SYSTEM AND METHOD FOR CATASTROPHIC EVENT MODELING
A system and method for identifying a catastrophic cyber event of an organization is presented. The method includes creating a hazard table having a summary representation of assets of the organization, wherein the summary representation is represented as parameters of the organization; simulating, based on the parameters of the organization, a cyber event in a subset of a cyber event catalog that includes potential catastrophic cyber events, wherein the cyber event includes descriptors; and estimating a damage of the simulated cyber event that indicates malicious cyber activity on the organization.
1 . A method for identifying a catastrophic cyber event of an organization, comprising:
creating a hazard table having a summary representation of assets of the organization, wherein the summary representation is represented as parameters of the organization;
simulating, based on the parameters of the organization, a cyber event in a subset of a cyber event catalog that includes potential catastrophic cyber events, wherein the cyber event includes descriptors; and
estimating a damage of the simulated cyber event that indicates malicious cyber activity on the organization.
2 . The method of claim 1 , wherein creating the hazard table further comprises:
actively mapping the parameters to security controls.
3 . The method of claim 1 , wherein the descriptors define providers affected by the cyber event and implemented by the organization, wherein the providers are any one of: a technology and a service.
4 . The method of claim 1 , wherein the subset of the cyber event catalog is generated using a K-means algorithm.
5 . The method of claim 1 , further comprising:
generating the cyber event catalog, wherein the generating further comprises:
determining a distribution of event parameters by extrapolating past cyber events; and
assigning a set of restriction rules.
6 . The method of claim 5 , wherein determining the distribution of event parameters further comprises:
examining possible distributions of at least one event parameter; and
combining the examined distributions of the at least one event parameter using a Bayesian inference.
7 . The method of claim 5 , wherein generating the cyber event catalog further comprises:
formatting cyber event data in preferred format;
removing irrelevant data from the cyber event data;
augmenting the cyber event data; and
grouping the cyber event data into at least one input group.
8 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for catastrophic event modeling, the process comprising:
creating a hazard table having a summary representation of assets of the organization, wherein the summary representation is represented as parameters of the organization;
simulating, based on parameters of the organization, a cyber event in a subset of a cyber event catalog that includes potential catastrophic cyber events, wherein the cyber event includes descriptors; and
estimating a damage of the simulated cyber event that indicates malicious cyber activity on the organization.
9 . A system for identifying a catastrophic cyber event of an organization, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
create a hazard table having a summary representation of assets of the organization, wherein the summary representation is represented as parameters of the organization;
simulate, based on parameters of the organization, a cyber event in a subset of a cyber event catalog that includes potential catastrophic cyber events, wherein the cyber event includes descriptors; and
estimate a damage of the simulated cyber event that indicates malicious cyber activity on the organization.
10 . The system of claim 9 , wherein the system is further configured to:
actively map the parameters to security controls.
11 . The system of claim 9 , wherein the descriptors define providers affected by the cyber event and implemented by the organization, wherein the providers are any one of: a technology and a service.
12 . The system of claim 9 , wherein the subset of the cyber event catalog is generated using a K-means algorithm.
13 . The system of claim 9 , wherein the system is further configured to:
generate the cyber event catalog;
determine a distribution of event parameters by extrapolating past cyber events; and
assign a set of restriction rules.
14 . The system of claim 12 , wherein the system is further configured to:
examine possible distributions of at least one event parameter; and
combine the examined distributions of the at least one event parameter using a Bayesian inference.
15 . The system of claim 12 , wherein the system is further configured to:
format cyber event data in preferred format;
remove irrelevant data from the cyber event data;
augment the cyber event data; and
group the cyber event data into at least one input group.