Malicious-Attack Exposure Assessment via Field Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for determining malicious-attack exposure levels in computing systems are inadequate as they rely on direct examination of software components, which fails to accurately reflect real-world exposure levels, necessitating a more effective approach based on field-data analysis.

Innovation Solution

A computer-implemented method and system that receives and analyzes attack reports from multiple computing systems to determine the level of exposure of software components to malicious attacks, making security determinations based on the number and type of attacks identified, and correlating these with properties of the software components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If direct examination of software component configuration is used to estimate malicious-attack exposure levels, then the estimation process is simple and quick, but the accuracy of the exposure level estimation is insufficient

Engineering Contradiction:
Improveexposure level estimation accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces attack report data as an intermediary element between the software component and the exposure level assessment. Instead of directly examining software configuration, the system uses third-party attack reports that document actual malicious attacks against similar software components. This intermediary data source provides objective, field-based evidence of real-world attack patterns, thereby improving measurement precision without requiring direct complex analysis of the software's internal state.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual model of exposure levels by copying and analyzing attack report data from multiple sources rather than directly measuring the actual software component's vulnerability. The system aggregates attack reports that contain information about malicious attacks, software identifiers, and exposure conditions, then uses this copied data to infer the exposure level of the target software component. This approach achieves high accuracy by leveraging existing attack data without requiring direct penetration testing or deep software analysis.

Inventive Principle:
Principle #26Copying

2Measurement precision

If field-data analysis using multiple attack reports is implemented, then the exposure level assessment accuracy improves, but the data processing complexity and time consumption increase

Engineering Contradiction:
Improveexposure level assessment accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-aggregating and organizing attack report data into structured formats before actual exposure assessment is needed. The system collects attack reports containing software identifiers, attack types, and exposure information in advance, and organizes this data for efficient querying. When an exposure level assessment is required, the system can quickly retrieve and analyze pre-processed data rather than collecting and processing raw attack reports from scratch, significantly reducing processing time while maintaining high accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal attack report database that serves multiple functions: it provides exposure level assessment data, identifies attack patterns, supports security trend analysis, and enables comparison across different software components. By building a multi-functional system that processes diverse attack report data in a unified framework, the patent achieves high assessment accuracy through comprehensive data analysis while avoiding redundant processing steps that would increase time consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If attack reports from multiple computing systems are aggregated and analyzed, then the reliability of exposure level determination improves, but the quantity of data to be processed increases

Engineering Contradiction:
Improveexposure level determination reliabilityVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential and relevant information from attack reports, such as software component identifiers, attack type classifications, exposure level indicators, and key attack characteristics. Instead of processing the complete raw attack report data which may contain extensive contextual information, the system selectively extracts and analyzes only the critical fields necessary for exposure level determination. This extraction approach maintains high reliability by focusing on the most informative data elements while significantly reducing the volume of data that requires processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by treating different types of attack report data with different levels of processing intensity. The system identifies and prioritizes key fields such as software identifiers and attack outcomes that directly impact exposure level assessment, applying rigorous analysis to these critical elements. For less critical contextual information, the system applies lighter processing or aggregation. This differentiated approach ensures high reliability for the most important assessment factors while reducing overall data processing requirements by not uniformly processing all data elements at the same level of detail.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9043922B1Systems and methods for determining malicious-attack exposure levels based on field-data analysis
Publication Date: 2015.05.26 GEN DIGITAL INC
  • US9043922B1 patent drawing
  • US9043922B1 patent drawing
  • US9043922B1 patent drawing

AI summary

A computer-implemented method for determining malicious-attack exposure levels based on field-data analysis may include (1) receiving a plurality of attack reports from a plurality of computing systems, wherein at least one attack report includes an identifier of a software component of a computing system within the plurality of computing systems from which the attack report was received and an indication that a malicious attack was detected at the computing system, (2) determining a number of attack reports within the plurality of attack reports that identify the software component, (3) analyzing the plurality of attack reports to determine, based at least in part on the number of attack reports, a level of exposure to malicious attacks of the software component, and (4) making, based at least in part on the level of exposure, a security determination related to the software component. Various other methods, systems, and computer-readable media are also disclosed.