The Boeing Company
SYSTEMS AND METHODS FOR PERFORMING CYBERSECURITY RISK ASSESSMENTS

Last updated:

Abstract:

A system for assessing potential cybersecurity threats to a subject system is provided. The system includes a computer system including at least one processor in communication with at least one memory device. The at least one processor is programmed to: receive a subject system to analyze, determine a potential hazard event associated with the subject system, generate an attack graph associated with the potential hazard event, wherein the attack graph includes a plurality of actions, determine an exploitability score for each of the plurality of actions, determine an uncertainty level for each of the plurality of actions based on the corresponding exploitability score, aggregate the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system, and generate a response to the one or more vulnerabilities of the subject system.

Status:
Application
Type:

Utility

Filling date:

8 Oct 2019

Issue date:

8 Apr 2021