IP Library Granted Patent US 11,757,919
Granted Patent B2
US 11,757,919 · App. 17/235,461 · Granted Sep 12, 2023

System and method for catastrophic event modeling

Inventors: Avi Bashan (Givat Shmuel, IL); Amir Kessler (Tel Aviv, IL); Shalom Bublil (Tel Aviv, IL); Marco Lo Giudice (London, GB); Yakir Golan (Kibbutz Yagur, IL)
Assignee: KOVRR RISK MODELING LTD.
H04L63/1433H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,919
App. No.
17/235,461
Granted
Sep 12, 2023
Kind
B2
Abstract

A system and method for catastrophic event modeling are provided. The method includes generating a cyber event catalog based on a past cyber event, the cyber event catalog including a plurality of cyber events; and simulating a cyber event, of the plurality of cyber events included in the cyber event catalog, to predict whether an organization is affected by a simulated cyber event, wherein the organization is an organization selected from a hazard table.

Claims (66)

1. A method for catastrophic cyber event modeling, comprising:

generating a cyber event catalog based on a past cyber event, the cyber event catalog including a plurality of cyber events, wherein generating the cyber event catalog further comprises:

determining a distribution of all event parameters by extrapolating one or more data points from a past event; and

assigning a set of restriction rules, wherein the parameter distribution and the set of restriction rules are used to create events in the event catalog;

simulating a cyber event, of the plurality of cyber events included in the cyber event catalog, to predict whether an organization is affected by a simulated cyber event, wherein the organization is an organization selected from a hazard table, and wherein the simulating cyber event simulates malicious activity in the organization; and

estimating a damage of the cyber event on the organization by employing a damage function.

2. The method of claim 1 , wherein simulating the cyber event further comprises:

simulating the cyber event via a Monte Carlo simulation.

3. The method of claim 1 , wherein the event catalog includes a plurality of potential catastrophic events.

4. The method of claim 1 , wherein determining the distribution of all event parameters further comprises:

collecting data from at least one of: a CVE database, and an open-source monitoring dashboard.

5. The method of claim 1 , wherein determining the distribution of all event parameters further comprises:

accessing an active exploitation database; and

collecting threat intelligence data.

6. The method of claim 1 , wherein determining the distribution of all event parameters further comprises:

using validation and test sets as control groups.

7. The method of claim 1 , wherein determining the distribution of all event parameters further comprises:

using a K-means algorithm to distill a full event catalog to a smaller subset.

8. The method of claim 1 , wherein estimating the damage further comprising:

processing an input, the input including an input group;

generating one or more hazard tables;

evaluating the damage function;

determining a damage estimation;

generating a yearly loss table (YLT); and

generating an exceedance probability (EP) curve.

9. The method of claim 8 , wherein generating one or more hazard tables further comprises:

actively mapping, to one or more security controls of a plurality of security controls, one or more assets used by one or more insured companies.

10. The method of claim 8 , wherein generating one or more EP curves further comprises:

calculating at least one of: an annual exceedance probability (AEP), and an overall exceedance probability (OEP), wherein an AEP is calculated by summing damages of each year, and wherein an OEP is calculated by focusing on an event with the maximum damage for each year.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for catastrophic event modeling, the process comprising:

generating a cyber event catalog based on a past cyber event, the cyber event catalog including a plurality of cyber events, wherein generating the cyber event catalog further comprises:

determining a distribution of all event parameters by extrapolating one or more data points from a past event; and

assigning a set of restriction rules, wherein the parameter distribution and the set of restriction rules are used to create events in the event catalog;

simulating a cyber event, of the plurality of cyber events included in the cyber event catalog, to predict whether an organization is affected by a simulated cyber event, wherein the organization is an organization selected from a hazard table, and wherein the simulating cyber event simulates malicious activity in the organization; and

estimating a damage of the cyber event on the organization by employing a damage function.

12. A system for catastrophic cyber event modeling, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a cyber event catalog based on a past cyber event, the cyber event catalog including a plurality of cyber events, wherein the system is further configured to:

determine a distribution of all event parameters by extrapolating one or more data points from a past event; and

assign a set of restriction rules, wherein the parameter distribution and set of restriction rules are used to create events in the event catalog;

simulate a cyber event, of the plurality of cyber events included in the cyber event catalog, to predict whether an organization is affected by a simulated cyber event, wherein the organization is an organization selected from a hazard table, and wherein the simulating cyber event simulates malicious activity in the organization; and

estimate a damage of the cyber event on the organization by employing a damage function.

13. The system of claim 12 , wherein the system is further configured to:

simulating the cyber event via a Monte Carlo simulation.

14. The system of claim 12 , wherein the event catalog includes a plurality of potential catastrophic events.

15. The system of claim 12 , wherein the system is further configured to:

collect data from at least one of: a CVE database, and an open-source monitoring dashboard.

16. The system of claim 12 , wherein the system is further configured to:

access an active exploitation database; and

collect threat intelligence data.

17. The system of claim 12 , wherein the system is further configured to:

use validation and test sets as control groups.

18. The system of claim 12 , wherein the system is further configured to:

use a K-means algorithm to distill a full event catalog to a smaller subset.

19. The system of claim 12 , wherein the system is further configured to:

process an input, the input including an input group;

generate one or more hazard tables;

evaluate the damage function;

determine a damage estimation;

generate a yearly loss table (YLT); and

generate an exceedance probability (EP) curve.

20. The system of claim 19 , wherein the system is further configured to:

actively map, to one or more security controls of a plurality of security controls, one or more assets used by one or more insured companies.

21. The system of claim 19 , wherein the system is further configured to:

calculate at least one of: an annual exceedance probability (AEP), and an overall exceedance probability (OEP), wherein an AEP is calculated by summing the damages of each year, and wherein an OEP is calculated by focusing on an event with the maximum damage for each year.

Assignments (2)
SECURITY INTEREST Recorded Jun 16, 2024
From: KOVRR RISK MODELING LTD.
To: BANK LEUMI LE-ISRAEL B.M.
Reel/Frame 067739/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2021
From: BASHAN, AVI; KESSLER, AMIR; BUBLIL, SHALOM; LO GIUDICE, MARCO; GOLAN, YAKIR
To: KOVRR RISK MODELING LTD.
Reel/Frame 055977/0687 →
Continuity (2)
Provisional Application 63012421 · Apr 20, 2020
Related Publication 20220191231A1 · Jun 16, 2022