Security model utilizing multi-channel data
Abstract
Systems, methods and computer-readable storage media are utilized dynamically discovering components of a computer network environment. The processing circuit of a data acquisition engine configured to determine a network identifier associated with an entity, the entity comprising information associated with previously stored device connectivity data for the entity, determine network data based on the network identifier, validate the network name and the network data, comprising determining whether the network data is included in the previously stored device connectivity data, and provide additionally collected device connectivity data to a security model.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of dynamically discovering new components of a computer network environment, the method comprising:
determining, by processing circuits, a network identifier associated with an entity, the entity comprising information associated with previously stored device connectivity data for the entity; determining, by the processing circuits, network data based on the network identifier; validating, by the processing circuits, the network name and the network data, comprising determining whether the network data is included in the previously stored device connectivity data; and providing, by the processing circuits, additionally collected device connectivity data to a security model.
2 . The method of claim 1 , further comprising:
analyzing, by the processing circuits, the network data to identify port data and vulnerability data.
3 . The method of claim 2 , further comprising:
generating, by the processing circuits, a cyber hygiene score based on historical data of the entity, wherein the historical data comprises previously collected vulnerability data and remediation data.
4 . The method of claim 2 , wherein identifying vulnerability data comprises cross-referencing the vulnerability data with a plurality of security parameters, and wherein the vulnerability data comprises subsets of vulnerability data associated with the network data.
5 . The method of claim 2 , wherein the port data comprises at least one port number and a target computer network environment associated with the entity, wherein each port number comprises a designation of an open state or a closed state.
6 . The method of claim 2 , wherein the at least one of the port data or the vulnerability data comprises virus data, threat data, and source data.
7 . The method of claim 2 , wherein a plurality of cybersecurity scores is generated utilizing at least the port data and the vulnerability data.
8 . The method of claim 2 , further comprising:
updating, by the processing circuits, a database table associated with an entity dataset and to comprise the port data, the vulnerability data, and a first time stamp associated with both the port data and the vulnerability data, wherein the first time stamp comprises a first moment in time and a first expiration time.
9 . The method of claim 8 , further comprising:
determining, by the processing circuits, the first expiration time of the first time stamp is lapsed; analyzing, by the processing circuits, a network identifier system zone of the network identifier to identify updated network data and updated subdomain data; determining, by the processing circuits, an updated IP range based on the updated network data, wherein the updated IP range comprises an updated IP address; analyzing, by the processing circuits, the updated IP address to identify updated port data and updated vulnerability data; updating, by the processing circuits, the database table to comprise the updated port data, the updated vulnerability data, and a second time stamp associated with both the updated port data and the updated vulnerability data, wherein the second time stamp comprises a second moment in time and a second expiration time; and providing, by the processing circuits, the updated port data and the updated vulnerability data to the security model.
10 . The method of claim 9 , further comprising:
storing, by the processing circuits, a first entity snapshot in the entity dataset, the first entity snapshot comprising the port data, the vulnerability data, and the first time stamp; storing, by the processing circuits, a second entity snapshot into the entity dataset comprising the updated port data, the updated vulnerability data, and the second time stamp; receiving, by the processing circuits, a request for entity snapshots associated with a period of time; analyzing, by the processing circuits, the entity dataset to determine which time stamps of the plurality of entity snapshots occur within the period of time; and providing, by the processing circuits, the entity snapshots that occur within the period of time.
11 . The method of claim 1 , further comprising:
determining, by the processing circuits, the network data and subdomain data is consistent with previously collected network data and previously collected subdomain data based on cross-referencing the network data and subdomain data with the previously collected network data and the previously collected subdomain data.
12 . The method of claim 1 , further comprising:
matching, by the processing circuits, an internet service provider (ISP) of an IP range to a particular domain of a plurality of domains; and determining, by the processing circuits, a magnitude of association between the ISP and the network identifier associated with the entity, wherein a strong magnitude of association or a weak magnitude of association is based on a relationship between the ISP and the network identifier associated with the entity.
13 . The method of claim 12 , wherein matching the internet service provider (ISP) of the IP range to the particular domain further comprises validating the particular domain of the plurality of domains utilizing at least one of a reverse lookup comparison, a network data comparison, an ISP comparison, an ISP to ISP comparison.
14 . The method of claim 1 , wherein the entity comprises an entity dataset and is associated with a plurality of cybersecurity scores and a multi-dimensional score.
15 . The method of claim 1 , wherein determining the network identifier comprises parsing out the network identifier from an email address identifier.
16 . A system comprising:
processing circuits configured to:
determine a network identifier associated with an entity, the entity comprising information associated with previously stored device connectivity data for the entity;
determine network data based on the network identifier;
validate the network name and the network data, comprising determining whether the network data is included in the previously stored device connectivity data; and
provide additionally collected device connectivity data to a security model.
17 . The system of claim 16 , wherein the processing circuits are further configured to:
analyze the network data to identify port data and vulnerability data.
18 . The system of claim 17 , wherein the processing circuits are further configured to:
update a database table associated with an entity dataset and to comprise the port data, the vulnerability data, and a first time stamp associated with both the port data and the vulnerability data, wherein the first time stamp comprises a first moment in time and a first expiration time.
19 . The system of claim 17 , wherein the processing circuits are further configured to:
match an internet service provider (ISP) of an IP range to a particular domain of a plurality of domains; and determine a magnitude of association between the ISP and the network identifier associated with the entity, wherein a strong magnitude of association or a weak magnitude of association is based on a relationship between the ISP and the network identifier associated with the entity.
20 . One or more non-transitory computer-readable storage media having instructions stored thereon that, when executed by processing circuits, cause the processing circuits to:
determine a network identifier associated with an entity, the entity comprising information associated with previously stored device connectivity data for the entity; determine network data based on the network identifier; validate the network name and the network data, comprising determining whether the network data is included in the previously stored device connectivity data; and provide additionally collected device connectivity data to a security model.Join the waitlist — get patent alerts
Track US2024015185A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.