System and method for continuous improvement of a cyber security rating of a firm
A system and method for continuously improving the cybersecurity rating of a firm includes a feed processor configured to parse at least one cybersecurity report and to feed for building an instance graph. The system may identify, measure, and monitor portfolio dimensions of public-facing digital artifacts. In addition, the system and method may each include the instance graph being compared by a correlation engine with a reference graph to generate automated or semi-automated remediation recommendations that may lead to continuous improvement of a cybersecurity rating for an organization or firm.
1 . A system to continuously improve the cybersecurity rating of a firm, comprising:
at least one processor;
at least one memory coupled to the at least one processor;
an endpoint;
an endpoint detection response and intrusion prevention device, executed by the at least one processor, wherein the endpoint detection response and intrusion prevention device evaluates cybersecurity information of the endpoint by monitoring network and system activity at the endpoint for at least one malicious behavior and at least one policy violation in real-time and automatically preventing detected malicious activity by blocking malicious network traffic;
a feed processor executed by the at least one processor and configured to:
ingest a cybersecurity feed comprising cybersecurity posture information from the endpoint detection response and intrusion prevention device,
parse the cybersecurity feeds to extract cybersecurity attributes, entities and relationships, and
construct a knowledge graph based on the extracted attributes, entities and relationships;
a graph database stored in the at least one memory and configured to:
store the knowledge graph as an instance graph,
version the instance graph to maintain historical states, and
annotate at least one node and at least one edge of the instance graph with cybersecurity taxonomy information from a knowledge base,
the knowledge base configured to provide cybersecurity taxonomy information for annotating the at least one node and the at least one edge of the instance graph;
a correlation engine executed by the at least one processor and configured to:
compare the versioned instance graph with a reference graph,
identify differences between the versioned instance graph and the reference graph, and
generate a difference graph representing the identified differences; and
an auto-remediation workflow engine executed by the at least one processor and configured to:
analyze the difference graph to detect security vulnerabilities,
automatically generate remediation instructions based on the detected vulnerabilities,
execute the remediation instructions against an organization's software and security systems by performing at least one of run-time application self-protection to automatically block malicious activity during application execution, intrusion detection and prevention, pathing, endpoint detection and response, static application security testing, or dynamic application security testing, to adjust security policies and fix the vulnerabilities, and
trigger generation of an updated reference graph reflecting the executed remediation.
2 . The system of claim 1 , further comprising a cybersecurity knowledge graph builder configured to take input from an organization's software and security events and build the reference graph while assigning a cyber score to the at least one node.
3 . The system as claimed in claim 1 , further comprising a recommendation engine configured to parse the difference graph for generating the auto-remediation workflow, or for generating a risk registration.
4 . The system as claimed in claim 3 , further comprising the auto-remediation workflow being configured to remediate vulnerabilities and trigger the cybersecurity knowledge graph builder to generate an updated and versioned cybersecurity reference graph.
5 . A method for continuously improving the cybersecurity rating of a firm, comprising:
evaluating, using at least one processor, cybersecurity information of an endpoint via an endpoint detection response and intrusion prevention device by:
monitoring network and system activity at the endpoint for malicious behavior and policy violations in real-time, automatically preventing detected malicious activity by blocking malicious network traffic, and
generating cybersecurity event data based on the detected behavior and violations;
constructing, using the at least one processor, a cybersecurity knowledge graph by:
ingesting the cybersecurity event data from the endpoint detection response and intrusion prevention device,
parsing the cybersecurity event data to extract cybersecurity attributes, entities and relationships, and
building an instance graph based on the extracted attributes, entities and relationships;
processing, using the at least one processor, the instance graph by:
storing the instance graph in a graph database stored in at least one memory,
versioning the instance graph to maintain historical states, and
annotating at least one node and at least one edge of the instance graph with cybersecurity taxonomy information from a knowledge base;
performing, using the at least one processor, security analysis by:
comparing the versioned instance graph with a reference graph,
identifying differences between the instance graph and reference graph,
generating a difference graph representing the identified differences, and
detecting security vulnerabilities based on analysis of the difference graph; and
executing, using the at least one processor, automated remediation by:
generating remediation instructions based on the detected vulnerabilities,
automatically implementing the remediation instructions against the organization's software and security systems by performing a least one of: run-time application self protection to automatically block malicious activity during application execution, intrusion detection and prevention, patching, endpoint detection and response, static application security testing, or dynamic application security testing, to adjust security policies and fix the vulnerabilities, and
triggering generation of an updated reference graph reflecting the implemented remediation.
6 . The method as claimed in claim 5 , further comprising configuring a cybersecurity knowledge graph builder to take input from an organization's software and security events for building the reference graph while assigning a cyber score to the at least one node.
7 . The method as claimed in claim 6 , further comprising configuring a correlation engine to compare the instance graph that has been versioned with the reference graph and generating the difference graph.
8 . The method as claimed in claim 7 , further comprising configuring a recommendation engine to parse the difference graph and
generate the auto-remediation workflow, or
generate a risk registration.
9 . The method as claimed in claim 8 , further comprising configuring the auto-remediation workflow to remediate vulnerabilities and trigger the cybersecurity knowledge graph builder to generate an updated and versioned cybersecurity reference graph.