IP Library › Granted Patent US 12,579,277
Granted Patent B2
US 12,579,277 · App. 17/993,073 · Granted Mar 17, 2026

Quantifying satisfaction of security features of cloud software systems

Inventors: Armstrong Nhlabatsi (Doha, QA); Khaled Khan (Doha, QA); Jin Hong (Doha, QA); Dong Seong Kim (Doha, QA); Rachel Fernandez (Doha, QA); Noora Fetais (Doha, QA)
Assignees: QATAR FOUNDATION FOR EDUCATION, SCIENCE AND COMMUNITY DEVELOPMENT; QATAR UNIVERSITY
G06F21/577G06F21/53H04L63/1433G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,277
App. No.
17/993,073
Granted
Mar 17, 2026
Kind
B2
Abstract

A method of quantifying the satisfaction of security requirements is provided via characterizing a security feature; matching the security feature to a security metric; computing a quantification score that indicates the exploitability of a system to which the security feature is applied; and outputting the quantification score to a security analyst.

Claims (50)

1 . A method, comprising:

characterizing a security requirement;

matching the security requirement to a security metric;

computing a quantification score that indicates an exploitability of a system to which the security requirement is applied; and

outputting the quantification score to a security analyst,

wherein the security metric is one of a plurality of security metrics matched to the security requirement, the method further comprising:

in response to the quantification score being below a satisfaction threshold, identifying, to the security analyst, at least one security requirement of a plurality of security requirements that was not satisfied, and

wherein the method is performed on a virtual machine of a cloud infrastructure including a virtual processor and a virtual memory.

2 . The method of claim 1 , wherein characterizing the security requirement further comprises:

identifying an asset in a computing environment to protect according to the security requirement; and

identifying a security objective of the security requirement to protect the asset.

3 . The method of claim 1 , wherein matching the security requirement to the security metric further comprises:

identifying an exploitability measure, a defense measure, and an attack strength measure.

4 . The method of claim 3 , wherein quantifying the security requirement further comprises:

computing the exploitability measure, the defense measure, and the attack strength measure to quantify a level of satisfaction of the security requirement.

5 . The method of claim 1 , wherein the security requirement is one of a plurality of security requirements characterized to quantify the exploitability of the system.

6 . A system, comprising:

a processor; and

a memory including instructions that when executed by the processor perform operations that comprise:

characterizing a security requirement;

matching the security requirement to a security metric;

computing a quantification score that indicates an exploitability of a system to which the security requirement is applied; and

outputting the quantification score to a security analyst,

wherein the security metric is one of a plurality of security metrics matched to the security requirement, the operations further comprising:

in response to the quantification score being below a satisfaction threshold, identifying, to the security analyst, at least one security requirement of a plurality of security requirements that was not satisfied, and

wherein the processor comprises a virtual processor and the memory comprises a virtual memory provided as part of a virtual machine of a cloud infrastructure.

7 . The system of claim 6 , wherein characterizing the security requirement further comprises:

identifying an asset in a computing environment to protect according to the security requirement; and

identifying a security objective of the security requirement to protect the asset.

8 . The system of claim 6 , wherein matching the security requirement to the security metric further comprises:

identifying an exploitability measure, a defense measure, and an attack strength measure.

9 . The system of claim 8 , wherein quantifying the security requirement further comprises:

computing the exploitability measure, the defense measure, and the attack strength measure to quantify a level of satisfaction of the security requirement.

10 . The system of claim 6 , wherein the security requirement is one of a plurality of security requirements characterized to quantify the exploitability of the system.

11 . A non-transitory computer readable memory including instructions that when executed by a processor perform operations comprising:

characterizing a security requirement;

matching the security requirement to a security metric;

computing a quantification score that indicates an exploitability of a system to which the security requirement is applied; and

outputting the quantification score to a security analyst,

wherein the security metric is one of a plurality of security metrics matched to the security requirement, the operations further comprising:

in response to the quantification score being below a satisfaction threshold, identifying, to the security analyst, at least one security requirement of a plurality of security requirements that was not satisfied, and

wherein the operations are performed on a virtual machine of a cloud infrastructure including a virtual processor and a virtual memory.

12 . The computer readable memory of claim 11 , wherein characterizing the security requirement further comprises:

identifying an asset in a computing environment to protect according to the security requirement; and

identifying a security objective of the security requirement to protect the asset.

13 . The computer readable memory of claim 11 , wherein matching the security requirement to the security metric further comprises:

identifying an exploitability measure, a defense measure, and an attack strength measure.

14 . The computer readable memory of claim 13 , wherein quantifying the security requirement further comprises:

computing the exploitability measure, the defense measure, and the attack strength measure to quantify a level of satisfaction of the security requirement.

15 . The computer readable memory of claim 11 , wherein the security requirement is one of a plurality of security requirements characterized to quantify the exploitability of the system.

Assignments (1)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 63161 FRAME: 835. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 17, 2024
From: NHLABATSI, ARMSTRONG; KHAN, KHALED; HONG, JIN; KIM, DONG SEONG; FERNANDEZ, RACHEL; FETAIS, NOORA
To: QATAR FOUNDATION FOR EDUCATION, SCIENCE AND COMMUNITY DEVELOPMENT; QATAR UNIVERSITY
Reel/Frame 067134/0823 →
Continuity (2)
Provisional Application 63282468 · Nov 23, 2021
Related Publication 20230185925A1 · Jun 15, 2023
References Cited (8)
US 9462010B1 · Stevenson · 2016 [cited by applicant]
US 10404737B1 · Sweeney et al. · 2019 [cited by applicant]
US 20160241581A1 · Watters · 2016 [cited by examiner]
US 20190199740A1 · Zhang · 2019 [cited by examiner]
US 20230328094A1 · Brown · 2023 [cited by examiner]
Alberts et al., “Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0”, Technical Report Prepared for Carnegie Mellon Software Engineering Institute (Jun. 1999), 82 pages. [cited by applicant]
Drissi et al., “Survey: Risk Assessment for Cloud Computing”, International Journal of Advanced Computer Science and Applications (2013), 4(12), pp. 143-148. [cited by applicant]
Sharma et al. “Cloud Computing Risks and Recommendations for Security”, International Journal of Latest Research in Science and Technology (2017), 6(1), pp. 52-56. [cited by applicant]