System and method for technology risk ranking
A system and method for evaluating levels of risk utilizing a multi-tenant database to detect technologies is presented collecting a plurality of metadata for each technology in a plurality of technologies from a plurality of computing environments from a plurality of tenants; extracting a plurality of features from the metadata for each technology in the plurality of technologies; assigning a weight to each feature in the plurality of features for each technology in the plurality of technologies; determining a plurality of composite risk scores based on the plurality of weighted features for each technology in the plurality of technologies; and initiating a mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the composite risk scores.
1 . A method for evaluating levels of risk utilizing a multi-tenant database to detect technologies, comprising:
collecting a plurality of metadata for each technology in a plurality of technologies from a plurality of computing environments from a plurality of tenants;
extracting a plurality of features from the metadata for each technology in the plurality of technologies;
assigning a weight to each feature in the plurality of features for each technology in the plurality of technologies;
determining a plurality of composite risk scores based on the plurality of weighted features for each technology in the plurality of technologies;
triggering an event, and in response to the triggered event:
refining an at least one scope of an at least one metadata in the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
collecting a plurality of refined metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
extracting a plurality of refined features based on the plurality of refined metadata;
assigning a refined weight to each refined feature in the plurality of refined features;
determining a plurality of refined composite risk scores based on the plurality of weighted refined features for each technology in the plurality of technologies;
sorting each technology in the plurality of technologies based on the plurality of refined composite risk scores;
generating a refined list of sorted technologies; and
storing the refined list of sorted technologies in a central repository; and initiating a mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the composite risk scores.
2 . The method of claim 1 , further comprising:
collecting the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants to include, in part, a plurality of incident history reports, where the plurality of incident history reports includes at least one Common Vulnerabilities and Exposures (CVE) report.
3 . The method of claim 1 , further comprising,
collecting the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants to include, in part, a plurality of software files that are installed or deployed on a resource from each technology in the plurality of technologies, where the resource is deployed on a cloud computing environment.
4 . The method of claim 1 , further comprising:
extracting the plurality of features to include at least one of a prevalence score, a vulnerability score, an incident score or a privilege score.
5 . The method of claim 1 , further comprising:
determining a composite risk score based on a weighted sum of the plurality of weighted features for each technology in the plurality of technologies.
6 . The method of claim 1 , further comprising:
sorting each technology in the plurality of technologies based on the plurality of composite risk scores;
generating a list of sorted technologies; and
storing the list of sorted technologies in a central repository.
7 . The method of claim 6 , further comprising:
initiating the mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the list of sorted technologies.
8 . The method of claim 7 , further comprising:
initiating the mitigatory action to include at least one of: modifying resource allocation for monitoring the at least one technology in the plurality of technologies, modifying privileges associated with the at least one technology in the plurality of technologies or requiring additional factors of authentication for the at least one technology in the plurality of technologies.
9 . The method of claim 1 , wherein the event is based on a response to a detection of one or more technologies not in the plurality of technologies, one or more computing environments for one or more tenants different from the plurality of computing environments or one or more tenants different from the plurality of tenants.
10 . The method of claim 1 , wherein the event is based on a trend analysis of the stored lists of sorted technologies.
11 . The method of claim 1 , further comprising:
refining the scope of at least one metadata in the plurality of metadata to include at least one of adding a new technology to the plurality of technologies, adding a new computing environment to the plurality of computing environments or adding a new tenant to the plurality of tenants.
12 . The method of claim 1 , further comprising:
refining the scope of at least one metadata in the plurality of metadata to include at least one of adjusting resource allocation to collect the at least one metadata in the plurality of metadata or adjusting a scale of at least one metadata in the plurality of metadata or adjusting a precision of at least one metadata in the plurality of metadata.
13 . A non-transitory computer-readable medium storing a set of instructions for evaluating levels of risk utilizing a multi-tenant database to detect technologies, the set of instructions comprising:
one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:
collect a plurality of metadata for each technology in a plurality of technologies from a plurality of computing environments from a plurality of tenants;
extract a plurality of features from the metadata for each technology in the plurality of technologies;
assign a weight to each feature in the plurality of features for each technology in the plurality of technologies;
determine a plurality of composite risk scores based on the plurality of weighted features for each technology in the plurality of technologies;
trigger an event, and in response to the triggered event:
refine an at least one scope of an at least one metadata in the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
collect a plurality of refined metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
extract a plurality of refined features based on the plurality of refined metadata;
assign a refined weight to each refined feature in the plurality of refined features;
determine a plurality of refined composite risk scores based on the plurality of weighted refined features for each technology in the plurality of technologies;
sort each technology in the plurality of technologies based on the plurality of refined composite risk scores;
generate a refined list of sorted technologies; and
store the refined list of sorted technologies in a central repository; and
initiate a mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the composite risk scores.
14 . A system for evaluating levels of risk utilizing a multi-tenant database to detect technologies comprising:
a processing circuitry;
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
collect a plurality of metadata for each technology in a plurality of technologies from a plurality of computing environments from a plurality of tenants;
extract a plurality of features from the metadata for each technology in the plurality of technologies;
assign a weight to each feature in the plurality of features for each technology in the plurality of technologies;
determine a plurality of composite risk scores based on the plurality of weighted features for each technology in the plurality of technologies;
trigger an event, and in response to the triggered event:
refine an at least one scope of an at least one metadata in the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
collect a plurality of refined metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants;
extract a plurality of refined features based on the plurality of refined metadata;
assign a refined weight to each refined feature in the plurality of refined features;
determine a plurality of refined composite risk scores based on the plurality of weighted refined features for each technology in the plurality of technologies;
sort each technology in the plurality of technologies based on the plurality of refined composite risk scores;
generate a refined list of sorted technologies; and
store the refined list of sorted technologies in a central repository; and
initiate a mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the composite risk scores.
15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
collect the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants to include, in part, a plurality of incident history reports, where the plurality of incident history reports includes at least one Common Vulnerabilities and Exposures (CVE) report.
16 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
collect the plurality of metadata of the plurality of technologies from the plurality of computing environments from the plurality of tenants to include, in part, a plurality of software files that are installed or deployed on a resource from each technology in the plurality of technologies, where the resource is deployed on a cloud computing environment.
17 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
extract the plurality of features to include at least one of a prevalence score, a vulnerability score, an incident score or a privilege score.
18 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
determine a composite risk score based on a weighted sum of the plurality of weighted features for each technology in the plurality of technologies.
19 . The system of claim 14 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:
sort each technology in the plurality of technologies based on the plurality of composite risk scores;
generate a list of sorted technologies; and
store the list of sorted technologies in a central repository.
20 . The system of claim 19 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:
initiate the mitigatory action for at least one technology in the plurality of technologies from the plurality of computing environments from the plurality of tenants based on the list of sorted technologies.
21 . The system of claim 20 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:
initiate the mitigatory action to include at least one of:
modify resource allocation for monitoring the at least one technology in the plurality of technologies, modifying privileges associated with the at least one technology in the plurality of technologies or requiring additional factors of authentication for the at least one technology in the plurality of technologies.
22 . The system of claim 14 , wherein event is based on a response to a detection of one or more technologies not in the plurality of technologies, one or more computing environments for one or more tenants different from the plurality of computing environments or one or more tenants different from the plurality of tenants.
23 . The system of claim 14 , wherein the event is based on a trend analysis of the stored lists of sorted technologies.
24 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
refine the scope of at least one metadata in the plurality of metadata to include at least one of adding a new technology to the plurality of technologies, adding a new computing environment to the plurality of computing environments or adding a new tenant to the plurality of tenants.
25 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
refine the scope of at least one metadata in the plurality of metadata to include at least one of adjusting resource allocation to collect the at least one metadata in the plurality of metadata or adjusting a scale of at least one metadata in the plurality of metadata or adjusting a precision of at least one metadata in the plurality of metadata.