US2014208429A1PendingUtilityA1
Method for Evaluating System Risk
Assignee: NORWICH UNIVERSITY APPLIED RES INST NUARIPriority: May 19, 2006Filed: Sep 11, 2013Published: Jul 24, 2014
Est. expiryMay 19, 2026(expired)· nominal 20-yr term from priority
Inventors:Peter Stephenson
G06Q 10/06G06F 21/55
56
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method for evaluating the vulnerability of a system having at least one portal is provided, wherein at least a portion of the method is implemented via a controller. The method includes examining the at least one portal to identify at least one accessible portal, performing a qualitative analysis responsive to the at least one accessible portal, generating a risk profile responsive to the performing a qualitative analysis and operating the controller to cause the controller to at least one of log the risk profile in a storage device, and display the risk profile via a display device.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for evaluating vulnerability of a system having at least one portal, wherein at least a portion of the method is implemented via a controller, the method comprising:
examining the at least one portal to identify at least one accessible portal; performing a qualitative analysis responsive to the at least one accessible portal; generating a risk profile responsive to the performing a qualitative analysis; and operating the controller to cause the controller to at least one of log the risk profile in a storage device, and display the risk profile via a display device.
2 . The method of claim 1 , wherein the performing a qualitative analysis includes,
identifying potential threats against the system; and identifying qualitative risks to the system.
3 . The method of claim 2 , wherein the identifying potential threats against the system includes performing an inter-domain communications analysis, wherein the inter-domain communications analysis includes,
defining a set of criteria for the system; and analyzing the criteria to generate a security policy domain.
4 . The method of claim 3 , wherein the security policy domain includes at least a portion of the elements of the system, wherein each of the at least a portion of the elements are subject to the same security policy.
5 . The method of claim 2 , wherein the identifying qualitative risks to the system includes,
obtaining system data responsive to threats to the system at a policy domain level, vulnerabilities to the system at the policy domain level and the impact of the threats and the vulnerabilities on the system; and generating at least one scoped ontology individual by processing the system data responsive to at least one predetermined ontology, wherein the at least one scoped ontology individual is responsive to at least one possible risk to the system.
6 . The method of claim 5 , wherein the identifying qualitative risks to the system includes performing a first order risk analysis on the at least one scoped ontology individual.
7 . The method of claim 6 , wherein the first order risk analysis is responsive to the relationship,
(T·V i),
where V is the vulnerability of at least one element in the system, T is the threat to the at least one element in the system and i is the impact on the system.
8 . The method of claim 7 , wherein the result of the first order risk analysis is either true or false.
9 . The method of claim 7 , wherein if the result is false, the method includes,
determining that no risk to the system is present; and terminating the system evaluation.
10 . The method of claim 1 , further comprising performing a quantitative analysis responsive to the qualitative analysis and wherein the risk profile is further responsive to the quantitative analysis, wherein the quantitative analysis includes,
generating a risk probability for the at least one accessible portal; generating a total risk probability for the system; and generating a financial representation of the risk exposure of the system.
11 . The method of claim 10 , wherein the generating a risk probability for the at least one accessible portal includes,
obtaining attack data responsive to the system; identifying attack data for each of the at least one accessible portal; and determining a weighted risk probability for each of the at least one accessible portal.
12 . The method of claim 11 , wherein the generating a total risk probability for the system includes,
aggregating the weighted risk probability for each of the at least one accessible portal to generate an aggregated risk probability.
13 . The method of claim 10 , wherein the generating a financial representation of the risk exposure of the system includes,
determining a risk exposure factor using an aggregated risk probability.
14 . The method of claim 13 , wherein the generating a financial representation of the risk exposure of the system further includes,
determining a risk exposure factor using a predetermined set of variables responsive to the system.
15 . The method of claim 1 , wherein the performing a quantitative analysis responsive to the qualitative analysis includes,
generating a risk exposure factor responsive to the relationship,
R e =f q ( V a ),
wherein R e is the risk exposure factor, V a is an Attack Value Factor and f q is a quantitative analysis factor which is responsive to the financial baseline data of the system.
16 . An evaluation system for implementing a method for evaluating the vulnerability of a system having at least one portal, the evaluation system comprising:
a controller, wherein the controller is configured to implement at least a portion of the method, wherein the method includes, examining the at least one portal to identify at least one accessible portal; analyzing the system to determine a probability that a threat to the system will result in an impact to the system responsive to the relationship given by:
R=P ( T·V i ),
wherein R is risk, V is vulnerability, T is threat, P is probability and i is the impact on the system; generating a risk profile responsive to the analyzing the system; and operating the controller to cause the controller to at least one of log the risk profile in a storage device, and
display the risk profile via a display device.
17 . The evaluation system of claim 16 , wherein analyzing the system includes performing a qualitative analysis responsive to the at least one accessible portal, the qualitative analysis including identifying potential threats against the system comprising,
defining a set of criteria for the system; and analyzing the criteria to generate a security policy domain, wherein the security policy domain includes at least a portion of the elements of the system, wherein each of the at least a portion of the elements are subject to the same security policy.
18 . The evaluation system of claim 16 , wherein analyzing the system includes performing a qualitative analysis responsive to the at least one accessible portal, the qualitative analysis including identifying qualitative risks to the system comprising,
obtaining system data responsive to threats to the system at a policy domain level, vulnerabilities to the system at the policy domain level and the impact of the threats and the vulnerabilities on the system; generating at least one scoped ontology individual by processing the system data responsive to at least one predetermined ontology, wherein the at least one scoped ontology individual is responsive to at least one possible risk to the system; and performing a first order risk analysis on the at least one scoped ontology individual, the first order risk analysis being responsive to the relationship,
(T·V i),
where V is the vulnerability of at least one element in the system, T is the threat to the at least one element in the system and i is the impact on the system.
19 . The evaluation system of claim 16 , wherein analyzing the system includes, performing a quantitative analysis, the quantitative analysis including,
generating a risk probability for the at least one accessible portal, generating a total risk probability for the system; and generating a financial representation of the risk exposure of the system, wherein the generating a risk probability for the at least one accessible portal includes,
obtaining attack data responsive to the system;
identifying attack data for each of the at least one accessible portal;
and
determining a weighted risk probability for each of the at least one accessible portal.
20 . The evaluation system of claim 19 , wherein the generating a total risk probability for the system includes,
aggregating the weighted risk probability for each of the at least one accessible portal to generate an aggregated risk probability.Join the waitlist — get patent alerts
Track US2014208429A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.