Computing System Risk Scoring for Automated Vulnerability Reconfiguration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems have numerous vulnerabilities that attackers can exploit due to outdated or improperly configured software and hardware, often lacking cybersecurity considerations in their design.

Innovation Solution

A computer-implemented method and system for cyber risk assessment that computes a risk score for computing systems, identifies vulnerable components, and automatically determines modifications to enhance security by reconfiguring or replacing components, while performing defensive actions like changing IP addresses or port numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software and hardware are updated frequently to fix vulnerabilities, then security reliability is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs automatic vulnerability scanning, risk scoring, and prioritization without requiring manual security analysis. The computer automatically identifies vulnerabilities, calculates risk scores based on multiple factors, and generates remediation recommendations, enabling self-service security management that reduces operational complexity while maintaining high security reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts risk scores by changing parameters such as vulnerability severity, exploitability, asset criticality, and threat intelligence data. By modifying these parameters automatically based on real-time conditions, the system adapts security priorities without manual intervention, resolving the contradiction between maintaining high security reliability and reducing system complexity

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive vulnerability scanning is performed across all components, then measurement precision of security risks is improved, but loss of time and computational resources increase

Engineering Contradiction:
Improverisk assessment precisionVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies different scanning depths and risk assessment methodologies to different components based on their criticality and vulnerability profiles. High-criticality components receive comprehensive scanning for precise measurement, while lower-criticality components receive streamlined assessment, optimizing the balance between measurement precision and time consumption across the entire system

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs risk scoring on all components but focuses detailed remediation efforts only on high-risk vulnerabilities identified through initial screening. This partial action approach maintains measurement precision for priority risks while reducing overall assessment time by not exhaustively analyzing every single vulnerability in detail

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple defensive actions are implemented simultaneously, then security reliability is improved, but ease of operation and system complexity worsen

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system pre-calculates risk scores, prioritizes vulnerabilities, and prepares remediation recommendations before actual security incidents occur. By performing these actions preliminarily and automatically, the system maintains high security reliability while reducing operational complexity during incident response, as defenders can simply follow pre-prepared guidance rather than making complex decisions under pressure

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12418557B2Systems and methods for cyber risk assessment for computing systems
Publication Date: 2025.09.16 TENNESSEE TECHNOLOGICAL UNIVERSITY
  • US12418557B2 patent drawing
  • US12418557B2 patent drawing
  • US12418557B2 patent drawing

AI summary

A computer-implemented method for cyber risk assessment for computing systems may include computing a risk score for a computing system. The computing system may include one or more components. The one or more components may include one or more physical components or one or more software components. The risk score may include a value indicating a risk of exploitation of the computing system. The method may include determining one or more modifications to at least one of the one or more components of the computing system. The one or more modifications may increase the security of the computing system. The method may include performing a sensitivity analysis on the computing system. The method may include generating an order of reconfiguring or replacing vulnerable components of the computing system. The method may include performing a defensive action on the computing system.