Abstract:
A method and apparatus is provided for determining aggregated value of risk and resilience metrics of critical nodes in a network of computer nodes, comprising determining a status of each node in a plurality of nodes, computing one or more effectiveness attributes for each node in the plurality of nodes, ranking the plurality of nodes based upon at least the one or more effectiveness attributes of each node, determining one or more nodes as critical nodes based on the ranking and computing a criticality surface of the one or more critical nodes as the aggregated value of risk and resilience metrics, wherein the criticality surface is an aggregation of the one or more effectiveness attribute for each of the one or more critical nodes.
Abstract:
A method and apparatus is provided for determining aggregated value of risk and resilience metrics of critical nodes in a network of computer nodes, comprising determining a status of each node in a plurality of nodes, computing one or more effectiveness attributes for each node in the plurality of nodes, ranking the plurality of nodes based upon at least the one or more effectiveness attributes of each node, determining one or more nodes as critical nodes based on the ranking and computing a criticality surface of the one or more critical nodes as the aggregated value of risk and resilience metrics, wherein the criticality surface is an aggregation of the one or more effectiveness attribute for each of the one or more critical nodes.
Abstract:
Provided are processes of monitoring or modifying a network of electronically connected assets that dynamically builds relationships and dependencies among detected vulnerabilities in one or more of the assets and sensor measurements so that risk assessment can be achieved more accurately and in real-time. A process includes: identifying a plurality of vulnerabilities on a network of electronically interconnected devices representing one or more critical assets; determining dependencies between each vulnerability in the plurality of vulnerabilities; creating a hidden Markov model representing an attack state of each vulnerability of the plurality of vulnerabilities; determining the exploit likelihood of each of the attack states at a first time; determining the most probable sequences or paths of the attack states; and identifying dynamically the risk of one or more of the critical assets based on the sequences or paths of attack states.
Abstract:
Provided are processes of monitoring or modifying a network of electronically connected assets that dynamically builds relationships and dependencies among detected vulnerabilities in one or more of the assets and sensor measurements so that risk assessment can be achieved more accurately and in real-time. A process includes: identifying a plurality of vulnerabilities on a network of electronically interconnected devices representing one or more critical assets; determining dependencies between each vulnerability in the plurality of vulnerabilities; creating a hidden Markov model representing an attack state of each vulnerability of the plurality of vulnerabilities; determining the exploit likelihood of each of the attack states at a first time; determining the most probable sequences or paths of the attack states; and identifying dynamically the risk of one or more of the critical assets based on the sequences or paths of attack states.