IP Library Granted Patent US 11,637,853
Granted Patent B2
US 11,637,853 · App. 17/203,057 · Granted Apr 25, 2023

Operational network risk mitigation system and method

Inventors: Yair Attar (Tel-Aviv, IL); Leon Levitsky (Petach Tikva, IL); Matan Dobrushin (Givatayim, IL); Aviad Elizur (Sderot, IL); Ido Peled (Tel Mond, IL)
Assignee: OTORIO LTD.
H04L63/1433H04L41/0816H04L41/0879H04L41/0886H04L41/22H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,637,853
App. No.
17/203,057
Granted
Apr 25, 2023
Kind
B2
Abstract

A computer network risk mitigation system includes a computerized platform configured to utilize gathered contextual data regarding cyber-risk metrics in are operational technology network. The computerized platform is configured to conduct network configuration changes in accordance with the gathered contextual data in order to mitigate cyber-security threats. Methods for refining a network attack graph and for utilizing risk score evaluation are also described.

Claims (16)

1. A method for utilizing a risk score evaluation, comprising the steps of:

(i) computing node sums for each node by summing the importance scores of vulnerable devices which belong to a respective node,

(ii) computing edge sums for each edge by summing the vulnerability scores of the vulnerabilities on a respective edge,

(iii) computing inward edge sum for each node by summing the edge sums of edges directed to a respective node,

(iv) computing edge weights by normalizing the edge sum with an inward edge sum of a target node,

(v) computing a node weights vector, wherein a weighted adjacency matrix is set in accordance with the values obtained in step (iv), and

wherein an intrinsic value vector is set in accordance with the values obtained in step (i),

(vi) computing device impact scores,

(vii) computing the security risk scores for each separate vulnerability, wherein the calculated risk score evaluation is utilized as part of a network risk mitigation and followed by protective measures to be conducted upon the network,

wherein an automated network segmentation is facilitated to mitigate relevant network vulnerabilities; wherein short execution times are enabled during the conduction of the network segmentation by detecting and removing cyclic edges from network attack graph thereby restricting the number of devices in the network and

(viii) computing security metrics over the resulting network attack graph and evaluating and prioritizing the security gaps detected in the network for mitigation.

2. The method of claim 1 , wherein a detailed report is created based on said risk score evaluation.

3. The method of claim 1 , wherein a user resolves the detected security gaps by manually applying configuration changes to mitigate relevant network vulnerabilities.

4. The method of claim 1 , wherein the protective measures comprise blocking of malicious application signatures.

5. The method of claim 1 , wherein the protective measures comprise applying blocking rules for unwanted communication in the network.

6. The method of claim 1 , wherein the protective measures comprise modifying login credentials to an asset within the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2021
From: ATTAR, YAIR; LEVITSKY, LEON; DOBRUSHIN, MATAN; ELIZUR, AVIAD; PELED, IDO
To: OTORIO LTD.
Reel/Frame 056133/0319 →
Priority Claims (1)
IL 273321 · Mar 16, 2020 · national
Continuity (1)
Related Publication 20210288992A1 · Sep 16, 2021