IP Library Granted Patent US 10,313,385
Granted Patent B2
US 10,313,385 · App. 15/362,730 · Granted Jun 4, 2019

Systems and methods for data driven game theoretic cyber threat mitigation

Inventors: Paulo Shakarian (Chandler, AZ); John Robertson (Prescott, AZ); Jana Shakarian (Chandler, AZ); Vivin Paliath (Chandler, AZ); Amanda Thart (Scottsdale, AZ)
Assignee: Arizona Board of Regents on Behalf of Arizona State University
H04L63/1433G06Q30/0201H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,313,385
App. No.
15/362,730
Granted
Jun 4, 2019
Kind
B2
Abstract

System and methods for a data-driven security game framework that models an attacker based on exploit market data actively mined from the darknet to develop strategies for the defender are disclosed.

Claims (42)

1. A system for protecting a computer system from attack, the system comprising:

a network connection;

a processing device; and

a non-transitory computer-readable medium connected to the processing device configured to store instructions that, when executed by the processing device, performs the operations of:

accessing data through the network connection, the data comprising dark net information associated with exploits of a computer system, comprising:

obtaining a set of exploits from the dark net information, the set of exploits configured to penetrate the computer system;

applying an exploit function which takes the set of exploits as input and returns a set of vulnerabilities;

creating a constraint set of the computer system from the set of vulnerabilities, the constraint set comprising a minimum set of dependencies to operate the computer system;

applying the set of exploits to the constraint set of the computer system;

analyzing the application of the set of exploits on the computer system to detect a particular vulnerability of the computer system; and

altering a configuration of the computer system in response to the analysis of the application of the set of exploits to reduce potential damage of a cyberattack.

2. The system of claim 1 , wherein analyzing the application of the set of exploits on the computer system comprises quantifying a risk level posed to the computer system related to a cost to obtain the set of exploits.

3. The system of claim 2 , wherein the processing device further performs the operation of:

aligning Internet data with the constraint set of vulnerabilities based on information obtained about the set of exploits.

4. The system of claim 3 , wherein obtaining a set of exploits through the network connection comprises:

applying one or more algorithms to obtain the set of exploits.

5. The system of claim 4 , wherein the one or more algorithms determine the cost to obtain the set of exploits to create a budget and obtains the set of exploits constrained by the determined cost to obtain the set of exploits.

6. The system of claim 5 , wherein obtaining the set of exploits is based on maximizing the quantifying of the risk level posed to the computer system related to the cost to obtain the set of exploits.

7. The system of claim 1 , wherein altering the configuration of the computer system comprises removing a software component of the computer system that is utilized by the set of exploits to attack the computer system.

8. A method for improving a computing device, the method comprising:

accessing data comprising dark net information associated with a computer system;

obtaining a set of exploits from the dark net information, the set of exploits configured to bypass a security feature of the computer system;

applying an exploit function which takes the set of exploits as input and returns a set of vulnerabilities;

creating a constraint set of vulnerabilities of the computer system from the set of vulnerabilities comprising a minimum set of dependencies to operate the computer system, wherein application of the set of exploits on the computer system comprises determining the effect of the set of exploits on the constraint set of vulnerabilities of the computer system;

analyzing an application associated with the set of exploits on the computer system to detect a particular vulnerability of the constraint set of vulnerabilities of the computer system; and

altering a configuration of the computer system in response to the analysis of the application of the set of exploits to reduce potential damage of a cyberattack.

9. The method of claim 8 , wherein analyzing the application of the set of exploits on the computer system comprises quantifying a risk level posed to the computer system related to a cost to obtain the set of exploits.

10. The method of claim 9 , wherein obtaining a set of exploits comprises:

applying one or more algorithms to obtain the set of exploits based on the constraint set of vulnerabilities of the computer system from one or more darknet marketplaces on the Internet.

11. The method of claim 10 , wherein the one or more algorithms determine the cost to obtain the set of exploits to create a budget and obtains the set of exploits constrained by the determined cost to obtain the set of exploits.

12. The method of claim 11 , wherein obtaining the set of exploits is based on maximizing the quantifying of the risk level posed to the computer system related to the cost to obtain the set of exploits.

13. The method of claim 8 , wherein altering the configuration of the computer system comprises removing a software component of the computer system that is utilized by the set of exploits to attack the computer system.

14. The method of claim 8 , wherein altering the configuration of the computer system comprises installing a patch to a software component of the computer system that is exposed by the set of exploits to attack the computer system.

15. One or more non-transitory tangible computer-readable storage media storing computer-executable instructions for performing a computer process on a machine, the computer process comprising:

obtaining a set of exploits from dark net information, the set of exploits configured to bypass a security feature of a computer system;

applying an exploit function which takes the set of exploits as input and returns a set of vulnerabilities;

creating a constraint set of vulnerabilities of the computer system from the set of vulnerabilities comprising a minimum set of dependencies to operate the computer system;

applying the set of exploits to the constraint set of vulnerabilities of the computer system;

analyzing the application of the set of exploits on the computer system to detect a particular vulnerability of the computer system; and

altering a configuration of the computer system in response to the analysis of the application of the set of exploits to reduce potential damage of a cyberattack.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein analyzing the application of the set of exploits on the computer system comprises quantifying a risk level posed to the computer system related to a cost to obtain the set of exploits.

17. The one or more non-transitory computer-readable storage media of claim 15 , wherein obtaining a set of exploits comprises applying one or more algorithms to obtain the set of exploits from one or more darknet marketplaces on the Internet.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2025
From: ARIZONA BOARD OF REGENTS ON BEHALF OF ARIZONA STATE UNIVERSITY
To: SKYSONG INNOVATIONS, LLC
Reel/Frame 070067/0096 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2016
From: SHAKARIAN, PAULO; ROBERTSON, JOHN; SHAKARIAN, JANA; PALIATH, VIVIN; THART, AMANDA
To: ARIZONA BOARD OF REGENTS ON BEHALF OF ARIZONA STATE UNIVERSITY
Reel/Frame 041165/0676 →
Continuity (2)
Provisional Application 62261200 · Nov 30, 2015
Related Publication 20170155677A1 · Jun 1, 2017
Cited By (3)
US 12,355,804 US 12,380,221 US 12,436,827