Cyber Asset Identification Through Democratic Matching for Risk Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying cyber assets and managing cyber security risks are complex, resource-intensive, and prone to misclassification, especially when dealing with large numbers of domains and entities with similar names, leading to incomplete and inaccurate risk assessments.
Innovation Solution
A democratic matching algorithm is employed to identify cyber assets by executing multiple identification algorithms, determining true match probabilities, and generating databases for entities, enabling accurate classification and automated cyber risk mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple cyber asset identification algorithms are executed to improve identification accuracy, then the true match probability increases, but the computational resources and time required increase
Solution Approach 1:
The system segments the identification process into multiple independent algorithms, each handling specific aspects of cyber asset identification. These algorithms operate in parallel and contribute independently to the overall true match probability calculation, allowing selective execution based on resource availability while maintaining high accuracy through combined results
Solution Approach 2:
The system executes multiple identification algorithms beyond what a single algorithm could provide, using the excess computational effort to calculate true match probabilities that aggregate evidence from multiple sources. This partial excessive action ensures comprehensive coverage of identification scenarios and improves robustness against false positives and false negatives
2Measurement precision
If multiple cyber asset identification algorithms are executed to improve identification accuracy, then the true match probability increases, but the time required for processing increases
Solution Approach 1:
The identification process is segmented into multiple algorithms that can execute in parallel, reducing the sequential processing time. Each algorithm processes specific subsets of cyber assets or applies different identification criteria simultaneously, with results aggregated through true match probability calculations
Solution Approach 2:
The system maintains continuous identification processing by executing multiple algorithms concurrently rather than sequentially. The true match probability mechanism allows continuous aggregation of identification results without interruption, ensuring that cyber asset identification remains an ongoing process that leverages all available algorithmic capabilities simultaneously
3Device complexity
If existing cyber asset identification methods are used, then the process is simpler, but misclassification errors increase leading to incomplete risk assessments
Solution Approach 1:
The system applies multiple identification algorithms excessively to ensure comprehensive coverage of all possible cyber asset classifications. This over-application of identification methods ensures that even edge cases and ambiguous classifications are addressed by at least one algorithm, reducing misclassification errors while maintaining a unified simple interface
Solution Approach 2:
The true match probability mechanism provides feedback by continuously comparing identification results across multiple algorithms and adjusting classifications based on agreement levels. This feedback loop ensures that only classifications supported by multiple algorithmic perspectives are accepted, reducing misclassification errors and improving overall reliability
Data Source
AI summary
A method for identifying cyber assets and implementing cyber risk mitigation actions based on a democratic matching algorithm is disclosed. In one aspect, the method includes executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, wherein each candidate match pair comprises two cyber assets identified as potential assets of the same entity by at least one of the cyber asset identification algorithms. The method can further include determining a true match probability for each candidate match pair, wherein the true match probability is the probability that the two cyber assets in the candidate match pair are assets of the same entity, and wherein the true match probability is based on which of the cyber asset identification algorithms identified the candidate match pair.


