AI Cyber Risk Prediction System for Vulnerability Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk assessment systems, such as CVSS, are not effective in predicting which vulnerabilities will be exploited, leading to inefficient prioritization of patches and resource allocation in cybersecurity.

Innovation Solution

A computer-implemented system that uses artificial intelligence to calculate the probability of a cyber attack and its associated cost, taking into account industry verticals and specific vulnerabilities, to determine cyber aggregation risk and identify organizations to be incentivized to reduce this risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard risk assessment systems (CVSS) are used to prioritize vulnerabilities, then organizations err on the side of caution by patching severe vulnerabilities, but most flagged vulnerabilities will not be attacked resulting in wasted resources

Engineering Contradiction:
Improveaccuracy of vulnerability exploitation predictionVSAvoidcybersecurity resource allocation efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent changes the parameters used for risk assessment from static CVSS scores to dynamic parameters including AI-predicted exploitation probability, industry vertical risk factors, vulnerability age, and patch availability. This transforms the risk calculation from a generic severity-based metric to a targeted prediction of actual exploitation likelihood, resolving the contradiction between reliable prediction and resource efficiency

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system incorporates feedback loops where AI models continuously learn from exploitation data, patching patterns, and threat intelligence to improve prediction accuracy over time. This feedback mechanism allows the system to adapt to emerging threats and refine which vulnerabilities require immediate attention versus those that can be deferred, optimizing resource allocation while maintaining reliable predictions

Inventive Principle:
Principle #23Feedback

2Reliability

If organizations patch all severe vulnerabilities flagged by CVSS, then they maintain high security posture, but they cannot prioritize effectively since the majority of flagged vulnerabilities will not be attacked

Engineering Contradiction:
Improvesecurity postureVSAvoidvulnerability patching efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by focusing patching efforts only on vulnerabilities with high predicted exploitation probability rather than all severe vulnerabilities. The AI system identifies a subset of critical vulnerabilities that require immediate attention, allowing organizations to maintain adequate security posture while avoiding excessive patching of low-risk vulnerabilities that would waste productivity

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system segments vulnerabilities into distinct risk categories based on AI predictions, industry vertical, and exploitation patterns. This segmentation creates prioritized groups (e.g., critical, high, medium, low) that enable targeted patching strategies, improving productivity by focusing resources on the most dangerous vulnerabilities while maintaining security through systematic handling of less critical issues

Inventive Principle:
Principle #1Segmentation

3Loss of information

If comprehensive vulnerability databases (NVD) are used to track all disclosed vulnerabilities, then complete visibility is achieved, but less than 3% are found to be exploited in the wild making the comprehensive tracking inefficient

Engineering Contradiction:
Improvevulnerability tracking completenessVSAvoidtracking and monitoring resources
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts the essential predictive elements from the comprehensive NVD database using AI models that identify patterns in exploitation behavior, threat actor preferences, and vulnerability characteristics. Instead of tracking all vulnerabilities equally, the system extracts and focuses on the subset of vulnerabilities with high exploitation probability, maintaining information completeness about all vulnerabilities while reducing tracking resources by prioritizing based on predicted risk

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12235969B2System and method for calculating and understanding aggregation risk and systemic risk across a population of organizations with respect to cybersecurity for purposes of damage coverage, consequence management, and disaster avoidance
Publication Date: 2025.02.25 SECURIN INC
  • US12235969B2 patent drawing
  • US12235969B2 patent drawing
  • US12235969B2 patent drawing

AI summary

Embodiments of a computer-implemented system and methods for predicting and/or determining a probability of a cyber-related attack and associated costs are disclosed.