Patents Assigned to NormShield, Inc.
  • Publication number: 20240273214
    Abstract: A method of cyber risk assessment includes uploading a user cybersecurity standard comprising a user compliance item represented by text and converting the text to a numeric array to generate an embedded user compliance item. A standard compliance item represented by text is retrieved from a standard database. The text to a numeric array is converted to generate an embedded standard compliance item. The embedded user compliance item and the embedded standard compliance item are correlated to generate a compliance item map. A digital footprint of an entity based on an associated domain name is discovered using non-intrusive information gathering. An entity technical finding is generated based on the discovered digital footprint of the entity and a control item. An entity compliance level estimate is computed. A computer process of the entity is then adjusted based on the computed entity compliance level estimate.
    Type: Application
    Filed: February 11, 2023
    Publication date: August 15, 2024
    Applicant: NormShield, Inc.
    Inventors: Candan Bolukbas, Muzeyyen Gokcen Arslan Tapkan, Gulsum Budakoglu, Ferhat Dikbiyik, Robert Maley
  • Patent number: 11979427
    Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.
    Type: Grant
    Filed: October 15, 2022
    Date of Patent: May 7, 2024
    Assignee: NormShield, Inc.
    Inventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
  • Publication number: 20240126892
    Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.
    Type: Application
    Filed: December 21, 2023
    Publication date: April 18, 2024
    Applicant: NormShield, Inc.
    Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
  • Patent number: 11886598
    Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.
    Type: Grant
    Filed: February 11, 2021
    Date of Patent: January 30, 2024
    Assignee: NormShield, Inc.
    Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
  • Publication number: 20230081144
    Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.
    Type: Application
    Filed: October 15, 2022
    Publication date: March 16, 2023
    Applicant: NormShield, Inc.
    Inventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
  • Patent number: 11509682
    Abstract: A method of cyber-risk assessment includes populating a database with ransomware attack information non-intrusively gathered from a plurality of data sources. A request for a ransomware susceptibility assessment of an entity associated with a domain name is received. A digital footprint of an entity is discovered in response to the associated domain name using non-intrusive information gathering. Commercial information associated with the entity is collected in response to the domain name. The database is scanned in response to the discovered digital footprint and at least one ransomware factor associated with the entity is generated in response to the scan. An impact parameter and a ransomware factor coefficient is computed based on the collected commercial information. Then an entity susceptibility index is computed based on the impact parameter, the ransomware factor coefficient, and the at least one ransomware factor.
    Type: Grant
    Filed: September 15, 2021
    Date of Patent: November 22, 2022
    Assignee: NormShield, Inc
    Inventors: Paul Paget, Ferhat Dikbiyik, Candan Bolukbas
  • Publication number: 20210334387
    Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.
    Type: Application
    Filed: February 11, 2021
    Publication date: October 28, 2021
    Applicant: NormShield, Inc.
    Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik
  • Patent number: 10949543
    Abstract: A method of cyber risk assessment includes receiving request for a quantitative cyber risk assessment from an entity associated with a domain name. Entity information is non-intrusively gathered from a plurality of data sources about the entity based on the domain name. A digital footprint of the entity is discovered based the associated domain name using non-intrusive information gathering. At least one characteristic of the entity is classified to determine an entity classification and at least one entity risk quantification parameter. At least one control item is fetched from the knowledge database. An entity technical finding is determined based on the fetched at least one control item and based on the discovered digital footprint. At least one industry-related quantification parameter is fetched based on the entity technical finding and based on the entity classification. A quantitative risk value is calculated from a determination of loss frequency and loss magnitude.
    Type: Grant
    Filed: April 22, 2020
    Date of Patent: March 16, 2021
    Assignee: NormShield, Inc.
    Inventors: Candan Bolukbas, Robert Maley, Ferhat Dikbiyik