Systems and methods for capturing and preserving cyber resilience performance primitives
Systems, methods, and computer-readable media for modeling cyber resilience data are disclosed. A system can include one or more processing circuits configured to receive a request to re-model one or more safeguards of at least one entity including modeling parameters and a temporal interval. The processing circuits can identify one or more tokens including the safeguards and one or more proofs of the entity at the temporal interval. The processing circuits can generate at least one re-modeled output at the temporal interval based at least on re-modeling the one or more tokens. The re-modeled output can include an update to at least one of (i) a safeguard status or (ii) a resilience score. The processing circuits can generate at least one new token including the re-modeled output, the safeguards, and the proofs and record the new token in a token storage.
1 . A method, comprising:
receiving, by one or more processing circuits from a third-party computing system, a request to re-model one or more safeguards of at least one entity, wherein the request comprises one or more modeling parameters and a temporal interval;
identifying, by the one or more processing circuits, one or more tokens comprising the one or more safeguards and one or more proofs of the at least one entity at the temporal interval, wherein the one or more safeguards correspond with a plurality of modeled outputs, and wherein the plurality of modeled outputs comprise at least one first modeled output corresponding with a safeguard status based at least on a safeguard threshold and at least one second modeled output corresponding with at least one resilience score;
generating, by the one or more processing circuits using the one or more tokens, at least one re-modeled output at the temporal interval based at least on re-modeling the one or more tokens, wherein the at least one re-modeled output comprises an update, based on the one or more modeling parameters, to at least one of (i) the safeguard status or (ii) the at least one resilience score, and wherein the update to at least one of (i) the safeguard status or (ii) the at least one resilience score is based at least on the one or more safeguards or the one or more proofs;
generating, by the one or more processing circuits, at least one new token comprising the at least one re-modeled output, the one or more safeguards, and the one or more proofs; and
recording, by the one or more processing circuits, the at least one new token in a token storage.
2 . The method of claim 1 , comprising:
receiving, by the one or more processing circuits, an updated safeguard threshold corresponding with the at least one entity; and
generating, by the one or more processing circuits, the at least one re-modeled output comprising an update to the safeguard status based on the updated safeguard threshold.
3 . The method of claim 1 , comprising:
receiving, by the one or more processing circuits, a heuristic scoring model corresponding with the at least one entity; and
generating, by the one or more processing circuits using the heuristic scoring model and the one or more safeguards, the at least one re-modeled output comprising an update to the at least one resilience score or one or more protection sub-scores, wherein generating the one or more protection sub-scores comprises generating the at least one resilience score.
4 . The method of claim 1 , comprising:
receiving, by the one or more processing circuits, an updated safeguard threshold corresponding with the at least one entity and a heuristic scoring model corresponding with the at least one entity; and
generating, by the one or more processing circuits, the at least one re-modeled output comprising an update to the safeguard status based on the updated safeguard threshold and an update to the at least one resilience score or one or more protection sub-scores using the heuristic scoring model and the one or more safeguards.
5 . The method of claim 1 , comprising:
generating, by the one or more processing circuits, a first plurality of protection sub-scores based on the one or more safeguards and one or more coverage parameters of a heuristic scoring model, the one or more coverage parameters corresponding with safeguard types of the one or more safeguards implemented in one or more entity computing systems of the at least one entity;
generating, by the one or more processing circuits, a second plurality of protection sub-scores based on the one or more safeguards and one or more configuration parameters of the heuristic scoring model, the one or more configuration parameters corresponding with entity configurations associated with the safeguard types; and
generating, by the one or more processing circuits, the at least one resilience score based on a weighted aggregation of the first plurality of protection sub-scores and the second plurality of protection sub-scores.
6 . The method of claim 1 , wherein the one or more tokens correspond with the temporal interval, wherein the temporal interval corresponds with a time period for evaluating the at least one entity, wherein at least one token of the one or more tokens corresponds with a temporal sub-interval comprising a portion of the temporal interval.
7 . The method of claim 1 , comprising:
responsive to determining the safeguard status fails to satisfy the safeguard threshold, determining, by the one or more processing circuits, one or more actions to perform the update to the at least one of (i) the safeguard status or (ii) the at least one resilience score.
8 . The method of claim 1 , wherein generating the at least one new token comprises:
retrieving or extracting, by the one or more processing circuits, the at least one re-modeled output, the one or more safeguards, the one or more proofs; and
encapsulating, by the one or more processing circuits, the at least one re-modeled output, the one or more safeguards, the one or more proofs in a structured format corresponding with the at least one new token, the structured format comprising a plurality of metadata fields corresponding with the one or more safeguards and the one or more proofs.
9 . The method of claim 1 , comprising:
updating, by the one or more processing circuits, the at least one new token as a third-party token by adding or updating a metadata field of the at least one new token indicating an association with a third-party entity corresponding with the third-party computing system; and
responsive to generating one or more additional tokens, programmatically establishing, by the one or more processing circuits, a data link between the at least one new token and the one or more additional tokens based on determining one or more metadata fields of the one or more additional tokens indicate the association with the third-party entity.
10 . The method of claim 1 , comprising:
responsive to determining the request corresponds with re-analysis of the one or more safeguards, re-analyzing, by the one or more processing circuits, the one or more safeguards and the one or more proofs; and
determining, by the one or more processing circuits, an update to at least one safeguard of the one or more safeguards based on the re-analysis.
11 . The method of claim 1 , wherein the request comprises a requirements token comprising one or more third-party requirements of a third-party associated with the third-party computing system, the method comprising:
identifying, by the one or more processing circuits, the one or more modeling parameters based on extracting the one or more third-party requirements from the requirements token.
12 . The method of claim 1 , comprising:
receiving, by the one or more processing circuits from the third-party computing system in real-time, a second request comprising a second set of modeling parameters to re-model the one or more safeguards.
13 . A system, comprising:
one or more processing circuits configured to:
receive, from a third-party computing system, a request to re-model one or more safeguards of at least one entity, wherein the request comprises one or more modeling parameters and a temporal interval;
identify one or more tokens comprising the one or more safeguards and one or more proofs of the at least one entity at the temporal interval, wherein the one or more safeguards correspond with a plurality of modeled outputs, and wherein the plurality of modeled outputs comprise at least one first modeled output corresponding with a safeguard status based at least on a safeguard threshold and at least one second modeled output corresponding with at least one resilience score;
generate, using the one or more tokens, at least one re-modeled output at the temporal interval based at least on re-modeling the one or more tokens, wherein the at least one re-modeled output comprises an update, based on the one or more modeling parameters, to at least one of (i) the safeguard status or (ii) the at least one resilience score, and wherein the update to at least one of (i) the safeguard status or (ii) the at least one resilience score is based at least on the one or more safeguards or the one or more proofs;
generate at least one new token comprising the at least one re-modeled output, the one or more safeguards, and the one or more proofs; and
record the at least one new token in a token storage.
14 . The system of claim 13 , the one or more processing circuits configured to:
receive an updated safeguard threshold corresponds with the at least one entity; and
generate the at least one re-modeled output comprising an update to the safeguard status based on the updated safeguard threshold.
15 . The system of claim 13 , the one or more processing circuits configured to:
receive a heuristic scoring model corresponding with the at least one entity; and
generate, using the heuristic scoring model and the one or more safeguards, the at least one re-modeled output comprising an update to the at least one resilience score or one or more protection sub-scores, wherein generating the one or more protection sub-scores comprises generating the at least one resilience score.
16 . The system of claim 13 , the one or more processing circuits configured to:
receive an updated safeguard threshold corresponding with the at least one entity and a heuristic scoring model corresponding with the at least one entity; and
generate the at least one re-modeled output comprising an update to the safeguard status based on the updated safeguard threshold and an update to the at least one resilience score or one or more protection sub-scores using the heuristic scoring model and the one or more safeguards.
17 . The system of claim 13 , the one or more processing circuits configured to:
generate a first plurality of protection sub-scores based on the one or more safeguards and one or more coverage parameters of a heuristic scoring model, the one or more coverage parameters corresponding with safeguard types of the one or more safeguards implemented in one or more entity computing systems of the at least one entity;
generate a second plurality of protection sub-scores based on the one or more safeguards and one or more configuration parameters of the heuristic scoring model, the one or more configuration parameters corresponding with entity configurations associated with the safeguard types; and
generate the at least one resilience score based on a weighted aggregation of the first plurality of protection sub-scores and the second plurality of protection sub-scores.
18 . The system of claim 13 , wherein the one or more tokens correspond with the temporal interval, wherein the temporal interval corresponds with a time period for evaluating the at least one entity, and wherein at least one token of the one or more tokens corresponds with a temporal sub-interval comprising a portion of the temporal interval.
19 . The system of claim 13 , the one or more processing circuits configured to:
responsive to determining the safeguard status fails to satisfy the safeguard threshold, determine, by the one or more processing circuits, one or more actions to perform the update to the at least one of (i) the safeguard status or (ii) the at least one resilience score.
20 . A non-transitory computer readable medium (CRM) comprising one or more instructions stored thereon and executable by one or more processors to:
receive, from a third-party computing system, a request to re-model one or more safeguards of at least one entity, wherein the request comprises one or more modeling parameters;
identify one or more tokens comprising the one or more safeguards of the at least one entity, wherein the one or more safeguards correspond with a plurality of modeled outputs;
generate, using the one or more tokens, at least one re-modeled output based at least on re-modeling the one or more tokens, wherein the at least one re-modeled output comprises an update, based on the one or more modeling parameters, to at least one of (i) a safeguard status or (ii) at least one resilience score based at least on the one or more safeguards;
generate at least one new token comprising the at least one re-modeled output and the one or more safeguards; and
record the at least one new token in a token storage.