首页> 外国专利> System and method for automatic calculation of cyber-risk in business-critical applications

System and method for automatic calculation of cyber-risk in business-critical applications

机译:在关键业务应用程序中自动计算网络风险的系统和方法

摘要

A system for calculating cyber-risk in a software application includes a cyber-risk calculator. The cyber-risk calculator receives a security assessment result sample having a list of security modules, each security module listing including a respective result of a security assessment of the application identifying a vulnerability and/or misconfiguration capable of being exploited and/or abused. When run in a risk calculation mode, the cyber-risk calculator determines a world partition of the application in the security assessment result sample belongs to, references a set of parameters from a parametrization database according to the world partition corresponding to the application, determines a cyber-risk exposure level for the application based upon the security assessment result sample and the set of parameters, and reports results of the cyber-risk calculation.
机译:用于计算软件应用程序中的网络风险的系统包括网络风险计算器。网络风险计算器接收具有安全模块列表的安全评估结果样本,每个安全模块列表包括应用程序安全评估的相应结果,这些结果标识了能够被利用和/或滥用的漏洞和/或错误配置。当以风险计算模式运行时,网络风险计算器确定安全评估结果样本所属的应用程序的世界分区,根据与该应用程序对应的世界分区从参数化数据库中引用一组参数,确定一个基于安全评估结果样本和参数集的应用程序网络风险暴露级别,并报告网络风险计算结果。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号