Cyber Risk Prediction Model for Limited Scan Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods struggle to accurately determine the cyber risk score of assets that have been scanned with limited information, as the list of vulnerabilities found is often incomplete.

Innovation Solution

A machine learning model is trained on scan-to-risk maps that include low scan metadata and corresponding cyber risk scores from full scans, enabling the prediction of cyber risk scores for assets scanned at low depths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If security scanning is performed with limited credentials or plugins, then scanning coverage and speed are improved, but measurement precision of cyber risk score deteriorates

Engineering Contradiction:
Improvescanning speedVSAvoidcyber risk score accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by conducting a full-depth scan on a subset of assets to build training data, then uses this pre-trained model to quickly assess remaining assets with limited scan depth, achieving both speed and accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A machine learning model serves as an intermediary between limited scan data and accurate risk scores, translating incomplete vulnerability information into reliable risk assessments through pattern recognition from training data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If full-depth scanning is performed on all assets, then measurement precision of cyber risk score is improved, but loss of time increases

Engineering Contradiction:
Improvecyber risk score accuracyVSAvoidscanning time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The asset population is segmented into two groups: a training subset that receives full-depth scanning to build the ML model, and a target subset that receives rapid assessment using the trained model, dividing the workload to minimize total time

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of performing excessive full-depth scanning on all assets, the system applies partial scanning (limited depth) to target assets and compensates with ML-based risk inference, achieving sufficient accuracy without complete scans

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If scanning is performed without authentication, then ease of operation is improved, but loss of information increases

Engineering Contradiction:
Improvescanning simplicityVSAvoidvulnerability information completeness
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The mechanical process of authentication-based scanning is replaced with an ML-based inference system that can predict vulnerabilities from unauthenticated scan patterns, eliminating the need for credential management while recovering information completeness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12335298B2Predicting cyber risk for assets with limited scan information using machine learning
Publication Date: 2025.06.17 TENABLE INC
  • US12335298B2 patent drawing
  • US12335298B2 patent drawing
  • US12335298B2 patent drawing

AI summary

Techniques, methods and/or apparatuses are disclosed that enable prediction of cyber risks of assets of networks. Through the disclosed techniques, a cyber risk prediction model, which may be a form of a machine learning model, may be trained to predict cyber risks. The cyber risk model may be provided to a cyber risk predictor two predict cyber risks of an asset, without the need to scan the asset at a very deep scan level.