发明名称 Assessment of cyber threats
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for assessing cyber threats. In some implementations, data indicating a time window is received. Data indicating at least one dynamic Bayesian network (DBN) is accessed. A plurality of simulations are performed using the DBN, and outcomes of the plurality of simulations are sampled according to the state of the DBN representing the end of the time window. Based on the sampled outcomes of the simulations, a measure of impact of the computer-based threats to the organization over the time window is determined. The determined measure is provided for output to a user.
申请公布号 US9537884(B1) 申请公布日期 2017.01.03
申请号 US201615170369 申请日期 2016.06.01
申请人 Cyberpoint International LLC 发明人 Raugas Mark V.;Ulrich James L.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Fish & Richardson P.C. 代理人 Fish & Richardson P.C.
主权项 1. A system comprising: one or more computers comprising one or more hardware processors; one or more computer-readable media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform operations comprising: receiving, by the one or more computers, data indicating a time window having a beginning and an end;accessing, by the one or more computers, data indicating at least one dynamic Bayesian network (DBN) that specifies relationships among (i) infrastructure nodes representing computing devices of an organization and a network connecting the computing devices, (ii) asset nodes indicating characteristics of assets of the organization, (iii) threat nodes representing computer-based threats including at least one selected from the group consisting of a virus, malware, a network intrusion, and a denial of service attack, and (iv) mitigation nodes representing threat mitigation measures of the organization;performing, by the one or more computers, a plurality of simulations using the DBN, each simulation involving propagating data through the DBN for various time steps within the time window;sampling, by the one or more computers, outcomes of the plurality of simulations according to the state of the DBN representing the end of the time window;based on the sampled outcomes of the simulations, determining, by the one or more computers, a measure of impact of the computer-based threats to the organization over the time window; andproviding, by the one or more computers and for output to a user, a graphical representation of the determined measure of impact of the computer-based threats to the organization over the time window in a graphical user interface.
地址 Baltimore MD US