IP Library › Granted Patent US 10,116,682
Granted Patent B2
US 10,116,682 · App. 15/611,495 · Granted Oct 30, 2018

System and method for evaluating and enhancing the security level of a network system

Inventor: Jacques Remi Francoeur (Los Gatos, CA)
Assignee: SPHERIC SECURITY SOLUTIONS
H04L63/1433G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,682
App. No.
15/611,495
Granted
Oct 30, 2018
Kind
B2
Abstract

Examples described herein provide for a system that evaluates a security level of a network system. Additionally, examples described herein evaluate a security level of a network system in order to enable a determination of components that can be used to enhance the security level of the network system.

Claims (41)

1. A method for evaluating a security level of a network system, the method being implemented by one or more processors and comprising:

identifying a plurality of security elements of the network system;

determining a security architecture of the network system based on the identified plurality of security elements;

wherein determining the security architecture includes implementing a security model that identifies a plurality of pre-determined relationships as between individual security elements in the plurality of security elements, in connection with possible types of threats to the network system and one or more types of assets that can be exposed as a result of a breach;

evaluating the security architecture to determine an evaluation for the network system, the evaluation identifying a monetary value for a risk to the security network as a result of one or more security elements being breached;

determining a set of recommendations based at least in part on the evaluation, each recommendation in the set of recommendations identifying a new component to add to the security network to improve the evaluation of the security architecture;

wherein determining the set of recommendations includes determining the new component based at least in part on both the cost for implementing the new component on the network system as compared to the monetary value for the breach if the new component is not implemented; and

outputting the evaluation to a user, wherein the output includes the determined set of recommendations.

2. The method of claim 1 , wherein each element in the plurality of identified elements corresponds to one of a component, a component class, a process or a capability.

3. The method of claim 1 , wherein identifying the plurality of security elements incudes providing the user with one or more prompts to enter input regarding the plurality of security elements in accordance with the security model.

4. The method of claim 1 , wherein evaluating the security architecture includes determining a parameter score for individual security elements in the plurality of identified security elements.

5. The method of claim 4 , wherein the parameter score is based at least in part on a measure of effectiveness for the individual security elements of the plurality of security elements.

6. The method of claim 4 , wherein the parameter score is based at least in part on a measure of coverage for the individual security elements of the plurality of security elements.

7. The method of claim 4 , wherein the parameter score is based at least in part on a measure of maturity for the individual security elements of the plurality of security elements.

8. The method of claim 4 , wherein evaluating the security architecture includes determining a protection index for the security architecture based on the parameter score for the individual security elements in the plurality of identified security elements.

9. The method of claim 1 , further comprising updating the security architecture to include the new component.

10. The method of claim 1 , wherein updating the security architecture includes repeating each of evaluating the security architecture and outputting the evaluation, for the updated security architecture.

11. The method of claim 1 , further comprising receiving a budget from the user, and wherein determining the set of recommendations includes selecting the new component based on the cost for implementing the new component on the network system.

12. The method of claim 1 , wherein determining the new component includes determining the monetary in connection with a risk to the security network as a result of the new component being breached as compared to the monetary value for the risk to the security network as a result of one or more other comparable components being alternatively implemented on the network system.

13. The method of claim 1 , wherein determining the monetary value includes identifying a plurality of assets of the network system that are to be protected by the plurality of security elements.

14. The method of claim 1 , wherein identifying the one or more assets includes prompting the user to enter information that identifies the plurality of assets, the plurality of assets including one or more hardware assets and/or one or more information assets.

15. The method of claim 1 , wherein outputting the evaluation for the user includes outputting a visual of the security model.

16. The method of claim 1 , wherein the visual of the security model includes a multi-dimensional sphere that arranges the plurality of security elements based at least in part on the plurality of pre-determined relationships.

17. A non-transitory computer-readable medium that stores instructions for evaluating the security level of a network system, the instructions being executable by one or more processors to cause the one or more processors to perform operations that include:

identifying a plurality of security elements of the network system;

determining a security architecture of the network system based on the identified plurality of security elements;

wherein determining the security architecture includes implementing a security model that identifies a plurality of pre-determined relationships as between individual security elements in the plurality of security elements, in connection with possible types of threats to the network system and one or more types of assets that can be exposed as a result of a breach;

evaluating the security architecture to determine an evaluation for the network system, the evaluation identifying a monetary value for a risk to the security network as a result of one or more security elements being breached;

determining a set of recommendations based at least in part on evaluating the security architecture, each recommendation in the set of recommendations identifying a new component to add to the security network to improve the evaluation of the security architecture;

wherein determining the set of recommendations includes determining the new component based at least in part on both the cost for implementing the new component on the network system as compared to the monetary value for the breach if the new component is not implemented; and

outputting the evaluation to a user, wherein the output includes the determined set of recommendations.

18. A computer system comprising:

a memory that stores a set of instructions;

one or more processors that access the instructions in the memory to:

identify a plurality of security elements of the network system;

determine a security architecture of the network system based on the identified plurality of security elements;

wherein the one or more processors determine the security architecture by implementing a security model that identifies a plurality of pre-determined relationships as between individual security elements in the plurality of security elements, in connection with possible types of threats to the network system and one or more types of assets that can be exposed as a result of a breach;

evaluate the security architecture to determine an evaluation for the network system, the evaluation identifying a monetary value for a risk to the security network as a result of one or more security elements being breached;

determine a set of recommendations based at least in part on evaluating the security architecture, each recommendation in the set of recommendations identifying a new component to add to the security network to improve the evaluation of the security architecture;

wherein the one or more processors determine the set of recommendations by determining the new component based at least in part on both the cost for implementing the new component on the network system as compared to the monetary value for the breach if the new component is not implemented; and

output the evaluation to a user, wherein the output includes the determined set of recommendations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2019
From: SPHERIC SECURITY SOLUTIONS
To: SECURITY INCLUSION NOW USA LLC
Reel/Frame 051329/0534 →
Continuity (4)
Continuation 15041923 · Feb 11, 2016
Continuation 14148685 · Jan 6, 2014
Provisional Application 61749357 · Jan 6, 2013
Related Publication 20170324764A1 · Nov 9, 2017