Invention Grant
US09537881B2 Security risk mapping of potential targets 有权
潜在目标的安全风险映射

Security risk mapping of potential targets
Abstract:
A method for security risk mapping of attack vectors of target assets of an organization at risk of being attacked, wherein each of the attack vectors is defined by target dimensions, each target dimension characterized by a combination of a technology layer and an attack method, the method comprising using at least one hardware processor for: receiving an identification of the target assets at risk of being attacked and of the technology layers of the organization, wherein each of the target assets may instantiate in multiple ones of the technology layers; constructing multiple attack vectors for each of at least a portion of said target assets, by determining for each attack vector three target dimensions, each of a category of: method of achieving a malicious objective, method of attack enablement and method of initial penetration; and estimating the security risk of each of said multiple attack vectors, wherein the estimating of the security risk of an attack vector of said multiple attack vectors is based on probabilities of success of the combinations of a technology layer and an attack method characterizing each of the target dimensions of the attack vector.
Public/Granted literature
Information query
Patent Agency Ranking
0/0