Patents Assigned to NormShield, Inc.
-
Publication number: 20240273214Abstract: A method of cyber risk assessment includes uploading a user cybersecurity standard comprising a user compliance item represented by text and converting the text to a numeric array to generate an embedded user compliance item. A standard compliance item represented by text is retrieved from a standard database. The text to a numeric array is converted to generate an embedded standard compliance item. The embedded user compliance item and the embedded standard compliance item are correlated to generate a compliance item map. A digital footprint of an entity based on an associated domain name is discovered using non-intrusive information gathering. An entity technical finding is generated based on the discovered digital footprint of the entity and a control item. An entity compliance level estimate is computed. A computer process of the entity is then adjusted based on the computed entity compliance level estimate.Type: ApplicationFiled: February 11, 2023Publication date: August 15, 2024Applicant: NormShield, Inc.Inventors: Candan Bolukbas, Muzeyyen Gokcen Arslan Tapkan, Gulsum Budakoglu, Ferhat Dikbiyik, Robert Maley
-
Patent number: 11979427Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.Type: GrantFiled: October 15, 2022Date of Patent: May 7, 2024Assignee: NormShield, Inc.Inventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
-
Publication number: 20240126892Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.Type: ApplicationFiled: December 21, 2023Publication date: April 18, 2024Applicant: NormShield, Inc.Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
-
Patent number: 11886598Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.Type: GrantFiled: February 11, 2021Date of Patent: January 30, 2024Assignee: NormShield, Inc.Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
-
Publication number: 20230081144Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.Type: ApplicationFiled: October 15, 2022Publication date: March 16, 2023Applicant: NormShield, Inc.Inventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
-
Patent number: 11509682Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.Type: GrantFiled: September 15, 2021Date of Patent: November 22, 2022Assignee: NormShield, IncInventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
-
Publication number: 20210334387Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.Type: ApplicationFiled: February 11, 2021Publication date: October 28, 2021Applicant: NormShield, Inc.Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
-
Patent number: 10949543Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.Type: GrantFiled: April 22, 2020Date of Patent: March 16, 2021Assignee: NormShield, Inc.Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik