EP4500377A1 - Risikoanalyse eines verteilten untersuchungsgegenstands - Google Patents

Risikoanalyse eines verteilten untersuchungsgegenstands

Info

Publication number
EP4500377A1
EP4500377A1 EP23713644.5A EP23713644A EP4500377A1 EP 4500377 A1 EP4500377 A1 EP 4500377A1 EP 23713644 A EP23713644 A EP 23713644A EP 4500377 A1 EP4500377 A1 EP 4500377A1
Authority
EP
European Patent Office
Prior art keywords
analysis
context
risk
investigation
sba2
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23713644.5A
Other languages
English (en)
French (fr)
Inventor
Marcel LOTZE
Jörn Eichler
Alexander Tschache
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Volkswagen AG
Original Assignee
Volkswagen AG
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Volkswagen AG filed Critical Volkswagen AG
Publication of EP4500377A1 publication Critical patent/EP4500377A1/de
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system

Definitions

  • the present invention relates to a method, a computer program with instructions and a system for risk analysis of a distributed object of examination.
  • the invention further relates to devices for use in such a system.
  • An object of investigation for a cybersecurity risk analysis can have parts in different analysis contexts.
  • the analysis contexts can be, for example, an embedded system, a backend or IT system or a mobile device.
  • a risk analysis is carried out for the part of the subject of the investigation that is located in a context in a defined analysis context.
  • This analysis context can be delimited by various properties, such as a distinct set of rules or a distinct analysis method, and a distinct rule for modeling the object of investigation.
  • US 2010/0250476 A1 describes a method for assessing a risk of conflict between a number of security solutions to be integrated.
  • a number of fragmentary security solutions are received in a computer system.
  • a set of the received fragmentary security solutions is integrated into a composite security solution to meet a number of security requirements.
  • the risk of conflict between the fragmentary security solutions to be integrated is assessed.
  • CAIRIS tool is an open source platform for the collection, specification and validation of secure and usable systems.
  • CAIRIS supports the concept of environments and thus enables the modeling of usage contexts.
  • a method for risk analysis of a distributed object of examination comprises the steps:
  • a computer program includes instructions that, when executed by a computer, cause the computer to carry out the following steps for risk analysis of a distributed subject of investigation:
  • the term computer is to be understood broadly. In particular, it also includes workstations, distributed systems and other processor-based data processing devices.
  • the computer program can, for example, be made available for electronic retrieval or stored on a computer-readable storage medium.
  • a system for risk analysis of a distributed object of examination has:
  • a first analysis module for carrying out a partially or fully automated risk analysis for a part of the object of investigation located in a first context in a first analysis context, the first analysis context being delimited by a distinct evaluation model or a distinct analysis method and a distinct regulation for modeling the object of investigation;
  • a second analysis module for carrying out a partially or fully automated risk analysis for a part of the subject of investigation located in a second context in a second analysis context, the second analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation; wherein the first analysis module and the second analysis module are set up to exchange information about an identified need for protection, using a transmission path of a date for which a need for protection was determined to automatically determine which further risk analysis the need for protection should be taken into account.
  • a first device for use in a system has a first analysis module for carrying out a partially or fully automated risk analysis for a part of an examination subject located in a first context in a first analysis context, the first analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation.
  • the first analysis module is set up to transmit information about an identified need for protection to a second analysis module for carrying out a risk analysis for a part of the subject of the investigation located in a second context, using a transmission path to automatically determine a date for which a need for protection was determined, in which further risk analysis the need for protection should be taken into account.
  • a second device for use in a system according to the invention has a second analysis module for carrying out a partially or fully automated risk analysis for a part of an examination subject located in a second context in a second analysis context, the second analysis context being delimited by a distinct evaluation model or a distinct Analysis method and a distinct rule for modeling the object of investigation.
  • the second analysis module is set up to take into account a need for protection determined by a first analysis module when carrying out a risk analysis for a part of the subject of the investigation located in a first context in the risk analysis in the second context.
  • the addition of a modeling step in which information on an identified need for protection is exchanged between the risk analyzes makes it possible to automate the resolution of the mutual dependencies.
  • the same protection requirements can be adopted based on the information transmitted.
  • the risk analyzes are carried out taking different regulations into account.
  • a risk analysis is carried out for the part of the subject of the investigation that is located in a context in a defined analysis context.
  • This analysis context is delimited by various properties, such as a distinct set of rules or a distinct analysis method, and a distinct rule for modeling the object of investigation.
  • a transmission path of a date for which a need for protection was determined is used to determine which further risk analysis the need for protection should be taken into account.
  • a cross-context composition of the context-specific risk analyzes can be achieved particularly advantageously by considering the information flows between the parts of the subject matter under consideration. These information flows transport goods worthy of protection, i.e. data that should be represented in the risk analyzes of the parts of the subject of investigation. This representation can, if necessary, take place at different levels of abstraction.
  • the identified need for protection is taken into account by defining a risk-mitigating measure. Defining or implementing a suitable risk-mitigating measure ensures that the identified need for protection is taken into account.
  • information on the defined risk-mitigating measure is exchanged between the risk analyses.
  • the measure can now be reversed in the risk analysis that determined the original need for protection. This allows the risk-mitigating effect to be taken into account there too.
  • the risk-mitigating measure is automated or determined by manual intervention.
  • the risk-mitigating Measures can be automatically selected from relevant catalogs of measures based on the transferred protection requirement. This has the advantage that no manual intervention is required.
  • the risk-mitigating measure can also be determined at the personal discretion of a specialist. In this way, the decision-making authority over the measures taken rests with the responsible specialist.
  • a threat to the need for protection identified in the risk analysis in one context is taken into account in the risk analysis in the other context.
  • threats to a protection need that are identified in another risk analysis can also be taken into account in the risk analysis that is the origin of the protection need determination.
  • an identified need for protection is also taken into account in a risk analysis for a part of the subject of the investigation located in a third context. Traceability is also possible across multiple analyzes or analysis networks, provided that the data is identified uniformly. Implementation can be done using any algorithm that can identify all loop-free communication paths in a risk analysis “network”. The propagation of the protection needs and the protective measures can then take place with or against the direction of communication of the data.
  • the first context relates to a means of transport, a mobile device or an embedded system.
  • the second context can concern, for example, a backend or an IT system.
  • the solution according to the invention can be used in all applications in which risk analyzes are carried out on distributed examination objects. Examples of this are applications on mobile phones with communication to an IT backend, the communication of industrial systems with IT systems or the communication of embedded systems, such as chip cards or similar, with other systems.
  • Fig. 1 shows schematically a method for risk analysis of a distributed object of investigation
  • Fig. 2 shows a system for risk analysis of a distributed object of investigation
  • Fig. 3 illustrates a known approach to risk analysis of a distributed
  • Fig. 5 illustrates an object of investigation that is distributed over a means of transport and an IT backend
  • Fig. 6 illustrates a risk analysis of the subject of investigation from Fig. 5;
  • FIG. 7 illustrates a first phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts;
  • FIG. 9 illustrates a third phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts.
  • Fig. 1 shows schematically a method for risk analysis of a distributed object of investigation.
  • a partially or fully automated risk analysis is carried out for a part of the object of investigation located in a first context 10.
  • the first context can relate to a means of transport, a mobile device or an embedded system.
  • a partially or fully automated risk analysis is carried out for a person located in a second context Part of the subject of the investigation carried out 11.
  • the second context can, for example, concern a backend or an IT system.
  • the risk-mitigating measure can, for example, be automated or determined through manual intervention. Information on the defined 14 risk-mitigating measure can then be exchanged between the risk analyses. 15 Preferably, a threat to the need for protection identified in the risk analysis in one context is also taken into account in the risk analysis in the other context. An identified need for protection can also be taken into account in a risk analysis for a part of the subject of the investigation located in a third context.
  • Fig. 2 shows a system 70 for risk analysis of a distributed object of examination.
  • the system 70 includes a first device 20 for risk analysis and a second device 30 for risk analysis.
  • the two devices 20, 30 communicate with each other via respective interfaces 21, 31.
  • the first device 20 has a first analysis module 22 for carrying out a partially or fully automated risk analysis for a part of the subject of the examination located in a first context.
  • the first context may concern a means of transport, a mobile device or an embedded system.
  • the second device 30 has a second analysis module 32 for carrying out a partially or fully automated risk analysis for a part of the subject of the investigation located in a second context.
  • the second context can concern, for example, a backend or an IT system.
  • the first analysis module 22 and the second analysis module 32 are set up to exchange information about an identified protection requirement SB via the interfaces 21, 31.
  • the identified need for protection SB can then be taken into account by the analysis modules 22, 32 by defining a risk-mitigating measure M.
  • the risk-mitigating measure M can, for example, be determined automatically or through manual intervention.
  • the analysis modules 22, 32 can then be connected via the interfaces 21, 31 Exchange information on the defined risk-mitigating measure M.
  • information about threats to the need for protection identified during the risk analyzes is also exchanged so that they can be taken into account by the analysis modules 22, 32.
  • the analysis modules 22, 32 can each be controlled by a control module 23, 33. If necessary, settings of the analysis modules can be made via user interfaces 25, 35
  • the analysis modules 22, 32 and the control modules 23, 33 can be implemented as dedicated hardware, for example as integrated circuits. Of course, they can also be partially or completely combined or implemented as software that runs on a suitable processor, for example a GPU or a CPU.
  • the interfaces 21, 31 can alternatively also be divided into separate inputs and outputs.
  • the memories 24, 34 of the devices 20, 30 described can have both volatile and non-volatile memory areas and include a wide variety of storage devices and storage media, for example hard drives, optical storage media or semiconductor memories.
  • Fig. 3 illustrates a known approach for risk analysis of a distributed object of investigation UG.
  • a first part 40 of the subject of investigation UG is located in a first context
  • a second part 40 'of the subject of investigation UG is located in a second context.
  • a risk analysis Ri, R2 is carried out for the part 40, 40' of the subject of investigation UG located in a context in a defined analysis context.
  • This analysis context can be delimited by various properties, such as a distinct evaluation model BM1, BM 2 or a distinct analysis method AM1, AM 2 , and a distinct regulation for modeling MV1, MV 2 of the subject of investigation UG.
  • a cross-context composition of the context-specific analyzes Ri, R 2 is not possible.
  • FIG. 4 illustrates an approach according to the invention for risk analysis of a distributed object of investigation UG.
  • a first part 40 of the subject of investigation UG is located in a first context
  • a second part 40 'of the subject of investigation UG is located in a second context.
  • a risk analysis Ri, R2 is carried out partially or fully automatically for the part 40, 40' of the subject of investigation UG located in a context in a defined analysis context.
  • this analysis context is delimited by various properties, such as a distinct evaluation model BM1, BM 2 or a distinct analysis method AM1, AM 2 , and a distinct regulation for modeling MV1, MV 2 of the object of investigation UG.
  • a cross-context composition of the context-specific analyzes Ri, R2 is achieved by considering the information flows between the parts 40, 40 'of the object of investigation UG under consideration. These information flows transport goods worthy of protection, ie data D, which must be represented in the analyzes Ri, R2 of parts 40, 40' of the subject of investigation UG.
  • the partial analyzes Ri, R2 can be carried out in parallel and a mutual consideration of the analysis results AE can be carried out assisted or automated.
  • Fig. 5 illustrates an examination subject that is distributed over a means of transport 50 and an IT backend 60.
  • a function for user registration in the means of transport 50 is to be considered.
  • This function has a part Fi in the means of transport 50 for carrying out the registration and storage of the logged in user and a part F2 in the IT backend 60, which is responsible for user management and user authentication.
  • Means of transport 50 and backend 60 communicate via a mobile phone network. Separate risk analyzes are carried out for both parts Fi, F2 of the function, ie in the means of transport 50 and in the backend 60 regarding cybersecurity.
  • the respective analysis determines that a) the user data from the means of transport 50 must be treated confidentially and b) the result of the authentication must be authentic.
  • a risk arises that, depending on the circumstances, requires mitigation, i.e. risk treatment through reduction, through suitable security measures.
  • these security measures cannot be defined and implemented unilaterally in all cases. If the result of the authentication is received by the means of transport 50, the means of transport 50 cannot do anything to ensure the required authenticity. This must be guaranteed by the backend 60.
  • a first assumption is that the means of transport 50 ensures the confidentiality of the user data during storage, processing and transmission.
  • a second assumption is that the backend 60 ensures the authenticity of the authentication result during processing and transmission.
  • a functional requirement for the means of transport 50 is, for example, that the means of transport 50 stores the user data confidentially in a secure storage area using suitable encryption and transmits the data via a channel that enables confidential transmission, for example TLS (Transport Layer Security).
  • a functional requirement for the backend 60 is, for example, that the backend 60 displays the result of the authentication via a Channel that enables authentic transmission, e.g. TLS.
  • FIG. 6 illustrates a risk analysis according to the invention of the subject of investigation UG from FIG .
  • Backend 60.
  • an assessment model BMi for the context of “embedded system” can be used, e.g. an assessment according to the specifications of the UNECE (United Nations Economic Commission for Europe).
  • an analysis method AMi for the context of “embedded system” e.g. a methodology according to UNECE specifications
  • a modeling rule MVi for the context of “embedded system” can be used.
  • the modeling rule MVi can also be part of the external specifications, as shown in Fig. 6.
  • an evaluation model BM 2 for the context of “IT system” can be used, e.g. an analysis according to the specifications of local institutions such as the BSI (Federal Office for Information Security).
  • an AM 2 analysis method can be used for the “IT system” context, e.g. a methodology according to BSI specifications, and an MV 2 modeling rule can be used for the “IT system” context.
  • modeling rule MV 2 can be part of the external specifications.
  • a protection requirement SB for a date D is determined as the analysis result AE in a protection needs determination SBF, for example in the case of the means of transport 50 an authenticity of the authentication result, it can be automatically tracked in which ways the date D is transmitted, here from the backend 60, and The same protection requirement SB is adopted in the analysis Ri, R2 of the transmission partner.
  • a risk-mitigating measure M can then be determined, for example an authentic transfer, which can be automatically selected from relevant catalogs of measures based on the transferred protection requirement SB or is determined at personal discretion.
  • the measure M here the authentic transfer of the date, can now be reversed in the analysis Ri, R 2 , which has determined the original protection requirement SB and the risk-mitigating effect can also be taken into account there.
  • Ri, R 2 which has determined the original protection requirement SB and the risk-mitigating effect can also be taken into account there.
  • Traceability is also possible across several analyzes Ri, R2 or analysis networks, provided that the data D is identified uniformly. Implementation can be done using any algorithm that can identify all loop-free communication paths in a “network” of risk analysis Ri, R2. The propagation of the protection requirements SB and the protective measures M can then take place with or against the communication direction of the data D.
  • the protection requirement SB of a date D is determined by the risk analysis Ri, R2 on whose side the date D is sent.
  • the protection requirement SB can just as easily be determined by the risk analysis Ri, R2 on whose side the date D is received.
  • FIG. 7 illustrates a first phase of a risk analysis according to the invention of an object of investigation, which extends to four contexts.
  • Four associated risk analyzes RA1-RA4 are carried out for the four contexts.
  • the need for protection is determined by the receiving side.
  • the transmission of a first date DA to a part of the subject of the examination in a second context is determined.
  • the risk analysis RA2 in the second context also shows that the first date DA is attached to part of the
  • the subject of the investigation is transmitted in a third context for which a third risk analysis RA3 is carried out.
  • the transmission of a second date DB to the part of the subject of the investigation in the third context is also determined.
  • Fig. 8 illustrates a second phase of the risk analysis according to the invention.
  • the fourth risk analysis RA4 transmits a protection requirement SBB determined for the second date DB to the third risk analysis RA3.
  • a protection requirement SB A 2 determined for the first date DA is transmitted to the second risk analysis RA 2 .
  • the second risk analysis RA 2 determines an overall resulting protection requirement SB A2 ,I based on the transmitted protection requirement SB A 2 and transmits this to the first risk analysis RA1.
  • Fig. 9 illustrates a third phase of the risk analysis according to the invention.
  • the first risk analysis RA1 determines a suitable risk-mitigating measure M A I and transmits corresponding information to the second risk analysis RA2.
  • the second risk analysis RA2 determines a suitable risk-mitigating measure M A 2 in response to the identified need for protection SB A 2 and transmits the corresponding information to the third risk analysis RA3.
  • the fourth risk analysis RA4 determines a suitable risk-mitigating measure MB in response to the identified need for protection by SBB and transmits the corresponding information to the third risk analysis RA3. This means that none of the risk analyzes RA1-RA4 is dependent on making assumptions about the respective communication partners.
  • AMi AM 2 Analysis method BMi, BM 2 Assessment model D, DA, DB Date FI, F 2 Functional component M, MAI, risk-mitigating measure MA2, MB

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

Die vorliegende Erfindung betrifft ein Verfahren, ein Computerprogramm mit Instruktionen und ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Die Erfindung betrifft weiterhin Vorrichtungen zur Verwendung in einem solchen System. Erfindungsgemäß wird eine Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt (10). Zudem wird eine Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt (11). Wird nun bei einer der Risikoanalysen ein Schutzbedarf festgestellt (12), so werden Informationen zu diesem festgestellten (12) Schutzbedarf zwischen den Risikoanalysen ausgetauscht (13). Der festgestellte (12) Schutzbedarf kann dann berücksichtigt werden, indem eine risikomitigierende Maßnahme festgelegt wird (14). In diesem Fall können Informationen zur festgelegten (14) risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht werden (15).

Description

Beschreibung
Risikoanalyse eines verteilten Untersuchungsgegenstands
Die vorliegende Erfindung betrifft ein Verfahren, ein Computerprogramm mit Instruktionen und ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Die Erfindung betrifft weiterhin Vorrichtungen zur Verwendung in einem solchen System.
Ein Untersuchungsgegenstand für eine Risikoanalyse hinsichtlich Cybersicherheit, z.B. eine verteilte Funktion, kann Anteile in verschiedenen Analysekontexten haben. Bei den Analysekontexten kann es sich beispielsweise um ein eingebettetes System, ein Backendoder IT-System oder ein Mobilgerät handeln. Eine Risikoanalyse wird für den in einem Kontext verorteten Teil des Untersuchungsgegenstands in einem definierten Analysekontext durchgeführt. Dieser Analysekontext kann durch verschiedene Eigenschaften, wie z.B. ein distinktes Regelwerk oder eine distinkte Analysemethode, und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands abgegrenzt werden.
Vor diesem Hintergrund beschreibt US 2010/0250476 A1 ein Verfahren zur Bewertung eines Konfliktrisikos zwischen einer Anzahl von zu integrierenden Sicherheitslösungen. In einem Computersystem wird eine Anzahl von fragmentarischen Sicherheitslösungen empfangen. Ein Satz der empfangenen fragmentarischen Sicherheitslösungen wird zu einer zusammengesetzten Sicherheitslösung integriert, um eine Anzahl von Sicherheitsanforderungen zu erfüllen. Das Risiko eines Konflikts zwischen den zu integrierenden fragmentarischen Sicherheitslösungen wird bewertet.
Bei dem Werkzeug CAIRIS handelt es sich um eine Open-Source-Plattform für die Erhebung, Spezifikation und Validierung sicherer und nutzbarer Systeme. CAIRIS unterstützt den Begriff der Umgebungen und ermöglicht damit die Modellierung von Nutzungskontexten.
Es gibt momentan keine technische Lösung, die die Betrachtung von verteilten Untersuchungsgegenständen in verschiedenen Kontexten erlaubt. Es wird entweder eine gesamtheitliche Risikoanalyse durchgeführt, die keine dedizierten Annahmen über den Kontext eines Teils des Untersuchungsgegenstands erlaubt, oder es werden mehrere Analysen durchgeführt, die wechselseitige Annahmen treffen. Eine Komponierbarkeit von Risikoanalysen eines verteilten Untersuchungsgegenstands in verschiedenen Kontexten ist nicht bekannt. Im Fall einer gesamtheitlichen Analyse sind ein einheitliches Regelwerk, eine einheitliche Analysemethode und eine einheitliche Modellierung der verteilten Teile des Untersuchungsgegenstands erforderlich. Im Falle von getrennten Analysen müssen Annahmen über die verschiedenen Teile des Untersuchungsgegenstands manuell übertragen werden.
Es wäre daher wünschenswert, ein Werkzeug zur Durchführung von Risikoanalysen zur Verfügung zu haben, das einerseits die Durchführung von Analysen von Funktionsanteilen in verschiedenen Kontexten und andererseits die Verknüpfung über verschiedene Kontexte hinweg zur gesamtheitlichen Betrachtung verteilter Funktionen erlaubt.
Es ist eine Aufgabe der Erfindung, verbesserte Lösungen zur Risikoanalyse eines verteilten Untersuchungsgegenstands bereitzustellen.
Diese Aufgabe wird durch ein Verfahren mit den Merkmalen des Anspruchs 1 , durch ein Computerprogramm mit Instruktionen gemäß Anspruch 9, durch ein System mit den Merkmalen des Anspruchs 10 sowie durch Vorrichtungen gemäß Anspruch 11 und Anspruch 12 gelöst. Bevorzugte Ausgestaltungen der Erfindung sind Gegenstand der abhängigen Ansprüche.
Gemäß einem ersten Aspekt der Erfindung umfasst ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands die Schritte:
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands;
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- Austauschen von Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll. Gemäß einem weiteren Aspekt der Erfindung umfasst ein Computerprogramm Instruktionen, die bei Ausführung durch einen Computer den Computer zur Ausführung der folgenden Schritte zur Risikoanalyse eines verteilten Untersuchungsgegenstands veranlassen:
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands;
- Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- Austauschen von Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Der Begriff Computer ist dabei breit zu verstehen. Insbesondere umfasst er auch Workstations, verteilte Systeme und andere prozessorbasierte Datenverarbeitungsvorrichtungen.
Das Computerprogramm kann beispielsweise für einen elektronischen Abruf bereitgestellt werden oder auf einem computerlesbaren Speichermedium gespeichert sein.
Gemäß einem weiteren Aspekt der Erfindung weist ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands auf:
- ein erstes Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; und
- ein zweites Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands; wobei das erste Analysemodul und das zweite Analysemodul eingerichtet sind, Informationen zu einem festgestellten Schutzbedarf auszutauschen, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Eine erste Vorrichtung zur Verwendung in einem erfindungsgemäßen System weist ein erstes Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil eines Untersuchungsgegenstands in einem ersten Analysekontext auf, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands. Das erste Analysemodul ist eingerichtet, Informationen zu einem festgestellten Schutzbedarf an ein zweites Analysemodul zum Durchführen einer Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands zu übermitteln, wobei anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, automatisiert bestimmt wird, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll.
Eine zweite Vorrichtung zur Verwendung in einem erfindungsgemäßen System weist ein zweites Analysemodul zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil eines Untersuchungsgegenstands in einem zweiten Analysekontext auf, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell oder eine distinkte Analysemethode und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands. Das zweite Analysemodul ist eingerichtet, einen von einem ersten Analysemodul beim Durchführen einer Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands festgestellten Schutzbedarf bei der Risikoanalyse im zweiten Kontext zu berücksichtigen.
Bei der erfindungsgemäßen Lösung wird durch das Hinzufügen eines Modellierungsschritts, bei dem Informationen zu einem festgestellten Schutzbedarf zwischen den Risikoanalysen ausgetauscht werden, eine Automatisierung der Auflösung der wechselseitigen Abhängigkeiten ermöglicht. In den beteiligten Risikoanalysen kann auf Basis der übermittelten Informationen jeweils derselbe Schutzbedarf übernommen werden. Dadurch entfällt die Notwendigkeit einer iterativen, in der Regel manuellen Synchronisierung der Risikoanalysen in unterschiedlichen Kontexten. Da eine manuelle Umsetzung und Wartung der Risikoanalyse durch eine Fachperson entfallen kann, ist die erfindungsgemäße Lösung weniger aufwendig und fehleranfällig als bekannte Lösungen. Insbesondere entfällt der zeitliche Mehraufwand für eine repetitive Ablage- und Prüftätigkeit durch eine Fachperson.
Erfindungsgemäß werden die Risikoanalysen unter Berücksichtigung unterschiedlicher Vorschriften durchgeführt. Eine Risikoanalyse wird für den in einem Kontext verorteten Teil des Untersuchungsgegenstands in einem definierten Analysekontext durchgeführt. Dieser Analysekontext wird durch verschiedene Eigenschaften, wie z.B. ein distinktes Regelwerk oder eine distinkte Analysemethode, und eine distinkte Vorschrift zur Modellierung des Untersuchungsgegenstands abgegrenzt.
Erfindungsgemäß wird anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, bestimmt, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll. Eine kontextübergreifende Komposition der kontextspezifischen Risikoanalysen kann besonders vorteilhaft durch eine Betrachtung der Informationsflüsse zwischen den betrachteten Teilen des Untersuchungsgegenstands erreicht werden. Diese Informationsflüsse transportieren schützenswerte Güter, d.h. Daten, die in den Risikoanalysen der Teile des Untersuchungsgenstands repräsentiert sein sollten. Diese Repräsentation kann dabei gegebenenfalls auf verschiedenen Abstraktionsebenen erfolgen.
Gemäß einem Aspekt der Erfindung wird der festgestellte Schutzbedarf berücksichtigt, indem eine risikomitigierende Maßnahme festgelegt wird. Durch die Festlegung bzw. Umsetzung einer geeigneten risikomitigierenden Maßnahme wird sichergestellt, dass dem festgestellten Schutzbedarf Rechnung getragen wird.
Gemäß einem Aspekt der Erfindung werden Informationen zur festgelegten risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht. Die Maßnahme kann auf diese Weise nun umgekehrt in der Risikoanalyse übernommen werden, die den ursprünglichen Schutzbedarf festgestellt hat. Dies erlaubt es, die risikomitigierende Wirkung auch dort zu berücksichtigen. Insbesondere bedarf es keines weiteren Abgleichs der Konsistenz von Annahmen und Maßnahmen, da keine Annahmen mehr getroffen werden müssen.
Gemäß einem Aspekt der Erfindung wird die risikomitigierende Maßnahme automatisiert oder durch einen manuellen Eingriff festgelegt. Beispielsweise kann die risikomitigierende Maßnahme anhand des übertragenen Schutzbedarfs automatisiert aus einschlägigen Maßnahmenkatalogen ausgewählt werden. Dies hat den Vorteil, dass keine manuellen Eingriffe erforderlich sind. Alternativ kann die risikomitigierende Maßnahme aber auch im persönlichen Ermessen einer Fachperson festgelegt werden. Auf diese Weise liegt die Entscheidungshoheit über die getroffenen Maßnahmen bei der zuständigen Fachperson.
Gemäß einem Aspekt der Erfindung wird eine bei der Risikoanalyse in einem Kontext festgestellte Gefährdung des Schutzbedarfs bei der Risikoanalyse im anderen Kontext berücksichtigt. Über die wechselseitige Verknüpfung der Risikoanalysen in den verschiedenen Kontexten können neben den ermittelten Schutzbedarfen und den jeweiligen risikomitigierenden Maßnahmen auch Gefährdungen eines Schutzbedarfs, die in einer anderen Risikoanalyse festgestellt werden, in derjenigen Risikoanalyse Berücksichtigung finden, die Ursprung der Schutzbedarfsfeststellung ist.
Gemäß einem Aspekt der Erfindung wird ein festgestellter Schutzbedarf zusätzlich auch bei einer Risikoanalyse für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands berücksichtigt. Die Rückverfolgbarkeit ist auch über mehrere Analysen oder Analyseverbünde hinweg gegeben, sofern eine einheitliche Identifizierung der Daten gegeben ist. Eine Implementierung kann mittels jedes Algorithmus erfolgen, der alle schleifenfreien Kommunikationspfade in einem „Netzwerk“ aus Risikoanalysen identifizieren kann. Die Propagation der Schutzbedarfe und der Schutzmaßnahmen kann dann mit oder entgegen der Kommunikationsrichtung der Daten erfolgen.
Gemäß einem Aspekt der Erfindung betrifft der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Die erfindungsgemäße Lösung kann in allen Anwendungsfällen zum Einsatz kommen, bei denen Risikoanalysen auf verteilten Untersuchungsgegenständen durchgeführt werden. Beispiele dafür sind Applikationen auf Mobiltelefonen mit einer Kommunikation zu einem IT-Backend, die Kommunikation von Industrieanalagen mit IT-Systemen oder die Kommunikation von eingebetteten Systemen, wie z.B. Chipkarten o.ä., mit anderen Systemen.
Weitere Merkmale der vorliegenden Erfindung werden aus der nachfolgenden Beschreibung und den angehängten Ansprüchen in Verbindung mit den Figuren ersichtlich.
Fig. 1 zeigt schematisch ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands; Fig. 2 zeigt ein System zur Risikoanalyse eines verteilten Untersuchungsgegenstands;
Fig. 3 veranschaulicht einen bekannten Ansatz zur Risikoanalyse eines verteilten
Untersuchungsgegenstands;
Fig. 4 veranschaulicht einen erfindungsgemäßen Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands;
Fig. 5 veranschaulicht einen Untersuchungsgegenstand, der sich auf ein Fortbewegungsmittel und ein IT-Backend verteilt;
Fig. 6 veranschaulicht eine Risikoanalyse des Untersuchungsgegenstands aus Fig. 5; und
Fig. 7 veranschaulicht eine erste Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt;
Fig. 8 veranschaulicht eine zweite Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt; und
Fig. 9 veranschaulicht eine dritte Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt.
Zum besseren Verständnis der Prinzipien der vorliegenden Erfindung werden nachfolgend Ausführungsformen der Erfindung anhand der Figuren detaillierter erläutert. Es versteht sich, dass sich die Erfindung nicht auf diese Ausführungsformen beschränkt und dass die beschriebenen Merkmale auch kombiniert oder modifiziert werden können, ohne den Schutzbereich der Erfindung zu verlassen, wie er in den angehängten Ansprüchen definiert ist.
Fig. 1 zeigt schematisch ein Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Bei dem Verfahren wird eine teil- oder vollautomatisierte Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt 10. Beispielsweise kann der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System betreffen. Zudem wird eine teil- oder vollautomatisierte Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands durchgeführt 11. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Wird nun bei einer der Risikoanalysen ein Schutzbedarf festgestellt 12, so werden Informationen zu diesem festgestellten 12 Schutzbedarf zwischen den Risikoanalysen ausgetauscht 13. Insbesondere wird anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf festgestellt wurde, bestimmt, bei welcher weiteren Risikoanalyse der Schutzbedarf berücksichtigt werden soll. Der festgestellte 12 Schutzbedarf kann dann berücksichtigt werden, indem eine risikomitigierende Maßnahme festgelegt wird 14. Die risikomitigierende Maßnahme kann z.B. automatisiert oder durch einen manuellen Eingriff festgelegt werden. Anschließend können Informationen zur festgelegten 14 risikomitigierenden Maßnahme zwischen den Risikoanalysen ausgetauscht werden 15. Vorzugsweise wird auch eine bei der Risikoanalyse in einem Kontext festgestellte Gefährdung des Schutzbedarfs bei der Risikoanalyse im anderen Kontext berücksichtigt. Ein festgestellter Schutzbedarf kann zudem auch zusätzlich bei einer Risikoanalyse für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands berücksichtigt werden.
Fig. 2 zeigt ein System 70 zur Risikoanalyse eines verteilten Untersuchungsgegenstands. Das System 70 umfasst in diesem Beispiel eine erste Vorrichtung 20 zur Risikoanalyse und eine zweite Vorrichtung 30 zur Risikoanalyse. Die beiden Vorrichtungen 20, 30 kommunizieren miteinander über jeweilige Schnittstellen 21, 31. Die erste Vorrichtung 20 hat ein erstes Analysemodul 22 zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem ersten Kontext verorteten Teil des Untersuchungsgegenstands. Beispielsweise kann der erste Kontext ein Fortbewegungsmittel, ein Mobilgerät oder ein eingebettetes System betreffen. Entsprechend hat die zweite Vorrichtung 30 ein zweites Analysemodul 32 zum Durchführen einer teil- oder vollautomatisierten Risikoanalyse für einen in einem zweiten Kontext verorteten Teil des Untersuchungsgegenstands. Der zweite Kontext kann beispielsweise ein Backend oder ein IT-System betreffen. Das erste Analysemodul 22 und das zweite Analysemodul 32 sind eingerichtet, über die Schnittstellen 21, 31 Informationen zu einem festgestellten Schutzbedarf SB auszutauschen. Dabei wird insbesondere anhand eines Übertragungsweges eines Datums, für das ein Schutzbedarf SB festgestellt wurde, bestimmt, bei weicher weiteren Risikoanalyse der Schutzbedarf SB berücksichtigt werden soll, d.h. mit welchem Analysemodul 22, 32 entsprechende Informationen ausgetauscht werden sollen. Der festgestellte Schutzbedarf SB kann dann von den Analysemodulen 22, 32 berücksichtigt werden, indem eine risikomitigierende Maßnahme M festgelegt wird. Die risikomitigierende Maßnahme M kann z.B. automatisiert oder durch einen manuellen Eingriff festgelegt werden. Anschließend können die Analysemodule 22, 32 über die Schnittstellen 21, 31 Informationen zur festgelegten risikomitigierenden Maßnahme M austauschen. Vorzugsweise werden auch Informationen zu bei den Risikoanalysen festgestellten Gefährdungen des Schutzbedarfs ausgetauscht, sodass sie von den Analysemodulen 22, 32 berücksichtigt werden können.
Die Analysemodule 22, 32 können jeweils von einem Kontrollmodul 23, 33 gesteuert werden. Über Benutzerschnittstellen 25, 35 können gegebenenfalls Einstellungen der Analysemodule
22, 32 oder der Kontrollmodule 23, 33 geändert werden. Die in den Vorrichtungen 20, 30 anfallenden Daten können bei Bedarf jeweils in einem Speicher 24, 34 abgelegt werden, beispielsweise für eine spätere Auswertung oder für eine Nutzung durch die Komponenten der Vorrichtung 20, 30. Die Analysemodule 22, 32 sowie die Kontrollmodule 23, 33 können als dedizierte Hardware realisiert sein, beispielsweise als integrierte Schaltungen. Natürlich können sie aber auch teilweise oder vollständig kombiniert oder als Software implementiert werden, die auf einem geeigneten Prozessor läuft, beispielsweise auf einer GPU oder einer CPU. Die Schnittstellen 21, 31 können alternativ auch in getrennte Ein- und Ausgänge aufgeteilt sein.
Die Speicher 24, 34 der beschriebenen Vorrichtungen 20, 30 können sowohl volatile als auch nichtvolatile Speicherbereiche aufweisen und unterschiedlichste Speichergeräte und Speichermedien umfassen, beispielsweise Festplatten, optische Speichermedien oder Halbleiterspeicher.
Fig. 3 veranschaulicht einen bekannten Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands UG. Ein erster Teil 40 des Untersuchungsgegenstands UG ist in einem ersten Kontext verortet, ein zweiter Teil 40‘ des Untersuchungsgegenstands UG ist in einem zweiten Kontext verortet. Eine Risikoanalyse Ri, R2 wird für den in einem Kontext verorteten Teil 40, 40‘ des Untersuchungsgegenstands UG in einem definierten Analysekontext durchgeführt. Dieser Analysekontext kann durch verschiedene Eigenschaften, wie z.B. ein distinktes Bewertungsmodell BM1, BM2 oder eine distinkte Analysemethode AM1, AM2, und eine distinkte Vorschrift zur Modellierung MV1, MV2 des Untersuchungsgegenstands UG abgegrenzt werden. Eine kontextübergreifende Komposition der kontextspezifischen Analysen Ri, R2 ist nicht möglich. Ergibt sich als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ein Schutzbedarf SB, der nur durch eine schützende Maßnahme eines in einem anderen Kontext verorteten Teils 40, 40‘ des verteilten Untersuchungsgegenstands UG erfüllt werden kann, so muss eine Annahme A über die Existenz dieser Maßnahme getroffen werden. Diese Maßnahme kann dann in der betroffenen Teilanalyse Ri, R2 berücksichtigt werden, muss allerdings selbst Teil des Analyseumfangs der Teilanalyse Ri, R2 im anderen Kontext sein. Das Analyseergebnis AE muss dann sequentiell in die anfordernde Teilanalyse Ri, R2 übertragen werden. Dieser Vorgang muss so oft wiederholt werden, bis alle wechselseitigen Effekte berücksichtigt wurden.
Fig. 4 veranschaulicht einen erfindungsgemäßen Ansatz zur Risikoanalyse eines verteilten Untersuchungsgegenstands UG. Ein erster Teil 40 des Untersuchungsgegenstands UG ist in einem ersten Kontext verortet, ein zweiter Teil 40‘ des Untersuchungsgegenstands UG ist in einem zweiten Kontext verortet. Eine Risikoanalyse Ri, R2 wird teil- oder vollautomatisiert für den in einem Kontext verorteten Teil 40, 40‘ des Untersuchungsgegenstands UG in einem definierten Analysekontext durchgeführt. Dieser Analysekontext wird wie gehabt durch verschiedene Eigenschaften, wie z.B. ein distinktes Bewertungsmodell BM1, BM2 oder eine distinkte Analysemethode AM1, AM2, und eine distinkte Vorschrift zur Modellierung MV1, MV2 des Untersuchungsgegenstands UG abgegrenzt. Eine kontextübergreifende Komposition der kontextspezifischen Analysen Ri, R2 wird durch eine Betrachtung der Informationsflüsse zwischen den betrachteten Teilen 40, 40‘ des Untersuchungsgegenstands UG erreicht. Diese Informationsflüsse transportieren schützenswerte Güter, d.h. Daten D, die in den Analysen Ri, R2 der Teile 40, 40‘ des Untersuchungsgenstands UG repräsentiert sein müssen. Der als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ermittelte Schutzbedarf SB und die eventuell daraus risikomitigierende Maßnahme M können durch Nachverfolgung des Informationsflusses unabhängig von der Modellierung der Teile 40, 40‘ des verteilten Untersuchungsgegenstands UG kontextübergreifend wechselseitig berücksichtigt werden. Die Durchführung der Teilanalysen Ri, R2 kann in diesem Fall parallel erfolgen und eine wechselseitige Berücksichtigung der Analyseergebnisse AE kann assistiert oder automatisiert durchgeführt werden.
Nachfolgend soll eine bevorzugte Ausführungsform einer erfindungsgemäßen Lösung anhand von Fig. 5 bis Fig. 9 an einem konkreten Anwendungsbeispiel beschrieben werden.
Fig. 5 veranschaulicht einen Untersuchungsgegenstand, der sich auf ein Fortbewegungsmittel 50 und ein IT-Backend 60 verteilt. Im gezeigten Beispiel soll eine Funktion zur Nutzeranmeldung im Fortbewegungsmittel 50 betrachtet werden. Diese Funktion hat einen Anteil Fi im Fortbewegungsmittel 50 zur Durchführung der Anmeldung und Speicherung des angemeldeten Nutzers und einen Anteil F2 im IT-Backend 60, der für die Nutzerverwaltung und Nutzerauthentifizierung zuständig ist. Fortbewegungsmittel 50 und Backend 60 kommunizieren dafür über ein Mobilfunknetz. Für beide Anteile Fi , F2 der Funktion, d.h. im Fortbewegungsmittel 50 und im Backend 60, sind getrennte Risikoanalysen bezüglich der Cybersicherheit durchzuführen. Zwischen den Funktionsanteilen gibt es zwei Signale mit zwei übermittelten Daten D, den Anmeldedaten aus dem Fortbewegungsmittel 50 und dem Ergebnis der Nutzerauthentifizierung aus dem Backend 60.
Die Problemstellung ergibt sich daraus, dass die Risikoanalysen unter Berücksichtigung unterschiedlicher Vorschriften betreffend Bewertungsmodell, Analysemethodik, Modellierungsvorschrift durchgeführt werden, d.h. es liegen unterschiedliche Analysekontexte vor. Dies verhindert, dass die Risikoanalyse der beiden Funktionsanteile in einem Zug durchgeführt wird, d.h. in einem Werkzeug oder in einer gesamthaften Risikoanalyse. Die Analyse der beiden Anteile muss aufgrund der unterschiedlichen Vorschriften bzw. Prämissen getrennt erfolgen.
Angenommen sei, dass in der jeweiligen Analyse festgestellt wird, dass a) die Nutzerdaten aus dem Fortbewegungsmittel 50 vertraulich behandelt werden müssen und b) das Ergebnis der Authentifizierung authentisch sein muss. Unter Berücksichtigung des jeweiligen Schadenszenarios, nämlich a) einer Verletzung der Privatsphäre des Nutzers und b) einer illegitimen Anmeldung im Fortbewegungsmittel 50, ergibt sich ein Risiko, das je nach Umständen einer Mitigation, d.h. einer Risikobehandlung durch Minderung, durch eine geeignete Sicherungsmaßnahmen bedarf. Diese Sicherungsmaßnahmen können aber nicht in allen Fällen einseitig definiert und umgesetzt werden. Wird das Ergebnis der Authentifizierung vom Fortbewegungsmittel 50 empfangen, so kann das Fortbewegungsmittel 50 nichts unternehmen, um die erforderliche Authentizität sicherzustellen. Diese muss durch das Backend 60 gewährleistet werden.
Üblicherweise wird daher mit Annahmen über den Kommunikationspartner gearbeitet. Eine erste Annahme besteht etwa darin, dass das Fortbewegungsmittel 50 die Vertraulichkeit der Nutzerdaten bei der Speicherung, Verarbeitung und Übertragung sicherstellt. Eine zweite Annahme besteht etwa darin, dass das Backend 60 die Authentizität des Ergebnisses der Authentifizierung bei der Verarbeitung und Übertragung sicherstellt.
Aus diesen Annahmen über den Kommunikationspartner ergeben sich funktionale Anforderungen. Eine funktionale Anforderung an das Fortbewegungsmittel 50 besteht etwa darin, dass das Fortbewegungsmittel 50 die Nutzerdaten vertraulich mittels geeigneter Verschlüsselung in einem sicheren Speicherbereich speichert und die Daten über einen Kanal überträgt, der eine vertrauliche Übertragung ermöglicht, z.B. TLS (Transport Layer Security, Transportschichtsicherheit). Eine funktionale Anforderung an das Backend 60 besteht etwa darin, dass das Backend 60 das Ergebnis der Authentifizierung über einen Kanal überträgt, der eine authentische Übertragung ermöglicht, z.B. TLS. Diese funktionalen Anforderungen müssen in der Analyse der jeweiligen Gegenstelle wiederum Berücksichtigung finden. Die Durchführung der Analysen mit wechselseitiger Abhängigkeit ist daher bei bekannten Ansätzen ein manueller und vor allem iterativer Prozess, da die Annahmen nach erfolgter (Erst-)Analyse übertragen und die funktionale Umsetzung dann wiederum in einer (Zweit-)Analyse berücksichtigt werden muss.
Fig. 6 veranschaulicht eine erfindungsgemäße Risikoanalyse des Untersuchungsgegenstands UG aus Fig. 5. Auch in diesem Fall werden aufgrund der differierenden Analysekontexte zwei Analysen durchgeführt, d.h. eine erste Risikoanalyse Ri im Kontext „Fortbewegungsmittel“ 50 und eine zweite Risikoanalyse R2 im Kontext „IT- Backend“ 60.
Für die Risikoanalyse Ri im Kontext „Fortbewegungsmittel“ 50 kann ein Bewertungsmodell BMi für den Kontext „eingebettetes System“ herangezogen werden, z.B. eine Bewertung nach Vorgaben der UNECE (United Nations Economic Commission for Europe; Wirtschaftskommission für Europa der Vereinten Nationen). Dementsprechend können eine Analysemethode AMi für den Kontext „eingebettetes System“, z.B. eine Methodik nach Vorgaben der UNECE, und eine Modellierungsvorschrift MVi für den Kontext „eingebettetes System“ verwendet werden. Auch die Modellierungsvorschrift MVi kann Teil der externen Vorgaben sein, wie dies in Fig. 6 dargestellt ist.
Für die Risikoanalyse R2 im Kontext „IT-Backend“ 60 kann ein Bewertungsmodell BM2 für den Kontext „IT-System“ herangezogen werden, z.B. eine Analyse nach Vorgaben lokaler Institutionen wie dem BSI (Bundesamt für Sicherheit in der Informationstechnik).
Dementsprechend können eine Analysemethode AM2 für den Kontext „IT-System“, z.B. eine Methodik nach BSI-Vorgaben, und eine Modellierungsvorschrift MV2 für den Kontext „IT- System“ verwendet werden. Wie auch bei der Risikoanalyse Ri kann Modellierungsvorschrift MV2 Teil der externen Vorgaben sein.
Allerdings wird für Daten D, die zwischen dem Fortbewegungsmittel 50 und dem Backend 60 ausgetauscht werden, die jeweilige Datenherkunft annotiert bzw. berücksichtigt. Zwischen den durchgeführten Analysen Ri, R2 wird dann, entweder durch Angleichung oder Zuordnung, eine einheitliche Identifizierung übertragener Daten D ermöglicht. Dies kann unabhängig vom Analysekontext und insbesondere der jeweiligen Modellierungsvorschrift MVi, MV2 geschehen. Die Modellierung des Untersuchungsgegenstands UG auf Seiten des Fortbewegungsmittels 50 und des Backends 60 wird also um lediglich einen Schritt ergänzt. Wird nun als Analyseergebnis AE in einer Schutzbedarfsfeststellung SBF ein Schutzbedarf SB für ein Datum D festgestellt, z.B. beim Fortbewegungsmittel 50 eine Authentizität des Authentifizierungsergebnisses, so kann automatisiert nachverfolgt werden, auf welchen Wegen das Datum D übertragen wird, hier also aus dem Backend 60, und in der Analyse Ri, R2 des Übertragungspartners derselbe Schutzbedarf SB übernommen werden. In der Analyse Ri, R2 des Übertragungspartners kann dann eine risikomitigierende Maßnahme M festgelegt werden, z.B. eine authentische Übertragung, die anhand des übertragenen Schutzbedarfs SB automatisiert aus einschlägigen Maßnahmenkatalogen ausgewählt werden kann oder im persönlichen Ermessen festgelegt wird.
Die Maßnahme M, hier also die authentische Übertragung des Datums, kann nun wiederum umgekehrt in der Analyse Ri, R2 übernommen werden, die den ursprünglichen Schutzbedarf SB festgestellt hat und die risikomitigierende Wirkung auch dort berücksichtigt werden. Insbesondere bedarf es keines weiteren Abgleichs der Konsistenz von Annahmen und Maßnahmen, da keine Annahmen mehr getroffen werden müssen.
Die Rückverfolgbarkeit ist auch über mehrere Analysen Ri, R2 oder Analyseverbünde hinweg gegeben, sofern eine einheitliche Identifizierung der Daten D gegeben ist. Eine Implementierung kann mittels jedes Algorithmus erfolgen, der alle schleifenfreien Kommunikationspfade in einem „Netzwerk“ aus Risikoanalysen Ri, R2 identifizieren kann. Die Propagation der Schutzbedarfe SB und der Schutzmaßnahmen M kann dann mit oder entgegen der Kommunikationsrichtung der Daten D erfolgen.
In den Beispielen in Fig. 5 und Fig. 6 wird der Schutzbedarf SB eines Datums D von derjenigen Risikoanalyse Ri, R2 festgestellt, auf deren Seite das Datum D gesendet wird. Der Schutzbedarf SB kann aber ebenso gut von derjenigen Risikoanalyse Ri, R2 festgestellt werden, auf deren Seite das Datum D empfangen wird.
Fig. 7 veranschaulicht eine erste Phase einer erfindungsgemäßen Risikoanalyse eines Untersuchungsgegenstands, der sich auf vier Kontexte erstreckt. Für die vier Kontexte werden vier zugehörige Risikoanalysen RA1-RA4 durchgeführt. In diesem Beispiel wird der Schutzbedarf jeweils von der empfangenden Seite festgestellt. Bei dem dargestellten Beispiel wird bei einer ersten Risikoanalyse RA1 eines Teils des Untersuchungsgegenstands in einem ersten Kontext die Übermittlung eines ersten Datums DA an einen Teil des Untersuchungsgegenstands in einem zweiten Kontext festgestellt. Die Risikoanalyse RA2 im zweiten Kontext ergibt zudem, dass das erste Datum DA an einen Teil des Untersuchungsgegenstands in einem dritten Kontext übermittelt wird, für den eine dritte Risikoanalyse RA3 durchgeführt wird. Bei einer vierten Risikoanalyse RA4 eines Teils des Untersuchungsgegenstands in einem vierten Kontext wird zudem die Übermittlung eines zweiten Datums DB an den Teil des Untersuchungsgegenstands im dritten Kontext festgestellt.
Fig. 8 veranschaulicht eine zweite Phase der erfindungsgemäßen Risikoanalyse. Die vierte Risikoanalyse RA4 übermittelt einen für das zweite Datum DB festgestellten Schutzbedarf SBB an die dritte Risikoanalyse RA3. Zudem wird ein für das erste Datum DA festgestellter Schutzbedarf SBA2 an die zweite Risikoanalyse RA2 übermittelt. Die zweite Risikoanalyse RA2 ermittelt auf Grundlage des übermittelten Schutzbedarfs SBA2 einen insgesamt resultierenden Schutzbedarf SBA2,I und übermittelt diesen an die erste Risikoanalyse RA1.
Fig. 9 veranschaulicht eine dritte Phase der erfindungsgemäßen Risikoanalyse. Im Ansprechen auf den festgestellten Schutzbedarf SBA2,I legt die erste Risikoanalyse RA1 eine geeignete risikomitigierende Maßnahme MAI fest und übermittelt entsprechende Informationen an die zweite Risikoanalyse RA2. Dementsprechend legt die die zweite Risikoanalyse RA2 im Ansprechen auf den festgestellten Schutzbedarf SBA2 eine geeignete risikomitigierende Maßnahme MA2 fest und übermittelt die entsprechenden Informationen an die dritte Risikoanalyse RA3. Die vierte Risikoanalyse RA4 legt im Ansprechen auf den festgestellten Schutzbedarf SBB eine geeignete risikomitigierende Maßnahme MB fest und übermittelt die entsprechenden Informationen an die dritte Risikoanalyse RA3. Somit ist keine der Risikoanalysen RA1-RA4 darauf angewiesen, Annahmen über die jeweiligen Kommunikationspartner zu treffen.
Bezugszeichenliste
10 Durchführen einer Risikoanalyse in einem ersten Kontext
11 Durchführen einer Risikoanalyse in einem zweiten Kontext
12 Feststellen eines Schutzbedarfs
13 Austauschen von Informationen zum Schutzbedarf
14 Festlegen einer risikomitigierenden Maßnahme
15 Austauschen von Informationen zur festgelegten Maßnahme
20 Vorrichtung
21 Schnittstelle
22 Analysemodul
23 Kontrollmodul
24 Speicher
25 Benutzerschnittstelle
30 Vorrichtung
31 Schnittstelle
32 Analysemodul
33 Kontrollmodul
34 Speicher
35 Benutzerschnittstelle
40, 40‘ Untersuchungsgegenstand
50 Fortbewegungsmittel
60 Backend
70 System
A Annahme
AE Analyseergebnis
AMi, AM2 Analysemethode BMi, BM2 Bewertungsmodell D, DA, DB Datum FI, F2 Funktionsanteil M, MAI, Risikomitigierende Maßnahme MA2, MB
MF Maßnahmenfestlegung
MVi, MV2 Modellierungsvorschrift RA1-RA4 Risikoanalyse SB, SBB Schutzbedarf SBA2, SBA2,1
SBF Schutzbedarfsfeststellung
UG Untersuchungsgegenstand

Claims

Patentansprüche Verfahren zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG), mit den Schritten:
- Durchführen (10) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG);
- Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG); und
- Austauschen (13) von Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) zwischen den Risikoanalysen (R1-R4), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Verfahren gemäß Anspruch 1 , wobei der festgestellte (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt wird, indem eine risikomitigierende Maßnahme (M, MAI, MA2, MB) festgelegt wird (14). Verfahren gemäß Anspruch 2, wobei Informationen zur festgelegten (14) risikomitigierenden Maßnahme (M, MAI, MA2, MB) zwischen den Risikoanalysen (R1-R4) ausgetauscht werden (15). Verfahren gemäß Anspruch 2 oder 3, wobei die risikomitigierende Maßnahme (M, MAI, MA2, MB) automatisiert oder durch einen manuellen Eingriff festgelegt wird (14). Verfahren gemäß einem der vorherigen Ansprüche, wobei eine bei der Risikoanalyse (R1-R4) in einem Kontext festgestellte Gefährdung des Schutzbedarfs (SB, SBB, SBA2, SBA2,I) bei der Risikoanalyse (R1-R4) im anderen Kontext berücksichtigt wird. Verfahren gemäß einem der vorherigen Ansprüche, wobei ein festgestellter (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) zusätzlich auch bei einer Risikoanalyse (R1-R4) für einen in einem dritten Kontext verorteten Teil des Untersuchungsgegenstands (UG) berücksichtigt wird. Verfahren gemäß einem der vorherigen Ansprüche, wobei der erste Kontext ein Fortbewegungsmittel (50), ein Mobilgerät oder ein eingebettetes System betrifft. Verfahren gemäß einem der vorherigen Ansprüche, wobei der zweite Kontext ein Backend (60) oder ein IT-System betrifft. Computerprogramm mit Instruktionen, die bei Ausführung durch einen Computer den Computer zur Ausführung der Schritte eines Verfahrens gemäß einem der Ansprüche 1 bis 8 zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG) veranlassen. System (70) zur Risikoanalyse eines verteilten Untersuchungsgegenstands (UG), mit:
- einem ersten Analysemodul (22) zum Durchführen (10) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG); und
- einem zweiten Analysemodul (32) zum Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG); wobei das erste Analysemodul (22) und das zweite Analysemodul (32) eingerichtet sind, Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) auszutauschen (13), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Vorrichtung (20) zur Verwendung in einem System gemäß Anspruch 10, mit einem ersten Analysemodul (22) zum Durchführen (10) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) eines Untersuchungsgegenstands (UG) in einem ersten Analysekontext, wobei der erste Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM1) oder eine distinkte Analysemethode (AM1) und eine distinkte Vorschrift zur Modellierung (MV1) des Untersuchungsgegenstands (UG), wobei das erste Analysemodul (22) eingerichtet ist, Informationen zu einem festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) an ein zweites Analysemodul (32) zum Durchführen (11) einer Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) des Untersuchungsgegenstands (UG) zu übermitteln (13), wobei anhand eines Übertragungsweges eines Datums (D, DA, DB), für das ein Schutzbedarf (SB, SBB, SBA2, SBA2,I) festgestellt wurde (12), automatisiert bestimmt wird, bei weicher weiteren Risikoanalyse (R1-R4) der Schutzbedarf (SB, SBB, SBA2, SBA2,I) berücksichtigt werden soll. Vorrichtung (30) zur Verwendung in einem System gemäß Anspruch 10, mit einem zweiten Analysemodul (32) zum Durchführen (11) einer teil- oder vollautomatisierten Risikoanalyse (R1-R4) für einen in einem zweiten Kontext verorteten Teil (40‘) eines Untersuchungsgegenstands (UG) in einem zweiten Analysekontext, wobei der zweite Analysekontext abgegrenzt ist durch ein distinktes Bewertungsmodell (BM2) oder eine distinkte Analysemethode (AM2) und eine distinkte Vorschrift zur Modellierung (MV2) des Untersuchungsgegenstands (UG), wobei das zweite Analysemodul (32) eingerichtet ist, einen von einem ersten Analysemodul (22) beim Durchführen (10) einer Risikoanalyse (R1-R4) für einen in einem ersten Kontext verorteten Teil (40) des Untersuchungsgegenstands (UG) festgestellten (12) Schutzbedarf (SB, SBB, SBA2, SBA2,I) bei der Risikoanalyse (R1-R4) im zweiten Kontext zu berücksichtigen.
EP23713644.5A 2022-03-29 2023-03-22 Risikoanalyse eines verteilten untersuchungsgegenstands Pending EP4500377A1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE102022203086.9A DE102022203086A1 (de) 2022-03-29 2022-03-29 Risikoanalyse eines verteilten Untersuchungsgegenstands
PCT/EP2023/057325 WO2023186655A1 (de) 2022-03-29 2023-03-22 Risikoanalyse eines verteilten untersuchungsgegenstands

Publications (1)

Publication Number Publication Date
EP4500377A1 true EP4500377A1 (de) 2025-02-05

Family

ID=85776097

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23713644.5A Pending EP4500377A1 (de) 2022-03-29 2023-03-22 Risikoanalyse eines verteilten untersuchungsgegenstands

Country Status (4)

Country Link
US (1) US20250200191A1 (de)
EP (1) EP4500377A1 (de)
DE (1) DE102022203086A1 (de)
WO (1) WO2023186655A1 (de)

Family Cites Families (221)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
AU1690597A (en) * 1996-01-11 1997-08-01 Mitre Corporation, The System for controlling access and distribution of digital property
US20060178997A1 (en) * 1996-01-11 2006-08-10 General Dynamics Advanced Information Systems, Inc. Systems and methods for authoring and protecting digital property
US7162649B1 (en) * 2000-06-30 2007-01-09 Internet Security Systems, Inc. Method and apparatus for network assessment and authentication
US7096498B2 (en) * 2002-03-08 2006-08-22 Cipher Trust, Inc. Systems and methods for message threat management
AU2003217021A1 (en) * 2002-03-28 2003-10-13 British Telecommunications Public Limited Company Method and apparatus for network security
IL149583A0 (en) * 2002-05-09 2003-07-06 Kavado Israel Ltd Method for automatic setting and updating of a security policy
US20050066195A1 (en) * 2003-08-08 2005-03-24 Jones Jack A. Factor analysis of information risk
US20070180490A1 (en) * 2004-05-20 2007-08-02 Renzi Silvio J System and method for policy management
US7490356B2 (en) * 2004-07-20 2009-02-10 Reflectent Software, Inc. End user risk management
WO2007019349A2 (en) * 2005-08-03 2007-02-15 Calyptix Security Systems and methods for dynamically learning network environments to achieve adaptive security
GB0518405D0 (en) * 2005-09-09 2005-10-19 Ibm Operational risk control apparatus and method for data processing
US8544098B2 (en) * 2005-09-22 2013-09-24 Alcatel Lucent Security vulnerability information aggregation
US8869270B2 (en) * 2008-03-26 2014-10-21 Cupp Computing As System and method for implementing content and network security inside a chip
US8392999B2 (en) * 2005-12-19 2013-03-05 White Cyber Knight Ltd. Apparatus and methods for assessing and maintaining security of a computerized system under development
US20080047017A1 (en) * 2006-06-23 2008-02-21 Martin Renaud System and method for dynamically assessing security risks attributed to a computer user's behavior
US20080047016A1 (en) * 2006-08-16 2008-02-21 Cybrinth, Llc CCLIF: A quantified methodology system to assess risk of IT architectures and cyber operations
US8234641B2 (en) * 2006-10-17 2012-07-31 Managelq, Inc. Compliance-based adaptations in managed virtual systems
US9697019B1 (en) * 2006-10-17 2017-07-04 Manageiq, Inc. Adapt a virtual machine to comply with system enforced policies and derive an optimized variant of the adapted virtual machine
US9015842B2 (en) * 2008-03-19 2015-04-21 Websense, Inc. Method and system for protection against information stealing software
US9781148B2 (en) * 2008-10-21 2017-10-03 Lookout, Inc. Methods and systems for sharing risk responses between collections of mobile communications devices
US8683546B2 (en) * 2009-01-26 2014-03-25 Microsoft Corporation Managing security configuration through machine learning, combinatorial optimization and attack graphs
US20100218256A1 (en) * 2009-02-26 2010-08-26 Network Security Systems plus, Inc. System and method of integrating and managing information system assessments
US8495744B2 (en) 2009-03-25 2013-07-23 Sap Ag Evaluation of risk of conflict for security solutions integration
WO2011063269A1 (en) * 2009-11-20 2011-05-26 Alert Enterprise, Inc. Method and apparatus for risk visualization and remediation
US10027711B2 (en) * 2009-11-20 2018-07-17 Alert Enterprise, Inc. Situational intelligence
US10019677B2 (en) * 2009-11-20 2018-07-10 Alert Enterprise, Inc. Active policy enforcement
US8495745B1 (en) * 2009-11-30 2013-07-23 Mcafee, Inc. Asset risk analysis
US8621636B2 (en) * 2009-12-17 2013-12-31 American Express Travel Related Services Company, Inc. Systems, methods, and computer program products for collecting and reporting sensor data in a communication network
US9317692B2 (en) * 2009-12-21 2016-04-19 Symantec Corporation System and method for vulnerability risk analysis
US8813232B2 (en) * 2010-03-04 2014-08-19 Mcafee Inc. Systems and methods for risk rating and pro-actively detecting malicious online ads
US9619652B2 (en) * 2010-03-31 2017-04-11 Salesforce.Com, Inc. System, method and computer program product for determining a risk score for an entity
US8375427B2 (en) * 2010-04-21 2013-02-12 International Business Machines Corporation Holistic risk-based identity establishment for eligibility determinations in context of an application
US8849734B2 (en) * 2010-06-29 2014-09-30 Mcafee Inc. System, method, and computer program product for updating an algorithm
US8677497B2 (en) * 2011-10-17 2014-03-18 Mcafee, Inc. Mobile risk assessment
US8595845B2 (en) * 2012-01-19 2013-11-26 Mcafee, Inc. Calculating quantitative asset risk
US8904538B1 (en) * 2012-03-13 2014-12-02 Symantec Corporation Systems and methods for user-directed malware remediation
US8819772B2 (en) * 2012-06-25 2014-08-26 Appthority, Inc. In-line filtering of insecure or unwanted mobile device software components or communications
US9330262B2 (en) * 2012-09-21 2016-05-03 University Of Limerick Systems and methods for runtime adaptive security to protect variable assets
US9672360B2 (en) * 2012-10-02 2017-06-06 Mordecai Barkan Secure computer architectures, systems, and applications
US11188652B2 (en) * 2012-10-02 2021-11-30 Mordecai Barkan Access management and credential protection
US20140137257A1 (en) * 2012-11-12 2014-05-15 Board Of Regents, The University Of Texas System System, Method and Apparatus for Assessing a Risk of One or More Assets Within an Operational Technology Infrastructure
US9219720B1 (en) * 2012-12-06 2015-12-22 Intuit Inc. Method and system for authenticating a user using media objects
US9954883B2 (en) * 2012-12-18 2018-04-24 Mcafee, Inc. Automated asset criticality assessment
US20140325670A1 (en) * 2013-04-25 2014-10-30 Rivendale Software Solution Private Limited System and method for providing risk score based on sensitive information inside user device
US10839082B2 (en) * 2014-01-06 2020-11-17 International Business Machines Corporation Identifying, categorizing and recording a quality of an entity/resource association
US9563771B2 (en) * 2014-01-22 2017-02-07 Object Security LTD Automated and adaptive model-driven security system and method for operating the same
US9319430B2 (en) * 2014-06-17 2016-04-19 International Business Machines Corporation Managing software deployment
US10164995B1 (en) * 2014-08-14 2018-12-25 Pivotal Software, Inc. Determining malware infection risk
EP3210364B8 (de) * 2014-10-21 2021-03-10 Proofpoint, Inc. Systeme und verfahren zur anwendungssicherheitsanalyse
US9838391B2 (en) * 2014-10-31 2017-12-05 Proofpoint, Inc. Systems and methods for privately performing application security analysis
KR101616989B1 (ko) * 2014-12-10 2016-04-29 고려대학교 산학협력단 정보 보안 통제 상태 평가 방법 및 장치
US10104097B1 (en) * 2014-12-12 2018-10-16 Symantec Corporation Systems and methods for preventing targeted malware attacks
US9372994B1 (en) * 2014-12-13 2016-06-21 Security Scorecard, Inc. Entity IP mapping
US9648036B2 (en) * 2014-12-29 2017-05-09 Palantir Technologies Inc. Systems for network risk assessment including processing of user access rights associated with a network of devices
US9294497B1 (en) * 2014-12-29 2016-03-22 Nice-Systems Ltd. Method and system for behavioral and risk prediction in networks using automatic feature generation and selection using network topolgies
EP3248360B1 (de) * 2015-01-19 2020-05-06 Inauth, Inc. Systeme und verfahren für sichere kommunikation mit sicherem weg
US20160246966A1 (en) * 2015-02-24 2016-08-25 Vertafore, Inc. Method and system of assessing risk associated with users based at least in part on online presence of the user
US10140453B1 (en) * 2015-03-16 2018-11-27 Amazon Technologies, Inc. Vulnerability management using taxonomy-based normalization
US20160344772A1 (en) * 2015-05-22 2016-11-24 Brian Quentin Monahan Modelling network to assess security properties
US20160364727A1 (en) * 2015-06-11 2016-12-15 Early Warning Services, Llc System and method for identifying compromised accounts
US10127403B2 (en) * 2015-07-30 2018-11-13 Samsung Electronics Co., Ltd. Computing system with privacy control mechanism and method of operation thereof
US10693903B2 (en) * 2015-07-30 2020-06-23 IOR Analytics, LLC. Method and apparatus for data security analysis of data flows
US10715542B1 (en) * 2015-08-14 2020-07-14 Fireeye, Inc. Mobile application risk analysis
US20210173711A1 (en) * 2015-10-28 2021-06-10 Qomplx, Inc. Integrated value chain risk-based profiling and optimization
US20220210200A1 (en) * 2015-10-28 2022-06-30 Qomplx, Inc. Ai-driven defensive cybersecurity strategy analysis and recommendation system
US9578063B1 (en) * 2015-11-20 2017-02-21 International Business Machines Corporation Application self-service for assured log management in cloud environments
US10445516B1 (en) * 2015-12-03 2019-10-15 Symantec Corporation Systems and methods for preventing vulnerable files from being opened
US10503907B2 (en) * 2015-12-14 2019-12-10 Fmr Llc Intelligent threat modeling and visualization
US9830449B1 (en) * 2015-12-16 2017-11-28 Amazon Technologies, Inc. Execution locations for request-driven code
EP3407050A4 (de) * 2016-01-19 2019-08-21 IUCF-HYU (Industry-University Cooperation Foundation Hanyang University) Netzwerkvorrichtung für fahrzeugsicherheit und verfahren zur steuerung davon
US9762599B2 (en) * 2016-01-29 2017-09-12 Varmour Networks, Inc. Multi-node affinity-based examination for computer network security remediation
US10296748B2 (en) * 2016-02-25 2019-05-21 Sas Institute Inc. Simulated attack generator for testing a cybersecurity system
US10332211B1 (en) * 2016-03-03 2019-06-25 State Farm Mutual Automobile Insurance Company Risk analysis based on electronic security levels of a vehicle
US10826940B2 (en) * 2016-03-11 2020-11-03 Netskope, Inc. Systems and methods of enforcing multi-part policies on data-deficient transactions of cloud computing services
US10108803B2 (en) * 2016-03-31 2018-10-23 International Business Machines Corporation Automatic generation of data-centric attack graphs
US20170339160A1 (en) * 2016-05-17 2017-11-23 International Business Machines Corporation Threat-aware provisioning and governance
US11100444B2 (en) * 2016-06-10 2021-08-24 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US11341447B2 (en) * 2016-06-10 2022-05-24 OneTrust, LLC Privacy management systems and methods
US20220164476A1 (en) * 2016-06-10 2022-05-26 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US10282559B2 (en) * 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11138299B2 (en) * 2016-06-10 2021-10-05 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US12052289B2 (en) * 2016-06-10 2024-07-30 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11366786B2 (en) * 2016-06-10 2022-06-21 OneTrust, LLC Data processing systems for processing data subject access requests
US11475136B2 (en) * 2016-06-10 2022-10-18 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US11023842B2 (en) * 2016-06-10 2021-06-01 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US20220164475A1 (en) * 2016-06-10 2022-05-26 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11294939B2 (en) * 2016-06-10 2022-04-05 OneTrust, LLC Data processing systems and methods for automatically detecting and documenting privacy-related aspects of computer software
US10467432B2 (en) * 2016-06-10 2019-11-05 OneTrust, LLC Data processing systems for use in automatically generating, populating, and submitting data subject access requests
US11038925B2 (en) * 2016-06-10 2021-06-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10796260B2 (en) * 2016-06-10 2020-10-06 OneTrust, LLC Privacy management systems and methods
US10685140B2 (en) * 2016-06-10 2020-06-16 OneTrust, LLC Consent receipt management systems and related methods
US11416798B2 (en) * 2016-06-10 2022-08-16 OneTrust, LLC Data processing systems and methods for providing training in a vendor procurement process
US20220156657A1 (en) * 2016-06-10 2022-05-19 OneTrust, LLC Privacy management systems and methods
US11227247B2 (en) * 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems and methods for bundled privacy policies
US11238390B2 (en) * 2016-06-10 2022-02-01 OneTrust, LLC Privacy management systems and methods
US20200311233A1 (en) * 2016-06-10 2020-10-01 OneTrust, LLC Data processing and scanning systems for assessing vendor risk
US11410106B2 (en) * 2016-06-10 2022-08-09 OneTrust, LLC Privacy management systems and methods
US10885485B2 (en) * 2016-06-10 2021-01-05 OneTrust, LLC Privacy management systems and methods
US10798133B2 (en) * 2016-06-10 2020-10-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11438386B2 (en) * 2016-06-10 2022-09-06 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11301796B2 (en) * 2016-06-10 2022-04-12 OneTrust, LLC Data processing systems and methods for customizing privacy training
US10848523B2 (en) * 2016-06-10 2020-11-24 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11336697B2 (en) * 2016-06-10 2022-05-17 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10509920B2 (en) * 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for processing data subject access requests
US11188862B2 (en) * 2016-06-10 2021-11-30 OneTrust, LLC Privacy management systems and methods
US10873606B2 (en) * 2016-06-10 2020-12-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10909488B2 (en) * 2016-06-10 2021-02-02 OneTrust, LLC Data processing systems for assessing readiness for responding to privacy-related incidents
US10454973B2 (en) * 2016-06-10 2019-10-22 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US11277448B2 (en) * 2016-06-10 2022-03-15 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US10896394B2 (en) * 2016-06-10 2021-01-19 OneTrust, LLC Privacy management systems and methods
US10783256B2 (en) * 2016-06-10 2020-09-22 OneTrust, LLC Data processing systems for data transfer risk identification and related methods
US10565161B2 (en) * 2016-06-10 2020-02-18 OneTrust, LLC Data processing systems for processing data subject access requests
US10438017B2 (en) * 2016-06-10 2019-10-08 OneTrust, LLC Data processing systems for processing data subject access requests
US10282692B2 (en) * 2016-06-10 2019-05-07 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11481710B2 (en) * 2016-06-10 2022-10-25 OneTrust, LLC Privacy management systems and methods
US20210142239A1 (en) * 2016-06-10 2021-05-13 OneTrust, LLC Data processing systems and methods for estimating vendor procurement timing
US11087260B2 (en) * 2016-06-10 2021-08-10 OneTrust, LLC Data processing systems and methods for customizing privacy training
US10510031B2 (en) * 2016-06-10 2019-12-17 OneTrust, LLC Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
US11228620B2 (en) * 2016-06-10 2022-01-18 OneTrust, LLC Data processing systems for data-transfer risk identification, cross-border visualization generation, and related methods
US9973525B1 (en) * 2016-06-14 2018-05-15 Symantec Corporation Systems and methods for determining the risk of information leaks from cloud-based services
US11238176B1 (en) * 2016-06-17 2022-02-01 BigID Inc. System and methods for privacy management
US10528741B1 (en) * 2016-07-13 2020-01-07 VCE IP Holding Company LLC Computer implemented systems and methods for assessing operational risks and mitigating operational risks associated with using a third party software component in a software application
US10073974B2 (en) * 2016-07-21 2018-09-11 International Business Machines Corporation Generating containers for applications utilizing reduced sets of libraries based on risk analysis
CN107645533A (zh) * 2016-07-22 2018-01-30 阿里巴巴集团控股有限公司 数据处理方法、数据发送方法、风险识别方法及设备
US10733301B2 (en) * 2016-08-24 2020-08-04 Microsoft Technology Licensing, Llc Computing device protection based on device attributes and device risk factor
US20180068241A1 (en) * 2016-09-07 2018-03-08 Wipro Limited Methods and systems for integrated risk management in enterprise environments
US10754958B1 (en) * 2016-09-19 2020-08-25 Nopsec Inc. Vulnerability risk mitigation platform apparatuses, methods and systems
US10855714B2 (en) * 2016-10-31 2020-12-01 KnowBe4, Inc. Systems and methods for an artificial intelligence driven agent
US20180121657A1 (en) * 2016-11-01 2018-05-03 International Business Machines Corporation Security risk evaluation
US10380348B2 (en) * 2016-11-21 2019-08-13 ZingBox, Inc. IoT device risk assessment
US10754959B1 (en) * 2017-01-20 2020-08-25 University Of South Florida Non-linear stochastic models for predicting exploitability
US10650150B1 (en) * 2017-02-28 2020-05-12 University Of South Florida Vulnerability life cycle exploitation timing modeling
US10862916B2 (en) * 2017-04-03 2020-12-08 Netskope, Inc. Simulation and visualization of malware spread in a cloud-based collaboration environment
US10862919B2 (en) * 2017-04-21 2020-12-08 The Mitre Corporation Methods and systems for evaluating effects of cyber-attacks on cyber-physical systems
US10445490B2 (en) * 2017-06-12 2019-10-15 Cyberark Software Ltd. Remote desktop access to a target machine
US10142794B1 (en) * 2017-07-10 2018-11-27 International Business Machines Corporation Real-time, location-aware mobile device data breach prevention
US10803177B2 (en) * 2017-07-19 2020-10-13 International Business Machines Corporation Compliance-aware runtime generation based on application patterns and risk assessment
US11070568B2 (en) * 2017-09-27 2021-07-20 Palo Alto Networks, Inc. IoT device management visualization
US10643002B1 (en) * 2017-09-28 2020-05-05 Amazon Technologies, Inc. Provision and execution of customized security assessments of resources in a virtual computing environment
US10706155B1 (en) * 2017-09-28 2020-07-07 Amazon Technologies, Inc. Provision and execution of customized security assessments of resources in a computing environment
US10540496B2 (en) * 2017-09-29 2020-01-21 International Business Machines Corporation Dynamic re-composition of patch groups using stream clustering
US20190102841A1 (en) * 2017-10-04 2019-04-04 Servicenow, Inc. Mapping engine configurations with task managed workflows and grid user interfaces
WO2019089654A1 (en) * 2017-10-30 2019-05-09 Pricewaterhousecoopers Llp Implementation of continuous real-time validation of distributed data storage systems
US10715549B2 (en) * 2017-12-01 2020-07-14 KnowBe4, Inc. Systems and methods for AIDA based role models
US10348762B2 (en) * 2017-12-01 2019-07-09 KnowBe4, Inc. Systems and methods for serving module
US10812527B2 (en) * 2017-12-01 2020-10-20 KnowBe4, Inc. Systems and methods for aida based second chance
US10839083B2 (en) * 2017-12-01 2020-11-17 KnowBe4, Inc. Systems and methods for AIDA campaign controller intelligent records
US10009375B1 (en) * 2017-12-01 2018-06-26 KnowBe4, Inc. Systems and methods for artificial model building techniques
US10257225B1 (en) * 2017-12-01 2019-04-09 KnowBe4, Inc. Systems and methods for artificial intelligence driven agent campaign controller
US10673895B2 (en) * 2017-12-01 2020-06-02 KnowBe4, Inc. Systems and methods for AIDA based grouping
US10853499B2 (en) * 2017-12-06 2020-12-01 Cisco Technology, Inc. Key threat prediction
US12182260B2 (en) * 2017-12-18 2024-12-31 Nuvoton Technology Corporation System and method for detecting fault injection attacks
US10990682B2 (en) * 2017-12-18 2021-04-27 Nuvoton Technology Corporation System and method for coping with fault injection attacks
US20190197461A1 (en) * 2017-12-27 2019-06-27 Pearson Education, Inc. On-demand utilization of proctoring resources
US10733668B2 (en) * 2018-01-30 2020-08-04 PointPredictive Inc. Multi-layer machine learning classifier
US10958683B2 (en) * 2018-04-26 2021-03-23 Wipro Limited Method and device for classifying uniform resource locators based on content in corresponding websites
US10831899B2 (en) * 2018-05-14 2020-11-10 Sap Se Security-relevant code detection system
US10817604B1 (en) * 2018-06-19 2020-10-27 Architecture Technology Corporation Systems and methods for processing source codes to detect non-malicious faults
US10885162B2 (en) * 2018-06-29 2021-01-05 Rsa Security Llc Automated determination of device identifiers for risk-based access control in a computer network
WO2020056314A1 (en) * 2018-09-13 2020-03-19 Arizona Board Of Regents On Behalf Of Arizona State University Systems and methods for a simulation program of a percolation model for the loss distribution caused by a cyber attack
US10540493B1 (en) * 2018-09-19 2020-01-21 KnowBe4, Inc. System and methods for minimizing organization risk from users associated with a password breach
US10984102B2 (en) * 2018-10-01 2021-04-20 Blackberry Limited Determining security risks in binary software code
US10936718B2 (en) * 2018-10-01 2021-03-02 Blackberry Limited Detecting security risks in binary software code
US11200323B2 (en) * 2018-10-17 2021-12-14 BitSight Technologies, Inc. Systems and methods for forecasting cybersecurity ratings based on event-rate scenarios
US11038911B2 (en) * 2018-10-19 2021-06-15 Blackberry Limited Method and system for determining risk in automotive ECU components
EP3874390A4 (de) * 2018-11-02 2022-07-06 Arizona Board of Regents on behalf of the University of Arizona Laufzeitadaptive risikobeurteilung und automatisierte minderung
US11995593B2 (en) * 2018-11-28 2024-05-28 Merck Sharp & Dohme Llc Adaptive enterprise risk evaluation
US12299619B2 (en) * 2018-11-28 2025-05-13 Merck Sharp & Dohme Llc Adaptive enterprise risk evaluation
US11281806B2 (en) * 2018-12-03 2022-03-22 Accenture Global Solutions Limited Generating attack graphs in agile security platforms
US11283825B2 (en) * 2018-12-03 2022-03-22 Accenture Global Solutions Limited Leveraging attack graphs of agile security platform
US11184385B2 (en) * 2018-12-03 2021-11-23 Accenture Global Solutions Limited Generating attack graphs in agile security platforms
US11277432B2 (en) * 2018-12-03 2022-03-15 Accenture Global Solutions Limited Generating attack graphs in agile security platforms
US11574179B2 (en) * 2019-01-07 2023-02-07 International Business Machines Corporation Deep symbolic validation of information extraction systems
US11301569B2 (en) * 2019-03-07 2022-04-12 Lookout, Inc. Quarantine of software based on analysis of updated device data
US11409887B2 (en) * 2019-05-08 2022-08-09 Battelle Memorial Institute Cybersecurity vulnerability mitigation framework
US10607015B1 (en) * 2019-05-16 2020-03-31 Cyberark Software Ltd. Security risk assessment and control for code
US11704431B2 (en) * 2019-05-29 2023-07-18 Microsoft Technology Licensing, Llc Data security classification sampling and labeling
US11711374B2 (en) * 2019-05-31 2023-07-25 Varmour Networks, Inc. Systems and methods for understanding identity and organizational access to applications within an enterprise environment
US11863580B2 (en) * 2019-05-31 2024-01-02 Varmour Networks, Inc. Modeling application dependencies to identify operational risk
US11290494B2 (en) * 2019-05-31 2022-03-29 Varmour Networks, Inc. Reliability prediction for cloud security policies
US11403405B1 (en) * 2019-06-27 2022-08-02 Architecture Technology Corporation Portable vulnerability identification tool for embedded non-IP devices
EP3764263B1 (de) * 2019-07-12 2024-09-11 Accenture Global Solutions Limited Bewertung der wirksamkeit von sicherheitskontrollen in unternehmensnetzwerken unter verwendung von graphenwerten
US10726136B1 (en) * 2019-07-17 2020-07-28 BitSight Technologies, Inc. Systems and methods for generating security improvement plans for entities
US11481499B2 (en) * 2019-08-05 2022-10-25 Visa International Service Association Blockchain security system
US10628576B1 (en) * 2019-08-20 2020-04-21 Capital One Services, Llc Computer-based platforms or systems, computing devices or components and/or computing methods for technological applications involving provision of a portal for managing user accounts having a login portal configured to defend against credential replay attacks
US10673886B1 (en) * 2019-09-26 2020-06-02 Packetsled, Inc. Assigning and representing security risks on a computer network
US20210110319A1 (en) * 2019-10-09 2021-04-15 Battelle Memorial Institute Framework to quantify cybersecurity risks and consequences for critical infrastructure
US11677768B2 (en) * 2019-10-22 2023-06-13 Honeywell International Inc. Apparatuses, methods, and computer program products for automatic improved network architecture generation
US11444974B1 (en) * 2019-10-23 2022-09-13 Architecture Technology Corporation Systems and methods for cyber-physical threat modeling
CA3100378A1 (en) * 2019-11-20 2021-05-20 Royal Bank Of Canada System and method for unauthorized activity detection
US11615191B2 (en) * 2020-02-26 2023-03-28 Butchko Inc. Flexible risk assessment and management system for integrated risk and value analysis
EP3872665B1 (de) * 2020-02-28 2025-11-26 Accenture Global Solutions Limited Digitaler cyber-zwilling-simulator für sicherheitssteuerungsanforderungen
US11947956B2 (en) * 2020-03-06 2024-04-02 International Business Machines Corporation Software intelligence as-a-service
US11777992B1 (en) * 2020-04-08 2023-10-03 Wells Fargo Bank, N.A. Security model utilizing multi-channel data
US11720686B1 (en) * 2020-04-08 2023-08-08 Wells Fargo Bank, N.A. Security model utilizing multi-channel data with risk-entity facing cybersecurity alert engine and portal
US12118088B2 (en) * 2020-04-22 2024-10-15 Arm Limited Moderator system for a security analytics framework
US11411918B2 (en) * 2020-05-26 2022-08-09 Microsoft Technology Licensing, Llc User interface for web server risk awareness
US11023585B1 (en) * 2020-05-27 2021-06-01 BitSight Technologies, Inc. Systems and methods for managing cybersecurity alerts
US12169528B2 (en) * 2020-06-07 2024-12-17 Info Trust, LLC Systems and methods for web content inspection
US11463483B2 (en) * 2020-07-06 2022-10-04 Cisco Technology, Inc. Systems and methods for determining effectiveness of network segmentation policies
US11411976B2 (en) * 2020-07-09 2022-08-09 Accenture Global Solutions Limited Resource-efficient generation of analytical attack graphs
US20220019676A1 (en) * 2020-07-15 2022-01-20 VULTARA, Inc. Threat analysis and risk assessment for cyber-physical systems based on physical architecture and asset-centric threat modeling
US11546368B2 (en) * 2020-09-28 2023-01-03 T-Mobile Usa, Inc. Network security system including a multi-dimensional domain name system to protect against cybersecurity threats
US11516222B1 (en) * 2020-09-28 2022-11-29 Amazon Technologies, Inc. Automatically prioritizing computing resource configurations for remediation
US11973790B2 (en) * 2020-11-10 2024-04-30 Accenture Global Solutions Limited Cyber digital twin simulator for automotive security assessment based on attack graphs
US11954208B1 (en) * 2020-11-24 2024-04-09 Bae Systems Information And Electronic Systems Integration Inc. System security evaluation model
US11687648B2 (en) * 2020-12-10 2023-06-27 Abnormal Security Corporation Deriving and surfacing insights regarding security threats
US11122073B1 (en) * 2020-12-11 2021-09-14 BitSight Technologies, Inc. Systems and methods for cybersecurity risk mitigation and management
US12086254B2 (en) * 2020-12-22 2024-09-10 International Business Machines Corporation Adjusting role-based access control of a user based on behavior data of the user
US12050693B2 (en) * 2021-01-29 2024-07-30 Varmour Networks, Inc. System and method for attributing user behavior from multiple technical telemetry sources
WO2022195848A1 (ja) * 2021-03-19 2022-09-22 日本電気株式会社 分析条件生成装置、分析システム、分析条件生成プログラム、分析プログラム、分析条件生成方法、及び分析方法
US11790081B2 (en) * 2021-04-14 2023-10-17 General Electric Company Systems and methods for controlling an industrial asset in the presence of a cyber-attack
US11775655B2 (en) * 2021-05-11 2023-10-03 International Business Machines Corporation Risk assessment of a container build
US12112155B2 (en) * 2021-05-19 2024-10-08 Kyndryl, Inc. Software application container hosting
US11681811B1 (en) * 2021-06-25 2023-06-20 Northrop Grumman Systems Corporation Cybersecurity for configuration and software updates of vehicle hardware and software based on fleet level information
US11409866B1 (en) * 2021-06-25 2022-08-09 Northrop Grumman Systems Corporation Adaptive cybersecurity for vehicles
US11895150B2 (en) * 2021-07-28 2024-02-06 Accenture Global Solutions Limited Discovering cyber-attack process model based on analytical attack graphs
US12010145B2 (en) * 2021-07-29 2024-06-11 International Business Machines Corporation Certification of computer pipeline results
US12135788B1 (en) * 2021-07-30 2024-11-05 Splunk Inc. Generating information technology incident risk score narratives
US12608223B2 (en) * 2021-11-12 2026-04-21 Dell Products, L.P. Systems and methods for migrating users and modifying workspace definitions of persona groups
US12216761B2 (en) * 2022-03-08 2025-02-04 Denso Corporation Dynamic adaptation of memory elements to prevent malicious attacks

Also Published As

Publication number Publication date
DE102022203086A1 (de) 2023-10-05
US20250200191A1 (en) 2025-06-19
WO2023186655A1 (de) 2023-10-05

Similar Documents

Publication Publication Date Title
DE60104876T2 (de) Prüfung der Konfiguration einer Firewall
DE112010003464B4 (de) Modifikation von Zugangskontrolllisten
EP2417550B1 (de) Verfahren zur durchführung einer applikation mit hilfe eines tragbaren datenträgers
DE112017007510T5 (de) Blockchain für offene wissenschaftliche forschung
DE102013212525A1 (de) Datenspeichervorrichtung zum geschützten Datenaustausch zwischen verschiedenen Sicherheitszonen
DE19924628A1 (de) Einrichtung und Verfahren zur biometrischen Authentisierung
DE112021004613T5 (de) Redigierbare blockchain
EP3023896B1 (de) Verfahren zum Übertragen von medizinischen Datensätzen
EP3743844B1 (de) Blockchain-basiertes identitätssystem
DE112021005552B4 (de) Mehrfaktorauthentifizierung von einheiten des internets der dinge
EP3695337B1 (de) Verfahren und bestätigungsvorrichtung zur integritätsbestätigung eines systems
DE102021130811A1 (de) Blockchain-selektive world-state-datenbank
EP3062255A1 (de) Lizensierung von Softwareprodukten
DE102011010627A1 (de) Verfahren zur Programmierung eines Mobilendgeräte-Chips
WO2023186655A1 (de) Risikoanalyse eines verteilten untersuchungsgegenstands
DE112021000709B4 (de) Schlüsselattributüberprüfung
EP2639729A2 (de) Automatisches Zugriffsteuersystem zum Steuern des Zugriffs auf ein physikalisches Objekt oder des Zugangs zu einem physikalischen Objekt und Verfahren
DE102017105396A1 (de) System zum elektronischen Signieren eines Dokuments
DE102019202381A1 (de) Verfahren zum Transfer von Daten
WO2020043588A1 (de) Einrichtung und verfahren zum ermitteln einer konsensversion eines transaktionsbuchs und einrichtung und verfahren zum überwachen eines verteilten datenbanksystems
DE102017000167A1 (de) Anonymisierung einer Blockkette
DE102019112589A1 (de) Mehr-Kern-Prozessorsystem
DE102008022839A1 (de) Verfahren und Vorrichtung zur Korrektur von digital übertragenen Informationen
DE102017218547A1 (de) Serveranwendung und Verfahren zur Plausibilisierung von Datenschutzangaben
DE102015210275A1 (de) Vorrichtung und Verfahren zum Bereitstellen eines Teils einer Zertifikatsperrliste

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20241029

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)