IP Library Granted Patent US 10,944,778
Granted Patent B1
US 10,944,778 · App. 15/795,967 · Granted Mar 9, 2021

Method and system for implementing risk based cyber security

Inventors: Oron Golan (Meitar, IL); Assaf Natanzon (Tel Aviv, IL); Amit Lieberman (Raanana, IL); Yuri Manusov (Beer Sheva, IL); Raul Shnier (Kibbutz Ruhama, IL)
Assignee: EMC IP Holding Company LLC
H04L63/1433G06F21/566G06F21/577H04L63/1416G06F21/552G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,944,778
App. No.
15/795,967
Granted
Mar 9, 2021
Kind
B1
Abstract

A method and system for implementing risk-based cyber security. Specifically, the disclosed method and system entail evaluating risk as a decision threshold for conducting cyber security assessments of system images within cloud computing environments. Further, the disclosed method and system pivot on intelligence pertaining to the latest cyber threats and/or vulnerabilities found worldwide.

Claims (74)

1. A method for measuring cyber security risk, comprising:

selecting a set of application granularity images (AGIs);

compiling an environment properties list (EPL) derived from the set of AGIs;

obtaining relevant attack information (RAI) based on the EPL;

computing an attack risk metric (ARM) using at least a portion of the RAI;

making a determination that the ARM exceeds an attack risk threshold;

based on the determination:

restoring the set of AGIs within a restored image environment (RIE), wherein the RIE is an isolated cloud computing environment, wherein the set of restored AGIs execute on the isolated cloud computing environment, wherein the isolated cloud computing environment limits access to the RIE from one or more external sources or other RIEs except for an available one or more ports through which an authorized RIE manager monitors the RIE;

administering a known cyber security attack to the set of AGIs restored within the RIE; and

monitoring the set of AGIs administered with the known cyber security attack to compile a cyber attack assessment (CAA).

2. The method of claim 1 , wherein the set of AGIs represents one selected from a group consisting of a computer process, an application comprising a plurality of computer processes, and a plurality of applications comprising a plurality of mutually exclusive sets of computer processes.

3. The method of claim 1 , wherein the EPL specifies at least one selected from a group consisting of a hardware component installed on a computing system and a software component installed on the computing system, wherein the set of AGIs is based on at least a portion of the computing system.

4. The method of claim 3 , wherein the RAI specifies metadata describing at least one known cyber security attack that targets the at least one selected from the group consisting of the hardware component installed on the computing system and the software component installed on the computing system.

5. The method of claim 1 , further comprising:

obtaining relevant vulnerability information (RVI) based on the EPL; and

computing a vulnerability risk metric (VRM) using at least a portion of the RVI.

6. The method of claim 5 , wherein the RVI specifies metadata describing at least one cyber security vulnerability that is exhibited by at least one selected from a group consisting of a hardware component installed on a computing system and a software component installed on the computing system, wherein the set of AGIs is based on at least a portion of the computing system.

7. The method of claim 5 , further comprising:

determining that the VRM exceeds a vulnerability risk threshold;

based on the determining:

instantiating RIE;

configuring the RIE through restoration of the set of AGIs therein;

identifying a potential threat signature (PTS) exhibited by the set of AGIs while restored in the RIE;

matching the PTS to a known cyber security threat signature; and

based on the matching, compiling a cyber vulnerability assessment (CVA).

8. A system, comprising:

a data repository; and

a cyber security service (CSS) operatively connected to the data repository, and programmed to:

select a set of application granularity images (AGIs) stored in the data repository;

compile an environment properties list (EPL) derived from the set of AGIs;

obtain relevant attack information (RAI) based on the EPL;

compute an attack risk metric (ARM) using at least a portion of the RAI;

make a determination that the ARM exceeds an attack risk threshold;

based on the determination:

restore the set of AGIs within a restored image environment (RIE), wherein the RIE is an isolated cloud computing environment, wherein the set of restored AGIs execute on the isolated cloud computing environment, wherein the isolated cloud computing environment is configured to limit access to the RIE from one or more external sources or other RIEs except for an available one or more ports through which an authorized RIE manager monitors the RIE;

administer a known cyber security attack to the set of AGIs restored within the RIE; and

monitor the set of AGIs administered with the known cyber security attack to compile a cyber attack assessment (CAA).

9. The system of claim 8 , further comprising:

a disaster recovery platform (DRP) comprising the data repository and the CSS.

10. The system of claim 8 , further comprising:

an attack monitoring service (AMS) operatively connected to the CSS, and programmed to:

track intelligence on at least one latest cyber security attack; and

share the intelligence with the CSS,

wherein the at least one latest cyber security attack targets at least one selected from a group consisting of a hardware component and a software component, specified in the EPL.

11. The system of claim 8 , further comprising:

a vulnerability monitoring service (VMS) operatively connected to the CSS, and programmed to:

track intelligence on at least one latest cyber security vulnerability; and

share the intelligence with the CSS,

wherein the at least one latest cyber security vulnerability resides on at least one selected from a group consisting of a hardware component and a software component, specified in the EPL.

12. A non-transitory computer readable medium (CRM) comprising computer readable program code, which when executed by a computer processor, enables the computer processor to:

select a set of application granularity images (AGIs);

compile an environment properties list (EPL) derived from the set of AGIs;

obtain relevant attack information (RAI) based on the EPL;

compute an attack risk metric (ARM) using at least a portion of the RAI;

make a determination that the ARM exceeds an attack risk threshold;

based on the determination:

restore the set of AGIs within a restored image environment (RIE), wherein the RIE is an isolated cloud computing environment, wherein the set of restored AGIs execute on the isolated cloud computing environment, wherein the isolated cloud computing environment limits access to the RIE from one or more external sources or other RIEs except for an available one or more ports through which an authorized RIE manager monitors the RIE;

administer a known cyber security attack to the set of AGIs restored within the RIE; and

monitor the set of AGIs administered with the known cyber security attack to compile a cyber attack assessment (CAA).

13. The non-transitory CRM of claim 12 , wherein the set of AGIs represents one selected from a group consisting of a computer process, an application comprising a plurality of computer processes, and a plurality of applications comprising a plurality of mutually exclusive sets of computer processes.

14. The non-transitory CRM of claim 12 , wherein the EPL specifies at least one selected from a group consisting of a hardware component installed on a computing system and a software component installed on the computing system, wherein the set of AGIs is based on at least a portion of the computing system.

15. The non-transitory CRM of claim 14 , wherein the RAI specifies metadata describing at least one known cyber security attack that targets the at least one selected from the group consisting of the hardware component installed on the computing system and the software component installed on the computing system.

16. The non-transitory CRM of claim 12 , further comprising computer readable program code, which when executed by the computer processor, enables the computer processor to:

obtain relevant vulnerability information (RVI) based on the EPL; and

compute a vulnerability risk metric (VRM) using at least a portion of the RVI.

17. The non-transitory CRM of claim 16 , wherein the RVI specifies metadata describing at least one cyber security vulnerability that is exhibited by at least one selected from a group consisting of a hardware component installed on a computing system and a software component installed on the computing system, wherein the set of AGIs is based on at least a portion of the computing system.

18. The non-transitory CRM of claim 16 , further comprising computer readable program code, which when executed by the computer processor, enables the computer processor to:

determine that the VRM exceeds a vulnerability risk threshold;

based on the determining:

instantiate RIE;

configure the RIE through restoration of the set of AGIs therein;

identify a potential threat signature (PTS) exhibited by the set of AGIs while restored in the RIE;

match the PTS to a known cyber security threat signature; and

based on the matching, compile a cyber vulnerability assessment (CVA).

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (044535/0109) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0414 →
RELEASE OF SECURITY INTEREST AT REEL 044535 FRAME 0001 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0475 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2018
From: LIEBERMAN, AMIT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045964/0127 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2018
From: GOLAN, ORON; NATANZON, ASSAF; MANUSOV, YURI; SHNIER, RAUL
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045944/0937 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 044535/0109 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 044535/0001 →
Cited By (23)
US 12,204,930 US 12,235,969 US 12,355,787 US 12,363,148 US 12,368,746 US 12,375,573 US 12,401,670 US 12,411,939 US 12,464,003 US 12,470,577 US 12,470,578 US 12,481,566 US 12,483,576 US 12,489,770 US 12,500,911 US 12,513,221 US 12,537,837 US 12,537,839 US 12,556,548 US 12,587,553 US 12,659,326 US 12,689,638 US 12,706,932