Cyber Risk Assessment via Incident-Origin Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in assessing and managing cyber risks, which can impact their operations and reputation, and these risks often affect associated entities such as customers and supply chain partners who lack insight into the organization's security hygiene and risk management practices.
Innovation Solution
A computer-implemented method and system that assesses cyber risks using incident-origin information by translating entity identifiers into Internet addresses and mapping externally-detected security incidents to generate a cyber-risk assessment, enabling entities to understand their exposure to cyber risks without relying on insider information or cooperation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If entities use internally-collected data to assess cyber risk, then they gain insight into their own security hygiene, but they cannot assess the risk of other entities without those entities' cooperation or disclosure
Solution Approach 1:
The patent introduces a third-party assessment system that acts as an intermediary between entities and their security incident data. This intermediary collects incident-origin information from multiple sources, processes it through standardized methodologies, and provides assessments to requesting entities. This resolves the contradiction by enabling cross-entity risk assessment without requiring direct cooperation or data sharing between the entities themselves.
Solution Approach 2:
The system implements feedback loops where security incident information is continuously collected, processed, and used to update risk assessments. These assessments are then fed back to entities and their associates, creating a closed-loop system that improves information availability over time without requiring entities to directly share their internal data.
2Measurement precision
If entities share internal security data to enable risk assessment of other entities, then accurate assessments become possible, but security hygiene and risk management information becomes vulnerable to exposure
Solution Approach 1:
The third-party assessment system serves as a trusted intermediary that collects, processes, and analyzes security incident data without exposing raw internal information. The intermediary transforms sensitive internal data into standardized risk assessments, maintaining measurement precision while protecting the original security hygiene information from direct exposure to requesting entities.
Solution Approach 2:
The system creates processed copies of security incident information rather than sharing the original internal data. These copies are transformed into standardized risk assessments that capture the essential risk information without revealing the detailed internal security hygiene practices, thus maintaining accuracy while reducing exposure risk.
3Measurement precision
If manual methods are used to collect and analyze security incident data from multiple sources, then comprehensive risk assessment is possible, but the process becomes time-consuming and resource-intensive
Solution Approach 1:
The patent replaces manual mechanical processes of data collection and analysis with automated computer-implemented systems. The system automatically collects incident-origin information from multiple sources, processes the data through standardized algorithms, and generates risk assessments without human intervention, thereby maintaining comprehensive assessment quality while dramatically reducing the time and resources required.
Solution Approach 2:
The system performs preliminary actions by pre-collecting and pre-processing security incident data from multiple sources into standardized formats. This preliminary preparation work is done in advance, so when risk assessments are requested, the system can quickly retrieve and analyze the pre-processed data, reducing the time required for actual assessment while maintaining completeness.
4Reliability
If organizations focus on managing their own cyber risk, then they improve their own security hygiene, but associated entities remain unaware of the risk exposure and cannot take protective measures
Solution Approach 1:
The system implements feedback mechanisms that deliver risk assessment information to associated entities about their connections to assessed organizations. This feedback loop enables associates to understand their exposure to cyber risks without requiring the assessed organization to directly communicate its internal security status, thus preserving the organization's security hygiene while informing associates of risk exposure.
Data Source
AI summary
A computer-implemented method for assessing cyber risks using incident-origin information may include (1) receiving a request for a cyber-risk assessment of an entity of interest, (2) using an Internet-address data source that maps identifiers of entities to public Internet addresses of the entities to translate an identifier of the entity into a set of Internet addresses of the entity, (3) using an incident-origin data source that maps externally-detected security incidents to public Internet addresses from which the security incidents originated to translate the set of Internet addresses into a set of security incidents that originated from the entity, and (4) using the set of security incidents to generate the cyber-risk assessment of the entity. Various other methods, systems, and computer-readable media may have similar features.


