IP Library Granted Patent US 11,886,598
Granted Patent B2
US 11,886,598 · App. 17/174,307 · Granted Jan 30, 2024

System and method for scalable cyber-risk assessment of computer systems

Inventors: Candan Bolukbas (Stone Ridge, VA); Robert Maley (Chandler, AZ); Ferhat Dikbiyik (Sakarya, TR)
Assignee: NormShield, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,598
App. No.
17/174,307
Granted
Jan 30, 2024
Kind
B2
Abstract

A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.

Claims (30)

1. A method of cyber risk assessment, the method comprising:

a) receiving a request for a quantitative cyber risk assessment of an entity associated with a domain name;

b) discovering a digital footprint of the entity based on the domain name using non-intrusive information gathering;

c) determining an entity classification comprising a size and one of industry or country based on the digital footprint;

d) determining an entity technical finding comprising at least one of an asset vulnerability, a threat, a data loss, or a cyber event based on the discovered digital footprint;

e) computing a loss event frequency and a loss magnitude using the entity classification and the entity technical finding;

f) computing a probable financial impact of a cyber risk based on the loss event frequency and on the loss magnitude; and

g) providing recommendations for remediating the cyber risk based on the computed probable financial impact.

2. The method of cyber risk assessment of claim 1 wherein computing the loss event frequency comprises computing a level of difficulty a threat agent must overcome.

3. The method of cyber risk assessment of claim 1 wherein computing the loss event frequency comprises computing a probability of action for a threat agent.

4. The method of cyber risk assessment of claim 1 wherein computing the loss event frequency comprises computing a contact frequency of a threat agent.

5. The method of cyber risk assessment of claim 1 wherein computing the loss event frequency comprises computing an entity vulnerability parameter based on the entity classification.

6. The method of cyber risk assessment of claim 1 wherein computing the loss event frequency comprises computing a threat event frequency based on the entity technical findings and on the entity classification.

7. The method of cyber risk assessment of claim 1 wherein computing the loss magnitude comprises computing a financial loss resulting from the entity technical finding.

8. The method of cyber risk assessment of claim 1 wherein computing the loss magnitude comprises computing a secondary loss resulting from the entity technical finding.

9. The method of cyber risk assessment of claim 1 wherein the computing the probable financial impact of a cyber risk based on the loss event frequency and on the loss magnitude comprises calculating a minimum and a maximum risk exposure using a likelihood function.

10. The method of cyber risk assessment of claim 1 further comprising having a user initiate the request for the quantitative cyber risk assessment of the entity associated with the domain name.

11. The method of cyber risk assessment of claim 10 wherein the entity is the user's entity.

12. The method of cyber risk assessment of claim 10 wherein the entity is not the user's entity.

13. The method of cyber risk assessment of claim 1 further comprising presenting the probable financial impact with a graphical user interface.

14. The method of cyber risk assessment of claim 1 further comprising validating the request for the quantitative cyber risk assessment.

15. The method of cyber risk assessment of claim 1 further comprising prioritizing third parties with respect to at least one of the loss event frequency and the loss magnitude.

16. The method of cyber risk assessment of claim 1 further comprising providing off- or on-site audits.

17. A system of cyber risk assessment, the system comprising:

a) a first hardware processor coupled to a network that receives a request for a quantitative cyber risk assessment of an entity associated with a domain name and that discovers a digital footprint of the entity based the domain name using non-intrusive information gathering;

b) a second hardware processor in communication with the first hardware processor that determines an entity classification comprising a size and one of industry or country based on the digital footprint, determines an entity technical finding comprising at least one of an asset vulnerability, a threat, a data loss, or a cyber event based on the discovered digital footprint; computes a loss event frequency and a loss magnitude using the entity classification and the entity technical finding; and computes a probable financial impact based on the loss event frequency and the loss magnitude; and

c) a third hardware processor in communication with the second hardware processor that provides recommendations for remediating the risks based on the computed probably financial impact.

18. The system of cyber risk assessment of claim 17 wherein at least two of the first, second, and third hardware processor comprise the same hardware processor.

19. The system of cyber risk assessment of claim 17 wherein at least one of the first, second, and third hardware processor comprise an engine.

20. The system of cyber risk assessment of claim 19 wherein the engine comprises at least one of software, a CPU, a memory, and input/output device, and a communication adapter.

Assignments (1)
SECURITY INTEREST Recorded Aug 16, 2024
From: NORMSHIELD INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 068671/0314 →
Continuity (2)
Continuation 16855282 · Apr 22, 2020
Related Publication 20210334387A1 · Oct 28, 2021
Cited By (1)
US 12,443,724