EP1768043A2

Information system service-level security risk analysis

Abstract

Information system service-level security risk analysis systems, methods, and Graphical User Interfaces are disclosed. Assets of an information system that have relationships with a service provided by the information system are identified, and at least one security risk to the service is determined by analyzing security vulnerabilities associated with the identified assets. A consolidated representation of the service is provided, and includes an indication of the determined security risk(s) and an indication of a relationship between the service and at least one of the identified assets. The security risk indication may include indications of multiple security parameters. Security risks may be represented differently depending on whether they arise from a security vulnerability of an asset that has a relationship with the service or a security vulnerability of an asset that has a relationship with the service only through a relationship with an asset that has a relationship with the service.

EP1768043A2, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Projected expiry passed 21 September 2026, 0 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

26 claims: 11 independent, 15 dependent

  1. 1
    An apparatus comprising:a risk analyzer configured to identify one or more assets of an information system that have respective relationships with a service provided by the information system, and to determine one or more security risks to the service by analyzing security vulnerabilities associated with the identified assets;and an interface operatively coupled to the risk analyzer and configured to provide a consolidated representation of the service, the consolidated representation comprising an indication of the one or more determined security risks and an indication of at least one of the respective relationships between the service and the one or more identified assets.
  2. 5
    The apparatus of any one of claims 1 to 4, wherein the risk analyzer is configured to determine the one or more security risks to the service by aggregating security risks to multiple contributing assets of the one or more identified assets.
  3. 7
    The apparatus of any one of claims 1 to 4, wherein the risk analyzer is configured to determine an aggregated asset security risk to an asset of the one or more assets by aggregating security risks arising from multiple security vulnerabilities associated with the asset, and wherein aggregating comprises performing one of:determining the aggregated asset security risk based on a maximum of the security risks arising from the multiple security vulnerabilities;determining the aggregated asset security risk based on a minimum of the security risks arising from the multiple security vulnerabilities;and determining the aggregated asset security risk based on a combination of maximum and minimum security risks arising from the multiple security vulnerabilities.
  4. 8
    The apparatus of any one of claims 1 to 4, wherein the indication of the one or more determined security risks comprises an indication of at least one security parameter.
  5. 9
    The apparatus of any one of claims 1 to 4, wherein the consolidated representation of the service further comprises respective icons representing the service and at least one of the one or more identified assets, the indication of the at least one of the respective relationships between the service and the one or more identified assets comprising respective links between the respective icons representing the service and the at least one of the one or more identified assets.
  6. 12
    A method comprising:identifying one or more assets of an information system that have respective relationships with a service provided by the information system;analyzing security vulnerabilities associated with the identified assets to determine one or more security risks to the service;and providing, in a consolidated representation of the service, an indication of the one or more determined security risks and an indication of at least one of the respective relationships between the service and the one or more identified assets.
  7. 18
    A machine-readable medium storing instructions which when executed perform the method of any one of claims 12 to 17.
  8. 19
    A Graphical User Interface (GUI) comprising a consolidated representation of a service provided by an information system, the consolidated representation comprising:an indication of one or more security risks to the service;and an indication of at least one of one or more respective relationships between the service and one or more assets of the information system that contribute to the one or more security risks to the service.
  9. 22
    The GUI of any one of claims 19 to 21, wherein the consolidated representation of the service further comprises:respective icons representing the service and at least one of the one or more identified assets, the indication of the at least one of the respective relationships between the service and the one or more identified assets comprising respective links between the respective icons representing the service and the at least one of the one or more identified assets.
  10. 24
    The GUI of any one of claims 19 to 23, wherein the one or more security risks comprise one or more aggregated security risks determined by aggregating security risks to multiple contributing assets, and wherein the indication of the one or more security risks comprises a functional graphical element representing an aggregated security risk of the one or more aggregated security risks, the functional graphical element providing access to a record of at least one of the multiple contributing assets for the aggregated security risk.
  11. 25
    An icon for display in a Graphical User Interface (GUI) comprising:a representation of an asset of an information system;and respective indications of a plurality of security parameters for a security risk to the asset.