EP4500377A1 - Risikoanalyse eines verteilten untersuchungsgegenstands - Google Patents
Risikoanalyse eines verteilten untersuchungsgegenstandsInfo
- Publication number
- EP4500377A1 EP4500377A1 EP23713644.5A EP23713644A EP4500377A1 EP 4500377 A1 EP4500377 A1 EP 4500377A1 EP 23713644 A EP23713644 A EP 23713644A EP 4500377 A1 EP4500377 A1 EP 4500377A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- analysis
- context
- risk
- investigation
- sba2
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
Definitions
- the present invention relates to a method, a computer program with instructions and a system for risk analysis of a distributed object of examination.
- the invention further relates to devices for use in such a system.
- An object of investigation for a cybersecurity risk analysis can have parts in different analysis contexts.
- the analysis contexts can be, for example, an embedded system, a backend or IT system or a mobile device.
- a risk analysis is carried out for the part of the subject of the investigation that is located in a context in a defined analysis context.
- This analysis context can be delimited by various properties, such as a distinct set of rules or a distinct analysis method, and a distinct rule for modeling the object of investigation.
- US 2010/0250476 A1 describes a method for assessing a risk of conflict between a number of security solutions to be integrated.
- a number of fragmentary security solutions are received in a computer system.
- a set of the received fragmentary security solutions is integrated into a composite security solution to meet a number of security requirements.
- the risk of conflict between the fragmentary security solutions to be integrated is assessed.
- CAIRIS tool is an open source platform for the collection, specification and validation of secure and usable systems.
- CAIRIS supports the concept of environments and thus enables the modeling of usage contexts.
- a method for risk analysis of a distributed object of examination comprises the steps:
- a computer program includes instructions that, when executed by a computer, cause the computer to carry out the following steps for risk analysis of a distributed subject of investigation:
- the term computer is to be understood broadly. In particular, it also includes workstations, distributed systems and other processor-based data processing devices.
- the computer program can, for example, be made available for electronic retrieval or stored on a computer-readable storage medium.
- a system for risk analysis of a distributed object of examination has:
- a first analysis module for carrying out a partially or fully automated risk analysis for a part of the object of investigation located in a first context in a first analysis context, the first analysis context being delimited by a distinct evaluation model or a distinct analysis method and a distinct regulation for modeling the object of investigation;
- a second analysis module for carrying out a partially or fully automated risk analysis for a part of the subject of investigation located in a second context in a second analysis context, the second analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation; wherein the first analysis module and the second analysis module are set up to exchange information about an identified need for protection, using a transmission path of a date for which a need for protection was determined to automatically determine which further risk analysis the need for protection should be taken into account.
- a first device for use in a system has a first analysis module for carrying out a partially or fully automated risk analysis for a part of an examination subject located in a first context in a first analysis context, the first analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation.
- the first analysis module is set up to transmit information about an identified need for protection to a second analysis module for carrying out a risk analysis for a part of the subject of the investigation located in a second context, using a transmission path to automatically determine a date for which a need for protection was determined, in which further risk analysis the need for protection should be taken into account.
- a second device for use in a system according to the invention has a second analysis module for carrying out a partially or fully automated risk analysis for a part of an examination subject located in a second context in a second analysis context, the second analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation.
- the second analysis module is set up to take into account a need for protection determined by a first analysis module when carrying out a risk analysis for a part of the subject of the investigation located in a first context in the risk analysis in the second context.
- the addition of a modeling step in which information on an identified need for protection is exchanged between the risk analyzes makes it possible to automate the resolution of the mutual dependencies.
- the same protection requirements can be adopted based on the information transmitted.
- the risk analyzes are carried out taking different regulations into account.
- a risk analysis is carried out for the part of the subject of the investigation that is located in a context in a defined analysis context.
- This analysis context is delimited by various properties, such as a distinct set of rules or a distinct analysis method, and a distinct rule for modeling the object of investigation.
- a transmission path of a date for which a need for protection was determined is used to determine which further risk analysis the need for protection should be taken into account.
- a cross-context composition of the context-specific risk analyzes can be achieved particularly advantageously by considering the information flows between the parts of the subject matter under consideration. These information flows transport goods worthy of protection, i.e. data that should be represented in the risk analyzes of the parts of the subject of investigation. This representation can, if necessary, take place at different levels of abstraction.
- the identified need for protection is taken into account by defining a risk-mitigating measure. Defining or implementing a suitable risk-mitigating measure ensures that the identified need for protection is taken into account.
- information on the defined risk-mitigating measure is exchanged between the risk analyses.
- the measure can now be reversed in the risk analysis that determined the original need for protection. This allows the risk-mitigating effect to be taken into account there too.
- the risk-mitigating measure is automated or determined by manual intervention.
- the risk-mitigating Measures can be automatically selected from relevant catalogs of measures based on the transferred protection requirement. This has the advantage that no manual intervention is required.
- the risk-mitigating measure can also be determined at the personal discretion of a specialist. In this way, the decision-making authority over the measures taken rests with the responsible specialist.
- a threat to the need for protection identified in the risk analysis in one context is taken into account in the risk analysis in the other context.
- threats to a protection need that are identified in another risk analysis can also be taken into account in the risk analysis that is the origin of the protection need determination.
- an identified need for protection is also taken into account in a risk analysis for a part of the subject of the investigation located in a third context. Traceability is also possible across multiple analyzes or analysis networks, provided that the data is identified uniformly. Implementation can be done using any algorithm that can identify all loop-free communication paths in a risk analysis “network”. The propagation of the protection needs and the protective measures can then take place with or against the direction of communication of the data.
- the first context relates to a means of transport, a mobile device or an embedded system.
- the second context can concern, for example, a backend or an IT system.
- the solution according to the invention can be used in all applications in which risk analyzes are carried out on distributed examination objects. Examples of this are applications on mobile phones with communication to an IT backend, the communication of industrial systems with IT systems or the communication of embedded systems, such as chip cards or similar, with other systems.
- Fig. 1 shows schematically a method for risk analysis of a distributed object of investigation
- Fig. 2 shows a system for risk analysis of a distributed object of investigation
- Fig. 3 illustrates a known approach to risk analysis of a distributed
- Fig. 5 illustrates an object of investigation that is distributed over a means of transport and an IT backend
- Fig. 6 illustrates a risk analysis of the subject of investigation from Fig. 5;
- FIG. 7 illustrates a first phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts;
- FIG. 9 illustrates a third phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts.
- Fig. 1 shows schematically a method for risk analysis of a distributed object of investigation.
- a partially or fully automated risk analysis is carried out for a part of the object of investigation located in a first context 10.
- the first context can relate to a means of transport, a mobile device or an embedded system.
- a partially or fully automated risk analysis is carried out for a person located in a second context Part of the subject of the investigation carried out 11.
- the second context can, for example, concern a backend or an IT system.
- the risk-mitigating measure can, for example, be automated or determined through manual intervention. Information on the defined 14 risk-mitigating measure can then be exchanged between the risk analyses. 15 Preferably, a threat to the need for protection identified in the risk analysis in one context is also taken into account in the risk analysis in the other context. An identified need for protection can also be taken into account in a risk analysis for a part of the subject of the investigation located in a third context.
- Fig. 2 shows a system 70 for risk analysis of a distributed object of examination.
- the system 70 includes a first device 20 for risk analysis and a second device 30 for risk analysis.
- the two devices 20, 30 communicate with each other via respective interfaces 21, 31.
- the first device 20 has a first analysis module 22 for carrying out a partially or fully automated risk analysis for a part of the subject of the examination located in a first context.
- the first context may concern a means of transport, a mobile device or an embedded system.
- the second device 30 has a second analysis module 32 for carrying out a partially or fully automated risk analysis for a part of the subject of the investigation located in a second context.
- the second context can concern, for example, a backend or an IT system.
- the first analysis module 22 and the second analysis module 32 are set up to exchange information about an identified protection requirement SB via the interfaces 21, 31.
- the identified need for protection SB can then be taken into account by the analysis modules 22, 32 by defining a risk-mitigating measure M.
- the risk-mitigating measure M can, for example, be determined automatically or through manual intervention.
- the analysis modules 22, 32 can then be connected via the interfaces 21, 31 Exchange information on the defined risk-mitigating measure M.
- information about threats to the need for protection identified during the risk analyzes is also exchanged so that they can be taken into account by the analysis modules 22, 32.
- the analysis modules 22, 32 can each be controlled by a control module 23, 33. If necessary, settings of the analysis modules can be made via user interfaces 25, 35
- the analysis modules 22, 32 and the control modules 23, 33 can be implemented as dedicated hardware, for example as integrated circuits. Of course, they can also be partially or completely combined or implemented as software that runs on a suitable processor, for example a GPU or a CPU.
- the interfaces 21, 31 can alternatively also be divided into separate inputs and outputs.
- the memories 24, 34 of the devices 20, 30 described can have both volatile and non-volatile memory areas and include a wide variety of storage devices and storage media, for example hard drives, optical storage media or semiconductor memories.
- Fig. 3 illustrates a known approach for risk analysis of a distributed object of investigation UG.
- a first part 40 of the subject of investigation UG is located in a first context
- a second part 40 'of the subject of investigation UG is located in a second context.
- a risk analysis Ri, R2 is carried out for the part 40, 40' of the subject of investigation UG located in a context in a defined analysis context.
- This analysis context can be delimited by various properties, such as a distinct evaluation model BM1, BM 2 or a distinct analysis method AM1, AM 2 , and a distinct regulation for modeling MV1, MV 2 of the subject of investigation UG.
- a cross-context composition of the context-specific analyzes Ri, R 2 is not possible.
- FIG. 4 illustrates an approach according to the invention for risk analysis of a distributed object of investigation UG.
- a first part 40 of the subject of investigation UG is located in a first context
- a second part 40 'of the subject of investigation UG is located in a second context.
- a risk analysis Ri, R2 is carried out partially or fully automatically for the part 40, 40' of the subject of investigation UG located in a context in a defined analysis context.
- this analysis context is delimited by various properties, such as a distinct evaluation model BM1, BM 2 or a distinct analysis method AM1, AM 2 , and a distinct regulation for modeling MV1, MV 2 of the object of investigation UG.
- a cross-context composition of the context-specific analyzes Ri, R2 is achieved by considering the information flows between the parts 40, 40 'of the object of investigation UG under consideration. These information flows transport goods worthy of protection, ie data D, which must be represented in the analyzes Ri, R2 of parts 40, 40' of the subject of investigation UG.
- the partial analyzes Ri, R2 can be carried out in parallel and a mutual consideration of the analysis results AE can be carried out assisted or automated.
- Fig. 5 illustrates an examination subject that is distributed over a means of transport 50 and an IT backend 60.
- a function for user registration in the means of transport 50 is to be considered.
- This function has a part Fi in the means of transport 50 for carrying out the registration and storage of the logged in user and a part F2 in the IT backend 60, which is responsible for user management and user authentication.
- Means of transport 50 and backend 60 communicate via a mobile phone network. Separate risk analyzes are carried out for both parts Fi, F2 of the function, ie in the means of transport 50 and in the backend 60 regarding cybersecurity.
- the respective analysis determines that a) the user data from the means of transport 50 must be treated confidentially and b) the result of the authentication must be authentic.
- a risk arises that, depending on the circumstances, requires mitigation, i.e. risk treatment through reduction, through suitable security measures.
- these security measures cannot be defined and implemented unilaterally in all cases. If the result of the authentication is received by the means of transport 50, the means of transport 50 cannot do anything to ensure the required authenticity. This must be guaranteed by the backend 60.
- a first assumption is that the means of transport 50 ensures the confidentiality of the user data during storage, processing and transmission.
- a second assumption is that the backend 60 ensures the authenticity of the authentication result during processing and transmission.
- a functional requirement for the means of transport 50 is, for example, that the means of transport 50 stores the user data confidentially in a secure storage area using suitable encryption and transmits the data via a channel that enables confidential transmission, for example TLS (Transport Layer Security).
- a functional requirement for the backend 60 is, for example, that the backend 60 displays the result of the authentication via a Channel that enables authentic transmission, e.g. TLS.
- FIG. 6 illustrates a risk analysis according to the invention of the subject of investigation UG from FIG .
- Backend 60.
- an assessment model BMi for the context of “embedded system” can be used, e.g. an assessment according to the specifications of the UNECE (United Nations Economic Commission for Europe).
- an analysis method AMi for the context of “embedded system” e.g. a methodology according to UNECE specifications
- a modeling rule MVi for the context of “embedded system” can be used.
- the modeling rule MVi can also be part of the external specifications, as shown in Fig. 6.
- an evaluation model BM 2 for the context of “IT system” can be used, e.g. an analysis according to the specifications of local institutions such as the BSI (Federal Office for Information Security).
- an AM 2 analysis method can be used for the “IT system” context, e.g. a methodology according to BSI specifications, and an MV 2 modeling rule can be used for the “IT system” context.
- modeling rule MV 2 can be part of the external specifications.
- a protection requirement SB for a date D is determined as the analysis result AE in a protection needs determination SBF, for example in the case of the means of transport 50 an authenticity of the authentication result, it can be automatically tracked in which ways the date D is transmitted, here from the backend 60, and The same protection requirement SB is adopted in the analysis Ri, R2 of the transmission partner.
- a risk-mitigating measure M can then be determined, for example an authentic transfer, which can be automatically selected from relevant catalogs of measures based on the transferred protection requirement SB or is determined at personal discretion.
- the measure M here the authentic transfer of the date, can now be reversed in the analysis Ri, R 2 , which has determined the original protection requirement SB and the risk-mitigating effect can also be taken into account there.
- Ri, R 2 which has determined the original protection requirement SB and the risk-mitigating effect can also be taken into account there.
- Traceability is also possible across several analyzes Ri, R2 or analysis networks, provided that the data D is identified uniformly. Implementation can be done using any algorithm that can identify all loop-free communication paths in a “network” of risk analysis Ri, R2. The propagation of the protection requirements SB and the protective measures M can then take place with or against the communication direction of the data D.
- the protection requirement SB of a date D is determined by the risk analysis Ri, R2 on whose side the date D is sent.
- the protection requirement SB can just as easily be determined by the risk analysis Ri, R2 on whose side the date D is received.
- FIG. 7 illustrates a first phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts.
- Four associated risk analyzes RA1-RA4 are carried out for the four contexts.
- the need for protection is determined by the receiving side.
- the transmission of a first date DA to a part of the subject of the examination in a second context is determined.
- the risk analysis RA2 in the second context also shows that the first date DA is attached to part of the
- the subject of the investigation is transmitted in a third context for which a third risk analysis RA3 is carried out.
- the transmission of a second date DB to the part of the subject of the investigation in the third context is also determined.
- Fig. 8 illustrates a second phase of the risk analysis according to the invention.
- the fourth risk analysis RA4 transmits a protection requirement SBB determined for the second date DB to the third risk analysis RA3.
- a protection requirement SB A 2 determined for the first date DA is transmitted to the second risk analysis RA 2 .
- the second risk analysis RA 2 determines an overall resulting protection requirement SB A2 ,I based on the transmitted protection requirement SB A 2 and transmits this to the first risk analysis RA1.
- Fig. 9 illustrates a third phase of the risk analysis according to the invention.
- the first risk analysis RA1 determines a suitable risk-mitigating measure M A I and transmits corresponding information to the second risk analysis RA2.
- the second risk analysis RA2 determines a suitable risk-mitigating measure M A 2 in response to the identified need for protection SB A 2 and transmits the corresponding information to the third risk analysis RA3.
- the fourth risk analysis RA4 determines a suitable risk-mitigating measure MB in response to the identified need for protection by SBB and transmits the corresponding information to the third risk analysis RA3. This means that none of the risk analyzes RA1-RA4 is dependent on making assumptions about the respective communication partners.
- AMi AM 2 Analysis method BMi, BM 2 Assessment model D, DA, DB Date FI, F 2 Functional component M, MAI, risk-mitigating measure MA2, MB
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Die vorliegende Erfindung betrifft ein Verfahren, ein Computerprogramm mit Instruktionen und ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Die Erfindung betrifft weiterhin Vorrichtungen zur Verwendung in einem solchen System. Erfindungsgemäß wird eine Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt (10). Zudem wird eine Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt (11). Wird nun bei einer der Risikoanalysen ein Schutzbedarf festgestellt (12), so werden Informationen zu diesem festgestellten (12) Schutzbedarf zwischen den Risikoanalysen ausgetauscht (13). Der festgestellte (12) Schutzbedarf kann dann berücksichtigt werden, indem eine risikomitigierende Maßnahme festgelegt wird (14). In diesem Fall können Informationen zur festgelegten (14) risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht werden (15).
Description
Beschreibung
Risikoanalyse eines verteilten Untersuchungsgegenstands
Die vorliegende Erfindung betrifft ein Verfahren, ein Computerprogramm mit Instruktionen und ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Die Erfindung betrifft weiterhin Vorrichtungen zur Verwendung in einem solchen System.
Ein Untersuchungsgegenstand für eine Risikoanalyse hinsichtlich Cybersicherheit, z.B. eine verteilte Funktion, kann Anteile in verschiedenen Analysekontexten haben. Bei den Analysekontexten kann es sich beispielsweise um ein eingebettetes System, ein Backendoder IT-System oder ein Mobilgerät handeln. Eine Risikoanalyse wird für den in einem Kontext verorteten Teil des Untersuchungsgegenstands in einem definierten Analysekontext durchgeführt. Dieser Analysekontext kann durch verschiedene Eigenschaften, wie z.B. ein distinktes Regelwerk oder eine distinkte Analysemethode, und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands abgegrenzt werden.
Vor diesem Hintergrund beschreibt US 2010/0250476 A1 ein Verfahren zur Bewertung eines Konfliktrisikos zwischen einer Anzahl von zu integrierenden Sicherheitslösungen. In einem Computersystem wird eine Anzahl von fragmentarischen Sicherheitslösungen empfangen. Ein Satz der empfangenen fragmentarischen Sicherheitslösungen wird zu einer zusammengesetzten Sicherheitslösung integriert, um eine Anzahl von Sicherheitsanforderungen zu erfüllen. Das Risiko eines Konflikts zwischen den zu integrierenden fragmentarischen Sicherheitslösungen wird bewertet.
Bei dem Werkzeug CAIRIS handelt es sich um eine Open-Source-Plattform für die Erhebung, Spezifikation und Validierung sicherer und nutzbarer Systeme. CAIRIS unterstützt den Begriff der Umgebungen und ermöglicht damit die Modellierung von Nutzungskontexten.
Es gibt momentan keine technische Lösung, die die Betrachtung von verteilten Untersuchungsgegenständen in verschiedenen Kontexten erlaubt. Es wird entweder eine gesamtheitliche Risikoanalyse durchgeführt, die keine dedizierten Annahmen über den Kontext eines Teils des Untersuchungsgegenstands erlaubt, oder es werden mehrere Analysen durchgeführt, die wechselseitige Annahmen treffen. Eine Komponierbarkeit von Risikoanalysen eines verteilten Untersuchungsgegenstands in verschiedenen Kontexten ist nicht bekannt.
Im Fall einer gesamtheitlichen Analyse sind ein einheitliches Regelwerk, eine einheitliche Analysemethode und eine einheitliche Modellierung der verteilten Teile des Untersuchungsgegenstands erforderlich. Im Falle von getrennten Analysen müssen Annahmen über die verschiedenen Teile des Untersuchungsgegenstands manuell übertragen werden.
Es wäre daher wünschenswert, ein Werkzeug zur Durchführung von Risikoanalysen zur Verfügung zu haben, das einerseits die Durchführung von Analysen von Funktionsanteilen in verschiedenen Kontexten und andererseits die Verknüpfung über verschiedene Kontexte hinweg zur gesamtheitlichen Betrachtung verteilter Funktionen erlaubt.
Es ist eine Aufgabe der Erfindung, verbesserte Lösungen zur Risikoanalyse eines verteilten Untersuchungsgegenstands bereitzustellen.
Diese Aufgabe wird durch ein Verfahren mit den Merkmalen des Anspruchs 1 , durch ein Computerprogramm mit Instruktionen gemäß Anspruch 9, durch ein System mit den Merkmalen des Anspruchs 10 sowie durch Vorrichtungen gemäß Anspruch 11 und Anspruch 12 gelöst. Bevorzugte Ausgestaltungen der Erfindung sind Gegenstand der abhängigen Ansprüche.
Gemäß einem ersten Aspekt der Erfindung umfasst ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands die Schritte:
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands;
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- Austauschen von Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Gemäß einem weiteren Aspekt der Erfindung umfasst ein Computerprogramm Instruktionen, die bei Ausführung durch einen Computer den Computer zur Ausführung der folgenden Schritte zur Risikoanalyse eines verteilten Untersuchungsgegenstands veranlassen:
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands;
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- Austauschen von Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Der Begriff Computer ist dabei breit zu verstehen. Insbesondere umfasst er auch Workstations, verteilte Systeme und andere prozessorbasierte Datenverarbeitungsvorrichtungen.
Das Computerprogramm kann beispielsweise für einen elektronischen Abruf bereitgestellt werden oder auf einem computerlesbaren Speichermedium gespeichert sein.
Gemäß einem weiteren Aspekt der Erfindung weist ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands auf:
- ein erstes Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- ein zweites Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte
Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; wobei das erste Analysemodul und das zweite Analysemodul eingerichtet sind, Informationen zu einem festgestellten Schutzbedarf auszutauschen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Eine erste Vorrichtung zur Verwendung in einem erfindungsgemäßen System weist ein erstes Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil eines Untersuchungsgegenstands in einem ersten Analysekontext auf, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands. Das erste Analysemodul ist eingerichtet, Informationen zu einem festgestellten Schutzbedarf an ein zweites Analysemodul zum Durchführen einer Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands zu übermitteln, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Eine zweite Vorrichtung zur Verwendung in einem erfindungsgemäßen System weist ein zweites Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil eines Untersuchungsgegenstands in einem zweiten Analysekontext auf, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands. Das zweite Analysemodul ist eingerichtet, einen von einem ersten Analysemodul beim Durchführen einer Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands festgestellten Schutzbedarf bei der Risikoanalyse im zweiten Kontext zu berücksichtigen.
Bei der erfindungsgemäßen Lösung wird durch das Hinzufügen eines Modellierungsschritts, bei dem Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen ausgetauscht werden, eine Automatisierung der Auflösung der wechselseitigen Abhängigkeiten ermöglicht. In den beteiligten Risikoanalysen kann auf Basis der übermittelten Informationen jeweils derselbe Schutzbedarf übernommen werden. Dadurch entfällt die Notwendigkeit einer iterativen, in der Regel manuellen Synchronisierung der
Risikoanalysen in unterschiedlichen Kontexten. Da eine manuelle Umsetzung und Wartung der Risikoanalyse durch eine Fachperson entfallen kann, ist die erfindungsgemäße Lösung weniger aufwendig und fehleranfällig als bekannte Lösungen. Insbesondere entfällt der zeitliche Mehraufwand für eine repetitive Ablage- und Prüftätigkeit durch eine Fachperson.
Erfindungsgemäß werden die Risikoanalysen unter Berücksichtigung unterschiedlicher Vorschriften durchgeführt. Eine Risikoanalyse wird für den in einem Kontext verorteten Teil des Untersuchungsgegenstands in einem definierten Analysekontext durchgeführt. Dieser Analysekontext wird durch verschiedene Eigenschaften, wie z.B. ein distinktes Regelwerk oder eine distinkte Analysemethode, und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands abgegrenzt.
Erfindungsgemäß wird anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, bestimmt, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll. Eine kontextübergreifende Komposition der kontextspezifischen Risikoanalysen kann besonders vorteilhaft durch eine Betrachtung der Informationsflüsse zwischen den betrachteten Teilen des Untersuchungsgegenstands erreicht werden. Diese Informationsflüsse transportieren schützenswerte Güter, d.h. Daten, die in den Risikoanalysen der Teile des Untersuchungsgenstands repräsentiert sein sollten. Diese Repräsentation kann dabei gegebenenfalls auf verschiedenen Abstraktionsebenen erfolgen.
Gemäß einem Aspekt der Erfindung wird der festgestellte Schutzbedarf berücksichtigt, indem eine risikomitigierende Maßnahme festgelegt wird. Durch die Festlegung bzw. Umsetzung einer geeigneten risikomitigierenden Maßnahme wird sichergestellt, dass dem festgestellten Schutzbedarf Rechnung getragen wird.
Gemäß einem Aspekt der Erfindung werden Informationen zur festgelegten risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht. Die Maßnahme kann auf diese Weise nun umgekehrt in der Risikoanalyse übernommen werden, die den ursprünglichen Schutzbedarf festgestellt hat. Dies erlaubt es, die risikomitigierende Wirkung auch dort zu berücksichtigen. Insbesondere bedarf es keines weiteren Abgleichs der Konsistenz von Annahmen und Maßnahmen, da keine Annahmen mehr getroffen werden müssen.
Gemäß einem Aspekt der Erfindung wird die risikomitigierende Maßnahme automatisiert oder durch einen manuellen Eingriff festgelegt. Beispielsweise kann die risikomitigierende
Maßnahme anhand des übertragenen Schutzbedarfs automatisiert aus einschlägigen Maßnahmenkatalogen ausgewählt werden. Dies hat den Vorteil, dass keine manuellen Eingriffe erforderlich sind. Alternativ kann die risikomitigierende Maßnahme aber auch im persönlichen Ermessen einer Fachperson festgelegt werden. Auf diese Weise liegt die Entscheidungshoheit über die getroffenen Maßnahmen bei der zuständigen Fachperson.
Gemäß einem Aspekt der Erfindung wird eine bei der Risikoanalyse in einem Kontext festgestellte Gefährdung des Schutzbedarfs bei der Risikoanalyse im anderen Kontext berücksichtigt. Über die wechselseitige Verknüpfung der Risikoanalysen in den verschiedenen Kontexten können neben den ermittelten Schutzbedarfen und den jeweiligen risikomitigierenden Maßnahmen auch Gefährdungen eines Schutzbedarfs, die in einer anderen Risikoanalyse festgestellt werden, in derjenigen Risikoanalyse Berücksichtigung finden, die Ursprung der Schutzbedarfsfeststellung ist.
Gemäß einem Aspekt der Erfindung wird ein festgestellter Schutzbedarf zusätzlich auch bei einer Risikoanalyse für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands berücksichtigt. Die Rückverfolgbarkeit ist auch über mehrere Analysen oder Analyseverbünde hinweg gegeben, sofern eine einheitliche Identifizierung der Daten gegeben ist. Eine Implementierung kann mittels jedes Algorithmus erfolgen, der alle schleifenfreien Kommunikationspfade in einem „Netzwerk“ aus Risikoanalysen identifizieren kann. Die Propagation der Schutzbedarfe und der Schutzmaßnahmen kann dann mit oder entgegen der Kommunikationsrichtung der Daten erfolgen.
Gemäß einem Aspekt der Erfindung betrifft der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Die erfindungsgemäße Lösung kann in allen Anwendungsfällen zum Einsatz kommen, bei denen Risikoanalysen auf verteilten Untersuchungsgegenständen durchgeführt werden. Beispiele dafür sind Applikationen auf Mobiltelefonen mit einer Kommunikation zu einem IT-Backend, die Kommunikation von Industrieanalagen mit IT-Systemen oder die Kommunikation von eingebetteten Systemen, wie z.B. Chipkarten o.ä., mit anderen Systemen.
Weitere Merkmale der vorliegenden Erfindung werden aus der nachfolgenden Beschreibung und den angehängten Ansprüchen in Verbindung mit den Figuren ersichtlich.
Fig. 1 zeigt schematisch ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands;
Fig. 2 zeigt ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands;
Fig. 3 veranschaulicht einen bekannten Ansatz zur Risikoanalyse eines verteilten
Untersuchungsgegenstands;
Fig. 4 veranschaulicht einen erfindungsgemäßen Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands;
Fig. 5 veranschaulicht einen Untersuchungsgegenstand, der sich auf ein Fortbewegungsmittel und ein IT-Backend verteilt;
Fig. 6 veranschaulicht eine Risikoanalyse des Untersuchungsgegenstands aus Fig. 5; und
Fig. 7 veranschaulicht eine erste Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt;
Fig. 8 veranschaulicht eine zweite Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt; und
Fig. 9 veranschaulicht eine dritte Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt.
Zum besseren Verständnis der Prinzipien der vorliegenden Erfindung werden nachfolgend Ausführungsformen der Erfindung anhand der Figuren detaillierter erläutert. Es versteht sich, dass sich die Erfindung nicht auf diese Ausführungsformen beschränkt und dass die beschriebenen Merkmale auch kombiniert oder modifiziert werden können, ohne den Schutzbereich der Erfindung zu verlassen, wie er in den angehängten Ansprüchen definiert ist.
Fig. 1 zeigt schematisch ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Bei dem Verfahren wird eine teil- oder vollautomatisierte Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt 10. Beispielsweise kann der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System betreffen. Zudem wird eine teil- oder vollautomatisierte Risikoanalyse für einen in einem zweiten Kontext verorteten
Teil des Untersuchungsgegenstands durchgeführt 11. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Wird nun bei einer der Risikoanalysen ein Schutzbedarf festgestellt 12, so werden Informationen zu diesem festgestellten 12 Schutzbedarf zwischen den Risikoanalysen ausgetauscht 13. Insbesondere wird anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, bestimmt, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll. Der festgestellte 12 Schutzbedarf kann dann berücksichtigt werden, indem eine risikomitigierende Maßnahme festgelegt wird 14. Die risikomitigierende Maßnahme kann z.B. automatisiert oder durch einen manuellen Eingriff festgelegt werden. Anschließend können Informationen zur festgelegten 14 risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht werden 15. Vorzugsweise wird auch eine bei der Risikoanalyse in einem Kontext festgestellte Gefährdung des Schutzbedarfs bei der Risikoanalyse im anderen Kontext berücksichtigt. Ein festgestellter Schutzbedarf kann zudem auch zusätzlich bei einer Risikoanalyse für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands berücksichtigt werden.
Fig. 2 zeigt ein System 70 zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Das System 70 umfasst in diesem Beispiel eine erste Vorrichtung 20 zur Risikoanalyse und eine zweite Vorrichtung 30 zur Risikoanalyse. Die beiden Vorrichtungen 20, 30 kommunizieren miteinander über jeweilige Schnittstellen 21, 31. Die erste Vorrichtung 20 hat ein erstes Analysemodul 22 zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands. Beispielsweise kann der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System betreffen. Entsprechend hat die zweite Vorrichtung 30 ein zweites Analysemodul 32 zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Das erste Analysemodul 22 und das zweite Analysemodul 32 sind eingerichtet, über die Schnittstellen 21, 31 Informationen zu einem festgestellten Schutzbedarf SB auszutauschen. Dabei wird insbesondere anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf SB festgestellt wurde, bestimmt, bei weicher weiteren Risikoanalyse der Schutzbedarf SB berücksichtigt werden soll, d.h. mit welchem Analysemodul 22, 32 entsprechende Informationen ausgetauscht werden sollen. Der festgestellte Schutzbedarf SB kann dann von den Analysemodulen 22, 32 berücksichtigt werden, indem eine risikomitigierende Maßnahme M festgelegt wird. Die risikomitigierende Maßnahme M kann z.B. automatisiert oder durch einen manuellen Eingriff festgelegt werden. Anschließend können die Analysemodule 22, 32 über die Schnittstellen
21, 31 Informationen zur festgelegten risikomitigierenden Maßnahme M austauschen. Vorzugsweise werden auch Informationen zu bei den Risikoanalysen festgestellten Gefährdungen des Schutzbedarfs ausgetauscht, sodass sie von den Analysemodulen 22, 32 berücksichtigt werden können.
Die Analysemodule 22, 32 können jeweils von einem Kontrollmodul 23, 33 gesteuert werden. Über Benutzerschnittstellen 25, 35 können gegebenenfalls Einstellungen der Analysemodule
22, 32 oder der Kontrollmodule 23, 33 geändert werden. Die in den Vorrichtungen 20, 30 anfallenden Daten können bei Bedarf jeweils in einem Speicher 24, 34 abgelegt werden, beispielsweise für eine spätere Auswertung oder für eine Nutzung durch die Komponenten der Vorrichtung 20, 30. Die Analysemodule 22, 32 sowie die Kontrollmodule 23, 33 können als dedizierte Hardware realisiert sein, beispielsweise als integrierte Schaltungen. Natürlich können sie aber auch teilweise oder vollständig kombiniert oder als Software implementiert werden, die auf einem geeigneten Prozessor läuft, beispielsweise auf einer GPU oder einer CPU. Die Schnittstellen 21, 31 können alternativ auch in getrennte Ein- und Ausgänge aufgeteilt sein.
Die Speicher 24, 34 der beschriebenen Vorrichtungen 20, 30 können sowohl volatile als auch nichtvolatile Speicherbereiche aufweisen und unterschiedlichste Speichergeräte und Speichermedien umfassen, beispielsweise Festplatten, optische Speichermedien oder Halbleiterspeicher.
Fig. 3 veranschaulicht einen bekannten Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands UG. Ein erster Teil 40 des Untersuchungsgegenstands UG ist in einem ersten Kontext verortet, ein zweiter Teil 40‘ des Untersuchungsgegenstands UG ist in einem zweiten Kontext verortet. Eine Risikoanalyse Ri, R2 wird für den in einem Kontext verorteten Teil 40, 40‘ des Untersuchungsgegenstands UG in einem definierten Analysekontext durchgeführt. Dieser Analysekontext kann durch verschiedene Eigenschaften, wie z.B. ein distinktes Bewertungsmodell BM1, BM2 oder eine distinkte Analysemethode AM1, AM2, und eine distinkte Vorschrift zur Modellierung MV1, MV2 des Untersuchungsgegenstands UG abgegrenzt werden. Eine kontextübergreifende Komposition der kontextspezifischen Analysen Ri, R2 ist nicht möglich. Ergibt sich als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ein Schutzbedarf SB, der nur durch eine schützende Maßnahme eines in einem anderen Kontext verorteten Teils 40, 40‘ des verteilten Untersuchungsgegenstands UG erfüllt werden kann, so muss eine Annahme A über die Existenz dieser Maßnahme getroffen werden. Diese Maßnahme kann dann in der betroffenen Teilanalyse Ri, R2 berücksichtigt werden, muss allerdings selbst Teil des
Analyseumfangs der Teilanalyse Ri, R2 im anderen Kontext sein. Das Analyseergebnis AE muss dann sequentiell in die anfordernde Teilanalyse Ri, R2 übertragen werden. Dieser Vorgang muss so oft wiederholt werden, bis alle wechselseitigen Effekte berücksichtigt wurden.
Fig. 4 veranschaulicht einen erfindungsgemäßen Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands UG. Ein erster Teil 40 des Untersuchungsgegenstands UG ist in einem ersten Kontext verortet, ein zweiter Teil 40‘ des Untersuchungsgegenstands UG ist in einem zweiten Kontext verortet. Eine Risikoanalyse Ri, R2 wird teil- oder vollautomatisiert für den in einem Kontext verorteten Teil 40, 40‘ des Untersuchungsgegenstands UG in einem definierten Analysekontext durchgeführt. Dieser Analysekontext wird wie gehabt durch verschiedene Eigenschaften, wie z.B. ein distinktes Bewertungsmodell BM1, BM2 oder eine distinkte Analysemethode AM1, AM2, und eine distinkte Vorschrift zur Modellierung MV1, MV2 des Untersuchungsgegenstands UG abgegrenzt. Eine kontextübergreifende Komposition der kontextspezifischen Analysen Ri, R2 wird durch eine Betrachtung der Informationsflüsse zwischen den betrachteten Teilen 40, 40‘ des Untersuchungsgegenstands UG erreicht. Diese Informationsflüsse transportieren schützenswerte Güter, d.h. Daten D, die in den Analysen Ri, R2 der Teile 40, 40‘ des Untersuchungsgenstands UG repräsentiert sein müssen. Der als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ermittelte Schutzbedarf SB und die eventuell daraus risikomitigierende Maßnahme M können durch Nachverfolgung des Informationsflusses unabhängig von der Modellierung der Teile 40, 40‘ des verteilten Untersuchungsgegenstands UG kontextübergreifend wechselseitig berücksichtigt werden. Die Durchführung der Teilanalysen Ri, R2 kann in diesem Fall parallel erfolgen und eine wechselseitige Berücksichtigung der Analyseergebnisse AE kann assistiert oder automatisiert durchgeführt werden.
Nachfolgend soll eine bevorzugte Ausführungsform einer erfindungsgemäßen Lösung anhand von Fig. 5 bis Fig. 9 an einem konkreten Anwendungsbeispiel beschrieben werden.
Fig. 5 veranschaulicht einen Untersuchungsgegenstand, der sich auf ein Fortbewegungsmittel 50 und ein IT-Backend 60 verteilt. Im gezeigten Beispiel soll eine Funktion zur Nutzeranmeldung im Fortbewegungsmittel 50 betrachtet werden. Diese Funktion hat einen Anteil Fi im Fortbewegungsmittel 50 zur Durchführung der Anmeldung und Speicherung des angemeldeten Nutzers und einen Anteil F2 im IT-Backend 60, der für die Nutzerverwaltung und Nutzerauthentifizierung zuständig ist. Fortbewegungsmittel 50 und Backend 60 kommunizieren dafür über ein Mobilfunknetz. Für beide Anteile Fi , F2 der Funktion, d.h. im Fortbewegungsmittel 50 und im Backend 60, sind getrennte Risikoanalysen
bezüglich der Cybersicherheit durchzuführen. Zwischen den Funktionsanteilen gibt es zwei Signale mit zwei übermittelten Daten D, den Anmeldedaten aus dem Fortbewegungsmittel 50 und dem Ergebnis der Nutzerauthentifizierung aus dem Backend 60.
Die Problemstellung ergibt sich daraus, dass die Risikoanalysen unter Berücksichtigung unterschiedlicher Vorschriften betreffend Bewertungsmodell, Analysemethodik, Modellierungsvorschrift durchgeführt werden, d.h. es liegen unterschiedliche Analysekontexte vor. Dies verhindert, dass die Risikoanalyse der beiden Funktionsanteile in einem Zug durchgeführt wird, d.h. in einem Werkzeug oder in einer gesamthaften Risikoanalyse. Die Analyse der beiden Anteile muss aufgrund der unterschiedlichen Vorschriften bzw. Prämissen getrennt erfolgen.
Angenommen sei, dass in der jeweiligen Analyse festgestellt wird, dass a) die Nutzerdaten aus dem Fortbewegungsmittel 50 vertraulich behandelt werden müssen und b) das Ergebnis der Authentifizierung authentisch sein muss. Unter Berücksichtigung des jeweiligen Schadenszenarios, nämlich a) einer Verletzung der Privatsphäre des Nutzers und b) einer illegitimen Anmeldung im Fortbewegungsmittel 50, ergibt sich ein Risiko, das je nach Umständen einer Mitigation, d.h. einer Risikobehandlung durch Minderung, durch eine geeignete Sicherungsmaßnahmen bedarf. Diese Sicherungsmaßnahmen können aber nicht in allen Fällen einseitig definiert und umgesetzt werden. Wird das Ergebnis der Authentifizierung vom Fortbewegungsmittel 50 empfangen, so kann das Fortbewegungsmittel 50 nichts unternehmen, um die erforderliche Authentizität sicherzustellen. Diese muss durch das Backend 60 gewährleistet werden.
Üblicherweise wird daher mit Annahmen über den Kommunikationspartner gearbeitet. Eine erste Annahme besteht etwa darin, dass das Fortbewegungsmittel 50 die Vertraulichkeit der Nutzerdaten bei der Speicherung, Verarbeitung und Übertragung sicherstellt. Eine zweite Annahme besteht etwa darin, dass das Backend 60 die Authentizität des Ergebnisses der Authentifizierung bei der Verarbeitung und Übertragung sicherstellt.
Aus diesen Annahmen über den Kommunikationspartner ergeben sich funktionale Anforderungen. Eine funktionale Anforderung an das Fortbewegungsmittel 50 besteht etwa darin, dass das Fortbewegungsmittel 50 die Nutzerdaten vertraulich mittels geeigneter Verschlüsselung in einem sicheren Speicherbereich speichert und die Daten über einen Kanal überträgt, der eine vertrauliche Übertragung ermöglicht, z.B. TLS (Transport Layer Security, Transportschichtsicherheit). Eine funktionale Anforderung an das Backend 60 besteht etwa darin, dass das Backend 60 das Ergebnis der Authentifizierung über einen
Kanal überträgt, der eine authentische Übertragung ermöglicht, z.B. TLS. Diese funktionalen Anforderungen müssen in der Analyse der jeweiligen Gegenstelle wiederum Berücksichtigung finden. Die Durchführung der Analysen mit wechselseitiger Abhängigkeit ist daher bei bekannten Ansätzen ein manueller und vor allem iterativer Prozess, da die Annahmen nach erfolgter (Erst-)Analyse übertragen und die funktionale Umsetzung dann wiederum in einer (Zweit-)Analyse berücksichtigt werden muss.
Fig. 6 veranschaulicht eine erfindungsgemäße Risikoanalyse des Untersuchungsgegenstands UG aus Fig. 5. Auch in diesem Fall werden aufgrund der differierenden Analysekontexte zwei Analysen durchgeführt, d.h. eine erste Risikoanalyse Ri im Kontext „Fortbewegungsmittel“ 50 und eine zweite Risikoanalyse R2 im Kontext „IT- Backend“ 60.
Für die Risikoanalyse Ri im Kontext „Fortbewegungsmittel“ 50 kann ein Bewertungsmodell BMi für den Kontext „eingebettetes System“ herangezogen werden, z.B. eine Bewertung nach Vorgaben der UNECE (United Nations Economic Commission for Europe; Wirtschaftskommission für Europa der Vereinten Nationen). Dementsprechend können eine Analysemethode AMi für den Kontext „eingebettetes System“, z.B. eine Methodik nach Vorgaben der UNECE, und eine Modellierungsvorschrift MVi für den Kontext „eingebettetes System“ verwendet werden. Auch die Modellierungsvorschrift MVi kann Teil der externen Vorgaben sein, wie dies in Fig. 6 dargestellt ist.
Für die Risikoanalyse R2 im Kontext „IT-Backend“ 60 kann ein Bewertungsmodell BM2 für den Kontext „IT-System“ herangezogen werden, z.B. eine Analyse nach Vorgaben lokaler Institutionen wie dem BSI (Bundesamt für Sicherheit in der Informationstechnik).
Dementsprechend können eine Analysemethode AM2 für den Kontext „IT-System“, z.B. eine Methodik nach BSI-Vorgaben, und eine Modellierungsvorschrift MV2 für den Kontext „IT- System“ verwendet werden. Wie auch bei der Risikoanalyse Ri kann Modellierungsvorschrift MV2 Teil der externen Vorgaben sein.
Allerdings wird für Daten D, die zwischen dem Fortbewegungsmittel 50 und dem Backend 60 ausgetauscht werden, die jeweilige Datenherkunft annotiert bzw. berücksichtigt. Zwischen den durchgeführten Analysen Ri, R2 wird dann, entweder durch Angleichung oder Zuordnung, eine einheitliche Identifizierung übertragener Daten D ermöglicht. Dies kann unabhängig vom Analysekontext und insbesondere der jeweiligen Modellierungsvorschrift MVi, MV2 geschehen. Die Modellierung des Untersuchungsgegenstands UG auf Seiten des Fortbewegungsmittels 50 und des Backends 60 wird also um lediglich einen Schritt ergänzt.
Wird nun als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ein Schutzbedarf SB für ein Datum D festgestellt, z.B. beim Fortbewegungsmittel 50 eine Authentizität des Authentifizierungsergebnisses, so kann automatisiert nachverfolgt werden, auf welchen Wegen das Datum D übertragen wird, hier also aus dem Backend 60, und in der Analyse Ri, R2 des Übertragungspartners derselbe Schutzbedarf SB übernommen werden. In der Analyse Ri, R2 des Übertragungspartners kann dann eine risikomitigierende Maßnahme M festgelegt werden, z.B. eine authentische Übertragung, die anhand des übertragenen Schutzbedarfs SB automatisiert aus einschlägigen Maßnahmenkatalogen ausgewählt werden kann oder im persönlichen Ermessen festgelegt wird.
Die Maßnahme M, hier also die authentische Übertragung des Datums, kann nun wiederum umgekehrt in der Analyse Ri, R2 übernommen werden, die den ursprünglichen Schutzbedarf SB festgestellt hat und die risikomitigierende Wirkung auch dort berücksichtigt werden. Insbesondere bedarf es keines weiteren Abgleichs der Konsistenz von Annahmen und Maßnahmen, da keine Annahmen mehr getroffen werden müssen.
Die Rückverfolgbarkeit ist auch über mehrere Analysen Ri, R2 oder Analyseverbünde hinweg gegeben, sofern eine einheitliche Identifizierung der Daten D gegeben ist. Eine Implementierung kann mittels jedes Algorithmus erfolgen, der alle schleifenfreien Kommunikationspfade in einem „Netzwerk“ aus Risikoanalysen Ri, R2 identifizieren kann. Die Propagation der Schutzbedarfe SB und der Schutzmaßnahmen M kann dann mit oder entgegen der Kommunikationsrichtung der Daten D erfolgen.
In den Beispielen in Fig. 5 und Fig. 6 wird der Schutzbedarf SB eines Datums D von derjenigen Risikoanalyse Ri, R2 festgestellt, auf deren Seite das Datum D gesendet wird. Der Schutzbedarf SB kann aber ebenso gut von derjenigen Risikoanalyse Ri, R2 festgestellt werden, auf deren Seite das Datum D empfangen wird.
Fig. 7 veranschaulicht eine erste Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt. Für die vier Kontexte werden vier zugehörige Risikoanalysen RA1-RA4 durchgeführt. In diesem Beispiel wird der Schutzbedarf jeweils von der empfangenden Seite festgestellt. Bei dem dargestellten Beispiel wird bei einer ersten Risikoanalyse RA1 eines Teils des Untersuchungsgegenstands in einem ersten Kontext die Übermittlung eines ersten Datums DA an einen Teil des Untersuchungsgegenstands in einem zweiten Kontext festgestellt. Die Risikoanalyse RA2 im zweiten Kontext ergibt zudem, dass das erste Datum DA an einen Teil des
Untersuchungsgegenstands in einem dritten Kontext übermittelt wird, für den eine dritte Risikoanalyse RA3 durchgeführt wird. Bei einer vierten Risikoanalyse RA4 eines Teils des Untersuchungsgegenstands in einem vierten Kontext wird zudem die Übermittlung eines zweiten Datums DB an den Teil des Untersuchungsgegenstands im dritten Kontext festgestellt.
Fig. 8 veranschaulicht eine zweite Phase der erfindungsgemäßen Risikoanalyse. Die vierte Risikoanalyse RA4 übermittelt einen für das zweite Datum DB festgestellten Schutzbedarf SBB an die dritte Risikoanalyse RA3. Zudem wird ein für das erste Datum DA festgestellter Schutzbedarf SBA2 an die zweite Risikoanalyse RA2 übermittelt. Die zweite Risikoanalyse RA2 ermittelt auf Grundlage des übermittelten Schutzbedarfs SBA2 einen insgesamt resultierenden Schutzbedarf SBA2,I und übermittelt diesen an die erste Risikoanalyse RA1.
Fig. 9 veranschaulicht eine dritte Phase der erfindungsgemäßen Risikoanalyse. Im Ansprechen auf den festgestellten Schutzbedarf SBA2,I legt die erste Risikoanalyse RA1 eine geeignete risikomitigierende Maßnahme MAI fest und übermittelt entsprechende Informationen an die zweite Risikoanalyse RA2. Dementsprechend legt die die zweite Risikoanalyse RA2 im Ansprechen auf den festgestellten Schutzbedarf SBA2 eine geeignete risikomitigierende Maßnahme MA2 fest und übermittelt die entsprechenden Informationen an die dritte Risikoanalyse RA3. Die vierte Risikoanalyse RA4 legt im Ansprechen auf den festgestellten Schutzbedarf SBB eine geeignete risikomitigierende Maßnahme MB fest und übermittelt die entsprechenden Informationen an die dritte Risikoanalyse RA3. Somit ist keine der Risikoanalysen RA1-RA4 darauf angewiesen, Annahmen über die jeweiligen Kommunikationspartner zu treffen.
Bezugszeichenliste
10 Durchführen einer Risikoanalyse in einem ersten Kontext
11 Durchführen einer Risikoanalyse in einem zweiten Kontext
12 Feststellen eines Schutzbedarfs
13 Austauschen von Informationen zum Schutzbedarf
14 Festlegen einer risikomitigierenden Maßnahme
15 Austauschen von Informationen zur festgelegten Maßnahme
20 Vorrichtung
21 Schnittstelle
22 Analysemodul
23 Kontrollmodul
24 Speicher
25 Benutzerschnittstelle
30 Vorrichtung
31 Schnittstelle
32 Analysemodul
33 Kontrollmodul
34 Speicher
35 Benutzerschnittstelle
40, 40‘ Untersuchungsgegenstand
50 Fortbewegungsmittel
60 Backend
70 System
A Annahme
AE Analyseergebnis
AMi, AM2 Analysemethode BMi, BM2 Bewertungsmodell D, DA, DB Datum FI, F2 Funktionsanteil M, MAI, Risikomitigierende Maßnahme MA2, MB
MF Maßnahmenfestlegung
MVi, MV2 Modellierungsvorschrift RA1-RA4 Risikoanalyse SB, SBB Schutzbedarf
SBA2, SBA2,1
SBF Schutzbedarfsfeststellung
UG Untersuchungsgegenstand
Claims
Patentansprüche Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG), mit den Schritten:
- Durchführen (10) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG);
- Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG); und
- Austauschen (13) von Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) zwischen den Risikoanalysen (R1-R4), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Verfahren gemäß Anspruch 1 , wobei der festgestellte (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt wird, indem eine risikomitigierende Maßnahme (M, MAI, MA2, MB) festgelegt wird (14). Verfahren gemäß Anspruch 2, wobei Informationen zur festgelegten (14) risikomitigierenden Maßnahme (M, MAI, MA2, MB) zwischen den Risikoanalysen (R1-R4) ausgetauscht werden (15). Verfahren gemäß Anspruch 2 oder 3, wobei die risikomitigierende Maßnahme (M, MAI, MA2, MB) automatisiert oder durch einen manuellen Eingriff festgelegt wird (14). Verfahren gemäß einem der vorherigen Ansprüche, wobei eine bei der Risikoanalyse (R1-R4) in einem Kontext festgestellte Gefährdung des Schutzbedarfs (SB, SBB, SBA2, SBA2,I) bei der Risikoanalyse (R1-R4) im anderen Kontext berücksichtigt wird.
Verfahren gemäß einem der vorherigen Ansprüche, wobei ein festgestellter (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) zusätzlich auch bei einer Risikoanalyse (R1-R4) für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands (UG) berücksichtigt wird. Verfahren gemäß einem der vorherigen Ansprüche, wobei der erste Kontext ein Fortbewegungsmittel (50), ein Mobilgerät oder ein eingebettetes System betrifft. Verfahren gemäß einem der vorherigen Ansprüche, wobei der zweite Kontext ein Backend (60) oder ein IT-System betrifft. Computerprogramm mit Instruktionen, die bei Ausführung durch einen Computer den Computer zur Ausführung der Schritte eines Verfahrens gemäß einem der Ansprüche 1 bis 8 zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG) veranlassen. System (70) zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG), mit:
- einem ersten Analysemodul (22) zum Durchführen (10) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG); und
- einem zweiten Analysemodul (32) zum Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG); wobei das erste Analysemodul (22) und das zweite Analysemodul (32) eingerichtet sind, Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) auszutauschen (13), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Vorrichtung (20) zur Verwendung in einem System gemäß Anspruch 10, mit einem ersten Analysemodul (22) zum Durchführen (10) einer teil- oder vollautomatisierten
Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) eines Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG), wobei das erste Analysemodul (22) eingerichtet ist, Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) an ein zweites Analysemodul (32) zum Durchführen (11) einer Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) zu übermitteln (13), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Vorrichtung (30) zur Verwendung in einem System gemäß Anspruch 10, mit einem zweiten Analysemodul (32) zum Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) eines Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG), wobei das zweite Analysemodul (32) eingerichtet ist, einen von einem ersten Analysemodul (22) beim Durchführen (10) einer Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) bei der Risikoanalyse (R1-R4) im zweiten Kontext zu berücksichtigen.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102022203086.9A DE102022203086A1 (de) | 2022-03-29 | 2022-03-29 | Risikoanalyse eines verteilten Untersuchungsgegenstands |
| PCT/EP2023/057325 WO2023186655A1 (de) | 2022-03-29 | 2023-03-22 | Risikoanalyse eines verteilten untersuchungsgegenstands |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4500377A1 true EP4500377A1 (de) | 2025-02-05 |
Family
ID=85776097
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23713644.5A Pending EP4500377A1 (de) | 2022-03-29 | 2023-03-22 | Risikoanalyse eines verteilten untersuchungsgegenstands |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20250200191A1 (de) |
| EP (1) | EP4500377A1 (de) |
| DE (1) | DE102022203086A1 (de) |
| WO (1) | WO2023186655A1 (de) |
Family Cites Families (221)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| AU1690597A (en) * | 1996-01-11 | 1997-08-01 | Mitre Corporation, The | System for controlling access and distribution of digital property |
| US20060178997A1 (en) * | 1996-01-11 | 2006-08-10 | General Dynamics Advanced Information Systems, Inc. | Systems and methods for authoring and protecting digital property |
| US7162649B1 (en) * | 2000-06-30 | 2007-01-09 | Internet Security Systems, Inc. | Method and apparatus for network assessment and authentication |
| US7096498B2 (en) * | 2002-03-08 | 2006-08-22 | Cipher Trust, Inc. | Systems and methods for message threat management |
| AU2003217021A1 (en) * | 2002-03-28 | 2003-10-13 | British Telecommunications Public Limited Company | Method and apparatus for network security |
| IL149583A0 (en) * | 2002-05-09 | 2003-07-06 | Kavado Israel Ltd | Method for automatic setting and updating of a security policy |
| US20050066195A1 (en) * | 2003-08-08 | 2005-03-24 | Jones Jack A. | Factor analysis of information risk |
| US20070180490A1 (en) * | 2004-05-20 | 2007-08-02 | Renzi Silvio J | System and method for policy management |
| US7490356B2 (en) * | 2004-07-20 | 2009-02-10 | Reflectent Software, Inc. | End user risk management |
| WO2007019349A2 (en) * | 2005-08-03 | 2007-02-15 | Calyptix Security | Systems and methods for dynamically learning network environments to achieve adaptive security |
| GB0518405D0 (en) * | 2005-09-09 | 2005-10-19 | Ibm | Operational risk control apparatus and method for data processing |
| US8544098B2 (en) * | 2005-09-22 | 2013-09-24 | Alcatel Lucent | Security vulnerability information aggregation |
| US8869270B2 (en) * | 2008-03-26 | 2014-10-21 | Cupp Computing As | System and method for implementing content and network security inside a chip |
| US8392999B2 (en) * | 2005-12-19 | 2013-03-05 | White Cyber Knight Ltd. | Apparatus and methods for assessing and maintaining security of a computerized system under development |
| US20080047017A1 (en) * | 2006-06-23 | 2008-02-21 | Martin Renaud | System and method for dynamically assessing security risks attributed to a computer user's behavior |
| US20080047016A1 (en) * | 2006-08-16 | 2008-02-21 | Cybrinth, Llc | CCLIF: A quantified methodology system to assess risk of IT architectures and cyber operations |
| US8234641B2 (en) * | 2006-10-17 | 2012-07-31 | Managelq, Inc. | Compliance-based adaptations in managed virtual systems |
| US9697019B1 (en) * | 2006-10-17 | 2017-07-04 | Manageiq, Inc. | Adapt a virtual machine to comply with system enforced policies and derive an optimized variant of the adapted virtual machine |
| US9015842B2 (en) * | 2008-03-19 | 2015-04-21 | Websense, Inc. | Method and system for protection against information stealing software |
| US9781148B2 (en) * | 2008-10-21 | 2017-10-03 | Lookout, Inc. | Methods and systems for sharing risk responses between collections of mobile communications devices |
| US8683546B2 (en) * | 2009-01-26 | 2014-03-25 | Microsoft Corporation | Managing security configuration through machine learning, combinatorial optimization and attack graphs |
| US20100218256A1 (en) * | 2009-02-26 | 2010-08-26 | Network Security Systems plus, Inc. | System and method of integrating and managing information system assessments |
| US8495744B2 (en) | 2009-03-25 | 2013-07-23 | Sap Ag | Evaluation of risk of conflict for security solutions integration |
| WO2011063269A1 (en) * | 2009-11-20 | 2011-05-26 | Alert Enterprise, Inc. | Method and apparatus for risk visualization and remediation |
| US10027711B2 (en) * | 2009-11-20 | 2018-07-17 | Alert Enterprise, Inc. | Situational intelligence |
| US10019677B2 (en) * | 2009-11-20 | 2018-07-10 | Alert Enterprise, Inc. | Active policy enforcement |
| US8495745B1 (en) * | 2009-11-30 | 2013-07-23 | Mcafee, Inc. | Asset risk analysis |
| US8621636B2 (en) * | 2009-12-17 | 2013-12-31 | American Express Travel Related Services Company, Inc. | Systems, methods, and computer program products for collecting and reporting sensor data in a communication network |
| US9317692B2 (en) * | 2009-12-21 | 2016-04-19 | Symantec Corporation | System and method for vulnerability risk analysis |
| US8813232B2 (en) * | 2010-03-04 | 2014-08-19 | Mcafee Inc. | Systems and methods for risk rating and pro-actively detecting malicious online ads |
| US9619652B2 (en) * | 2010-03-31 | 2017-04-11 | Salesforce.Com, Inc. | System, method and computer program product for determining a risk score for an entity |
| US8375427B2 (en) * | 2010-04-21 | 2013-02-12 | International Business Machines Corporation | Holistic risk-based identity establishment for eligibility determinations in context of an application |
| US8849734B2 (en) * | 2010-06-29 | 2014-09-30 | Mcafee Inc. | System, method, and computer program product for updating an algorithm |
| US8677497B2 (en) * | 2011-10-17 | 2014-03-18 | Mcafee, Inc. | Mobile risk assessment |
| US8595845B2 (en) * | 2012-01-19 | 2013-11-26 | Mcafee, Inc. | Calculating quantitative asset risk |
| US8904538B1 (en) * | 2012-03-13 | 2014-12-02 | Symantec Corporation | Systems and methods for user-directed malware remediation |
| US8819772B2 (en) * | 2012-06-25 | 2014-08-26 | Appthority, Inc. | In-line filtering of insecure or unwanted mobile device software components or communications |
| US9330262B2 (en) * | 2012-09-21 | 2016-05-03 | University Of Limerick | Systems and methods for runtime adaptive security to protect variable assets |
| US9672360B2 (en) * | 2012-10-02 | 2017-06-06 | Mordecai Barkan | Secure computer architectures, systems, and applications |
| US11188652B2 (en) * | 2012-10-02 | 2021-11-30 | Mordecai Barkan | Access management and credential protection |
| US20140137257A1 (en) * | 2012-11-12 | 2014-05-15 | Board Of Regents, The University Of Texas System | System, Method and Apparatus for Assessing a Risk of One or More Assets Within an Operational Technology Infrastructure |
| US9219720B1 (en) * | 2012-12-06 | 2015-12-22 | Intuit Inc. | Method and system for authenticating a user using media objects |
| US9954883B2 (en) * | 2012-12-18 | 2018-04-24 | Mcafee, Inc. | Automated asset criticality assessment |
| US20140325670A1 (en) * | 2013-04-25 | 2014-10-30 | Rivendale Software Solution Private Limited | System and method for providing risk score based on sensitive information inside user device |
| US10839082B2 (en) * | 2014-01-06 | 2020-11-17 | International Business Machines Corporation | Identifying, categorizing and recording a quality of an entity/resource association |
| US9563771B2 (en) * | 2014-01-22 | 2017-02-07 | Object Security LTD | Automated and adaptive model-driven security system and method for operating the same |
| US9319430B2 (en) * | 2014-06-17 | 2016-04-19 | International Business Machines Corporation | Managing software deployment |
| US10164995B1 (en) * | 2014-08-14 | 2018-12-25 | Pivotal Software, Inc. | Determining malware infection risk |
| EP3210364B8 (de) * | 2014-10-21 | 2021-03-10 | Proofpoint, Inc. | Systeme und verfahren zur anwendungssicherheitsanalyse |
| US9838391B2 (en) * | 2014-10-31 | 2017-12-05 | Proofpoint, Inc. | Systems and methods for privately performing application security analysis |
| KR101616989B1 (ko) * | 2014-12-10 | 2016-04-29 | 고려대학교 산학협력단 | 정보 보안 통제 상태 평가 방법 및 장치 |
| US10104097B1 (en) * | 2014-12-12 | 2018-10-16 | Symantec Corporation | Systems and methods for preventing targeted malware attacks |
| US9372994B1 (en) * | 2014-12-13 | 2016-06-21 | Security Scorecard, Inc. | Entity IP mapping |
| US9648036B2 (en) * | 2014-12-29 | 2017-05-09 | Palantir Technologies Inc. | Systems for network risk assessment including processing of user access rights associated with a network of devices |
| US9294497B1 (en) * | 2014-12-29 | 2016-03-22 | Nice-Systems Ltd. | Method and system for behavioral and risk prediction in networks using automatic feature generation and selection using network topolgies |
| EP3248360B1 (de) * | 2015-01-19 | 2020-05-06 | Inauth, Inc. | Systeme und verfahren für sichere kommunikation mit sicherem weg |
| US20160246966A1 (en) * | 2015-02-24 | 2016-08-25 | Vertafore, Inc. | Method and system of assessing risk associated with users based at least in part on online presence of the user |
| US10140453B1 (en) * | 2015-03-16 | 2018-11-27 | Amazon Technologies, Inc. | Vulnerability management using taxonomy-based normalization |
| US20160344772A1 (en) * | 2015-05-22 | 2016-11-24 | Brian Quentin Monahan | Modelling network to assess security properties |
| US20160364727A1 (en) * | 2015-06-11 | 2016-12-15 | Early Warning Services, Llc | System and method for identifying compromised accounts |
| US10127403B2 (en) * | 2015-07-30 | 2018-11-13 | Samsung Electronics Co., Ltd. | Computing system with privacy control mechanism and method of operation thereof |
| US10693903B2 (en) * | 2015-07-30 | 2020-06-23 | IOR Analytics, LLC. | Method and apparatus for data security analysis of data flows |
| US10715542B1 (en) * | 2015-08-14 | 2020-07-14 | Fireeye, Inc. | Mobile application risk analysis |
| US20210173711A1 (en) * | 2015-10-28 | 2021-06-10 | Qomplx, Inc. | Integrated value chain risk-based profiling and optimization |
| US20220210200A1 (en) * | 2015-10-28 | 2022-06-30 | Qomplx, Inc. | Ai-driven defensive cybersecurity strategy analysis and recommendation system |
| US9578063B1 (en) * | 2015-11-20 | 2017-02-21 | International Business Machines Corporation | Application self-service for assured log management in cloud environments |
| US10445516B1 (en) * | 2015-12-03 | 2019-10-15 | Symantec Corporation | Systems and methods for preventing vulnerable files from being opened |
| US10503907B2 (en) * | 2015-12-14 | 2019-12-10 | Fmr Llc | Intelligent threat modeling and visualization |
| US9830449B1 (en) * | 2015-12-16 | 2017-11-28 | Amazon Technologies, Inc. | Execution locations for request-driven code |
| EP3407050A4 (de) * | 2016-01-19 | 2019-08-21 | IUCF-HYU (Industry-University Cooperation Foundation Hanyang University) | Netzwerkvorrichtung für fahrzeugsicherheit und verfahren zur steuerung davon |
| US9762599B2 (en) * | 2016-01-29 | 2017-09-12 | Varmour Networks, Inc. | Multi-node affinity-based examination for computer network security remediation |
| US10296748B2 (en) * | 2016-02-25 | 2019-05-21 | Sas Institute Inc. | Simulated attack generator for testing a cybersecurity system |
| US10332211B1 (en) * | 2016-03-03 | 2019-06-25 | State Farm Mutual Automobile Insurance Company | Risk analysis based on electronic security levels of a vehicle |
| US10826940B2 (en) * | 2016-03-11 | 2020-11-03 | Netskope, Inc. | Systems and methods of enforcing multi-part policies on data-deficient transactions of cloud computing services |
| US10108803B2 (en) * | 2016-03-31 | 2018-10-23 | International Business Machines Corporation | Automatic generation of data-centric attack graphs |
| US20170339160A1 (en) * | 2016-05-17 | 2017-11-23 | International Business Machines Corporation | Threat-aware provisioning and governance |
| US11100444B2 (en) * | 2016-06-10 | 2021-08-24 | OneTrust, LLC | Data processing systems and methods for providing training in a vendor procurement process |
| US11341447B2 (en) * | 2016-06-10 | 2022-05-24 | OneTrust, LLC | Privacy management systems and methods |
| US20220164476A1 (en) * | 2016-06-10 | 2022-05-26 | OneTrust, LLC | Data processing systems for use in automatically generating, populating, and submitting data subject access requests |
| US10282559B2 (en) * | 2016-06-10 | 2019-05-07 | OneTrust, LLC | Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques |
| US11138299B2 (en) * | 2016-06-10 | 2021-10-05 | OneTrust, LLC | Data processing and scanning systems for assessing vendor risk |
| US12052289B2 (en) * | 2016-06-10 | 2024-07-30 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US11366786B2 (en) * | 2016-06-10 | 2022-06-21 | OneTrust, LLC | Data processing systems for processing data subject access requests |
| US11475136B2 (en) * | 2016-06-10 | 2022-10-18 | OneTrust, LLC | Data processing systems for data transfer risk identification and related methods |
| US11023842B2 (en) * | 2016-06-10 | 2021-06-01 | OneTrust, LLC | Data processing systems and methods for bundled privacy policies |
| US20220164475A1 (en) * | 2016-06-10 | 2022-05-26 | OneTrust, LLC | Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques |
| US11294939B2 (en) * | 2016-06-10 | 2022-04-05 | OneTrust, LLC | Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software |
| US10467432B2 (en) * | 2016-06-10 | 2019-11-05 | OneTrust, LLC | Data processing systems for use in automatically generating, populating, and submitting data subject access requests |
| US11038925B2 (en) * | 2016-06-10 | 2021-06-15 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US10796260B2 (en) * | 2016-06-10 | 2020-10-06 | OneTrust, LLC | Privacy management systems and methods |
| US10685140B2 (en) * | 2016-06-10 | 2020-06-16 | OneTrust, LLC | Consent receipt management systems and related methods |
| US11416798B2 (en) * | 2016-06-10 | 2022-08-16 | OneTrust, LLC | Data processing systems and methods for providing training in a vendor procurement process |
| US20220156657A1 (en) * | 2016-06-10 | 2022-05-19 | OneTrust, LLC | Privacy management systems and methods |
| US11227247B2 (en) * | 2016-06-10 | 2022-01-18 | OneTrust, LLC | Data processing systems and methods for bundled privacy policies |
| US11238390B2 (en) * | 2016-06-10 | 2022-02-01 | OneTrust, LLC | Privacy management systems and methods |
| US20200311233A1 (en) * | 2016-06-10 | 2020-10-01 | OneTrust, LLC | Data processing and scanning systems for assessing vendor risk |
| US11410106B2 (en) * | 2016-06-10 | 2022-08-09 | OneTrust, LLC | Privacy management systems and methods |
| US10885485B2 (en) * | 2016-06-10 | 2021-01-05 | OneTrust, LLC | Privacy management systems and methods |
| US10798133B2 (en) * | 2016-06-10 | 2020-10-06 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US11438386B2 (en) * | 2016-06-10 | 2022-09-06 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US11301796B2 (en) * | 2016-06-10 | 2022-04-12 | OneTrust, LLC | Data processing systems and methods for customizing privacy training |
| US10848523B2 (en) * | 2016-06-10 | 2020-11-24 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US11336697B2 (en) * | 2016-06-10 | 2022-05-17 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US10509920B2 (en) * | 2016-06-10 | 2019-12-17 | OneTrust, LLC | Data processing systems for processing data subject access requests |
| US11188862B2 (en) * | 2016-06-10 | 2021-11-30 | OneTrust, LLC | Privacy management systems and methods |
| US10873606B2 (en) * | 2016-06-10 | 2020-12-22 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US10909488B2 (en) * | 2016-06-10 | 2021-02-02 | OneTrust, LLC | Data processing systems for assessing readiness for responding to privacy-related incidents |
| US10454973B2 (en) * | 2016-06-10 | 2019-10-22 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US11277448B2 (en) * | 2016-06-10 | 2022-03-15 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US10896394B2 (en) * | 2016-06-10 | 2021-01-19 | OneTrust, LLC | Privacy management systems and methods |
| US10783256B2 (en) * | 2016-06-10 | 2020-09-22 | OneTrust, LLC | Data processing systems for data transfer risk identification and related methods |
| US10565161B2 (en) * | 2016-06-10 | 2020-02-18 | OneTrust, LLC | Data processing systems for processing data subject access requests |
| US10438017B2 (en) * | 2016-06-10 | 2019-10-08 | OneTrust, LLC | Data processing systems for processing data subject access requests |
| US10282692B2 (en) * | 2016-06-10 | 2019-05-07 | OneTrust, LLC | Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques |
| US11481710B2 (en) * | 2016-06-10 | 2022-10-25 | OneTrust, LLC | Privacy management systems and methods |
| US20210142239A1 (en) * | 2016-06-10 | 2021-05-13 | OneTrust, LLC | Data processing systems and methods for estimating vendor procurement timing |
| US11087260B2 (en) * | 2016-06-10 | 2021-08-10 | OneTrust, LLC | Data processing systems and methods for customizing privacy training |
| US10510031B2 (en) * | 2016-06-10 | 2019-12-17 | OneTrust, LLC | Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques |
| US11228620B2 (en) * | 2016-06-10 | 2022-01-18 | OneTrust, LLC | Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods |
| US9973525B1 (en) * | 2016-06-14 | 2018-05-15 | Symantec Corporation | Systems and methods for determining the risk of information leaks from cloud-based services |
| US11238176B1 (en) * | 2016-06-17 | 2022-02-01 | BigID Inc. | System and methods for privacy management |
| US10528741B1 (en) * | 2016-07-13 | 2020-01-07 | VCE IP Holding Company LLC | Computer implemented systems and methods for assessing operational risks and mitigating operational risks associated with using a third party software component in a software application |
| US10073974B2 (en) * | 2016-07-21 | 2018-09-11 | International Business Machines Corporation | Generating containers for applications utilizing reduced sets of libraries based on risk analysis |
| CN107645533A (zh) * | 2016-07-22 | 2018-01-30 | 阿里巴巴集团控股有限公司 | 数据处理方法、数据发送方法、风险识别方法及设备 |
| US10733301B2 (en) * | 2016-08-24 | 2020-08-04 | Microsoft Technology Licensing, Llc | Computing device protection based on device attributes and device risk factor |
| US20180068241A1 (en) * | 2016-09-07 | 2018-03-08 | Wipro Limited | Methods and systems for integrated risk management in enterprise environments |
| US10754958B1 (en) * | 2016-09-19 | 2020-08-25 | Nopsec Inc. | Vulnerability risk mitigation platform apparatuses, methods and systems |
| US10855714B2 (en) * | 2016-10-31 | 2020-12-01 | KnowBe4, Inc. | Systems and methods for an artificial intelligence driven agent |
| US20180121657A1 (en) * | 2016-11-01 | 2018-05-03 | International Business Machines Corporation | Security risk evaluation |
| US10380348B2 (en) * | 2016-11-21 | 2019-08-13 | ZingBox, Inc. | IoT device risk assessment |
| US10754959B1 (en) * | 2017-01-20 | 2020-08-25 | University Of South Florida | Non-linear stochastic models for predicting exploitability |
| US10650150B1 (en) * | 2017-02-28 | 2020-05-12 | University Of South Florida | Vulnerability life cycle exploitation timing modeling |
| US10862916B2 (en) * | 2017-04-03 | 2020-12-08 | Netskope, Inc. | Simulation and visualization of malware spread in a cloud-based collaboration environment |
| US10862919B2 (en) * | 2017-04-21 | 2020-12-08 | The Mitre Corporation | Methods and systems for evaluating effects of cyber-attacks on cyber-physical systems |
| US10445490B2 (en) * | 2017-06-12 | 2019-10-15 | Cyberark Software Ltd. | Remote desktop access to a target machine |
| US10142794B1 (en) * | 2017-07-10 | 2018-11-27 | International Business Machines Corporation | Real-time, location-aware mobile device data breach prevention |
| US10803177B2 (en) * | 2017-07-19 | 2020-10-13 | International Business Machines Corporation | Compliance-aware runtime generation based on application patterns and risk assessment |
| US11070568B2 (en) * | 2017-09-27 | 2021-07-20 | Palo Alto Networks, Inc. | IoT device management visualization |
| US10643002B1 (en) * | 2017-09-28 | 2020-05-05 | Amazon Technologies, Inc. | Provision and execution of customized security assessments of resources in a virtual computing environment |
| US10706155B1 (en) * | 2017-09-28 | 2020-07-07 | Amazon Technologies, Inc. | Provision and execution of customized security assessments of resources in a computing environment |
| US10540496B2 (en) * | 2017-09-29 | 2020-01-21 | International Business Machines Corporation | Dynamic re-composition of patch groups using stream clustering |
| US20190102841A1 (en) * | 2017-10-04 | 2019-04-04 | Servicenow, Inc. | Mapping engine configurations with task managed workflows and grid user interfaces |
| WO2019089654A1 (en) * | 2017-10-30 | 2019-05-09 | Pricewaterhousecoopers Llp | Implementation of continuous real-time validation of distributed data storage systems |
| US10715549B2 (en) * | 2017-12-01 | 2020-07-14 | KnowBe4, Inc. | Systems and methods for AIDA based role models |
| US10348762B2 (en) * | 2017-12-01 | 2019-07-09 | KnowBe4, Inc. | Systems and methods for serving module |
| US10812527B2 (en) * | 2017-12-01 | 2020-10-20 | KnowBe4, Inc. | Systems and methods for aida based second chance |
| US10839083B2 (en) * | 2017-12-01 | 2020-11-17 | KnowBe4, Inc. | Systems and methods for AIDA campaign controller intelligent records |
| US10009375B1 (en) * | 2017-12-01 | 2018-06-26 | KnowBe4, Inc. | Systems and methods for artificial model building techniques |
| US10257225B1 (en) * | 2017-12-01 | 2019-04-09 | KnowBe4, Inc. | Systems and methods for artificial intelligence driven agent campaign controller |
| US10673895B2 (en) * | 2017-12-01 | 2020-06-02 | KnowBe4, Inc. | Systems and methods for AIDA based grouping |
| US10853499B2 (en) * | 2017-12-06 | 2020-12-01 | Cisco Technology, Inc. | Key threat prediction |
| US12182260B2 (en) * | 2017-12-18 | 2024-12-31 | Nuvoton Technology Corporation | System and method for detecting fault injection attacks |
| US10990682B2 (en) * | 2017-12-18 | 2021-04-27 | Nuvoton Technology Corporation | System and method for coping with fault injection attacks |
| US20190197461A1 (en) * | 2017-12-27 | 2019-06-27 | Pearson Education, Inc. | On-demand utilization of proctoring resources |
| US10733668B2 (en) * | 2018-01-30 | 2020-08-04 | PointPredictive Inc. | Multi-layer machine learning classifier |
| US10958683B2 (en) * | 2018-04-26 | 2021-03-23 | Wipro Limited | Method and device for classifying uniform resource locators based on content in corresponding websites |
| US10831899B2 (en) * | 2018-05-14 | 2020-11-10 | Sap Se | Security-relevant code detection system |
| US10817604B1 (en) * | 2018-06-19 | 2020-10-27 | Architecture Technology Corporation | Systems and methods for processing source codes to detect non-malicious faults |
| US10885162B2 (en) * | 2018-06-29 | 2021-01-05 | Rsa Security Llc | Automated determination of device identifiers for risk-based access control in a computer network |
| WO2020056314A1 (en) * | 2018-09-13 | 2020-03-19 | Arizona Board Of Regents On Behalf Of Arizona State University | Systems and methods for a simulation program of a percolation model for the loss distribution caused by a cyber attack |
| US10540493B1 (en) * | 2018-09-19 | 2020-01-21 | KnowBe4, Inc. | System and methods for minimizing organization risk from users associated with a password breach |
| US10984102B2 (en) * | 2018-10-01 | 2021-04-20 | Blackberry Limited | Determining security risks in binary software code |
| US10936718B2 (en) * | 2018-10-01 | 2021-03-02 | Blackberry Limited | Detecting security risks in binary software code |
| US11200323B2 (en) * | 2018-10-17 | 2021-12-14 | BitSight Technologies, Inc. | Systems and methods for forecasting cybersecurity ratings based on event-rate scenarios |
| US11038911B2 (en) * | 2018-10-19 | 2021-06-15 | Blackberry Limited | Method and system for determining risk in automotive ECU components |
| EP3874390A4 (de) * | 2018-11-02 | 2022-07-06 | Arizona Board of Regents on behalf of the University of Arizona | Laufzeitadaptive risikobeurteilung und automatisierte minderung |
| US11995593B2 (en) * | 2018-11-28 | 2024-05-28 | Merck Sharp & Dohme Llc | Adaptive enterprise risk evaluation |
| US12299619B2 (en) * | 2018-11-28 | 2025-05-13 | Merck Sharp & Dohme Llc | Adaptive enterprise risk evaluation |
| US11281806B2 (en) * | 2018-12-03 | 2022-03-22 | Accenture Global Solutions Limited | Generating attack graphs in agile security platforms |
| US11283825B2 (en) * | 2018-12-03 | 2022-03-22 | Accenture Global Solutions Limited | Leveraging attack graphs of agile security platform |
| US11184385B2 (en) * | 2018-12-03 | 2021-11-23 | Accenture Global Solutions Limited | Generating attack graphs in agile security platforms |
| US11277432B2 (en) * | 2018-12-03 | 2022-03-15 | Accenture Global Solutions Limited | Generating attack graphs in agile security platforms |
| US11574179B2 (en) * | 2019-01-07 | 2023-02-07 | International Business Machines Corporation | Deep symbolic validation of information extraction systems |
| US11301569B2 (en) * | 2019-03-07 | 2022-04-12 | Lookout, Inc. | Quarantine of software based on analysis of updated device data |
| US11409887B2 (en) * | 2019-05-08 | 2022-08-09 | Battelle Memorial Institute | Cybersecurity vulnerability mitigation framework |
| US10607015B1 (en) * | 2019-05-16 | 2020-03-31 | Cyberark Software Ltd. | Security risk assessment and control for code |
| US11704431B2 (en) * | 2019-05-29 | 2023-07-18 | Microsoft Technology Licensing, Llc | Data security classification sampling and labeling |
| US11711374B2 (en) * | 2019-05-31 | 2023-07-25 | Varmour Networks, Inc. | Systems and methods for understanding identity and organizational access to applications within an enterprise environment |
| US11863580B2 (en) * | 2019-05-31 | 2024-01-02 | Varmour Networks, Inc. | Modeling application dependencies to identify operational risk |
| US11290494B2 (en) * | 2019-05-31 | 2022-03-29 | Varmour Networks, Inc. | Reliability prediction for cloud security policies |
| US11403405B1 (en) * | 2019-06-27 | 2022-08-02 | Architecture Technology Corporation | Portable vulnerability identification tool for embedded non-IP devices |
| EP3764263B1 (de) * | 2019-07-12 | 2024-09-11 | Accenture Global Solutions Limited | Bewertung der wirksamkeit von sicherheitskontrollen in unternehmensnetzwerken unter verwendung von graphenwerten |
| US10726136B1 (en) * | 2019-07-17 | 2020-07-28 | BitSight Technologies, Inc. | Systems and methods for generating security improvement plans for entities |
| US11481499B2 (en) * | 2019-08-05 | 2022-10-25 | Visa International Service Association | Blockchain security system |
| US10628576B1 (en) * | 2019-08-20 | 2020-04-21 | Capital One Services, Llc | Computer-based platforms or systems, computing devices or components and/or computing methods for technological applications involving provision of a portal for managing user accounts having a login portal configured to defend against credential replay attacks |
| US10673886B1 (en) * | 2019-09-26 | 2020-06-02 | Packetsled, Inc. | Assigning and representing security risks on a computer network |
| US20210110319A1 (en) * | 2019-10-09 | 2021-04-15 | Battelle Memorial Institute | Framework to quantify cybersecurity risks and consequences for critical infrastructure |
| US11677768B2 (en) * | 2019-10-22 | 2023-06-13 | Honeywell International Inc. | Apparatuses, methods, and computer program products for automatic improved network architecture generation |
| US11444974B1 (en) * | 2019-10-23 | 2022-09-13 | Architecture Technology Corporation | Systems and methods for cyber-physical threat modeling |
| CA3100378A1 (en) * | 2019-11-20 | 2021-05-20 | Royal Bank Of Canada | System and method for unauthorized activity detection |
| US11615191B2 (en) * | 2020-02-26 | 2023-03-28 | Butchko Inc. | Flexible risk assessment and management system for integrated risk and value analysis |
| EP3872665B1 (de) * | 2020-02-28 | 2025-11-26 | Accenture Global Solutions Limited | Digitaler cyber-zwilling-simulator für sicherheitssteuerungsanforderungen |
| US11947956B2 (en) * | 2020-03-06 | 2024-04-02 | International Business Machines Corporation | Software intelligence as-a-service |
| US11777992B1 (en) * | 2020-04-08 | 2023-10-03 | Wells Fargo Bank, N.A. | Security model utilizing multi-channel data |
| US11720686B1 (en) * | 2020-04-08 | 2023-08-08 | Wells Fargo Bank, N.A. | Security model utilizing multi-channel data with risk-entity facing cybersecurity alert engine and portal |
| US12118088B2 (en) * | 2020-04-22 | 2024-10-15 | Arm Limited | Moderator system for a security analytics framework |
| US11411918B2 (en) * | 2020-05-26 | 2022-08-09 | Microsoft Technology Licensing, Llc | User interface for web server risk awareness |
| US11023585B1 (en) * | 2020-05-27 | 2021-06-01 | BitSight Technologies, Inc. | Systems and methods for managing cybersecurity alerts |
| US12169528B2 (en) * | 2020-06-07 | 2024-12-17 | Info Trust, LLC | Systems and methods for web content inspection |
| US11463483B2 (en) * | 2020-07-06 | 2022-10-04 | Cisco Technology, Inc. | Systems and methods for determining effectiveness of network segmentation policies |
| US11411976B2 (en) * | 2020-07-09 | 2022-08-09 | Accenture Global Solutions Limited | Resource-efficient generation of analytical attack graphs |
| US20220019676A1 (en) * | 2020-07-15 | 2022-01-20 | VULTARA, Inc. | Threat analysis and risk assessment for cyber-physical systems based on physical architecture and asset-centric threat modeling |
| US11546368B2 (en) * | 2020-09-28 | 2023-01-03 | T-Mobile Usa, Inc. | Network security system including a multi-dimensional domain name system to protect against cybersecurity threats |
| US11516222B1 (en) * | 2020-09-28 | 2022-11-29 | Amazon Technologies, Inc. | Automatically prioritizing computing resource configurations for remediation |
| US11973790B2 (en) * | 2020-11-10 | 2024-04-30 | Accenture Global Solutions Limited | Cyber digital twin simulator for automotive security assessment based on attack graphs |
| US11954208B1 (en) * | 2020-11-24 | 2024-04-09 | Bae Systems Information And Electronic Systems Integration Inc. | System security evaluation model |
| US11687648B2 (en) * | 2020-12-10 | 2023-06-27 | Abnormal Security Corporation | Deriving and surfacing insights regarding security threats |
| US11122073B1 (en) * | 2020-12-11 | 2021-09-14 | BitSight Technologies, Inc. | Systems and methods for cybersecurity risk mitigation and management |
| US12086254B2 (en) * | 2020-12-22 | 2024-09-10 | International Business Machines Corporation | Adjusting role-based access control of a user based on behavior data of the user |
| US12050693B2 (en) * | 2021-01-29 | 2024-07-30 | Varmour Networks, Inc. | System and method for attributing user behavior from multiple technical telemetry sources |
| WO2022195848A1 (ja) * | 2021-03-19 | 2022-09-22 | 日本電気株式会社 | 分析条件生成装置、分析システム、分析条件生成プログラム、分析プログラム、分析条件生成方法、及び分析方法 |
| US11790081B2 (en) * | 2021-04-14 | 2023-10-17 | General Electric Company | Systems and methods for controlling an industrial asset in the presence of a cyber-attack |
| US11775655B2 (en) * | 2021-05-11 | 2023-10-03 | International Business Machines Corporation | Risk assessment of a container build |
| US12112155B2 (en) * | 2021-05-19 | 2024-10-08 | Kyndryl, Inc. | Software application container hosting |
| US11681811B1 (en) * | 2021-06-25 | 2023-06-20 | Northrop Grumman Systems Corporation | Cybersecurity for configuration and software updates of vehicle hardware and software based on fleet level information |
| US11409866B1 (en) * | 2021-06-25 | 2022-08-09 | Northrop Grumman Systems Corporation | Adaptive cybersecurity for vehicles |
| US11895150B2 (en) * | 2021-07-28 | 2024-02-06 | Accenture Global Solutions Limited | Discovering cyber-attack process model based on analytical attack graphs |
| US12010145B2 (en) * | 2021-07-29 | 2024-06-11 | International Business Machines Corporation | Certification of computer pipeline results |
| US12135788B1 (en) * | 2021-07-30 | 2024-11-05 | Splunk Inc. | Generating information technology incident risk score narratives |
| US12608223B2 (en) * | 2021-11-12 | 2026-04-21 | Dell Products, L.P. | Systems and methods for migrating users and modifying workspace definitions of persona groups |
| US12216761B2 (en) * | 2022-03-08 | 2025-02-04 | Denso Corporation | Dynamic adaptation of memory elements to prevent malicious attacks |
-
2022
- 2022-03-29 DE DE102022203086.9A patent/DE102022203086A1/de active Pending
-
2023
- 2023-03-22 WO PCT/EP2023/057325 patent/WO2023186655A1/de not_active Ceased
- 2023-03-22 EP EP23713644.5A patent/EP4500377A1/de active Pending
- 2023-03-22 US US18/848,312 patent/US20250200191A1/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| DE102022203086A1 (de) | 2023-10-05 |
| US20250200191A1 (en) | 2025-06-19 |
| WO2023186655A1 (de) | 2023-10-05 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE60104876T2 (de) | Prüfung der Konfiguration einer Firewall | |
| DE112010003464B4 (de) | Modifikation von Zugangskontrolllisten | |
| EP2417550B1 (de) | Verfahren zur durchführung einer applikation mit hilfe eines tragbaren datenträgers | |
| DE112017007510T5 (de) | Blockchain für offene wissenschaftliche forschung | |
| DE102013212525A1 (de) | Datenspeichervorrichtung zum geschützten Datenaustausch zwischen verschiedenen Sicherheitszonen | |
| DE19924628A1 (de) | Einrichtung und Verfahren zur biometrischen Authentisierung | |
| DE112021004613T5 (de) | Redigierbare blockchain | |
| EP3023896B1 (de) | Verfahren zum Übertragen von medizinischen Datensätzen | |
| EP3743844B1 (de) | Blockchain-basiertes identitätssystem | |
| DE112021005552B4 (de) | Mehrfaktorauthentifizierung von einheiten des internets der dinge | |
| EP3695337B1 (de) | Verfahren und bestätigungsvorrichtung zur integritätsbestätigung eines systems | |
| DE102021130811A1 (de) | Blockchain-selektive world-state-datenbank | |
| EP3062255A1 (de) | Lizensierung von Softwareprodukten | |
| DE102011010627A1 (de) | Verfahren zur Programmierung eines Mobilendgeräte-Chips | |
| WO2023186655A1 (de) | Risikoanalyse eines verteilten untersuchungsgegenstands | |
| DE112021000709B4 (de) | Schlüsselattributüberprüfung | |
| EP2639729A2 (de) | Automatisches Zugriffsteuersystem zum Steuern des Zugriffs auf ein physikalisches Objekt oder des Zugangs zu einem physikalischen Objekt und Verfahren | |
| DE102017105396A1 (de) | System zum elektronischen Signieren eines Dokuments | |
| DE102019202381A1 (de) | Verfahren zum Transfer von Daten | |
| WO2020043588A1 (de) | Einrichtung und verfahren zum ermitteln einer konsensversion eines transaktionsbuchs und einrichtung und verfahren zum überwachen eines verteilten datenbanksystems | |
| DE102017000167A1 (de) | Anonymisierung einer Blockkette | |
| DE102019112589A1 (de) | Mehr-Kern-Prozessorsystem | |
| DE102008022839A1 (de) | Verfahren und Vorrichtung zur Korrektur von digital übertragenen Informationen | |
| DE102017218547A1 (de) | Serveranwendung und Verfahren zur Plausibilisierung von Datenschutzangaben | |
| DE102015210275A1 (de) | Vorrichtung und Verfahren zum Bereitstellen eines Teils einer Zertifikatsperrliste |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20241029 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) |