Holistic external network cybersecurity evaluation and scoring
A system and method for holistic network cybersecurity evaluation and risk rating that takes into account the operation of the entire target network environment comprising hardware, software, operating systems, and network connections. Not only are the hardware, software, operating system, and network evaluated separately for cybersecurity concerns, their interaction and operation as a whole are also evaluated and scored. The results of such analyses may be used, for example, by underwriters of cybersecurity insurance policies to determine policy terms and rates.
1 . A system for holistic network cybersecurity evaluation and rating, comprising:
a first computing device comprising a memory and a processor;
a reconnaissance engine comprising a first plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the first computing device to:
capture system information and characteristics about a target network comprising a plurality of computing devices; and
use the captured system information and characteristics to create a network definition of the target network, the network definition being in the form of a graph representation of the target network, wherein nodes of the graph represent hardware or computing devices, and edges between nodes represent physical and logical connections between and among the hardware or computing devices;
a hardware emulator comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the first computing device to:
emulate functioning of the target network on the first computing device by:
executing a set of functions that emulate the operation of the target network as defined by hardware definitions and the network definition;
installing operating systems on emulated computing devices of the target network;
installing applications on emulated computing devices of the target network; and
executing the applications on the emulated computing device using the operating systems; and
analyze the functioning of the target network by executing an attack on the emulated target network associated with a known hardware exploit to:
determine whether the emulated target network is susceptible to the known hardware exploit;
update a network cybersecurity score using the determination; and
send the updated network cybersecurity score to a scoring engine; and
the scoring engine comprising a third plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the third plurality of programming instructions, when operating on the processor, cause the first computing device to:
generate a cybersecurity score for the target network based on a combination of a software cybersecurity score, the hardware cybersecurity score, an operating system cybersecurity score, and the network cybersecurity score; and
update the cybersecurity score for the target network with the updated network cybersecurity score.
2 . The system of claim 1 , further comprising a system analyzer that receives a software definition comprising source code for an application, wherein the software definition is accompanied by source code for the application, and wherein the software cybersecurity score further comprises an analysis of coding complexity of the source code.
3 . The system of claim 1 , further comprising a system analyzer comprising a fourth plurality of programming instructions stored in the memory of, and operating on the processor of, the first computing device, wherein the fourth plurality of programming instructions, when operating on the processor, causes the first computing device to:
receive a system definition comprising:
a software definition comprising executable binary code for the application; and
an operating system definition for the target network, the operating system definition comprising executable binary code for the operating system;
identify a software function defined by the software definition and compare the software function to a database of software functions to establish the software cybersecurity score;
identify a hardware component defined by the hardware definition and compare the component to a database of components to establish the hardware cybersecurity score; and
identify an operating system function defined by the operating system definition and compare the operating system function to a database of operating system functions to establish the operating system cybersecurity score.
4 . The system of claim 1 , wherein the hardware definition comprises at least one or more memory maps, wherein the one or more memory maps associate hardware components of a physical hardware system and memory locations of the emulated computing devices of the target network.
5 . The system of claim 1 , wherein the first computing device is a cloud-based computing device external to the target network.
6 . The system of claim 1 , wherein a set of clones of the emulated computing devices of the target network are created and tools are injected in each clone for testing.
7 . The system of claim 1 , wherein the scoring engine is further configured to:
correlate cybersecurity signals received from multiple tools across a unified security platform including endpoint protection, identity management, data loss prevention, and threat analytics tools; and
adjust the cybersecurity score for the target network based on aggregated signal intelligence and risk profiles derived from over a threshold quantity of daily threat indicators.
8 . A method for holistic network cybersecurity evaluation and rating, comprising the steps of:
capturing system information and characteristics about a target network comprising a plurality of computing devices;
using the captured system information and characteristics to create a network definition of the target network, the network definition being in the form of a graph representation of the target network, wherein nodes of the graph represent hardware or computing devices, and edges between nodes represent physical and logical connections between and among the hardware or computing devices:
emulating functioning of the target network on a first computing device by:
executing a set of functions that emulate the operation of the target network as defined by a hardware definition and the network definition;
installing operating systems on the emulated computing devices of the target network;
installing applications on the emulated computing devices of the target network; and
executing the applications on the emulated computing devices using the operating systems; and
analyzing the functioning of the target network by executing an attack on the emulated target network associated with a known hardware exploit to:
determine whether the emulated target network is susceptible to the known hardware exploit; and
update a network cybersecurity score using the determination;
generating a cybersecurity score for the target network based on a combination of a software cybersecurity score, a hardware cybersecurity score, an operating system cybersecurity score, and a network cybersecurity score; and
updating the cybersecurity score for the target network using the updated network cybersecurity score.
9 . The method of claim 8 , wherein the software definition is accompanied by source code for the application, and wherein the software cybersecurity score further comprises an analysis of the coding complexity of the source code.
10 . The method of claim 8 , further comprising the steps of:
receiving a system definition comprising:
a software definition comprising executable binary code for the application;
the hardware definition comprising a specification for the target network; and
an operating system definition for the target network, the operating system definition comprising executable binary code for the operating system;
identifying a software function defined by the software definition and comparing the function to a database of software functions to establish the software cybersecurity score;
identifying a hardware component defined by the hardware definition and comparing the component to a database of components to establish the hardware cybersecurity score; and
identifying an operating system function defined by the operating system definition and comparing the function to a database of operating system functions to establish the operating system cybersecurity score.
11 . The method of claim 8 , wherein the hardware definition comprises at least one or more memory maps, wherein the one or more memory maps associate hardware components of a physical hardware system and memory locations of the emulated computing devices of the target network.
12 . The method of claim 8 , wherein the first computing device is a cloud-based computing device external to the target network.
13 . The method of claim 8 , wherein a set of clones of the emulated computing devices of the target network are created and tools are injected in each clone for testing.
14 . The method of claim 8 , further comprising the steps of:
receiving a plurality of cybersecurity threat signals from identity management systems, endpoint monitoring tools, and data protection systems;
generating a composite risk signal from the plurality of cybersecurity threat signals; and
adjusting the cybersecurity score of the target network based on the composite risk signal.