Cyber Risk Loss Frequency Calculation for Computing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methodologies for assessing cyber risk are cumbersome and inefficient, particularly in prioritizing vulnerabilities due to the complexity of the cyber risk landscape and the inaccuracies in existing vulnerability scoring systems like CVSS.

Innovation Solution

A system and method that assess vulnerability by determining an exposure window and frequency of contact with threat actors, normalizing these values, and calculating a loss event frequency to prioritize computing elements based on threat loss frequency and loss exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual decomposition and estimation methods are used to determine loss event frequency, then flexibility and adaptability are maintained, but the process becomes cumbersome and inefficient

Engineering Contradiction:
Improveefficiency of risk analysisVSAvoidcomplexity of analysis process
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces manual decomposition and estimation methods with an automated system that uses machine learning models and algorithms to calculate loss event frequency. The system automatically processes vulnerability data, threat data, and asset data to generate risk prioritization scores, eliminating the need for manual analysis while maintaining accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service risk analysis by automatically gathering data from multiple sources, processing it through standardized calculations, and generating prioritization results without requiring manual intervention. The automated calculation of exposure window, frequency of contact, and loss event frequency allows the system to serve itself in producing risk assessments.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If existing vulnerability scoring systems like CVSS are used, then vulnerability assessment is performed, but the frequency side of risk is ignored and accuracy deteriorates

Engineering Contradiction:
Improveaccuracy of vulnerability scoringVSAvoidloss of frequency information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the risk assessment into distinct components: exposure window calculation, frequency of contact determination, and loss event frequency calculation. Each component addresses a specific aspect of risk that was previously overlooked or inadequately measured by traditional systems like CVSS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds the frequency dimension to vulnerability assessment by calculating exposure window and frequency of contact. This transforms the assessment from a static vulnerability score to a dynamic risk measurement that incorporates temporal and probabilistic factors.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Quantity of substance

If hundreds or thousands of vulnerable conditions must be prioritized, then comprehensive coverage is achieved, but manual analysis methods become impractical

Engineering Contradiction:
Improvenumber of vulnerabilities assessedVSAvoidease of prioritization
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent replaces manual prioritization with automated calculation of loss event frequency and risk scoring. The system processes large volumes of vulnerability data, threat data, and asset data to generate prioritization rankings that would be impossible to produce manually at scale.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameters used for prioritization from traditional vulnerability scores to loss event frequency metrics. This transformation enables the system to handle large numbers of vulnerabilities by focusing on the most impactful factors: exposure window and frequency of contact.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4111666B1Systems, methods, and storage media for calculating the frequency of cyber risk loss within computing systems
Publication Date: 2025.04.09 RISKLENS INC
  • EP4111666B1 patent drawingFigure 1
  • EP4111666B1 patent drawingFigure 2
  • EP4111666B1 patent drawingFigure 3

AI summary

Systems, methods, and storage media for determining the probability of cyber risk-related loss within one or more computing systems composed of computing elements are disclosed. Exemplary implementations may: assess vulnerability by determining an exposure window for a computing element based on the number of discrete times within a given time frame where the computing element is in a vulnerable state; determine a frequency of contact of the computing element with threat actors; normalize the exposure window and the frequency of contact; calculate a threat event frequency by dividing the normalized exposure window by the normalized frequency of contact; and repeat the steps for multiple elements. When combined with liability data that describes the loss magnitude implications of these events,organizations can prioritize the elements based on loss exposure and take action to prevent loss exposure.