Organizational Behavior Risk Rating Through Asset Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security risk management systems struggle to effectively evaluate and manage security risks associated with other entities with which an entity communicates or collaborates, often leading to inadequate assessments and increased vulnerabilities.

Innovation Solution

A system and method that analyzes traces of online user activities, generates a map of technical and non-technical assets, and assigns security ratings to entities, utilizing passive DNS queries, social media data, and other data sources to automate the mapping and analysis process, thereby providing a comprehensive security risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security risk management systems are used to evaluate security risks of other entities, then security risk assessment can be performed, but the assessment accuracy is insufficient and vulnerabilities are not adequately identified

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidsecurity posture
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The security risk assessment system segments the evaluation into multiple independent components: technical asset analysis, organizational behavior analysis, trace data examination, and mapping processes. Each component evaluates specific aspects separately before integrating results, allowing for more precise and comprehensive security risk assessment of third-party entities.

Inventive Principle:
Principle #1Segmentation

2Productivity

If manual security risk assessment methods are used, then detailed analysis can be performed, but the process is time-consuming and inefficient

Engineering Contradiction:
Improvesecurity risk assessment speedVSAvoidassessment time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements automated self-service capabilities where the security risk assessment platform automatically collects trace data, performs entity mapping, analyzes organizational behaviors, and generates security ratings without requiring manual intervention for each assessment task, significantly improving productivity while maintaining comprehensive analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-establishing entity maps, pre-collecting trace data from multiple sources, and pre-analyzing organizational behaviors before actual security risk assessments are needed. This preparation work is stored and reused across multiple assessments, reducing the time required for individual evaluations.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive data collection methods are used to assess security risks, then more accurate evaluations can be obtained, but privacy concerns and data exposure increase

Engineering Contradiction:
Improvesecurity risk evaluation accuracyVSAvoidprivacy exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system uses trace data as an intermediary element that indirectly reveals organizational behaviors and security practices without requiring direct access to sensitive internal systems or personal information. The trace data serves as a mediator that provides comprehensive security assessment information while preserving privacy by analyzing only the digital footprints and behavioral patterns that entities leave in controlled and uncontrolled contexts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12587555B2Methods for using organizational behavior for risk ratings
Publication Date: 2026.03.24 BITSIGHT TECH
  • US12587555B2 patent drawing
  • US12587555B2 patent drawing
  • US12587555B2 patent drawing

AI summary

Among other things, traces are received of activities of an online user who is associated with an entity. By analysis of the traces a security state of the entity is inferred. Also, a map is generated between (a) technical assets that contribute to security characteristics of respective entities and (b) the identities of the entities that are associated with the respective technical assets. At least part of the generating of the map is done automatically. A user can be engaged to assist in the generating of the map by presenting to the user through a user interface (a) data about the technical assets of entities and (b) an interactive tool for associating the technical assets with the identities of the entities.