Causal Inference Scoring for Security Control Effectiveness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in accurately quantifying the effectiveness of security controls, such as patch management and antivirus software, due to limitations in existing assessment methods that do not provide clear visibility into their impact on security policies, leading to difficulties in prioritization and resource allocation.

Innovation Solution

A causal inference-based approach is introduced to measure the effectiveness of security controls by using a novel scoring function that considers multiple criteria, allowing for continuous evaluation of their impact on patching behavior and vulnerability mitigation, incorporating observational data to estimate the influence of security controls on patching timelines and threat mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If scenario-based red teaming exercises are used to test security controls, then security preparedness and resilience can be assessed, but the effectiveness of controls on existing security policies cannot be quantified

Engineering Contradiction:
Improvesecurity preparednessVSAvoidquantification of control effectiveness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces manual scenario-based red teaming exercises with an automated machine learning-based quantification system. The system uses ML models to process vulnerability scan data, security control information, and observational datasets to automatically calculate effective risk scores, eliminating the need for manual assessment while providing precise quantification of control effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary causal inference model that bridges the gap between security controls and risk outcomes. This model processes observational data about vulnerability checks and security control implementations to infer the causal relationship between controls and risk reduction, enabling quantification without direct experimentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If numerous security controls are deployed to identify and prioritize information security risks, then security coverage is improved, but visibility into overall risk posture and control effectiveness deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidvisibility into risk posture
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges multiple data sources including vulnerability scan data, security control metadata, and observational datasets into a unified risk assessment framework. The system consolidates information about numerous security controls and their impacts into integrated effective risk scores, providing visibility into overall risk posture while maintaining coverage of individual controls.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms by continuously analyzing observational data from vulnerability checks and updating the quantification of control effectiveness. The system uses this feedback to refine risk scores and provide ongoing visibility into how security controls perform in practice, enabling dynamic adjustment of risk posture assessments.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If continuous evaluation of security control effectiveness is implemented, then data-driven decision-making is enabled, but assessment complexity and resource requirements increase

Engineering Contradiction:
Improveeffectiveness assessmentVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent changes the parameters of the assessment system by using pre-trained machine learning models that process data in standardized formats. The system transforms complex security control evaluations into calculations of effective risk scores based on standardized inputs from vulnerability scanners and observational datasets, reducing operational complexity while maintaining continuous evaluation capability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent enables the system to self-service by using automated machine learning models that continuously process and analyze security data without requiring manual intervention. The system automatically updates its quantifications of control effectiveness using observational data, reducing the resource burden while maintaining continuous, precise evaluation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11973788B2Continuous scoring of security controls and dynamic tuning of security policies
Publication Date: 2024.04.30 TENABLE INC
  • US11973788B2 patent drawing
  • US11973788B2 patent drawing
  • US11973788B2 patent drawing

AI summary

Techniques, methods and/or apparatuses are disclosed that enable of cyber risks on assets of networks to be evaluated in presence of security controls on the assets. In this way, effect of security controls already in place may be quantified. A novel scoring technique is presented. Also, use of causal inference is in the context of security risk assessment is described.