IP Library Granted Patent US 12684001
Granted Patent B2
US 12684001 · App. 18/450,871 · Granted Jul 14, 2026

System and method for mitigating cyber threats using risk analysis

Inventors: Ben Seri (Ramat Gan, IL); Snir Havdala (Tel Aviv, IL)
Assignee: Zafran Security LTD
H04L63/1433H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12684001
App. No.
18/450,871
Granted
Jul 14, 2026
Kind
B2
Abstract

A system and method for mitigating cyber-threats. A method includes analyzing data in-memory for at least one software component during execution of each of the at least one software component; generating a base risk score based on the analysis of the data in-memory; analyzing a configuration of each of at least one security control with respect to the at least one software component; generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control; and mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.

Claims (41)

1 . A method for mitigating cyber-threats, including:

analyzing data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;

generating a base risk score based on the analysis of the data in-memory;

analyzing a configuration of each of at least one security control with respect to the at least one software component;

analyzing a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;

generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and

mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.

2 . The method of claim 1 , wherein analyzing the data in-memory further comprises:

identifying the at least one library loaded into the memory; and

identifying the at least one software component corresponding to the at least one library loaded into the memory.

3 . The method of claim 1 , further comprising:

applying a generative artificial intelligence (AI) model to generate a textual applicable score analysis based on the applicable score and the analysis of the data in-memory, wherein the textual applicable score analysis describes a history of potential vulnerabilities for the at least one software component.

4 . The method of claim 1 , wherein the base risk score is generated with respect to at least one of: exploitability of the at least one software component, and reachability of the at least one software component.

5 . The method of claim 1 , wherein the base risk score is generated with respect to asset criticality of at least one asset accessible via the at least one software component.

6 . The method of claim 1 , further comprising:

determining an existence of each of the at least one security control, wherein the applicable score is determined based further on the determined existence of each of the at least one security control.

7 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

analyzing data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;

generating a base risk score based on the analysis of the data in-memory;

analyzing a configuration of each of at least one security control with respect to the at least one software component;

analyzing a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;

generating an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and

mitigating at least one cyber-threat with respect to the at least one software component based on the applicable score.

8 . A system for mitigating cyber-threats, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

analyze data in-memory for at least one software component during execution of each of the at least one software component, wherein the analyzed data includes at least one library loaded into a memory, wherein the at least one software component is executed within the memory;

generate a base risk score based on the analysis of the data in-memory;

analyze a configuration of each of at least one security control with respect to the at least one software component;

analyze a plurality of capabilities of each of the at least one security control wherein the plurality of capabilities of each of the security controls are analyzed with respect to categories of vulnerabilities, wherein the categories of vulnerabilities are determined based on a plurality of probabilities, wherein the plurality of probabilities is divided into at least one probability of being triggered via a network and at least one probability of being triggered via an endpoint;

generate an applicable score based on the base risk score and the analysis of the configuration of each of the at least one security control, wherein the applicable score is also based on the plurality of capabilities of each of the at least one security control; and

mitigate at least one cyber-threat with respect to the at least one software component based on the applicable score.

9 . The system of claim 8 , wherein the system is further configured to:

identify the at least one library loaded into the memory; and

identify the at least one software component corresponding to the at least one library loaded into the memory.

10 . The system of claim 8 , wherein the system is further configured to:

apply a generative artificial intelligence (AI) model to generate a textual applicable score analysis based on the applicable score and the analysis of the data in-memory, wherein the textual applicable score analysis describes a history of potential vulnerabilities for the at least one software component.

11 . The system of claim 8 , wherein the base risk score is generated with respect to at least one of: exploitability of the at least one software component, and reachability of the at least one software component.

12 . The system of claim 8 , wherein the base risk score is generated with respect to asset criticality of at least one asset accessible via the at least one software component.

13 . The system of claim 8 , wherein the system is further configured to:

determine an existence of each of the at least one security control, wherein the applicable score is determined based further on the determined existence of each of the at least one security control.