IP Library Granted Patent US 10,887,324
Granted Patent B2
US 10,887,324 · App. 15/709,008 · Granted Jan 5, 2021

Threat scoring system and method

Inventors: Yasuyuki Kataoka (Palo Alto, CA); Douglas Junkins (Palo Alto, CA)
Assignee: NTT RESEARCH, INC.
H04L63/1416G06F21/552G06F21/577H04L63/1491G06N5/003G06N20/00H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,887,324
App. No.
15/709,008
Granted
Jan 5, 2021
Kind
B2
Abstract

A threat scoring system and method are provided in which the threat scoring system and method generates a better threat score. In one embodiment, the system and method may accept threat factors, accept weighting of the threat factors, generate a ground truth and generate a threat scoring using analytics based in part on the generated ground truth.

Claims (20)

1. A threat scoring system, comprising:

a threat scoring computer system having a processor, memory and a plurality of lines of instructions configured to:

select a plurality of threat factors, each threat factor being data about a cyber-threat attack, by generating a user interface with a list of threat factors, and selecting, by a user, the plurality of threat factors from the list of threat factors, the list of threat factors including a number of attacks, a diversity of sensors, and a honey pot detection;

assign a user defined weight to each selected threat factor to generate a plurality of weighted threat factors, wherein the user defined weight for each particular threat factor is determined by specifying an importance of the particular threat factor relative to another threat factor and by computing a reciprocal matrix containing the user defined weights of the selected threat factors;

generate a normalized weight from the plurality of weighted threat factors and generate a ground truth score for each of the plurality of weighted threat factors; and

determine a threat score using machine learning on the plurality of weighted threat factors.

2. The system of claim 1 , wherein the threat scoring computer system is further configured to scale each of the selected plurality of threat factors so that each threat factor has a score between 0 and 1.

3. The system of claim 1 , wherein the threat scoring computer system is further configured to use a regression model using the ground truth scores.

4. The system of claim 3 , wherein the threat scoring computer system is further configured to use one of logistic regression, deep learning and random forest.

5. The system of claim 4 , wherein the threat scoring computer system is further configured to generate a performance evaluation for the threat score.

6. The system of claim 5 , wherein the threat scoring computer system is further configured to determine a root mean squared error.

7. A threat scoring method, comprising:

selecting a plurality of threat factors, each threat factor being data about a cyber-threat attack, by generating a user interface with a list of threat factors and selecting, by a user, the plurality of threat factors from the list of threat factors, the list of threat factors including a number of attacks, a diversity of sensors, and a honey pot detection;

assigning a user defined weight to each selected threat factor to generate a plurality of weighted threat factors, wherein the user defined weight for each particular threat factor is determined by specifying an importance of the particular threat factor relative to another threat factor, wherein assigning the user defined weight to each selected threat factor further comprises computing a reciprocal matrix containing the user defined weights for each threat factor and generating a normalized weight from the plurality of weighted threat factors and generating a ground truth score for each of the plurality of weighted threat factors; and

determining a threat score using machine learning on the plurality of weighted threat factors.

8. The method of claim 7 , wherein selecting the plurality of threat factors further comprises scaling each of the selected plurality of threat factors so that each threat factor has a score between 0 and 1.

9. The method of claim 7 , wherein determining the threat score using machine learning further comprises using a regression model using the ground truth scores.

10. The method of claim 9 , wherein using a regression model further comprises using one of logistic regression, deep learning and random forest.

11. The method of claim 10 further comprising generating a performance evaluation for the threat score.

12. The method of claim 11 , wherein generating the performance evaluation further comprises determining a root mean squared error.

Assignments (2)
CHANGE OF NAME Recorded Apr 14, 2020
From: NTT INNOVATION INSTITUTE, INC.
To: NTT RESEARCH, INC.
Reel/Frame 052396/0582 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2018
From: KATAOKA, YASUYUKI; JUNKINS, DOUGLAS
To: NTT INNOVATION INSTITUTE, INC.
Reel/Frame 045579/0715 →
Continuity (2)
Provisional Application 62396591 · Sep 19, 2016
Related Publication 20180083988A1 · Mar 22, 2018
Cited By (1)
US 12,406,185