IP Library › Granted Patent US 12,223,062
Granted Patent B1
US 12,223,062 · App. 18/649,484 · Granted Feb 11, 2025

Techniques for identifying gaps in security controls

Inventors: Snir Havdala (Tel Aviv, IL); Ben Seri (Ramat Gan, IL)
Assignee: Zafran Security LTD
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,062
App. No.
18/649,484
Filed
Apr 29, 2024
Granted
Feb 11, 2025
Kind
B1
Art Unit
2436
USPC
726/25
Abstract

A system and method for identifying security control gaps. A method includes integrating with a set of security controls deployed with respect to a computing environment, wherein integrating with the set of security controls further comprises deploying an artifact in the computing environment, wherein the artifact is configured to record a plurality of activities performed in the computing environment by the set of controls; identifying at least one computing asset to be protected by the set of security controls; identifying at least one security control gap in the computing environment based on a configuration of the set of security controls, wherein each security control gap is defined with respect to one of the identified at least one computing asset; and performing at least one remediation action with respect to the identified at least one security control gap.

Claims (57)

1. A method for identifying security control gaps, comprising:

integrating with a set of security controls deployed with respect to a computing environment, wherein integrating with the set of security controls further comprises deploying an artifact in the computing environment, wherein the artifact is configured to record a plurality of activities performed in the computing environment by the set of controls, wherein integrating with the set of security controls further comprises enforcing at least one policy requiring code releases in the computing environment to be signed using an instance of the artifact;

identifying at least one computing asset to be protected by the set of security controls;

identifying at least one security control gap in the computing environment based on a configuration of the set of security controls, wherein each security control gap is defined with respect to one of the identified at least one computing asset; and

performing at least one remediation action with respect to the identified at least one security control gap.

2. The method of claim 1 , further comprising:

correlating between sets of asset-identifying data generated by the set of security controls; and

deduplicating a plurality of asset instances represented in the asset-identifying data generated by the set of security controls deployed with respect to the computing environment in order to create a set of deduplicated asset instances, wherein deduplicating the plurality of asset instances includes uniquely identifying each of the plurality of asset instances as corresponding to a respective protected computing asset of the at least one computing asset based on the correlation between the sets of asset-identifying data generated by the set of security controls, wherein the at least one security control gap is identified based further on the set of deduplicated asset instances.

3. The method of claim 1 , wherein integrating with the set of security controls further comprises:

determining a set of control deployments for the set of controls based on the plurality of activities recorded by the artifact, wherein the at least one security control gap is determined based further on the set of control deployments.

4. The method of claim 1 , further comprising:

mapping a plurality of capabilities of security controls among the set of security controls to respective cyber threats, wherein the at least one security control gap is identified based further on the mapping.

5. The method of claim 1 , wherein the set of security controls is a set of first security controls, wherein identifying the at least one security control gap further comprises:

determining at least one path of exploitation, wherein each path of exploitation is a path of communication between one of the at least one computing asset and at least one computing component, wherein the at least one security control gap includes a lack of a second security control at a deployment location defined with respect to the at least one path of exploitation.

6. The method of claim 1 , wherein identifying the at least one security control gap further comprises:

determining, for each security control of the set of security controls, a corresponding set of predetermined features to be used by the security control; and

determining whether each security control of the set of security controls is configured to utilize each feature of the corresponding set of predetermined features, wherein the at least one security control gap includes a first security control of the set of security controls lacking configuration to perform at least one feature of the corresponding set of predetermined features.

7. The method of claim 1 , wherein identifying the at least one security control gap further comprises:

analyzing a pair of security controls from among the set of security controls, the pair of security controls including a first security control and a second security control of the set of security controls, wherein at least one first security control policy is applied to the first security control, wherein at least one second security control policy is applied to the second security control, wherein analyzing the pair of security controls further comprises analyzing the at least one first security control policy and the at least one second security control policy based on a set of predetermined security control policy conflicts;

identifying at least one conflict between the at least one first security control policy and the at least one second security control policy based on the analysis, wherein the at least one security control gap includes the identified at least one conflict between the at least one first security control policy and the at least one second security control policy.

8. The method of claim 1 , wherein identifying the at least one security control gap further comprises:

determining, for each security control of the set of security controls, a corresponding set of predetermined software components to be used by the security control, wherein each predetermined software component to be used by the security control has a corresponding version; and

determining that a first security control of the set of security controls has an outdated version of at least one first software component of the set of predetermined software components, wherein the at least one security control gap includes the lack of the at least one first software component by the first security control.

9. The method of claim 1 , wherein performing the at least one remediation action includes reconfiguring at least one security control of the set of security controls.

10. The method of claim 1 , wherein the set of security controls is a set of first security controls, wherein performing the at least one remediation action includes deploying at least one second security control based on the identified at least one security control gap.

11. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

integrating with a set of security controls deployed with respect to a computing environment, wherein integrating with the set of security controls further comprises deploying an artifact in the computing environment, wherein the artifact is configured to record a plurality of activities performed in the computing environment by the set of controls, wherein integrating with the set of security controls further comprises enforcing at least one policy requiring code releases in the computing environment to be signed using an instance of the artifact;

identifying at least one computing asset to be protected by the set of security controls;

identifying at least one security control gap in the computing environment based on a configuration of the set of security controls, wherein each security control gap is defined with respect to one of the identified at least one computing asset; and

performing at least one remediation action with respect to the identified at least one security control gap.

12. A system for identifying security control gaps, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

integrate with a set of security controls deployed with respect to a computing environment, wherein integrating with the set of security controls further comprises deploying an artifact in the computing environment, wherein the artifact is configured to record a plurality of activities performed in the computing environment by the set of controls, wherein the system is further configured to enforce at least one policy requiring code releases in the computing environment to be signed using an instance of the artifact;

identify at least one computing asset to be protected by the set of security controls;

identify at least one security control gap in the computing environment based on a configuration of the set of security controls, wherein each security control gap is defined with respect to one of the identified at least one computing asset; and

perform at least one remediation action with respect to the identified at least one security control gap.

13. The system of claim 12 , wherein the system is further configured to:

correlate between sets of asset-identifying data generated by the set of security controls; and

deduplicate a plurality of asset instances represented in the asset-identifying data generated by the set of security controls deployed with respect to the computing environment in order to create a set of deduplicated asset instances, wherein deduplicating the plurality of asset instances includes uniquely identifying each of the plurality of asset instances as corresponding to a respective protected computing asset of the at least one computing asset based on the correlation between the sets of asset-identifying data generated by the set of security controls, wherein the at least one security control gap is identified based further on the set of deduplicated asset instances.

14. The system of claim 12 , wherein the system is further configured to:

determine a set of control deployments for the set of controls based on the plurality of activities recorded by the artifact, wherein the at least one security control gap is determined based further on the set of control deployments.

15. The system of claim 12 , wherein the system is further configured to:

map a plurality of capabilities of security controls among the set of security controls to respective cyber threats, wherein the at least one security control gap is identified based further on the mapping.

16. The system of claim 12 , wherein the set of security controls is a set of first security controls, wherein the system is further configured to:

determine at least one path of exploitation, wherein each path of exploitation is a path of communication between one of the at least one computing asset and at least one computing component, wherein the at least one security control gap includes a lack of a second security control at a deployment location defined with respect to the at least one path of exploitation.

17. The system of claim 12 , wherein the system is further configured to:

determine, for each security control of the set of security controls, a corresponding set of predetermined features to be used by the security control; and

determine whether each security control of the set of security controls is configured to utilize each feature of the corresponding set of predetermined features, wherein the at least one security control gap includes a first security control of the set of security controls lacking configuration to perform at least one feature of the corresponding set of predetermined features.

18. The system of claim 12 , wherein the system is further configured to:

analyze a pair of security controls from among the set of security controls, the pair of security controls including a first security control and a second security control of the set of security controls, wherein at least one first security control policy is applied to the first security control, wherein at least one second security control policy is applied to the second security control, wherein analyzing the pair of security controls further comprises analyzing the at least one first security control policy and the at least one second security control policy based on a set of predetermined security control policy conflicts;

identify at least one conflict between the at least one first security control policy and the at least one second security control policy based on the analysis, wherein the at least one security control gap includes the identified at least one conflict between the at least one first security control policy and the at least one second security control policy.

19. The system of claim 12 , wherein the system is further configured to:

determine, for each security control of the set of security controls, a corresponding set of predetermined software components to be used by the security control, wherein each predetermined software component to be used by the security control has a corresponding version; and

determine that a first security control of the set of security controls has an outdated version of at least one first software component of the set of predetermined software components, wherein the at least one security control gap includes the lack of the at least one first software component by the first security control.

20. The system of claim 12 , wherein performing the at least one remediation action includes reconfiguring at least one security control of the set of security controls.

21. The system of claim 12 , wherein the set of security controls is a set of first security controls, wherein performing the at least one remediation action includes deploying at least one second security control based on the identified at least one security control gap.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2024
From: HAVDALA, SNIR; SERI, BEN
To: ZAFRAN SECURITY LTD
Reel/Frame 067311/0307 →
Continuity (1)
Provisional Application 63570547 · Mar 27, 2024
References Cited (32)
US 8468244B2 · Redlich et al. · 2013 [cited by applicant]
US 9697355B1 · Park et al. · 2017 [cited by applicant]
US 9807109B2 · Laidlaw et al. · 2017 [cited by applicant]
US 10250619B1 · Park et al. · 2019 [cited by applicant]
US 10339321B2 · Tedeschi · 2019 [cited by applicant]
US 11184401B2 · Crabtree et al. · 2021 [cited by applicant]
US 11297109B2 · Crabtree et al. · 2022 [cited by applicant]
US 11316875B2 · Frey et al. · 2022 [cited by applicant]
US 11902322B2 · Hutchinson et al. · 2024 [cited by applicant]
US 20080282320A1 · DeNovo et al. · 2008 [cited by applicant]
US 20190025805A1 · Cella et al. · 2019 [cited by applicant]
US 20190025812A1 · Cella et al. · 2019 [cited by applicant]
US 20190034639A1 · Sloan · 2019 [cited by examiner]
US 20190207981A1 · Sweeney · 2019 [cited by examiner]
US 20200005633A1 · Jin et al. · 2020 [cited by applicant]
US 20200389495A1 · Crabtree et al. · 2020 [cited by applicant]
US 20200412767A1 · Crabtree et al. · 2020 [cited by applicant]
US 20210026960A1 · Martin et al. · 2021 [cited by applicant]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210075626A1 · Ilany · 2021 [cited by examiner]
US 20210234885A1 · Campbell · 2021 [cited by applicant]
US 20210336992A1 · Shivanna · 2021 [cited by examiner]
US 20220078210A1 · Crabtree et al. · 2022 [cited by applicant]
US 20220103577A1 · Shah et al. · 2022 [cited by applicant]
US 20220366045A1 · Summers et al. · 2022 [cited by applicant]
US 20230262073A1 · Sheu et al. · 2023 [cited by applicant]
US 20230328075A1 · Almasan et al. · 2023 [cited by applicant]
US 20230370439A1 · Crabtree et al. · 2023 [cited by applicant]
US 20230388320A1 · Lu et al. · 2023 [cited by applicant]
US 20240305664A1 · McCarthy et al. · 2024 [cited by applicant]
Andrew et al., “Knowledge Graphs for Cybersecurity: A Framework for Honeypot Data Analysis,” 2023 IEEE International Conference on Cryptography, Informatics, and Cybersecurity (ICoCICs) Year: 2023 | Conference Paper | P… [cited by applicant]
Zakaria et al., “Feature Extraction and Selection Method of Cyber-Attack and Thread Profiling in Cybersecurity Audit,” 2019 International Conference on Cybersecurity (ICoCSec) Year: 2019 | Conference Paper | Publisher: … [cited by applicant]
Cited By (1)
US 12,488,118