Connected Asset Vulnerability Scoring Across Network And Enterprise Layers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing risk assessment models for connected assets do not adequately consider the impact of vulnerabilities on other assets within a network, leading to insufficient risk evaluation.

Innovation Solution

A process that extracts technical impacts of vulnerabilities from network data, generates network and enterprise layer impact scores using business value contexts, and creates a remediation plan to ameliorate vulnerabilities by adjusting connected assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing risk assessment models are used for connected assets, then the assessment process is simple and quick, but the risk evaluation is insufficient and does not adequately consider network-level impacts

Engineering Contradiction:
Improverisk evaluation accuracyVSAvoidassessment model complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the risk assessment into multiple hierarchical layers: asset level, network level, and enterprise level. Each layer has its own impact scores and assessment criteria. This segmentation allows comprehensive evaluation without overwhelming complexity by breaking down the assessment into manageable components that can be processed systematically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multi-dimensional scoring by evaluating impacts at different hierarchical levels (asset, network, enterprise) and combining them into composite risk scores. This dimensional approach transforms the assessment from a single-dimensional view to a multi-dimensional framework, improving accuracy while maintaining structured complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive vulnerability assessment across all connected assets is performed, then complete risk coverage is achieved, but the time and computational resources required increase significantly

Engineering Contradiction:
Improverisk assessment completenessVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by assigning different weights and impact scores to different assets based on their specific roles, criticality, and position in the network. Rather than uniform assessment, each asset is evaluated with locally optimized criteria reflecting its actual importance to the enterprise, improving completeness while reducing unnecessary assessment overhead for less critical assets.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent dynamically adjusts assessment parameters including impact scores, weights, and priority levels based on the specific vulnerability, asset characteristics, and network context. This parameter adaptation allows the system to focus computational resources on high-risk areas while maintaining adequate coverage elsewhere, balancing completeness with time efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250298891A1Connected asset risk management
Publication Date: 2025.09.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250298891A1 patent drawing
  • US20250298891A1 patent drawing
  • US20250298891A1 patent drawing

AI summary

An embodiment extracts, from vulnerability data describing a vulnerability applicable to a connected asset within a network of connected assets, a set of technical impacts of the vulnerability. An embodiment generates, using a business value context of the connected asset and the set of technical impacts of the vulnerability, a network layer impact score corresponding to the connected asset and the vulnerability. An embodiment generates, using the business value context of the connected asset and the set of technical impacts of the vulnerability, an enterprise layer impact score corresponding to the connected asset and the vulnerability. An embodiment generates, using the network layer impact score and the enterprise layer impact score, a remediation plan for the connected asset, the remediation plan comprising a planned adjustment of the connected asset to ameliorate the vulnerability.