Cyber Asset Identification Through Democratic Matching for Risk Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying cyber assets and managing cyber security risks are complex, resource-intensive, and prone to misclassification, especially when dealing with large numbers of domains and entities with similar names, leading to incomplete and inaccurate risk assessments.

Innovation Solution

A democratic matching algorithm is employed to identify cyber assets by executing multiple identification algorithms, determining true match probabilities, and generating databases for entities, enabling accurate classification and automated cyber risk mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple cyber asset identification algorithms are executed to improve identification accuracy, then the true match probability increases, but the computational resources and time required increase

Engineering Contradiction:
Improveidentification accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system segments the identification process into multiple independent algorithms, each handling specific aspects of cyber asset identification. These algorithms operate in parallel and contribute independently to the overall true match probability calculation, allowing selective execution based on resource availability while maintaining high accuracy through combined results

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system executes multiple identification algorithms beyond what a single algorithm could provide, using the excess computational effort to calculate true match probabilities that aggregate evidence from multiple sources. This partial excessive action ensures comprehensive coverage of identification scenarios and improves robustness against false positives and false negatives

Inventive Principle:
Principle #16Partial or excessive action

2Measurement precision

If multiple cyber asset identification algorithms are executed to improve identification accuracy, then the true match probability increases, but the time required for processing increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The identification process is segmented into multiple algorithms that can execute in parallel, reducing the sequential processing time. Each algorithm processes specific subsets of cyber assets or applies different identification criteria simultaneously, with results aggregated through true match probability calculations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system maintains continuous identification processing by executing multiple algorithms concurrently rather than sequentially. The true match probability mechanism allows continuous aggregation of identification results without interruption, ensuring that cyber asset identification remains an ongoing process that leverages all available algorithmic capabilities simultaneously

Inventive Principle:
Principle #20Continuity of useful action

3Device complexity

If existing cyber asset identification methods are used, then the process is simpler, but misclassification errors increase leading to incomplete risk assessments

Engineering Contradiction:
Improveprocess simplicityVSAvoidclassification accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system applies multiple identification algorithms excessively to ensure comprehensive coverage of all possible cyber asset classifications. This over-application of identification methods ensures that even edge cases and ambiguous classifications are addressed by at least one algorithm, reducing misclassification errors while maintaining a unified simple interface

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The true match probability mechanism provides feedback by continuously comparing identification results across multiple algorithms and adjusting classifications based on agreement levels. This feedback loop ensures that only classifications supported by multiple algorithmic perspectives are accepted, reducing misclassification errors and improving overall reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250284799A1Devices, systems, and methods for identifying cyber assets and generating cyber risk mitigation actions based on a democratic matching algorithm
Publication Date: 2025.09.11 BLUEVOYANT LLC
  • US20250284799A1 patent drawing
  • US20250284799A1 patent drawing
  • US20250284799A1 patent drawing

AI summary

A method for identifying cyber assets and implementing cyber risk mitigation actions based on a democratic matching algorithm is disclosed. In one aspect, the method includes executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, wherein each candidate match pair comprises two cyber assets identified as potential assets of the same entity by at least one of the cyber asset identification algorithms. The method can further include determining a true match probability for each candidate match pair, wherein the true match probability is the probability that the two cyber assets in the candidate match pair are assets of the same entity, and wherein the true match probability is based on which of the cyber asset identification algorithms identified the candidate match pair.