Method and system for implementing a service that simplifies network cyber defense capabilities
A method, system, and computer-readable storage medium for implementing a service that simplifies network cyber defense capabilities. The method includes: compiling a resource list of resources that exist within a computer network; compiling a cyber defense list of cyber defense mechanisms that exist within the computer network; evaluating the resources and the cyber defense mechanisms, against any applicable threats or vulnerabilities, to determine whether there are any threats to the computer network or any vulnerabilities to that network; and generating a visual indication of any of the computer network's threats or vulnerabilities. The resource list may include a resource configuration of the resources, and the cyber defense list may include a cyber defense configuration of the cyber defense mechanisms.
1 . A method for implementing a service that simplifies network cyber defense capabilities, the method comprising:
utilizing at least one real-time data source to obtain resources of a private computer network and configurations of the resources;
compiling, by the processor, a cyber defense list of cyber defense mechanisms that exist within the private computer network, wherein the compiling the cyber defense list of cyber defense mechanisms comprises mining the private computer network to compile the cyber defense list which comprises a cyber defense configuration of the cyber defense mechanisms;
utilizing, by the processor, an artificial intelligence and machine learning (AI/ML) engine to evaluate the resources of the private computer network, the configurations of the resources, and the cyber defense mechanisms, against a set of at least one from among threats and vulnerabilities, to determine whether the set of the at least one from among threats and vulnerabilities comprises at least one from among an applicable threat and an applicable vulnerability,
wherein the AI/ML engine evaluates by evaluating tests that comprise at least one phishing test,
wherein the at least one from among the applicable threat and the applicable vulnerability comprises at least one from among: a threat to at least one from among the resources and the configurations of the resources; and a vulnerability of at least one from among the resources and the configurations of the resources, and
wherein the AI/ML engine comprises a recommendation system, a risk forecasting engine, and a monitoring system;
generating, by the processor, a visual indication of whether the set of the at least one from among threats and vulnerabilities comprises the at least one from among the applicable threat and the applicable vulnerability that threatens a security of the private computer network, wherein the visual indication comprises a defense ranking parameter that summarizes an overall performance of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability; and
when, as a result of the evaluating, a determination is made that the set of the at least one from among threats and vulnerabilities comprises the at least one from among the applicable threat and the applicable vulnerability:
recommending at least one network configuration change that addresses whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network;
implementing the at least one network configuration change;
continuously monitoring the private computer network to obtain, from the at least one real-time data source, feedback about the implementing the at least one network configuration change, wherein the continuously monitoring the private computer network to obtain the feedback comprises obtaining at least a portion of the feedback by mining the private computer network, and wherein the feedback comprises a feedback indication of how the implementing the at least one network configuration change affects whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network; and
updating, according to the feedback, an AI/ML model of the AI/ML engine.
2 . The method of claim 1 , wherein the visual indication is provided to at least one individual for analysis, and wherein the visual indication comprises an illustration of the private computer network, and wherein the illustration depicts a performance of at least one of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability.
3 . The method of claim 1 , wherein:
the resources comprise at least one from among: a client, a server, a gateway, a database, an application, an operating system, an IoT device, a router, a network hub, a network switch, a surveillance camera, a surveillance video recorder, a smart card, a biometric authentication device, an electronic lock, and an access control system; and
the cyber defense mechanisms comprise at least one from among: an antivirus service, a malware scanner, a spam filter, a firewall, an access control mechanism, sandboxing software, an encryption mechanism, an intrusion detection system (IDS), a denial-of-service (DoS) attack monitoring system, and best practices for security.
4 . The method of claim 1 , wherein the processor utilizes a curated repository to identify the set of the at least one from among threats and vulnerabilities.
5 . The method of claim 4 , wherein the curated repository comprises at least one from among: a Cyber Kill Chain framework; and an Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework.
6 . The method of claim 1 , wherein the utilizing comprises utilizing the AI/ML engine to predict whether there is a risk to which the private computer network will be susceptible.
7 . The method of claim 6 , wherein the utilizing comprises utilizing the AI/ML engine to:
receive training data, wherein the training data comprises at least one from among the configurations of the resources, the cyber defense configuration, and feedback about the private computer network;
train, according to the training data, an AI/ML model of the AI/ML engine; and
utilize the AI/ML model to determine whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network.
8 . The method of claim 1 , further comprising:
producing updated resource configurations by updating the configurations of the resources according to the at least one network configuration change; and
periodically re-evaluating, according to the updated resource configurations, the resources of the private computer network against the set of the at least one from among threats and vulnerabilities.
9 . A system for implementing a service that simplifies network cyber defense capabilities, the system comprising:
a processor; and
memory storing instructions that, when executed by the processor, cause the processor to:
utilize at least one real-time data source to obtain resources of a private computer network and configurations of the resources;
compile a cyber defense list of cyber defense mechanisms that exist within the private computer network, wherein the compiling the cyber defense list of cyber defense mechanisms comprises mining the private computer network to compile the cyber defense list which comprises a cyber defense configuration of the cyber defense mechanisms;
utilize an artificial intelligence and machine learning (AI/ML) engine to evaluate the resources of the private computer network, the configurations of the resources, and the cyber defense mechanisms, against a set of at least one from among threats and vulnerabilities, to determine whether the set of the at least one from among threats and vulnerabilities comprises at least one from among a threat and a vulnerability,
wherein the AI/ML engine evaluates by evaluating tests that comprise at least one phishing test,
wherein the at least one from among the threat and the vulnerability comprises at least one from among: a threat to at least one from among the resources and the configurations of the resources; and a vulnerability of at least one from among the resources and the configurations of the resources, and
wherein the AI/ML engine comprises a recommendation system, a risk forecasting engine, and a monitoring system;
generate a visual indication of whether the set of the at least one from among threats and vulnerabilities comprises the at least one from among the threat and the vulnerability threatens a security of the private computer network, wherein the visual indication comprises a defense ranking parameter that summarizes an overall performance of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability; and
when, as a result of the evaluating, a determination is made that the set of the at least one from among threats and vulnerabilities comprises the at least one from among the applicable threat and the applicable vulnerability:
recommend at least one network configuration change that addresses whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network;
implement the at least one network configuration change;
continuously monitor the private computer network to obtain, from the at least one real-time data source, feedback about the implementing the at least one network configuration change, wherein the continuously monitoring the private computer network to obtain the feedback comprises obtaining at least a portion of the feedback by mining the private computer network, and wherein the feedback comprises a feedback indication of how the implementing the at least one network configuration change affects whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network; and
update, according to the feedback, an AI/ML model of the AI/ML engine.
10 . The system of claim 9 , wherein the visual indication is provided to at least one individual for analysis, and wherein the visual indication comprises:
an illustration of the private computer network, wherein the illustration depicts a performance of at least one of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability.
11 . The system of claim 9 , wherein:
the resources comprise at least one from among a client, a server, a gateway, a database, an application, an operating system, an IoT device, a router, a network hub, a network switch, a surveillance camera, a surveillance video recorder, a smart card, a biometric authentication device, an electronic lock, and an access control system; and
the cyber defense mechanisms comprise at least one from among an antivirus service, a malware scanner, a spam filter, a firewall, an access control mechanism, sandboxing software, an encryption mechanism, an intrusion detection system (IDS), a denial-of-service (DoS) attack monitoring system, and best practices for security.
12 . The system of claim 9 , wherein the instructions, when executed by the processor, further cause the processor to:
utilize a curated repository to identify the set of the at least one from among threats and vulnerabilities, wherein the curated repository comprises at least one from among: a Cyber Kill Chain framework; and an Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework.
13 . The system of claim 9 , wherein the utilizing comprises utilizing the AI/ML engine to predict whether there is a risk to which the private computer network will be susceptible.
14 . The system of claim 13 , wherein the utilizing comprises utilizing the AI/ML engine to:
receive training data, wherein the training data comprises at least one from among the configurations of the resources, the cyber defense configuration, and feedback about the private computer network;
train, according to the training data, an AI/ML model of the AI/ML engine; and
utilize the AI/ML model to determine whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network.
15 . A non-transitory computer-readable medium storing instructions for implementing a service that simplifies network cyber defense capabilities, wherein the instructions, when executed by a processor, cause the processor to:
utilize at least one real-time data source to obtain resources of a private computer network and configurations of the resources;
compile a cyber defense list of cyber defense mechanisms that exist within the private computer network, wherein the compiling the cyber defense list of cyber defense mechanisms comprises mining the private computer network to compile the cyber defense list which comprises a cyber defense configuration of the private cyber defense mechanisms;
utilize an artificial intelligence and machine learning (AI/ML) engine to evaluate the resources of the private computer network, the configurations of the resources, and the cyber defense mechanisms, against a set of at least one from among threats and vulnerabilities, to determine whether the set of the at least one from among threats and vulnerabilities comprises at least one from among a threat and a vulnerability,
wherein the AI/ML engine evaluates by evaluating tests that comprise at least one phishing test,
wherein the at least one from among the threat and the vulnerability comprises at least one from among: a threat to at least one from among the resources and the configurations of the resources; and a vulnerability of at least one from among the resources and the configurations of the resources, and
wherein the AI/ML engine comprises a recommendation system, a risk forecasting engine, and a monitoring system;
generate a visual indication of whether the set of the at least one from among threats and vulnerabilities comprises the at least one from among the threat and the vulnerability threatens a security of the private computer network, wherein the visual indication comprises a defense ranking parameter that summarizes an overall performance of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability; and
when, as a result of the evaluating, a determination is made that the set of the at least one from among threats and vulnerabilities comprises the at least one from among the applicable threat and the applicable vulnerability:
recommend at least one network configuration change that addresses whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network;
implement the at least one network configuration change;
continuously monitor the private computer network to obtain, from the at least one real-time data source, feedback about the implementing the at least one network configuration change, wherein the continuously monitoring the private computer network to obtain the feedback comprises obtaining at least a portion of the feedback by mining the private computer network, and wherein the feedback comprises a feedback indication of how the implementing the at least one network configuration change affects whether the at least one from among the applicable threat and the applicable vulnerability threatens the security of the private computer network; and
update, according to the feedback, an AI/ML model of the AI/ML engine.
16 . The non-transitory computer-readable medium of claim 15 , wherein the visual indication is provided to at least one individual for analysis, and wherein the visual indication comprises:
a defense ranking parameter that summarizes an overall performance of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability; and
an illustration of the private computer network, wherein the illustration depicts a performance of at least one of the cyber defense mechanisms with respect to the at least one from among the applicable threat and the applicable vulnerability.