Adaptive Risk Analysis with Confidence Scoring for Incomplete Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in determining and prioritizing threats based on incomplete configuration data, as they struggle to provide effective visualization and risk management when data from network devices, such as firewalls and host application servers, is unavailable or incomplete.

Innovation Solution

The introduction of a 'confidence' or 'vulnerability certainty' factor, which is used to prioritize threats by considering the amount of information known about host servers, including their presence, network addresses, and software versions, allowing for adaptive risk assessment and remediation prioritization even with incomplete data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If complete configuration data is required for accurate threat determination, then measurement precision is improved, but productivity deteriorates due to system inability to operate with incomplete data

Engineering Contradiction:
Improvethreat determination accuracyVSAvoidsystem operational capability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs threat determination with partial configuration data rather than requiring complete data. By calculating confidence scores based on available information and proceeding with risk assessment even when data is incomplete, the system achieves partial action that maintains productivity while accepting reduced precision, or alternatively achieves high precision by gathering additional data when confidence is below thresholds

Inventive Principle:
Principle #16Partial or excessive action

2Adaptability or versatility

If confidence scoring is implemented to handle incomplete data, then adaptability is improved, but device complexity increases due to additional calculation mechanisms

Engineering Contradiction:
Improveability to operate with incomplete dataVSAvoidrisk calculation system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The risk calculation system is segmented into distinct components: data collection modules that gather available configuration information, confidence scoring modules that evaluate data completeness for each host, and risk determination modules that combine confidence scores with threat assessments. This segmentation allows the system to handle incomplete data adaptively while keeping each component's complexity manageable and independent

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive data collection is performed to ensure accurate risk assessment, then measurement precision is improved, but loss of time increases due to extended data gathering requirements

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata collection duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system collects only the minimum necessary configuration data required to achieve a satisfactory confidence score for risk assessment, rather than attempting to gather all possible data. When confidence thresholds are met with partial data collection, the system proceeds with risk determination, avoiding unnecessary time loss while maintaining sufficient assessment accuracy

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If the system waits for complete configuration data before providing risk information, then measurement precision is improved, but loss of time increases due to delayed information delivery

Engineering Contradiction:
Improvethreat information accuracyVSAvoidinformation delivery delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary risk assessment using available configuration data as soon as minimum requirements are met, rather than waiting for complete data collection. Confidence scores are calculated and used to provide preliminary threat information immediately, allowing organizations to take preliminary security actions while data collection continues in the background

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where confidence scores are continuously updated as additional configuration data becomes available. When confidence scores exceed predefined thresholds, the system automatically provides risk information. This feedback loop allows the system to balance precision and timing dynamically, providing information as soon as sufficient confidence is achieved without waiting for complete data

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8321944B1Adaptive risk analysis methods and apparatus
Publication Date: 2012.11.27 REDSEAL INC
  • US8321944B1 patent drawing
  • US8321944B1 patent drawing
  • US8321944B1 patent drawing

AI summary

A computer system method includes receiving a network topology and associated configuration data, wherein the network topology indicates a host location and a threat location, determining a vulnerability associated with the host location, determining a security exposure for the host location with respect to the threat location from the configuration data, the network topology, and to incomplete configuration data for the host location, determining a first vulnerability certainty for the host location with respect the vulnerability in response to incomplete configuration data, thereafter receiving updated network data selected from a group consisting of: updated configuration data, updated network topology, determining an updated security exposure for the host location with respect to the threat location from the updated network data, and to the incomplete configuration data, and displaying a difference between of the first security exposure and the second security exposure on the display.