System and method for mitigating cyber threats using risk analysis
A system and method for mitigating cyber-threats. A method includes analyzing data in-memory for at least one software component during execution of each of the at least one software component; generating a base risk score based on the analysis of the data in-memory; analyzing a configuration of each of at least one security control with respect to the at least one software component; generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control; and mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.
1 . A method for mitigating cyber-threats, including:
analyzing data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;
generating a base risk score based on the analysis of the data in-memory;
analyzing a configuration of each of at least one security control with respect to the at least one software component;
analyzing a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;
generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and
mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.
2 . The method of claim 1 , wherein analyzing the data in-memory further comprises:
identifying the at least one library loaded into the memory; and
identifying the at least one software component corresponding to the at least one library loaded into the memory.
3 . The method of claim 1 , further comprising:
applying a generative artificial intelligence (AI) model to generate a textual applicable score analysis based on the applicable score and the analysis of the data in-memory, wherein the textual applicable score analysis describes a history of potential vulnerabilities for the at least one software component.
4 . The method of claim 1 , wherein the base risk score is generated with respect to at least one of: exploitability of the at least one software component, and reachability of the at least one software component.
5 . The method of claim 1 , wherein the base risk score is generated with respect to asset criticality of at least one asset accessible via the at least one software component.
6 . The method of claim 1 , further comprising:
determining an existence of each of the at least one security control, wherein the applicable score is determined based further on the determined existence of each of the at least one security control.
7 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:
analyzing data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;
generating a base risk score based on the analysis of the data in-memory;
analyzing a configuration of each of at least one security control with respect to the at least one software component;
analyzing a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;
generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and
mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.
8 . A system for mitigating cyber-threats, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
analyze data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;
generate a base risk score based on the analysis of the data in-memory;
analyze a configuration of each of at least one security control with respect to the at least one software component;
analyze a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;
generate an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and
mitigate at least one cyber-threat with respect to the at least one software component based on the applicable score.
9 . The system of claim 8 , wherein the system is further configured to:
identify the at least one library loaded into the memory; and
identify the at least one software component corresponding to the at least one library loaded into the memory.
10 . The system of claim 8 , wherein the system is further configured to:
apply a generative artificial intelligence (AI) model to generate a textual applicable score analysis based on the applicable score and the analysis of the data in-memory, wherein the textual applicable score analysis describes a history of potential vulnerabilities for the at least one software component.
11 . The system of claim 8 , wherein the base risk score is generated with respect to at least one of: exploitability of the at least one software component, and reachability of the at least one software component.
12 . The system of claim 8 , wherein the base risk score is generated with respect to asset criticality of at least one asset accessible via the at least one software component.
13 . The system of claim 8 , wherein the system is further configured to:
determine an existence of each of the at least one security control, wherein the applicable score is determined based further on the determined existence of each of the at least one security control.