Adaptive Risk Management Application for Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity systems struggle to effectively adapt to evolving threats and react promptly to new security challenges, leading to inefficiencies in risk management and vulnerability assessment in complex system-of-systems environments.

Innovation Solution

An adaptive risk management application that retrieves data on assets within an enterprise system, identifies vulnerabilities, determines the likelihood of threat exploitation, calculates a risk score using Monte Carlo simulations, and integrates threat intelligence from external sources to provide real-time risk assessment and mitigation recommendations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional cybersecurity systems are used to assess vulnerabilities, then the system structure is simple and easy to operate, but the system cannot adapt quickly to evolving threats and reacts slowly to new security challenges

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The risk management system dynamically updates vulnerability data and threat intelligence in real-time, allowing the system to adapt to evolving threats. The system continuously refreshes asset vulnerability information and threat actor capabilities, enabling dynamic risk assessment rather than static evaluation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring threat intelligence data, exploitation likelihood, and vulnerability status. This feedback loop enables the system to learn from new threats and adjust risk assessments automatically, improving adaptability through continuous information circulation

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive vulnerability assessment is performed considering all factors and relationships, then the risk assessment accuracy is improved, but the time required for assessment increases significantly

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing the relationship model between vulnerabilities and conducting initial risk assessments. When new vulnerability data arrives, the system leverages pre-computed relationships to quickly update assessments without re-evaluating all factors from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by focusing assessment on specific vulnerability-exploitation pairs rather than evaluating all possible combinations. By parameterizing the assessment around exploitation likelihood and specific threat scenarios, the system achieves comprehensive accuracy with reduced computational time

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time risk assessment and automated data refreshment are implemented, then the system's ability to respond to new threats is improved, but the computational resources and system complexity increase

Engineering Contradiction:
Improveresponse speed to new threatsVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically refreshing vulnerability data and threat intelligence without manual intervention. The automated data refreshment mechanism enables real-time risk assessment while reducing operational complexity through self-managing data updates

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual risk assessment processes with automated computational methods. By substituting mechanical manual analysis with algorithmic Monte Carlo simulations and automated data processing, the system achieves faster response speeds while managing complexity through automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12299619B2Adaptive enterprise risk evaluation
Publication Date: 2025.05.13 MERCK SHARP & DOHME LLC
  • US12299619B2 patent drawing
  • US12299619B2 patent drawing
  • US12299619B2 patent drawing

AI summary

An adaptive risk management application retrieves data corresponding to an asset. The asset is a computing device or software application of an enterprise system. The adaptive risk management system identifies a set of vulnerabilities of the asset. For each vulnerability in the set of vulnerabilities, the adaptive risk management application generates a recommendation for mitigating the vulnerability. The adaptive risk management application generates a user interface for the asset. The user interface comprises a list of the recommendations. The adaptive risk management system provides the user interface for display.