Methods and systems for estimating risk of enterprise application for quantum cryptography migration
The disclosure generally relates to methods and systems for estimating risk of enterprise application for quantum cryptography migration. Conventional software risk assessment tools that assess the quantum computer related security attacks are limited. The present disclosure solves the technical problems in the art for estimating risk of enterprise application for quantum cryptography migration. The methods and systems of the present disclosure formulated the problem based on a survival function in the probability theory, where possible chances of the enterprise application crypto surviving the quantum computer are calculated, and an estimated risk value is assigned to the enterprise software application. The methods and systems of the present disclosure discloses a risk estimator which take enterprise application specific metadata as the inputs and produces the risk score associated to the enterprise application against the quantum threats using a modified cox model and a modified rule of Mosca.
1 . A processor-implemented method, comprising the steps of:
defining, via one or more hardware processors, one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;
receiving, via the one or more hardware processors, an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which a quantum computer manufactured;
extracting, via the one or more hardware processors, an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;
computing, via the one or more hardware processors, a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:
receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;
determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;
determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and
calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;
estimating, via the one or more hardware processors, a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;
determining, via the one or more hardware processors, a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;
calculating, via the one or more hardware processors, a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;
evaluating, via the one or more hardware processors, the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:
(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and
(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and
performing, via the one or more hardware processors, the quantum cryptography migration based on the evaluated risk of the host enterprise application.
2 . The processor-implemented method of claim 1 , wherein the application related data of the host enterprise application is received from one or more of: (i) one or more answers received for a questionnaire related to the host enterprise application, (ii) a source code of the host enterprise application, and (iii) one or more log files of the host enterprise application.
3 . The processor-implemented method of claim 1 , wherein the one or more application risk input parameters comprise of an application type, a threat type, a user type and validity, a vulnerability, and a third-party library validity.
4 . The processor-implemented method of claim 1 , wherein the one or more platform risk input parameters comprise of a language cohesion index, a lower environment risk parameter, an input and output movement, a shelf-life parameter, and a hardware security module (HSM) migration policy.
5 . The processor-implemented method of claim 1 , wherein the one or more risk policy input parameters comprise of a policy related parameter, a legacy application transformation, and a post quantum cryptography (PQC) algorithm vulnerability, wherein the PQC algorithm vulnerability parameters represent a risk condition and an associated impact on the migration, the risk condition being based on vulnerability information associated with at least one PQC algorithm as identified by a recognized standards or analysis authority.
6 . The processor-implemented method of claim 1 , wherein the Mosca risk value of the host enterprise application is determined using the rule of Mosca, according to a relation:
Mosca
risk
value
=
Z
-
(
X
+
Y
)
wherein Z is the time by which quantum computer manufactured with sufficient qubits, which breaks the predefined crypto scheme, X is the data shelf life of application related data of the host enterprise application, and Y is the time to migrate the host enterprise application.
7 . A system, comprising:
a memory storing instructions;
one or more input/output (I/O) interfaces; and
one or more hardware processors coupled to the memory via the one or more I/O interfaces,
wherein the one or more hardware processors are configured by the instructions to:
define one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;
receive an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which quantum computer manufactured;
extract an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;
compute a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:
receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;
determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;
determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and
calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;
estimate a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;
determine a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;
calculate a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;
evaluate the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:
(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and
(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and
perform the quantum cryptography migration based on the evaluated risk of the host enterprise application.
8 . The system of claim 7 , wherein the one or more hardware processors are configured to receive the application related data of the host enterprise application from one or more of: (i) one or more answers received for a questionnaire related to the host enterprise application, (ii) a source code of the host enterprise application, and (iii) one or more log files of the host enterprise application.
9 . The system of claim 7 , wherein the one or more application risk input parameters comprise of an application type, a threat type, a user type and validity, a vulnerability, and a third-party library validity.
10 . The system of claim 7 , wherein the one or more platform risk input parameters comprise of a language cohesion index, a lower environment risk parameter, an input and output movement, a shelf-life parameter, and a hardware security module (HSM) migration policy.
11 . The system of claim 7 , wherein the one or more risk policy input parameters comprise of a policy related parameter, a legacy application transformation, and a post quantum cryptography (PQC) algorithm vulnerability, wherein the PQC algorithm vulnerability parameters represent a risk condition and an associated impact on the migration, the risk condition being based on vulnerability information associated with at least one PQC algorithm as identified by a recognized standards or analysis authority.
12 . The system of claim 7 , wherein the one or more hardware processors are configured to determine Mosca risk value of the host enterprise application using the rule of Mosca, according to a relation:
Mosca
risk
value
=
Z
-
(
X
+
Y
)
wherein Z is the time by which quantum computer manufactured with sufficient qubits, which breaks the predefined crypto scheme, X is the data shelf life of application related data of the host enterprise application, and Y is the time to migrate the host enterprise application.
13 . One or more non-transitory machine-readable information storage mediums comprising one or more instructions which when executed by one or more hardware processors cause:
defining one or more application risk input parameters, one or more platform risk input parameters, and one or more risk policy input parameters, for a host enterprise application;
receiving an application related data of the host enterprise application, a data shelf life of the application related data of the host enterprise application, a time to migrate the host enterprise application whose risk is to be estimated from a quantum threat after migration, and a time by which a quantum computer manufactured;
extracting an input parameter value of each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, from the application related data of the host enterprise application whose risk is to be estimated from the quantum threat, using a data extraction technique, wherein a code parser is configured to fetch the input parameter value of an user type and a validity by analyzing an user access policy related data, and wherein the input parameter value corresponding to a vulnerability is extracted from an audit report or from vulnerability information generated during an application testing phase, and wherein the input parameter value associated with validity of a third party library is fetched based on dependency information of one or more third party libraries present in the host enterprise application;
computing a hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on an associated input parameter value, using a modified cox model, wherein computing the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, based on the associated input parameter value, using the modified cox model, comprising:
receiving a number of qubits of a quantum computer, and a number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application, of one or more predefined cryptographic schemes;
determining a quantum hazard value, based on the number of qubits of the quantum computer and the number of qubits needed to break a predefined cryptographic scheme defined for the host enterprise application;
determining a partial likelihood function value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters, using the modified cox model, by estimating a probability of attack on the predefined cryptographic scheme for a current instance with respect to one or more historical instances that are vulnerable to computing capability of the quantum computer; and
calculating the hazard value for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters values, using the quantum hazard value, an associated partial likelihood function value and the associated input parameter value;
estimating a hazard risk value of the host enterprise application, based on the hazard value computed for each of the one or more application risk input parameters, the one or more platform risk input parameters, and the one or more risk policy input parameters;
determining a Mosca risk value of the host enterprise application, based on the data shelf life of application related data of the host enterprise application, the time to migrate the host enterprise application, and the time by which quantum computer manufactured, using a rule of Mosca;
calculating a cumulative risk value of the host enterprise application, using the hazard risk value of the host enterprise application and the Mosca risk value of the host enterprise application;
evaluating the risk of the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and an average cumulative risk value, wherein evaluating the risk the host enterprise application for quantum cryptography migration, based on the cumulative risk value of the host enterprise application and the average cumulative risk value, comprising:
(i) assigning the host enterprise application with a high priority and allowing a migration of the host enterprise application when the cumulative risk value of the host enterprise application is higher than the average cumulative risk value; and
(ii) assigning the host enterprise application with a low priority and postponing the migration of the host enterprise application when the cumulative risk value of the host enterprise application is less than or equal to the average cumulative risk value; and
performing the quantum cryptography migration based on the evaluated risk of the host enterprise application.