IP Library Granted Patent US 10,333,963
Granted Patent B2
US 10,333,963 · App. 15/338,192 · Granted Jun 25, 2019

Identifying a vulnerability of an asset of a network infrastructure to mitigate

Inventors: Jonathan Pope (London, GB); Lewis Guignard (Charlotte, NC); Thomas Beale (San Francisco, CA)
Assignee: Corax Cyber Security, Inc.
H04L63/1433G06F21/577H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,963
App. No.
15/338,192
Granted
Jun 25, 2019
Kind
B2
Abstract

A first vulnerability that is associated with one or more nodes of a network graph that represent one or more assets of a network infrastructure may be identified. Furthermore, a second vulnerability that is associated with one or more nodes of the network graph may be identified. A determination may be made as to whether the first vulnerability or the second vulnerability contributes more to a probability of a security breach associated with the network infrastructure. A notification may be provided to mitigate the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

Claims (49)

1. A method comprising:

identifying a first vulnerability that is associated with one or more nodes of a network graph that represent one or more assets of a network infrastructure;

identifying a second vulnerability that is associated with one or more nodes of the network graph that represent one or more assets of the network infrastructure;

determining, by a processing device, whether the first vulnerability or the second vulnerability contributes more to a probability of a security breach associated with the network infrastructure by:

determining a first group of nodes of the network graph that are assigned the first vulnerability and a second group of nodes of the network graph that are assigned the second vulnerability;

receiving a first value assigned to each node of the first group of nodes of the network graph that is assigned the first vulnerability and a second value assigned to each node of the second group of nodes of the network graph that is assigned the second vulnerability;

modifying a first group of conditional probability tables for each node of the first group of nodes by reducing values of the first group of conditional probability tables based on the first value; and

modifying a second group of conditional probability tables for each node of the second group of nodes by reducing values of the second group of conditional probability tables based on the second value; and

providing a notification of a hardware change or a software change associated with the one or more assets of the network infrastructure to mitigate the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

2. The method of claim 1 , wherein the determining of whether the first vulnerability or the second vulnerability contributes more to the probability of the security breach further comprises:

calculating a first probability of the successful security breach when the first group of conditional probability tables are modified by using a joint probability function with the network graph and a second probability of the successful security breach when the second group of conditional probability tables are modified by using the joint probability function with the network graph.

3. The method of claim 1 , wherein the first value and the second value each correspond to a characteristic of the respective first or second vulnerability and a type of asset corresponding to the respective node.

4. The method of claim 1 , further comprising:

identifying a control to mitigate the vulnerability that contributes more to the probability of the security breach, wherein the control is based on the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

5. The method of claim 4 , wherein the control corresponds to a software or hardware change to the one or more assets of the network infrastructure that are represented by the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach.

6. The method of claim 1 , wherein the network graph is a Bayesian network.

7. A non-transitory computer readable medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

identifying a first vulnerability that is associated with one or more nodes of a network graph that represent one or more assets of a network infrastructure;

identifying a second vulnerability that is associated with one or more nodes of the network graph that represent one or more assets of the network infrastructure;

determining whether the first vulnerability or the second vulnerability contributes more to a probability of a security breach associated with the network infrastructure by:

determining a first group of nodes of the network graph that are assigned the first vulnerability and a second group of nodes of the network graph that are assigned the second vulnerability;

receiving a first value assigned to each node of the first group of nodes of the network graph that is assigned the first vulnerability and a second value assigned to each node of the second group of nodes of the network graph that is assigned the second vulnerability;

modifying a first group of conditional probability tables for each node of the first group of nodes by reducing values of the first group of conditional probability tables based on the first value; and

modifying a second group of conditional probability tables for each node of the second group of nodes by reducing values of the second group of conditional probability tables based on the second value; and

providing a notification of a hardware change or a software change associated with the one or more assets of the network infrastructure to mitigate the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

8. The non-transitory computer readable medium of claim 7 , wherein to determine whether the first vulnerability or the second vulnerability contributes more to the probability of the security breach, the operations further comprise:

calculating a first probability of the successful security breach when the first group of conditional probability tables are modified by using a joint probability function with the network graph and a second probability of the successful security breach when the second group of conditional probability tables are modified by using the joint probability function with the network graph.

9. The non-transitory computer readable medium of claim 7 , wherein the first value and the second value each correspond to a characteristic of the respective first or second vulnerability and a type of asset corresponding to the respective node.

10. The non-transitory computer readable medium of claim 7 , the operations further comprising:

identifying a control to mitigate the vulnerability that contributes more to the probability of the security breach, wherein the control is based on the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

11. The non-transitory computer readable medium of claim 10 , wherein the control corresponds to a software or hardware change to the one or more assets of the network infrastructure that are represented by the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach.

12. The non-transitory computer readable medium of claim 7 , wherein the network graph is a Bayesian network.

13. A system comprising:

a memory; and

a processing device, operatively coupled with the memory, to:

identify a first vulnerability that is associated with one or more nodes of a network graph that represent one or more assets of a network infrastructure;

identify a second vulnerability that is associated with one or more nodes of the network graph that represent one or more assets of the network infrastructure;

determine whether the first vulnerability or the second vulnerability contributes more to a probability of a security breach associated with the network infrastructure by:

determining a first group of nodes of the network graph that are assigned the first vulnerability and a second group of nodes of the network graph that are assigned the second vulnerability;

receiving a first value assigned to each node of the first group of nodes of the network graph that is assigned the first vulnerability and a second value assigned to each node of the second group of nodes of the network graph that is assigned the second vulnerability;

modifying a first group of conditional probability tables for each node of the first group of nodes by reducing values of the first group of conditional probability tables based on the first value; and

modifying a second group of conditional probability tables for each node of the second group of nodes by reducing values of the second group of conditional probability tables based on the second value; and

provide a notification of a hardware change or a software change associated with the one or more assets of the network infrastructure to mitigate the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

14. The system of claim 13 , wherein to determine whether the first vulnerability or the second vulnerability contributes more to the probability of the security breach, the processing device is further to:

calculate a first probability of the successful security breach when the first group of conditional probability tables are modified by using a joint probability function with the network graph and a second probability of the successful security breach when the second group of conditional probability tables are modified by using the joint probability function with the network graph.

15. The system of claim 13 , wherein the first value and the second value each correspond to a characteristic of the respective first or second vulnerability and a type of asset corresponding to the respective node.

16. The system of claim 13 , wherein the processing device is further to:

identify a control to mitigate the vulnerability that contributes more to the probability of the security breach, wherein the control is based on the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.

17. The system of claim 16 , wherein the control corresponds to a software or hardware change to the one or more assets of the network infrastructure that are represented by the one or more nodes of the network graph that are associated with the vulnerability that contributes more to the probability of the security breach.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2020
From: WELLS MARKET SQUARE MANAGEMENT COMPANY, LLC
To: QUANTUM FORT, INC.
Reel/Frame 054762/0383 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2020
From: CORAX CYBER SECURITY LTD; TAYLOR, DAVID RONALD; ELLISON, PAUL WILLIAM
To: WELLS MARKET SQUARE MANAGEMENT LLC
Reel/Frame 054667/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2016
From: POPE, JONATHAN; GUIGNARD, LEWIS; BEALE, THOMAS
To: CORAX CYBER SECURITY, INC.
Reel/Frame 040512/0265 →
Continuity (1)
Related Publication 20180124092A1 · May 3, 2018