Method for providing real time zero trust security in a shared resource network
A method for providing cyber security measures in a shared network estimates in a probabilistic model, a likelihood of a cybersecurity event occurring in a system. Based on the estimated likelihood selectively applies some but not all of the cyber security measures. Based constraints of system resources available for operations a combination discretionary security measures are selected for execution. During runtime of the system, security risk of an aspect of the system is periodically evaluated causing reconfiguration of the security measures for execution based on the estimated security risk and system resources available for operations. Timed automata corresponding to security threats are assigned a risk score associated with the security threat based on one or more states of the automata. An aggregation of multiple risk scores produces a trust score for the overall system. A number of security measures may be selected and allocated based on the trust score.
1 . A method for providing zero trust cyber security measures in a shared network requiring real-time communication quality of service, the method comprising:
estimate in a probabilistic model, a likelihood of a cybersecurity event occurring in a system, so as to define an estimated likelihood;
based on the estimated likelihood, selecting a portion of the zero trust cyber security measures, the portion less than all of the zero trust cyber security measures available in the system, so as to define a selected portion of the zero trust cyber security measures;
based on the estimated likelihood, applying only the selected portion of the zero trust cyber security measures in the system;
for each security measure, assigning an identifier to the security measure, the identifier comprising a priority level of critical, relevant, or useful;
allocating system resources for a critical security measure as a necessary security measure;
selectively allocating system resources for a relevant security measure on a condition that a security score of the relevant security measure exceeds a first threshold value; and
selectively allocating system resources for a useful security measure on a condition that a security score of the useful security measure exceeds a second threshold value.
2 . The method of claim 1 , further comprising:
ensuring that real time communication requirements of the system are provided while selecting the cyber security measures to be applied.
3 . The method of claim 1 , further comprising:
constructing a table containing the cyber security measures, the table being configurable for indicating a priority level of each of the cyber security measures.
4 . The method of claim 3 , wherein the cyber security measures are arranged in the table according to a security pillar corresponding to one of five pillars in a CISA zero trust cyber security model.
5 . The method of claim 1 , wherein the shared network is a fifth generation (5G) communication network.
6 . The method of claim 1 , wherein the system comprises an industrial operations environment.
7 . The method of claim 1 , wherein a total allocation of resources includes a sum of resources for execution of all critical security measures, all relevant security measures exceeding the first threshold and all useful security measures exceeding the second threshold.
8 . The method of claim 7 , further including selecting a combination of relevant security measures and useful security measures for execution based on a constraint of system resources available for operations.
9 . The method of claim 8 , wherein the selection of security measures for execution is based on a pillar of the CISA zero trust model associated with each of the selected security measures.
10 . The method of claim 9 , further comprising:
during runtime of the system, periodically estimating a security risk of an aspect of the system; and
reconfiguring the security measures for execution based on the estimated security risk and the constraint of system resources available for operations.
11 . The method of claim 1 , further comprising:
defining a timed automata corresponding to a security threat; and
assigning a risk score to the security threat based on one or more states of the automata.
12 . The method of claim 11 , further comprising:
aggregating a plurality of risk scores to produce a trust score for the system.
13 . The method of claim 12 , further comprising:
reselecting a number of security measures based on the trust score.
14 . A system for implementing security measures in a shared network requiring real time network communications, comprising:
a computer processor in communication with a non-transitory computer memory, the non-transitory computer memory storing instructions that when executed by the computer processor cause the computer processor to:
estimate in a probabilistic model, a likelihood of a cybersecurity event occurring in the system, so as to define an estimated likelihood;
based on the estimated likelihood, select a portion of a plurality of zero trust cyber security measures, the portion less than all of the plurality of zero trust cyber security measures available in the system, so as to define a selected portion of the zero trust cyber security measures;
based on the estimated likelihood, execute only the selected portion of the zero trust cyber security measures in the system;
for each security measure, assign an identifier to the security measure, the identifier comprising a priority level of critical, relevant, or useful;
allocate system resources for a critical security measure as a necessary security measure;
selectively allocate system resources for a relevant security measure on a condition that a security score of the relevant security measure exceeds a first threshold value; and
selectively allocate system resources for a useful security measure on a condition that a security score of the useful security measure exceeds a second threshold value.
15 . The system of claim 14 , the non-transitory computer memory further storing instructions that when executed by the computer processor, cause the computer processor to:
create an automata for each of a plurality of security threats;
associate a risk score with the security threat based on one or more states of the automata.
16 . The system of claim 15 , the non-transitory computer memory further storing instructions that when executed by the computer processor cause the computer processor to:
aggregate a plurality of risk scores to generate a trust score for the system.
17 . The system of claim 16 , the non-transitory computer memory further storing instructions that when executed by the computer processor cause the computer processor to:
reallocate an updated portion of the plurality of security measures based on the generated trust score.
18 . The system of claim 17 , the non-transitory computer memory further storing instructions that when executed by the computer processor cause the computer processor to:
periodically recalculate risk scores for a plurality of security threats to compute an updated trust score; and
update the selected security measures based on the updated trust score.