IP Library › Patent Application 18507819
Patent Application
App. No. 18/507,819

TECHNIQUES FOR DETERMINING DIGITAL ASSET SECURITY FROM AN EXTERNAL ATTACK SURFACE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/507,819
Abstract

A system and method for determining digital asset security from an external attack surface. The method includes: continuously detecting digital asset information from a networked computing environment; continuously determining a cybersecurity severity score for a digital asset based on the detected digital asset information; continuously determining an asset exposure score for the digital asset based on the detected digital asset information; continuously determining an asset importance score for the digital asset based on the detected digital asset information; generating a digital asset security score based on: the determined cybersecurity severity score, the asset exposure score, and the asset importance score.

Claims (77)

1 . A method for determining digital asset security from an external attack surface, comprising:

continuously detecting digital asset information from a networked computing environment;

continuously determining a cybersecurity severity score for a digital asset based on the detected digital asset information;

continuously determining an asset exposure score for the digital asset based on the detected digital asset information;

continuously determining an asset importance score for the digital asset based on the detected digital asset information;

generating a digital asset security score based on: the determined cybersecurity severity score, the asset exposure score, and the asset importance score.

2 . The method of claim 1 , further comprising:

continuously determining an attacker attractiveness score for the digital asset based on the detected digital asset information; and

generating the digital asset security score further based on: the determined attacker attractiveness score.

3 . The method of claim 2 , further comprising:

initiating a mitigation action based on a value of the digital asset security score.

4 . The method of claim 2 , further comprising:

generating the digital asset security score further based on: a determined cybersecurity severity score of a second digital asset, a second asset exposure score of the second digital asset, and a second asset importance score of the second digital asset.

5 . The method of claim 2 , further comprising:

detecting an attack path from the external attack surface to the digital asset; and

determining the asset exposure score further based on the detected attack path.

6 . The method of claim 2 , further comprising:

detecting on the digital asset any one of: a vulnerability, an exposure, and a combination thereof; and

determining the cybersecurity severity score further based on the detected: vulnerability, exposure, and the combination thereof.

7 . The method of claim 2 , further comprising:

sending a network protocol message to the digital asset;

receiving a reply to the network protocol message; and

determining the asset exposure score further based on the received reply.

8 . The method of claim 7 , wherein the reply includes any one of: a programmatic representation of a web page, an error message, an HTTP response, a data packet, an internal document, sensitive data, and a combination thereof.

9 . The method of claim 7 , further comprising:

performing deep inspection on a received content; and

determining a type of content based on the deep inspection.

10 . The method of claim 7 , further comprising:

parsing the reply to detect a data field value; and

determining a score further based on the detected data field value.

11 . The method of claim 7 , further comprising:

detecting in the reply to the network protocol message a content.

12 . The method of claim 11 , wherein the content includes: personal identifiable information, an email server identification, a sensitive data indicator, and any combination thereof.

13 . A non-transitory computer-readable medium storing a set of instructions for determining digital asset security from an external attack surface, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

continuously detect digital asset information from a networked computing environment;

continuously determine a cybersecurity severity score for a digital asset based on the detected digital asset information;

continuously determine an asset exposure score for the digital asset based on the detected digital asset information;

continuously determine an asset importance score for the digital asset based on the detected digital asset information;

generate a digital asset security score based on: the determined cybersecurity severity score, the asset exposure score, and the asset importance score.

14 . A system for determining digital asset security from an external attack surface comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

continuously detect digital asset information from a networked computing environment;

continuously determine a cybersecurity severity score for a digital asset based on the detected digital asset information;

continuously determine an asset exposure score for the digital asset based on the detected digital asset information;

continuously determine an asset importance score for the digital asset based on the detected digital asset information;

generate a digital asset security score based on: the determined cybersecurity severity score, the asset exposure score, and the asset importance score.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

continuously determine an attacker attractiveness score for the digital asset based on the detected digital asset information; and

generate the digital asset security score further based on: the determined attacker attractiveness score.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

initiate a mitigation action based on a value of the digital asset security score.

17 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the digital asset security score further based on: a determined cybersecurity severity score of a second digital asset, a second asset exposure score of the second digital asset, and a second asset importance score of the second digital asset.

18 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect an attack path from the external attack surface to the digital asset; and

determine the asset exposure score further based on the detected attack path.

19 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect on the digital asset any one of: a vulnerability, an exposure, and a combination thereof; and

determine the cybersecurity severity score further based on the detected: vulnerability, exposure, and the combination thereof.

20 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

send a network protocol message to the digital asset;

receive a reply to the network protocol message; and

determine the asset exposure score further based on the received reply.

21 . The system of claim 20 , wherein the reply includes any one of:

a programmatic representation of a web page, an error message, an HTTP response, a data packet, an internal document, sensitive data, and a combination thereof.

22 . The system of claim 20 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

perform deep inspection on a received content; and

determine a type of content based on the deep inspection.

23 . The system of claim 20 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

parse the reply to detect a data field value; and

determine a score further based on the detected data field value.

24 . The system of claim 20 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect in the reply to the network protocol message a content.

25 . The system of claim 24 , wherein the content includes:

personal identifiable information, an email server identification, a sensitive data indicator, and any combination thereof.

Assignments (1)
SECURITY INTEREST Recorded Jan 29, 2026
From: CYCOGNITO LTD
To: AVENUE VENTURES OPPORTUNITIES FUND II, L.P., AS COLLATERAL AGENT
Reel/Frame 073632/0936 →