US2017308707A1PendingUtilityA1
Mechanism to Calculate Probability of a Cyber Security Incident
Est. expiryJun 8, 2032(~5.8 yrs left)· nominal 20-yr term from priority
Inventors:Thomas Lee
G06F 2221/034G06F 21/577
55
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
An Archetype Software Invention which calculates the probability of a cyber security incident for a given computer by correlating the distribution of computer program files with the occurrences of security incidents across a large number of computers.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method for calculating the probability of a cyber security incident for a computer within a collection of computers comprising:
a. providing a means for compiling program file names, checksums, and locations within the file systems on each computer within said collection of computers, where the identity of each said program file is determined by a unique combination of filename and checksum, b. providing a means for organizing the said program files into Program File Bundles based upon similar distribution across said collection of computers, c. providing a means for calculating a probability value for each said Program File Bundle according to the distribution of said program file bundle relative to computers previously or currently involved in a security incident and computers never involved in a security incident and which are part of said collection of computers, d. providing a means for calculating said probability of a cyber security incident for said computer, as a sum of said probabilities values for each said Program File Bundle present on said computer.
2 . The method for calculating the probability of a cyber security of claim 1 wherein the function for calculating the probability value for any said Program File Bundle is:
P
b
,
a
=
(
I
b
,
a
C
b
,
a
-
I
a
C
a
)
×
C
b
,
a
C
_
B
,
a
where P b,a is the probability value for any said Program File Bundle b, at the time of an analysis a, where an analysis is defined as a point in time where said Program File Bundles are identified, recorded and their said probability values are calculated and recorded; I b,a is the number of said computers previously or currently involved in a security incident and that have said Program File Bundle b at the time of said analysis a, C b,a is the total number of computers with Program File Bundle b at the time of said analysis a and I a is the total number of said computers previously or currently involved in a security incident at the time of analysis a, C a is the total number of computers at the time of analysis a, and C B,a is the average number of computers per said Program File Bundle, across all said Program File Bundles B at the time of analysis a o
3 . The method for calculating the probability of a cyber security incident of claim 2 wherein said means for organizing the identities of said program files into Program File Bundles based upon similar distribution across said collection of computers comprising:
a. providing a means for dividing said computers into N cells, with one or more said computers in each said cell,
b. providing a means for obtaining a collection of values {G nf } which are the number of times each said program file f was found within said cell n, counting said program file no more than once per said computer even if it is found multiple times in the file system, and counting said program file once, even if it had been removed from said computer,
c. providing a means for calculating a distance value d ab =F 1 ({G nf a },{G nf b }), between every two said program files, symbolized by f a and f b , where said distance value is some function F 1 of said collection of {G nf } values for each said program file,
d. providing a means for compiling all said program files together into Program File Bundles, where each said Program File Bundle consists of said component program files for which the distance d ab between any two is zero or near zero,
4 . The method for calculating the probability of a cyber security incident of claim 3 wherein the function F 1 is
d
ab
=
∑
n
=
0
N
(
G
nf
a
-
G
nf
b
)
2
,
and where N is the total number of computer cells,Join the waitlist — get patent alerts
Track US2017308707A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.