IP Library Granted Patent US 12,225,041
Granted Patent B2
US 12,225,041 · App. 17/932,060 · Granted Feb 11, 2025

System and method for centralized cybersecurity configuration compliance management

Inventors: Eidan K. Aleidan (Dhahran, SA); Ziad I. Alomair (Khobar, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,041
App. No.
17/932,060
Granted
Feb 11, 2025
Kind
B2
Abstract

A system and method for centralized cybersecurity configuration compliance management for an enterprise having one or more assets operate to collect external inputs including one or more of open source cybersecurity configuration baselines (OSCSCBs), vendor hardening documentation (VHD), and information from exploitation and vulnerability public databases, collect internal inputs including cybersecurity standards of the enterprise and guidelines that are specific to the assets of the enterprise, consolidate the collected external and internal inputs, and apply supervised decision tree machine learning (ML) model to generate cybersecurity configuration baseline (CSCB) controls mapping to the assets in the enterprise.

Claims (40)

1. A method for centralized cybersecurity configuration compliance management for an enterprise having one or more assets, comprising:

collecting external inputs including open source cybersecurity configuration baselines (OSCSCBs), vendor hardening documentation (VHD), and information from exploitation and vulnerability public databases;

collecting internal inputs including cybersecurity standards of the enterprise and guidelines that are specific to the one or more assets of the enterprise;

monitoring, in real-time, changes that occur to the OSCSCBs, the VHDs, the information from the exploitation and vulnerability public databases, the cybersecurity standards of the enterprise, and the guidelines that are specific to the one or more assets of the enterprise;

identifying the collected external and internal inputs impacted by the changes;

updating, in real-time and based on the changes, the collected external and internal inputs;

consolidating the collected external and internal inputs into an up-to-date feed; and

applying, into an up-to-date feed, a supervised decision tree machine learning (ML) model to generate a mapping of cybersecurity configuration baseline (CSCB) controls to the one or more assets in the enterprise.

2. The method of claim 1 , further comprising:

identifying relevant standards for each of different asset types in the enterprise.

3. The method of claim 1 , wherein the ML model identifies a criticality of each of the one or more assets, checks a history of vulnerabilities, and identifies relevant controls from external and internal sources.

4. The method of claim 1 , wherein the OSCSCBs are obtained from one or more of the Center of Information Security (CIS) Benchmarks or the US Department of Defense Security Technical Implementation Guides (STIGs).

5. The method of claim 1 , wherein the mapping identifies one or more of:

an open source cybersecurity configuration baseline;

vendor hardening documentation;

high-level cybersecurity standards; and

system-specific guidelines.

6. The method of claim 1 , wherein the centralized cybersecurity standards manager is further operable to maintain an inventory of different asset types in the enterprise that require a CSCB.

7. The method of claim 6 , wherein the centralized cybersecurity standards manager is further operable to identity relevant standards for each of the different asset types in the enterprise.

8. The method of claim 1 , wherein the mapping is based on a severity and a criticality in a network associated with the one or more assets.

9. A system for centralized cybersecurity configuration compliance management for an enterprise having one or more assets, comprising:

a memory; and

a processor configured to execute instructions stored in the memory to implement a centralized cybersecurity standards manager, the centralized cybersecurity standards manager configured to cause the processors to:

collect external inputs including open source cybersecurity configuration baselines (OSCSCBs), vendor hardening documentation (VHD), and information from exploitation and vulnerability public databases,

collect internal inputs including cybersecurity standards of the enterprise and guidelines that are specific to the one or more assets of the enterprise,

monitor, in real-time, changes that occur to the OSCSCBs, the VHDs, the information from the exploitation and vulnerability public databases, the cybersecurity standards of the enterprise, and the guidelines that are specific to the one or more assets of the enterprise;

identify the collected external and internal inputs impacted by the changes;

update, in real-time and based on the changes, the collected external and internal inputs;

consolidate the collected external and internal inputs into an up-to-date feed, and

apply, to the up-to-date feed, a supervised decision tree machine learning (ML) model to generate a mapping of cybersecurity configuration baseline (CSCB) controls to the one or more assets in the enterprise.

10. The system of claim 9 , wherein the ML model identifies a criticality of each of the one or more assets, checks a history of vulnerabilities, and identifies relevant controls from external and internal sources.

11. The system of claim 9 , wherein the mapping is based on a severity and a criticality in a network associated with the one or more assets.

12. The system of claim 9 , wherein the OSCSCBs are obtained from one or more of the Center of Information Security (CIS) Benchmarks or the US Department of Defense Security Technical Implementation Guides (STIGs).

13. The system of claim 9 , wherein the mapping identifies one or more of:

an open source cybersecurity configuration baseline;

vendor hardening documentation;

high-level cybersecurity standards; and

system-specific guidelines.

14. The system of claim 9 , wherein the centralized cybersecurity standards manager is further operable to maintain an inventory of different asset types in the enterprise that require a CSCB.

15. The system of claim 14 , wherein the centralized cybersecurity standards manager is further operable to identity relevant standards for each of the different asset types in the enterprise.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2022
From: ALEIDAN, EIDAN K.
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 061092/0975 →
Continuity (1)
Related Publication 20240089283A1 · Mar 14, 2024
References Cited (5)
US 8990937B2 · Durie · 2015 [cited by applicant]
US 10097585B2 · Bush et al. · 2018 [cited by applicant]
US 10523709B2 · Bower · 2019 [cited by applicant]
US 20200119983A1 · D'Onofrio · 2020 [cited by examiner]
US 20240028009A1 · Mirth · 2024 [cited by examiner]