Correlated risk in cybersecurity

US11770401B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11770401-B2
Application numberUS-202117179630-A
CountryUS
Kind codeB2
Filing dateFeb 19, 2021
Priority dateMar 12, 2018
Publication dateSep 26, 2023
Grant dateSep 26, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Computer-implemented methods are provided herein for quantifying correlated risk in a network of a plurality of assets having at least one dependency, where each asset belongs to at least one entity. The method includes generating a dependency graph based on relationships between the assets, at least one dependency, and at least one entity, and executing a plurality of Monte Carlo simulations over the dependency graph. Executing a plurality of Monte Carlo simulations includes generating a seed event in the dependency graph, where the seed event has a probability distribution, and propagating disruption through the dependency graph based on the seed event. The method further includes assessing loss for each of the assets, and aggregating losses for two or more assets to determine correlated risk in the network.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for quantifying correlated risk in a network of a plurality of assets having at least one dependency, each asset belonging to at least one entity, the method comprising: generating a dependency graph based on relationships between the plurality of assets, the at least one dependency, and the at least one entity, wherein the dependency graph comprises (i) a plurality of edges representing relationships between the plurality of assets, the at least one dependency, and the at least one entity and (ii) a plurality of nodes representing the plurality of assets, the at least one dependency, and the at least one entity, wherein each edge has a conditional probability that the asset on a receiving node of a particular edge, of the plurality of edges, is compromised given that the providing node, of the plurality of nodes, is compromised; executing a plurality of Monte Carlo simulations over the dependency graph, wherein each of the plurality of Monte Carlo simulations executes by: generating a seed event in the dependency graph, the seed event having a probability distribution; propagating disruption through the dependency graph based on the seed event; and terminating the respective Monte Carlo Simulation when a threshold number of nodes is affected by the disruption or a threshold loss magnitude aggregated for two or more assets of the plurality of assets affected by the disruption is exceeded; assessing, based on the plurality of Monte Carlo simulations, a loss for each asset of the plurality of assets; and aggregating the losses for two or more assets of the plurality of assets to determine correlated risk in the network. 2. The method of claim 1 , wherein: each of the plurality of assets is selected from the group consisting of: Internet Protocol (IP) address, domain name, and server system; each of the at least one entity is selected from the group consisting of: a company and an organization; and each of the at least one dependency is selected from the group consisting of: hosting provider and software version. 3. The method of claim 1 , further comprising: receiving information indicative of the relationships between the plurality of assets, the at least one dependency, and the at least one entity. 4. The method of claim 3 , further comprising: storing information indicative of the relationships between the plurality of assets, the at least one dependency, and the at least one entity in a database, wherein the information is at least one of the group consisting of: domain name system (DNS) record, server banner, traffic data, malware infection, and software version. 5. The method of claim 3 , further comprising: observing traffic to and from a particular one of the plurality of assets in the network to identify at least one of (i) an entity and (ii) a dependency related to the particular asset. 6. The method of claim 3 , wherein the information indicative of the relationships includes inter-business payment data. 7. The method of claim 1 , wherein each of the plurality of assets is weighted according to an importance of each respective asset to the at least one entity having the asset. 8. The method of claim 1 , wherein the seed event is a breach or failure of the at least one dependency. 9. The method of claim 1 , wherein the probability distribution is a probability that the asset will become unavailable when the at least one dependency fails. 10. The method of claim 1 , further comprising: storing information related to the aggregated losses for the two or more assets of the plurality of assets in a database. 11. The method of claim 1 , wherein the at least one entity comprises at least two entities, and a first asset of the two or more assets belongs to a first entity of the at least two entities and a second entity of the two or more assets belongs to a second entity of the at least two entities. 12. The method of claim 11 , wherein at least one of the first and second assets belongs to another entity of the at least two entities. 13. The method of claim 11 , further comprising: aggregating losses for two or more entities of the at least two entities to determine correlated risk in the network. 14. The method of claim 13 , further comprising: storing information related to the aggregated losses for the two or more entities of the at least two entities in a database. 15. The method of claim 11 , wherein each of the at least two entities is assigned to at least one portfolio, and wherein the method further comprises: aggregating losses for two or more portfolios of the at least one portfolio to determine correlated risk in the network. 16. The method of claim 15 , further comprising: storing information related to the aggregated losses for the two or more entities of the at least two entities in a database. 17. The method of claim 1 , wherein the aggregating losses for two or more assets of the plurality of assets to determine correlated risk in the network further comprises: aggregating losses in a nonlinear sum for the two or more assets of the plurality of assets. 18. The method of claim 1 , wherein a number of the plurality of Monte Carlo simulations is selected to reduce a statistical variance of the plurality of Monte Carlo simulations. 19. The method of claim 1 , wherein the executing a plurality of Monte Carlo simulations over the dependency graph further comprises: comparing a statistical variance to a threshold; and terminating the plurality of Monte Carlo simulations when the statistical variance is equal to or less than the threshold.

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • using ranking · CPC title

  • Entity relationship models · CPC title

  • Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11770401B2 cover?
Computer-implemented methods are provided herein for quantifying correlated risk in a network of a plurality of assets having at least one dependency, where each asset belongs to at least one entity. The method includes generating a dependency graph based on relationships between the assets, at least one dependency, and at least one entity, and executing a plurality of Monte Carlo simulations o…
Who is the assignee on this patent?
Bitsight Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 26 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).