or more cyber attacks, wherein the insurability rating is determined at least in-part based on the real-time damage assessment and is changeable in response to changes in the received real-time data.   
     
     
         39 . A system for determining insurability rating of a service or product, comprising:
 a server device coupled to a computer network to receive real-time data indicative of cyber attacks that are likely to diminish a value of the product or service and to produce an insurance premium estimate based at least in-part on the received real-time data;   a client device coupled the computer network to receive the insurance premium estimate produced by the server device, wherein:
 the server device uses the real-time data to compute a real-time damage assessment associated with losses to the product or service due to occurrence of one or more cyber-attacks, the damage assessment computed using at least a likelihood of occurrence of the one or more cyber attacks, a likelihood of success of the one or more cyber attacks, and a measure of severity of damage to the product of service as a result of the occurrence of the one or more cyber attacks, and 
 the sever device determines an insurability rating for the product or service that is usable for determination of an amount of insurance that sufficiently insures against the occurrence of the one or more cyber attacks, the insurability rating determined at least in-part based on the real-time damage assessment and is changeable in response to changes in the received real-time data.

Join the waitlist — get patent alerts

Track US2016110819A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.