US2020396246A1PendingUtilityA1

System and method for empirical organizational cybersecurity risk assessment using externally-visible data

Assignee: FAIR ISAAC CORPPriority: Mar 20, 2017Filed: Aug 31, 2020Published: Dec 17, 2020
Est. expiryMar 20, 2037(~10.7 yrs left)· nominal 20-yr term from priority
G06Q 10/0635H04L 63/1433
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for assessing the cybersecurity breach risk associated with a given organization is disclosed. The system and method assume no internal visibility into any organizational network. A taxonomy of possible data sources is defined and motivated. The system and method are both purely empirical and robust against common difficulties in scoring organizational networks, such as the raw number of network assets owned by the organization.

Claims

exact text as granted — not AI-modified
1 .- 19 . (canceled) 
     
     
         20 . A system comprising:
 at least one programmable processor; and   a machine-readable medium storing instructions that, when executed by the at least one programmable processor, cause the at least one programmable processor to perform operations comprising:
 generating a set of features based on a plurality of datasets, the set of features indicative of cybersecurity data breach risks of a computer network associated with an organization, the plurality of datasets corresponding to a plurality of network prefixes of the computer network associated with the organization, the plurality of datasets comprising an IP address mapped to the network prefixes and comprising data representative of responses by the network prefixes to various requests at the IP address; 
 calibrating, in response to generating the set of features, the set of features with a quantile estimate from a database, the quantile estimate being calibrated by comparing cybersecurity breach risks across various organizations; and 
 scoring, based on the calibrated set of features, the plurality of datasets as an overall score, the scoring processed according to a cybersecurity breach risk scoring model executed by the at least one programmable processor on the plurality of datasets. 
   
     
     
         21 . The system of  claim 20 , wherein the quantile estimate corresponds to at least one feature of the set of features indicative of a corresponding cybersecurity data breach risk of the computer network associated with the organization. 
     
     
         22 . The system of  claim 20 , wherein the quantile estimate is determined based on a data segment, the data segment corresponding to at least one of an industry, a number of employees in the organization, the an annual revenue, a number of physical locations, a number of vendor relationships, and geographical location. 
     
     
         23 . The system of  claim 20 , wherein the operations further comprise:
 retrieving the plurality of datasets by scanning the plurality of network prefixes of the computer network associated with the organization over a period of time;   aggregating the plurality of datasets corresponding to the plurality of network prefixes of the computer network associated with the organization into an aggregated computer network dataset, the plurality of datasets further comprising mutually-disjoint set of IP address blocks mapped to the network prefixes and further comprising additional data representative of responses by the network prefixes to the various requests at the mutually-disjoint set of IP address blocks; and   scoring, based on the calibrated set of features, the aggregated computer network dataset, the scoring being processed according to the cybersecurity breach risk scoring model executed by the at least one programmable processor on the aggregated computer network dataset.   
     
     
         24 . The system of  claim 23 , wherein the operations further comprise:
 updating, in response to aggregating the plurality of datasets, the quantile estimate at the database based on the aggregated computer network dataset.   
     
     
         25 . The system of  claim 20 , wherein the cybersecurity breach risk scoring model is based on historical data related to at least one of the network prefixes, and wherein the historical data is tagged with breach versus no-breach incidents. 
     
     
         26 . The system of  claim 20 , wherein the plurality of datasets further comprises a plurality of historical network observations corresponding to the set of features indicative of cybersecurity data breach risks for the plurality of network prefixes. 
     
     
         27 . The system of  claim 20 , wherein the scoring weighs one or more riskiest of the network prefixes more heavily to generate an overall organization score, the one or more riskiest of the network prefixes being determined based on a threshold score determined by the at least one programmable processor according to the cybersecurity breach risk scoring model. 
     
     
         28 . The system of  claim 20 , wherein the operations further comprise:
 aggregating a first set of records in the plurality of datasets, wherein the first set of records is associated with organizational features to calculate a first subset of the one or more features for the plurality of network prefixes;   aggregating a second set of records in the plurality of datasets, wherein the second set of records is associated with network features of each network block of the plurality of network blocks to calculate a second subset of the one or more features indicative of a cybersecurity breach risk for the plurality of network prefixes;   calculating, according to an analytic organization model, an organizational cybersecurity breach probability score based on the first subset calculated by aggregating the records associated with the organizational features;   calculating, according to a network model, a network cybersecurity breach probability score based on the quantile estimate and the second subset calculated by aggregating the records associated with the network features; and   combining the organizational cybersecurity breach probability score and the network cybersecurity breach probability score with the overall score.   
     
     
         29 . The system of  claim 28 , wherein the analytic organization model is based on historical data related to one or more of the plurality of network prefixes and wherein the network model is based on the historical data related to one or more of the plurality of network prefixes, and wherein the historical data is tagged with breach versus no-breach incidents. 
     
     
         30 . A computer-implemented method comprising:
 generating, by at least one data processor, a set of features based on a plurality of datasets, the set of features indicative of cybersecurity data breach risks of a computer network associated with an organization, the plurality of datasets corresponding to a plurality of network prefixes of the computer network associated with the organization, the plurality of datasets comprising an IP address mapped to the network prefixes and comprising data representative of responses by the network prefixes to various requests at the IP address;   calibrating, by the at least one data processor and in response to generating the set of features, the set of features with a quantile estimate from a database, the quantile estimate being calibrated by comparing cybersecurity breach risks across various organizations; and   scoring, by the at least one data processor and based on the calibrated set of features, the plurality of datasets as an overall score, the scoring processed according to a cybersecurity breach risk scoring model executed by the at least one data processor on the plurality of datasets.   
     
     
         31 . The method of  claim 30 , wherein the quantile estimate corresponds to at least one feature of the set of features indicative of a corresponding cybersecurity data breach risk of the computer network associated with the organization. 
     
     
         32 . The method of  claim 30 , wherein the quantile estimate is determined based on a data segment, the data segment corresponding to at least one of an industry, a number of employees in the organization, the an annual revenue, a number of physical locations, a number of vendor relationships, and geographical location. 
     
     
         33 . The method of  claim 30 , further comprising:
 retrieving, by the at least one data processor, the plurality of datasets by scanning the plurality of network prefixes of the computer network associated with the organization over a period of time;   aggregating, by the at least one data processor, the plurality of datasets corresponding to the plurality of network prefixes of the computer network associated with the organization into an aggregated computer network dataset, the plurality of datasets further comprising mutually-disjoint set of IP address blocks mapped to the network prefixes and further comprising additional data representative of responses by the network prefixes to the various requests at the mutually-disjoint set of IP address blocks; and   scoring, by the at least one data processor and based on the calibrated set of features, the aggregated computer network dataset, the scoring being processed according to the cybersecurity breach risk scoring model executed by the at least one data processor on the aggregated computer network dataset.   
     
     
         34 . The method of  claim 33 , further comprising:
 updating, by the at least one data processor and in response to aggregating the plurality of datasets, the quantile estimate at the database based on the aggregated computer network dataset.   
     
     
         35 . A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising:
 generating a set of features based on a plurality of datasets, the set of features indicative of cybersecurity data breach risks of a computer network associated with an organization, the plurality of datasets corresponding to a plurality of network prefixes of the computer network associated with the organization, the plurality of datasets comprising an IP address mapped to the network prefixes and comprising data representative of responses by the network prefixes to various requests at the IP address;   calibrating, in response to generating the set of features, the set of features with a quantile estimate from a database, the quantile estimate being calibrated by comparing cybersecurity breach risks across various organizations; and   scoring, based on the calibrated set of features, the plurality of datasets as an overall score, the scoring processed according to a cybersecurity breach risk scoring model executed by the at least one programmable processor on the plurality of datasets.   
     
     
         36 . The computer program product of  claim 35 , wherein the quantile estimate corresponds to at least one feature of the set of features indicative of a corresponding cybersecurity data breach risk of the computer network associated with the organization. 
     
     
         37 . The computer program product of  claim 35 , wherein the quantile estimate is determined based on a data segment, the data segment corresponding to at least one of an industry, a number of employees in the organization, the an annual revenue, a number of physical locations, a number of vendor relationships, and geographical location. 
     
     
         38 . The computer program product of  claim 35 , wherein the operations further comprise:
 retrieving the plurality of datasets by scanning the plurality of network prefixes of the computer network associated with the organization over a period of time;   aggregating the plurality of datasets corresponding to the plurality of network prefixes of the computer network associated with the organization into an aggregated computer network dataset, the plurality of datasets further comprising mutually-disjoint set of IP address blocks mapped to the network prefixes and further comprising additional data representative of responses by the network prefixes to the various requests at the mutually-disjoint set of IP address blocks; and   scoring, by the at least one programmable processor and based on the calibrated set of features, the aggregated computer network dataset, the scoring being processed according to the cybersecurity breach risk scoring model executed by the at least one programmable processor on the aggregated computer network dataset.   
     
     
         39 . The computer program product of  claim 38 , wherein the operations further comprise:
 updating, in response to aggregating the plurality of datasets, the quantile estimate at the database based on the aggregated computer network dataset.

Join the waitlist — get patent alerts

Track US2020396246A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.