IP Library Granted Patent US 11,277,431
Granted Patent B2
US 11,277,431 · App. 16/454,729 · Granted Mar 15, 2022

Comprehensive risk assessment

Inventors: Daniel Trivellato (Eindhoven, NL); Emmanuele Zambon-Mazzocato (Helmond, NL)
Assignee: Forescout Technologies, Inc.
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,431
App. No.
16/454,729
Granted
Mar 15, 2022
Kind
B2
Abstract

Systems, methods, and related technologies for determining a comprehensive risk score or value are described. The risk score determination may include selecting an entity communicatively coupled to a network and determining a cyber-attack likelihood value and a cyber-attack impact value associated with the entity. A cyber-attack risk may then be determined based on the cyber-attack likelihood value and a cyber-attack impact value associated with the entity. An operational failure likelihood value and an operational failure impact value associated with the entity can be determined. An operational failure risk based on the operational failure likelihood value and the operational failure impact value associated with the entity can be determined. A risk value may then be determined for the entity based on the cyber-attack risk and the operational failure risk and the risk value for the entity can be stored.

Claims (55)

1. A method comprising:

performing, for each of a plurality of entities, a following comprising:

selecting an entity of the plurality of entities communicatively coupled to a network;

determining a cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determining a cyber-attack risk based on the cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determining an operational failure likelihood value and an operational failure impact value associated with the entity;

determining an operational failure risk based on the operational failure likelihood value and the operational failure impact value associated with the entity;

determining a risk value for the entity based on the cyber-attack risk and the operational failure risk;

storing the risk value for the entity;

determining a risk value for a location based on the plurality of risk values associated with the plurality of entities; and

performing a remediation action based on the risk value for the location, wherein the remediation action comprises at least one of changing network access of the entity, initiating a patch for the entity, or updating the entity.

2. The method of claim 1 , wherein the cyber-attack likelihood value is based on at least one of an alert, a vulnerability, a direct connection with a public entity, or a proximity to an infected or vulnerable entity.

3. The method of claim 1 , wherein the cyber-attack impact value is based on at least one of entity criticality, network criticality, or proximity to a critical entity.

4. The method of claim 1 , wherein the operational failure likelihood value is based on an alert.

5. The method of claim 1 , wherein the operational failure impact value is based on at least one of an entity criticality, a network criticality, or proximity to a critical entity.

6. The method of claim 1 , wherein the risk value for the entity is a maximum of the cyber-attack risk and the operational failure risk.

7. The method of claim 1 further comprising:

determining a risk value for a location based on a plurality of risk values associated with a plurality of entities associated with the location.

8. The method of claim 7 , wherein the location is at least one of a geographic region, a plant, a network, or a network segment.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

perform for each of a plurality of entities:

select an entity of the plurality of entities communicatively coupled to a network;

determine a cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determine a cyber-attack risk based on the cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determine an operational failure likelihood value and an operational failure impact value associated with the entity;

determine an operational failure risk based on the operational failure likelihood value and the operational failure impact value associated with the entity;

determine a risk value for the entity based on the cyber-attack risk and the operational failure risk;

store the risk value for the entity;

determine a risk value for a location based on the plurality of risk values associated with the plurality of entities; and

perform a remediation action based on the risk value for the location, wherein the remediation action comprises at least one of changing network access of the entity, initiating a patch for the entity, or updating the entity.

10. The system of claim 9 , wherein the cyber-attack likelihood value is based on at least one of an alert, a vulnerability, a direct connection with a public entity, or a proximity to an infected or vulnerable entity.

11. The system of claim 9 , wherein the cyber-attack impact value is based on at least one of entity criticality, network criticality, or proximity to a critical entity.

12. The system of claim 9 , wherein the operational failure likelihood value is based on an alert.

13. The system of claim 9 , wherein the operational failure impact value is based on at least one of an entity criticality, a network criticality, or proximity to a critical entity.

14. The system of claim 9 , wherein the risk value for the entity is a maximum of the cyber-attack risk and the operational failure risk.

15. The system of claim 9 , wherein the processing device further to:

determine a risk value for a location based on a plurality of risk values associated with a plurality of entities associated with the location.

16. The system of claim 15 , wherein the risk value for the entity is a maximum of the cyber-attack risk and the operational failure risk.

17. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

perform for each of a plurality of entities:

select an entity communicatively coupled to a network;

determine a cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determine a cyber-attack risk based on the cyber-attack likelihood value and a cyber-attack impact value associated with the entity;

determine an operational failure likelihood value and an operational failure impact value associated with the entity;

determine an operational failure risk based on the operational failure likelihood value and the operational failure impact value associated with the entity;

determine a risk value for the entity based on the cyber-attack risk and the operational failure risk;

store the risk value for the entity; and

determine a risk value for a location based on the plurality of risk values associated with the plurality of entities; and

perform a remediation action based on the risk value for the location, wherein the remediation action comprises at least one of changing network access of the entity, initiating a patch for the entity, or updating the entity.

18. The non-transitory computer readable medium of claim 17 , wherein the cyber-attack likelihood value is based on at least one of an alert, a vulnerability, a direct connection with a public entity, or a proximity to an infected or vulnerable entity.

19. The non-transitory computer readable medium of claim 17 , wherein the cyber-attack impact value is based on at least one of entity criticality, network criticality, or proximity to a critical entity.

20. The non-transitory computer readable medium of claim 17 , wherein the operational failure likelihood value is based on an alert.

21. The non-transitory computer readable medium of claim 17 , wherein the operational failure impact value is based on at least one of an entity criticality, a network criticality, or proximity to a critical entity.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2019
From: TRIVELLATO, DANIEL; ZAMBON-MAZZOCATO, EMMANUELE
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 049624/0524 →
Continuity (1)
Related Publication 20200412758A1 · Dec 31, 2020
Cited By (9)
US 12,231,461 US 12,284,200 US 12,289,336 US 12,335,296 US 12,348,552 US 12,355,798 US 12,470,591 US 12,476,994 US 12,608,484