US2021288995A1PendingUtilityA1

Operational Network Risk Mitigation System And Method

Assignee: OTORIO LTDPriority: Mar 16, 2020Filed: May 17, 2021Published: Sep 16, 2021
Est. expiryMar 16, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04L 63/1433H04L 41/0816H04L 63/1416G06F 21/577H04L 41/16G06F 16/9024H04L 43/045H04L 41/0876H04L 63/1425H04L 41/22H04L 41/0886H04L 41/0879
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer network risk mitigation system includes a computerized platform configured to utilize gathered contextual data regarding cyber-risk metrics in an operational technology network. The computerized platform is configured to conduct network configuration changes in accordance with the gathered contextual data in order to mitigate cyber-security threats. Methods for refining a network attack graph and for utilizing risk score evaluation are also described.

Claims

exact text as granted — not AI-modified
1 . A computer network risk mitigation system, comprising a computerized platform configured to utilize gathered contextual data regarding cyber-risk metrics in an operational technology network,
 wherein said computerized platform is configured to conduct network configuration changes in accordance with the gathered contextual data in order to mitigate cyber-security threats.   
     
     
         2 . The system of  claim 1 , wherein the gathered contextual data is used to facilitate a network segmentation by machine. 
     
     
         3 . The system of  claim 2 , wherein the network segmentation by machine is enabled in accordance with vulnerabilities of assets in the network. 
     
     
         4 . The system of  claim 1 , wherein the gathered contextual data is used to patch the vulnerable assets in the network in real time. 
     
     
         5 . The system of  claim 1 , wherein the gathered contextual data is translated into a detailed report. 
     
     
         6 . The system of  claim 1 , wherein the gathered contextual data is in the form of a network attack graph. 
     
     
         7 . The system of  claim 1 , wherein the gathered contextual data is in the form of any kind of vulnerability analysis. 
     
     
         8 . The system of  claim 1 , wherein the cyber security threats mitigation is conducted using prioritizing risk mitigation steps. 
     
     
         9 . The system of  claim 8 , wherein the prioritization of risk mitigation steps is conducted by utilizing risk scoring methods. 
     
     
         10 . A method for refining a network attack graph, comprising the steps of:
 (i) constructing a network attack graph that relates to potential exploitation of network vulnerabilities,   (ii) determining a score for each one of said detected vulnerabilities,   (iii) determining a score related to the importance level of every device in the network,   (iv) removal of cycles from a network attack graph in accordance with said determined scores.   
     
     
         11 . The method of  claim 10 , wherein a detection of cyclic edges of the cycles to be removed from the network attack graph is conducted using FindCyclicEdges type methods. 
     
     
         12 . A method for utilizing risk score evaluation, comprising the steps of:
 (i) removing cycles from a network attack graph,   (ii) computing security metrics in accordance with the produced network attack graph,   wherein a risk score evaluation is used to determine the priority of security gaps detected in the network attack graph,   wherein the risk score evaluation accounts for the severity of detected vulnerabilities in the network, the importance level of every device on the network and the potential distribution of detected exploits, and   wherein the risk score evaluation is followed by protective measures to be conducted upon the network.   
     
     
         13 . The method of  claim 12 , wherein the protective measures comprise patching the network. 
     
     
         14 . The method of  claim 12 , wherein the protective measures comprise manual reconfiguration of the network. 
     
     
         15 . The method of  claim 12 , wherein the protective measures comprise machine reconfiguration of the network. 
     
     
         16 . The method of  claim 12 , wherein the protective measures comprise segmentation of the network. 
     
     
         17 . The method of  claim 12 , wherein evaluating the risk score is conducted using ComputeRiskScores methods. 
     
     
         18 . The method of  claim 12 , wherein the protective measures comprise blocking of malicious application signatures. 
     
     
         19 . The method of  claim 12 , wherein the protective measures comprise applying blocking rules for unwanted communication in the network. 
     
     
         20 . The method of  claim 12 , wherein the protective measures comprise modifying login credentials to an asset within the network. 
     
     
         21 . A method for utilizing a risk score evaluation, comprising the steps of:
 (i) computing node sums for each node by summing the importance scores of vulnerable devices which belong to a respective node,   (ii) computing edge sums for each edge by summing the vulnerability scores of the vulnerabilities on a respective edge,   (iii) computing inward edge sum for each node by summing the edge sums of edges directed to a respective node,   (iv) computing edge weights by normalizing the edge sum with an inward edge sum of a target node,   (v) computing a node weights vector, wherein a weighted adjacency matrix is set in accordance with the values obtained in step (iv), and wherein an intrinsic value vector is set in accordance with the values obtained in step (i),   (vi) computing device impact scores,   (vii) computing the security risk scores for each separate vulnerability,   wherein the calculated risk score evaluation is utilized as part of a network risk mitigation and followed by protective measures to be conducted upon the network.   
     
     
         22 . The method of  claim 21 , wherein a detailed report is created based on said risk score evaluation. 
     
     
         23 . The method of  claim 21 , wherein a user resolves the detected security gaps by manually applying configuration changes to mitigate relevant network vulnerabilities. 
     
     
         24 . The method of  claim 21 , wherein an automated network segmentation is facilitated to mitigate relevant network vulnerabilities. 
     
     
         25 . The method of  claim 24 , wherein short execution times are enabled during the conduction of the network segmentation by restricting the number of devices in the network. 
     
     
         26 . The method of  claim 21 , wherein the protective measures comprise blocking of malicious application signatures. 
     
     
         27 . The method of  claim 21 , wherein the protective measures comprise applying blocking rules for unwanted communication in the network. 
     
     
         28 . The method of  claim 21 , wherein the protective measures comprise modifying login credentials to an asset within the network.

Join the waitlist — get patent alerts

Track US2021288995A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.