AI Risk Rating System for Information Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional risk rating analyses for information systems are time-consuming, inefficient, subjective, and often inaccurate due to the need to analyze millions of combinations of assets, threat agents, threat actions, vulnerabilities, and security controls, making it challenging to determine the likelihood, impact, and level of risk effectively.

Innovation Solution

A risk rating method and system that uses data mining and artificial intelligence to predict and recommend risk ratings by filtering input data, utilizing historical records, and evaluating the effectiveness of security controls, thereby providing more accurate, efficient, and objective risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional risk rating analysis methods are used to analyze all combinations of assets, threat agents, threat actions, vulnerabilities, and security controls, then comprehensive risk assessment coverage is achieved, but the analysis time and computational resources required become excessively large

Engineering Contradiction:
Improverisk assessment coverageVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-calculating and storing risk ratings for individual components (assets, threat agents, threat actions, vulnerabilities, and security controls) in separate databases. When a complete risk scenario is needed, the system retrieves these pre-computed values and combines them using a risk rating formula, avoiding the need to re-analyze all combinations from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the comprehensive risk analysis problem into smaller, independent components. Each component (asset, threat agent, threat action, vulnerability, security control) is analyzed separately and stored in individual databases. This segmentation allows the system to build comprehensive risk assessments from modular, pre-analyzed parts rather than analyzing all combinations simultaneously.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If manual risk rating analysis is performed by security professionals, then subjective judgment can be applied, but the process becomes time-consuming and inconsistent across different analysts

Engineering Contradiction:
Improvesubjective judgment capabilityVSAvoidanalysis efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system incorporates feedback mechanisms where risk ratings are calculated based on structured inputs from security professionals about asset values, threat likelihoods, vulnerability severities, and control effectiveness. The system then provides computed risk ratings that can be reviewed and adjusted by analysts, creating a feedback loop that combines automated calculation with human expertise for consistent yet adaptable results.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces the purely manual mechanical process of risk analysis with an automated computational system. The risk rating formula and database queries automatically compute risk assessments based on input parameters, substituting the manual calculation process with machine-executed algorithms while retaining the ability to incorporate human judgment through structured input data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive risk analysis of all system components is conducted, then accurate risk ratings are achieved, but the complexity of the analysis process increases significantly

Engineering Contradiction:
Improverisk rating accuracyVSAvoidanalysis process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system employs a universal risk rating formula that can be applied across all risk scenarios involving different assets, threat agents, threat actions, vulnerabilities, and security controls. This single multi-functional approach handles diverse risk assessment needs consistently, reducing the complexity that would arise from creating separate analysis methods for each component type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages complexity by organizing analysis parameters into standardized categories with consistent data structures. Each component (asset, threat, vulnerability, control) is represented by specific parameters stored in databases, allowing the system to handle complex multi-factor risk analysis through systematic parameter management rather than ad-hoc analysis procedures.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12079348B1Risk rating method and system
Publication Date: 2024.09.03 CLEARWATER COMPLIANCE LLC
  • US12079348B1 patent drawing
  • US12079348B1 patent drawing
  • US12079348B1 patent drawing

AI summary

A risk rating method and system that predicts the risk likelihood, the risk impact, and the risk rating of certain threats and vulnerabilities from exploiting different component groups. In some embodiments, the system's predictions (also referred to herein as inferences) are generated based on data elements provided by a user about its organization's information systems. In further embodiments, the method and system utilizes data mining, historical records, and an AI Engine to provide the predictions for the risk likelihood, the risk impact, and the risk rating posed by the various threat occurrences.