Cyber-Attack Analysis System Prioritizing Business Impact
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security systems for computer-based systems are limited in detecting and analyzing multiple simultaneous cyber-attacks, as they operate with linear processes that do not consider additional information and can only identify attacks based on predefined frameworks, making them ineffective in mitigating the full impact of complex cyber threats.
Innovation Solution
A method and system for analyzing, prioritizing, and mitigating cyber-attacks by detecting each attack, determining relevant data, identifying business impacts using predetermined and supplemental data, and generating a prioritized list based on the potential impact on the business, allowing for a more comprehensive and effective response to multiple threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional linear security processes are used to detect cyber-attacks, then the system can identify attacks based on predefined frameworks, but it cannot effectively analyze multiple simultaneous attacks or consider additional business impact information
Solution Approach 1:
The patent segments the security analysis process into distinct functional modules: a detection module that identifies individual attacks using predefined frameworks, a data collection module that gathers attack-specific information, and a prioritization module that ranks attacks based on business impact. This segmentation allows the system to handle multiple simultaneous attacks by processing them through separate, specialized components rather than a single linear process.
Solution Approach 2:
The patent adds a new dimension to traditional security analysis by incorporating business impact assessment alongside technical attack detection. Instead of solely relying on predefined technical frameworks, the system evaluates attacks based on their potential business consequences, creating a multi-dimensional analysis approach that prioritizes attacks based on both technical characteristics and organizational impact.
2Loss of information
If conventional security systems focus on high-level infrastructure detection, then they can identify attacks on computer-based systems, but they cannot determine specific business impacts on the organization
Solution Approach 1:
The patent implements preliminary action by pre-defining business impact categories and criteria before attacks occur. The system establishes a framework of potential business impacts (such as financial loss, operational disruption, reputational damage) and their associated metrics in advance, allowing for rapid assessment when attacks are detected without requiring complex real-time analysis of business consequences.
Solution Approach 2:
The patent introduces an intermediary prioritization module that bridges the gap between technical attack detection and business impact assessment. This intermediary component translates technical attack data into business-relevant information by mapping attack characteristics to predefined business impact categories, making the connection between infrastructure-level threats and organizational consequences.
3Reliability
If conventional systems process attacks one at a time, then they can analyze individual cyber-threats, but they become vulnerable when multiple simultaneous attacks occur on the system
Solution Approach 1:
The patent merges multiple attack analysis processes into a unified prioritization framework. Instead of processing attacks sequentially through separate linear processes, the system combines multiple attack detections into a single prioritized list based on business impact, allowing simultaneous attacks to be evaluated together and responded to in order of importance rather than in arbitrary detection order.
Solution Approach 2:
The patent implements dynamics by making the attack analysis process adaptive and flexible. The system continuously updates attack prioritization based on incoming attack data and changing business impact assessments, allowing the detection and response process to dynamically adjust to multiple simultaneous threats rather than following a fixed linear sequence.
Data Source
AI summary
Methods, systems, and program products for analyzing cyber-attacks on computing systems of a business are disclosed. The methods may include detecting each of the plurality of cyber-attacks. The plurality of cyber-attacks may target information systems stored on at least one information technology (IT) component of an infrastructure of the computing system of the business. The methods may also include determining cyber-attack data relating to the plurality of cyber-attacks, identifying a business impact on the business for each of the plurality of cyber-attacks. The identified business impact on the business for the plurality of cyber-attacks may be based on predetermined business impact data and the determined cyber-attack data. Additionally, the method may include prioritizing the plurality of cyber-attacks attempted on the computing system based on the identified business impact on the business for each of the plurality of cyber-attacks.


