Cyber Risk Assessment via Incident-Origin Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in assessing and managing cyber risks, which can impact their operations and reputation, and these risks often affect associated entities such as customers and supply chain partners who lack insight into the organization's security hygiene and risk management practices.

Innovation Solution

A computer-implemented method and system that assesses cyber risks using incident-origin information by translating entity identifiers into Internet addresses and mapping externally-detected security incidents to generate a cyber-risk assessment, enabling entities to understand their exposure to cyber risks without relying on insider information or cooperation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If entities use internally-collected data to assess cyber risk, then they gain insight into their own security hygiene, but they cannot assess the risk of other entities without those entities' cooperation or disclosure

Engineering Contradiction:
Improveaccess to security incident informationVSAvoidability to assess other entities' risk
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a third-party assessment system that acts as an intermediary between entities and their security incident data. This intermediary collects incident-origin information from multiple sources, processes it through standardized methodologies, and provides assessments to requesting entities. This resolves the contradiction by enabling cross-entity risk assessment without requiring direct cooperation or data sharing between the entities themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where security incident information is continuously collected, processed, and used to update risk assessments. These assessments are then fed back to entities and their associates, creating a closed-loop system that improves information availability over time without requiring entities to directly share their internal data.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If entities share internal security data to enable risk assessment of other entities, then accurate assessments become possible, but security hygiene and risk management information becomes vulnerable to exposure

Engineering Contradiction:
Improveaccuracy of cyber risk assessmentVSAvoidexposure of security hygiene information
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The third-party assessment system serves as a trusted intermediary that collects, processes, and analyzes security incident data without exposing raw internal information. The intermediary transforms sensitive internal data into standardized risk assessments, maintaining measurement precision while protecting the original security hygiene information from direct exposure to requesting entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates processed copies of security incident information rather than sharing the original internal data. These copies are transformed into standardized risk assessments that capture the essential risk information without revealing the detailed internal security hygiene practices, thus maintaining accuracy while reducing exposure risk.

Inventive Principle:
Principle #26Copying

3Measurement precision

If manual methods are used to collect and analyze security incident data from multiple sources, then comprehensive risk assessment is possible, but the process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvecompleteness of risk assessmentVSAvoidtime required for risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes of data collection and analysis with automated computer-implemented systems. The system automatically collects incident-origin information from multiple sources, processes the data through standardized algorithms, and generates risk assessments without human intervention, thereby maintaining comprehensive assessment quality while dramatically reducing the time and resources required.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary actions by pre-collecting and pre-processing security incident data from multiple sources into standardized formats. This preliminary preparation work is done in advance, so when risk assessments are requested, the system can quickly retrieve and analyze the pre-processed data, reducing the time required for actual assessment while maintaining completeness.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If organizations focus on managing their own cyber risk, then they improve their own security hygiene, but associated entities remain unaware of the risk exposure and cannot take protective measures

Engineering Contradiction:
Improvesecurity hygiene of organizationVSAvoidknowledge of cyber risk by associated entities
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms that deliver risk assessment information to associated entities about their connections to assessed organizations. This feedback loop enables associates to understand their exposure to cyber risks without requiring the assessed organization to directly communicate its internal security status, thus preserving the organization's security hygiene while informing associates of risk exposure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10516680B1Systems and methods for assessing cyber risks using incident-origin information
Publication Date: 2019.12.24 GEN DIGITAL INC
  • US10516680B1 patent drawing
  • US10516680B1 patent drawing
  • US10516680B1 patent drawing

AI summary

A computer-implemented method for assessing cyber risks using incident-origin information may include (1) receiving a request for a cyber-risk assessment of an entity of interest, (2) using an Internet-address data source that maps identifiers of entities to public Internet addresses of the entities to translate an identifier of the entity into a set of Internet addresses of the entity, (3) using an incident-origin data source that maps externally-detected security incidents to public Internet addresses from which the security incidents originated to translate the set of Internet addresses into a set of security incidents that originated from the entity, and (4) using the set of security incidents to generate the cyber-risk assessment of the entity. Various other methods, systems, and computer-readable media may have similar features.