Methods and mechanisms for predicting the likelihood of a vulnerability used in a ransomware event
A system configured to obtain, by a processor, a plurality of vulnerabilities associated with one or more computer systems. The system is further configured to generate a set of fingerprints, wherein each fingerprint of the set of fingerprints is associated with a respective vulnerability of the plurality of vulnerabilities, by assigning a set of labels to each of the plurality of vulnerabilities. The system is further configured to generate a set of reduced fingerprints, wherein each reduced fingerprint comprises a value generated from performing one or more dimensionality reduction operations on a respective fingerprint. The system is further configured to generate a coordinate system based on the set of reduced fingerprints and identify, based on the coordinate system, a group of reduced fingerprints based on one or more determined correlations.
1 . A method, comprising:
obtaining, by a processor, a plurality of vulnerabilities associated with one or more computer systems;
generating a set of fingerprints by assigning a set of labels to each of the plurality of vulnerabilities, wherein each fingerprint of the set of fingerprints is associated with a respective vulnerability of the plurality of vulnerabilities, wherein each label of each set of labels indicates at least one of a particular parameter or a particular attribute of the respective vulnerability;
generating a set of reduced fingerprints by performing one or more dimensionality reduction operations on each set of labels of each respective fingerprint, wherein each reduced fingerprint comprises a value configured to retain at least a portion of the information from the respective fingerprint;
generating a coordinate system based on the set of reduced fingerprints;
generating a predictive model comprising the coordinate system and one or more overlays applied on the coordinate system by identifying one or more groups of reduced fingerprints based on one or more determined correlations, wherein each overlay corresponds to a respective group of the one or more groups of reduced fingerprints, and assigning a ransomware likelihood rating to each overlay based on ransomware events data, wherein the ransomware likelihood rating indicates a likelihood that a vulnerability within the respective group will be used in a ransomware event;
receiving a new vulnerability;
generating a new fingerprint for the new vulnerability;
generating, from the new fingerprint, a reduced fingerprint for the new vulnerability;
determining a position, on the coordinate system, of the reduced fingerprint; and
determining a rating for the new vulnerability based on the position on the coordinate system, wherein the rating reflects a likelihood of the new vulnerability being used in a ransomware event.
2 . The method of claim 1 , wherein the rating is determined based on identifying a center of the group of reduced fingerprints in relation to the coordinate system.
3 . The method of claim 1 , wherein the group is identified using ransomware event data.
4 . The method of claim 1 , wherein each fingerprint of the set of fingerprints is a n-dimension binary array.
5 . The method of claim 1 , wherein each value comprises a pair of principal components.
6 . The method of claim 1 , wherein the coordinate system is generated using one or more dimensional reduction techniques.
7 . A system, comprising:
a memory device; and
a processing device, operatively coupled to the memory device, to perform operations comprising:
obtaining a plurality of vulnerabilities associated with one or more computer systems;
generating a set of fingerprints by assigning a set of labels to each of the plurality of vulnerabilities, wherein each fingerprint of the set of fingerprints is associated with a respective vulnerability of the plurality of vulnerabilities, wherein each label of each set of labels indicates at least one of a particular parameter or a particular attribute of the respective vulnerability;
generating a set of reduced fingerprints by performing one or more dimensionality reduction operations on each set of labels of each respective fingerprint, wherein each reduced fingerprint comprises a value configured to retain at least a portion of the information from the respective fingerprint;
generating a coordinate system based on the set of reduced fingerprints;
generating a predictive model comprising the coordinate system and one or more overlays applied on the coordinate system by identifying one or more groups of reduced fingerprints based on one or more determined correlations, wherein each overlay corresponds to a respective group of the one or more groups of reduced fingerprints, and assigning a ransomware likelihood rating to each overlay based on ransomware events data, wherein the ransomware likelihood rating indicates a likelihood that a vulnerability within the respective group will be used in a ransomware event;
receiving a new vulnerability;
generating a new fingerprint for the new vulnerability;
generating, from the new fingerprint, a reduced fingerprint for the new vulnerability;
determining a position, on the coordinate system, of the reduced fingerprint; and
determining a rating for the new vulnerability based on the position on the coordinate system, wherein the rating reflects a likelihood of the new vulnerability being used in a ransomware event.
8 . The system of claim 7 , wherein the rating is determined based on identifying a center of the group of reduced fingerprints in relation to the coordinate system.
9 . The system of claim 7 , wherein the group is identified using ransomware event data.
10 . The system of claim 7 , wherein each fingerprint of the set of fingerprints is a n-dimension binary array.
11 . The system of claim 7 , wherein each value comprises a pair of principal components.
12 . The system of claim 7 , wherein the coordinate system is generated using one or more dimensional reduction techniques.
13 . A non-transitory computer readable storage medium comprising instructions for a server that, when executed by a processing device, cause the processing device to perform operations comprising:
obtaining a plurality of vulnerabilities associated with one or more computer systems;
generating a set of fingerprints by assigning a set of labels to each of the plurality of vulnerabilities, wherein each fingerprint of the set of fingerprints is associated with a respective vulnerability of the plurality of vulnerabilities, wherein each label of each set of labels indicates at least one of a particular parameter or a particular attribute of the respective vulnerability;
generating a set of reduced fingerprints by performing one or more dimensionality reduction operations on each set of labels of each respective fingerprint, wherein each reduced fingerprint comprises a value configured to retain at least a portion of the information from the respective fingerprint;
generating a coordinate system based on the set of reduced fingerprints;
generating a predictive model comprising the coordinate system and one or more overlays applied on the coordinate system by identifying one or more groups of reduced fingerprints based on one or more determined correlations, wherein each overlay corresponds to a respective group of the one or more groups of reduced fingerprints, and assigning a ransomware likelihood rating to each overlay based on ransomware events data, wherein the ransomware likelihood rating indicates a likelihood that a vulnerability within the respective group will be used in a ransomware event;
receiving a new vulnerability;
generating a new fingerprint for the new vulnerability;
generating, from the new fingerprint, a reduced fingerprint for the new vulnerability;
determining a position, on the coordinate system, of the reduced fingerprint; and
determining a rating for the new vulnerability based on the position on the coordinate system, wherein the rating reflects a likelihood of the new vulnerability being used in a ransomware event.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the rating is determined based on identifying a center of the group of reduced fingerprints in relation to the coordinate system.
15 . The non-transitory computer readable storage medium of claim 13 , wherein the group is identified using ransomware event data.
16 . The non-transitory computer readable storage medium of claim 13 , wherein each fingerprint of the set of fingerprints is a n-dimension binary array.
17 . The non-transitory computer readable storage medium of claim 13 , wherein each value comprises a pair of principal components.