System for automatically discovering, enriching and remediating entities interacting in a computer network
An entity tracking system and method for a computer network employs proactive data collection and enrichment driven by configurable rules and workflows responsive to the discovery of new entities, changes to existing entities, and specifics about the entities' attributes. The data collection is used in conjunction with graph technologies to map interactions and relationships between various entities interacting in the computer environment and deduce interactions and relationships between the entities. Machine learning techniques further identify, group or categorize entities and identify patterns which are indicative of anomalies that might be due to nefarious actions or compromised security.
1 . A method for managing a computer environment, the method comprising:
rendering a graphical user interface on a display of a user device, the graphical user interface generating risk information based on input from a user via an input mechanism of the user device, the input indicating definitions of risk objects, risk scenarios, and mitigating controls relevant to the computer environment;
a database system receiving the risk information and generating a risk hierarchy indicating associations between the risk objects and the risk scenarios and associations between the risk scenarios and the mitigating controls based on the risk information;
calculating risk scores for the computer environment based on the risk hierarchy and conditions of the computer environment; and
managing the computer environment based on the calculated risk scores.
2 . The method of claim 1 , further comprising the risk objects representing risks affecting the computer environment, the risk scenarios representing conditions of the computer environment associated with the risks, and the mitigating controls representing existing safeguards within the computer environment for preventing the risk scenarios.
3 . The method of claim 1 , further comprising each of the mitigating controls including evaluation criteria for evaluating whether safeguards represented by the mitigating controls are properly implemented in the computer environment based on the evaluation criteria, wherein calculating the risk scores based on the risk hierarchy comprises calculating the risk scores based on evaluation results of the evaluation criteria for each of the mitigating controls.
4 . The method of claim 3 , further comprising each of the risk scenarios including an expected loss magnitude (ELM) and an expected loss frequency (ELF) and each of the mitigating controls including a mitigation control strength (MCS), wherein calculating the risk scores based on the risk hierarchy comprises calculating the risk scores based on the ELM and ELF values for each of the risk scenarios the MCS values for each of the mitigating controls.
5 . The method of claim 4 , wherein calculating the risk scores based on the risk hierarchy comprises calculating risk scores for each of the risk objects by determining a sum of scenario risk contributions (SRC) for each risk scenario associated with the risk object, wherein the SRC value for each risk scenario is calculated using the equation: SRC=(ELM)*(ELF)*(1−MCS #1)*(1−MCS #2)* . . . *(1−MCS #n), wherein each of the MCS values represents the MCS for each mitigating control that is associated with the risk scenario and is determined to be properly implemented in the computer environment based on evaluation criteria specified for the mitigating control.
6 . The method of claim 4 , further comprising specifying the ELF, ELM, and MCS values in the risk hierarchy as equations that are based on attributes of and relationships between entities of the computer environment as indicated in an entity relationship graph indicating the conditions of the computer environment.
7 . The method of claim 4 , further comprising specifying the ELF, ELM, and MCS values in the risk hierarchy as having minimum, most likely, and maximum values, wherein calculating the risk scores comprises generating probability distributions for each of the ELF, ELM, and MCS values, running simulations based on the probability distributions, and generating the risk scores as probabilities based on the simulations.
8 . The method of claim 3 , wherein calculating the risk scores based on the evaluation criteria for each of the mitigating controls comprises validating whether each mitigating control is properly implemented in the computer environment by executing queries specified in the evaluation criteria against a database storing information about the conditions of the computer environment.
9 . The method of claim 3 , wherein calculating the risk scores based on the evaluation criteria for each of the mitigating controls comprises validating whether each mitigating control is properly implemented in the computer environment by presenting a user interface via a user device associated with and individual or group identified in the evaluation criteria, wherein the user interface generates confirmation information concerning implementation of the mitigating control based on user input received via the user interface.
10 . The method of claim 1 , further comprising recurring the calculating of the risk score for each risk object based on an evaluation frequency associated with each risk object and storing the resulting scores for future reference and/or time series or trending analyses.
11 . The method of claim 10 , further comprising storing each of the resulting scores for each calculation of the risk scores for each risk object as a node in the risk hierarchy with an edge connecting the risk score node to the risk object node.
12 . The method of claim 1 , further comprising storing the risk hierarchy as a graph database with nodes representing the risk objects, the risk scenarios, and the mitigating controls, and edges representing the associations between the risk objects and the risk scenarios and the associations between the risk scenarios and the mitigating, wherein each node indicates properties for the risk object, risk scenario, or mitigating control represented by the node.
13 . A system for managing a computer environment, the system comprising:
a user device for executing a graph query and display app for rendering a graphical user interface on a display of the user device, wherein the graph query and display app generates risk information based on input from a user via an input mechanism of the user device, the input indicating definitions of risk objects, risk scenarios, and mitigating controls relevant to the computer environment; and
a server system for executing a database system, which receives the risk information and generates a risk hierarchy indicating associations between the risk objects and the risk scenarios and associations between the risk scenarios and the mitigating controls based on the risk information, wherein the server system calculates risk scores for the computer environment based on the risk hierarchy and conditions of the computer environment.
14 . The system of claim 13 , wherein the risk objects represent risks affecting the computer environment, the risk scenarios represent conditions of the computer environment associated with the risks, and the mitigating controls represent existing safeguards within the computer environment for preventing the risk scenarios.
15 . The system of claim 13 , wherein each of the mitigating controls includes evaluation criteria for evaluating whether safeguards represented by the mitigating controls are properly implemented in the computer environment based on the evaluation criteria, wherein the risk scores are calculated based on evaluation results of the evaluation criteria for each of the mitigating controls.
16 . The system of claim 15 , wherein each of the risk scenarios includes an expected loss magnitude (ELM) and an expected loss frequency (ELF) and each of the mitigating controls including a mitigation control strength (MCS), and wherein the risk scores are calculated based on the ELM and ELF values for each of the risk scenarios the MCS values for each of the mitigating controls.
17 . The system of claim 16 , wherein the risk scores are calculated for each of the risk objects by determining a sum of scenario risk contributions (SRC) for each risk scenario associated with the risk object, and wherein the SRC value for each risk scenario is calculated using the equation: SRC=(ELM)*(ELF)*(1−MCS #1)*(1−MCS #2)* . . . *(1−MCS #n), wherein each of the MCS values represents the MCS for each mitigating control that is associated with the risk scenario and is determined to be properly implemented in the computer environment based on evaluation criteria specified for the mitigating control.
18 . The system of claim 16 , wherein the ELF, ELM, and MCS values are specified in the risk hierarchy as equations that are based on attributes of and relationships between entities of the computer environment as indicated in an entity relationship graph indicating the conditions of the computer environment.
19 . The system of claim 16 , wherein the ELF, ELM, and MCS values in the risk hierarchy are specified as having minimum, most likely, and maximum values, and the server system calculates probability distributions for each of the ELF, ELM, and MCS values, runs simulations based on the probability distributions, and generates the risk scores as probabilities based on the simulations.
20 . The system of claim 15 , wherein the server system validates whether each mitigating control is properly implemented in the computer environment by executing queries specified in the evaluation criteria against a database storing information about the conditions of the computer environment.