Cyber-Attack Analysis System Prioritizing Business Impact

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for computer-based systems are limited in detecting and analyzing multiple simultaneous cyber-attacks, as they operate with linear processes that do not consider additional information and can only identify attacks based on predefined frameworks, making them ineffective in mitigating the full impact of complex cyber threats.

Innovation Solution

A method and system for analyzing, prioritizing, and mitigating cyber-attacks by detecting each attack, determining relevant data, identifying business impacts using predetermined and supplemental data, and generating a prioritized list based on the potential impact on the business, allowing for a more comprehensive and effective response to multiple threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional linear security processes are used to detect cyber-attacks, then the system can identify attacks based on predefined frameworks, but it cannot effectively analyze multiple simultaneous attacks or consider additional business impact information

Engineering Contradiction:
Improveability to analyze multiple simultaneous attacksVSAvoidcomplexity of security analysis system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security analysis process into distinct functional modules: a detection module that identifies individual attacks using predefined frameworks, a data collection module that gathers attack-specific information, and a prioritization module that ranks attacks based on business impact. This segmentation allows the system to handle multiple simultaneous attacks by processing them through separate, specialized components rather than a single linear process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to traditional security analysis by incorporating business impact assessment alongside technical attack detection. Instead of solely relying on predefined technical frameworks, the system evaluates attacks based on their potential business consequences, creating a multi-dimensional analysis approach that prioritizes attacks based on both technical characteristics and organizational impact.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If conventional security systems focus on high-level infrastructure detection, then they can identify attacks on computer-based systems, but they cannot determine specific business impacts on the organization

Engineering Contradiction:
Improvebusiness impact informationVSAvoiddifficulty of assessing business impact
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary action by pre-defining business impact categories and criteria before attacks occur. The system establishes a framework of potential business impacts (such as financial loss, operational disruption, reputational damage) and their associated metrics in advance, allowing for rapid assessment when attacks are detected without requiring complex real-time analysis of business consequences.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary prioritization module that bridges the gap between technical attack detection and business impact assessment. This intermediary component translates technical attack data into business-relevant information by mapping attack characteristics to predefined business impact categories, making the connection between infrastructure-level threats and organizational consequences.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional systems process attacks one at a time, then they can analyze individual cyber-threats, but they become vulnerable when multiple simultaneous attacks occur on the system

Engineering Contradiction:
Improvesystem reliability under multiple attacksVSAvoidattack detection and response speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple attack analysis processes into a unified prioritization framework. Instead of processing attacks sequentially through separate linear processes, the system combines multiple attack detections into a single prioritized list based on business impact, allowing simultaneous attacks to be evaluated together and responded to in order of importance rather than in arbitrary detection order.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamics by making the attack analysis process adaptive and flexible. The system continuously updates attack prioritization based on incoming attack data and changing business impact assessments, allowing the detection and response process to dynamically adjust to multiple simultaneous threats rather than following a fixed linear sequence.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10999301B2Methods, systems, and program product for analyzing cyber-attacks based on identified business impacts on businesses
Publication Date: 2021.05.04 KYNDRYL INC
  • US10999301B2 patent drawing
  • US10999301B2 patent drawing
  • US10999301B2 patent drawing

AI summary

Methods, systems, and program products for analyzing cyber-attacks on computing systems of a business are disclosed. The methods may include detecting each of the plurality of cyber-attacks. The plurality of cyber-attacks may target information systems stored on at least one information technology (IT) component of an infrastructure of the computing system of the business. The methods may also include determining cyber-attack data relating to the plurality of cyber-attacks, identifying a business impact on the business for each of the plurality of cyber-attacks. The identified business impact on the business for the plurality of cyber-attacks may be based on predetermined business impact data and the determined cyber-attack data. Additionally, the method may include prioritizing the plurality of cyber-attacks attempted on the computing system based on the identified business impact on the business for each of the plurality of cyber-attacks.