IP Library Granted Patent US 11,509,682
Granted Patent B1
US 11,509,682 · App. 17/476,210 · Granted Nov 22, 2022

System and method for computation of ransomware susceptibility

Inventors: Paul Paget (Hingham, MA); Ferhat Dikbiyik (Sakarya, TR); Candan Bolukbas (Stone Ridge, VA)
Assignee: NormShield, Inc
H04L63/1433G06N3/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,682
App. No.
17/476,210
Granted
Nov 22, 2022
Kind
B1
Abstract

A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor. A ransomware attack is then identified and the database is re-populating in response to the identified ransomware attack. At least one of impact parameter or a ransomware factor coefficient is re-computed based at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack to provide a cyber-risk assessment.

Claims (52)

1. A method of cyber-risk assessment, the method comprising:

a) populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources;

b) receiving a request for a ransomware susceptibility assessment of an entity associated with a domain name;

c) discovering a digital footprint of an entity in response to the associated domain name using non-intrusive information gathering;

d) collecting commercial information associated with the entity in response to the domain name;

e) scanning the database in response to the discovered digital footprint and generating at least one ransomware factor associated with the entity in response to the scan;

f) computing an impact parameter and a ransomware factor coefficient based on the collected commercial information;

g) computing an entity susceptibility index based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor; and

h) identifying a ransomware attack, re-populating the database in response to the identified ransomware attack, and re-computing at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack to provide a cyber-risk assessment to a user.

2. The method of claim 1 further comprising:

a) identifying a computer process associated with at least one ransomware factor;

b) adjusting the identified computer process in response to the susceptibility index;

and

c) recomputing an entity susceptibility index, thereby providing an improved cyber-risk assessment.

3. The method of claim 1 wherein the re-computing at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack is performed with a machine learning method.

4. The method of claim 3 wherein the machine learning method is based on an Convolutional Neural Network (CNN) for regression prediction algorithm.

5. The method of claim 1 wherein the ransomware information comprises at least one of an email misconfiguration, an open critical port finding, an open VPN finding, a critical vulnerability finding, an endpoint vulnerability finding, a leaked credentials finding, a cyber-incident finding, a darknet/deepweb mention finding, or a phishing domain finding.

6. The method of claim 1 wherein the commercial information comprises industry information.

7. The method of claim 1 wherein the commercial information comprises business-related information of the entity.

8. The method of claim 1 wherein the commercial information comprises at least one of an industry type, an industry size, or an industry geography.

9. The method of claim 1 wherein the commercial information comprises at least one of an industry of the entity, a number of employees of the entity, a country of operation of the entity, a revenue size of the entity, a market size of the entity, or a digital footprint size of the entity.

10. The method of claim 1 wherein the impact parameter comprises a number associated with at least some of the commercial information.

11. The method of claim 1 wherein the ransomware factor coefficient comprises a number associated with a relative importance of the at least one ransomware factor compared to at least one other ransomware factor.

12. The method of claim 1 further comprising performing a remediation action in response to a cyber-risk assessment.

13. The method of claim 12 wherein the remediation action comprises adjusting a computer process associated with at least one of an email misconfiguration, an open critical port finding, an open VPN finding, a critical vulnerability finding, an endpoint vulnerability finding, a leaked credentials finding, a cyber-incident finding, a darknet/deepweb mention finding, or a phishing domain finding.

14. A system for cyber-risk assessment, the system comprising:

a) a processor configured to perform the following operations:

i) populate a database with ransomware attack information non-intrusively gathered from a plurality of data sources;

ii) receive a request for a ransomware susceptibility assessment of an entity associated with a domain name;

iii) discover a digital footprint of an entity in response to the associated domain name using non-intrusive information gathering;

iv) collect commercial information associated with the entity in response to the domain name;

v) scan the database in response to the discovered digital footprint and generate at least one ransomware factor associated with the entity in response to the scan;

vi) compute an impact parameter and a ransomware factor coefficient based on the collected commercial information;

vii) compute an entity susceptibility index based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor; and

viii) identify a ransomware attack, re-populate the database in response to the identified ransomware attack, and re-compute at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack to provide a cyber-risk assessment.

15. The system for cyber-risk assessment of claim 14 further comprising:

a) a second processor configured to perform the following operations:

i) identify a computer process associated with at least one ransomware factor;

ii) adjust the identified computer process in response to the susceptibility index; and

iii) recompute an entity susceptibility index to provide an improved cyber-risk assessment to a user.

16. The system of claim 15 wherein the processor is one or more processors operating in a cloud environment.

17. The system of claim 15 wherein the re-computing at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack is performed with a machine learning method.

18. The system of claim 15 further comprising a processor configured to perform a remediation action in response to the cyber-risk assessment, the remediation action comprising at least one of adjusting a computer process associate with at least one of an email misconfiguration, an open critical port finding, an open VPN finding, a critical vulnerability finding, an endpoint vulnerability finding, a leaked credentials finding, a cyber-incident finding, a darknet/deepweb mention finding, or a phishing domain finding.

19. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations that determine a cyber-risk assessment for a user, the operations comprising:

a) populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources;

b) receiving a request for a ransomware susceptibility assessment of an entity associated with a domain name;

c) discovering a digital footprint of an entity in response to the associated domain name using non-intrusive information gathering;

d) collecting commercial information associated with the entity in response to the domain name;

e) scanning the database in response to the discovered digital footprint and generating at least one ransomware factor associated with the entity in response to the scan;

f) computing an impact parameter and a ransomware factor coefficient based on the collected commercial information;

g) computing an entity susceptibility index based on the impact parameter, the ransomware factor coefficient and the at least one ransomware factor; and

h) identifying a ransomware attack, re-populating the database in response to the identified ransomware attack, and re-computing at least one of an impact parameter or a ransomware factor coefficient based on the identified new ransomware attack to provide a cyber-risk assessment to the user.

Assignments (2)
SECURITY INTEREST Recorded Aug 16, 2024
From: NORMSHIELD INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 068671/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2021
From: PAGET, PAUL; DIKBIYIK, FERHAT; BOLUKBAS, CANDAN
To: NORMSHIELD, INC.
Reel/Frame 057688/0332 →
Cited By (6)
US 12,218,919 US 12,287,875 US 12,299,133 US 12,301,615 US 12,476,985 US 12,706,923