Cyber Risk Prediction Model for Limited Scan Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods struggle to accurately determine the cyber risk score of assets that have been scanned with limited information, as the list of vulnerabilities found is often incomplete.
Innovation Solution
A machine learning model is trained on scan-to-risk maps that include low scan metadata and corresponding cyber risk scores from full scans, enabling the prediction of cyber risk scores for assets scanned at low depths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If security scanning is performed with limited credentials or plugins, then scanning coverage and speed are improved, but measurement precision of cyber risk score deteriorates
Solution Approach 1:
The system performs preliminary actions by conducting a full-depth scan on a subset of assets to build training data, then uses this pre-trained model to quickly assess remaining assets with limited scan depth, achieving both speed and accuracy
Solution Approach 2:
A machine learning model serves as an intermediary between limited scan data and accurate risk scores, translating incomplete vulnerability information into reliable risk assessments through pattern recognition from training data
2Measurement precision
If full-depth scanning is performed on all assets, then measurement precision of cyber risk score is improved, but loss of time increases
Solution Approach 1:
The asset population is segmented into two groups: a training subset that receives full-depth scanning to build the ML model, and a target subset that receives rapid assessment using the trained model, dividing the workload to minimize total time
Solution Approach 2:
Instead of performing excessive full-depth scanning on all assets, the system applies partial scanning (limited depth) to target assets and compensates with ML-based risk inference, achieving sufficient accuracy without complete scans
3Ease of operation
If scanning is performed without authentication, then ease of operation is improved, but loss of information increases
Solution Approach 1:
The mechanical process of authentication-based scanning is replaced with an ML-based inference system that can predict vulnerabilities from unauthenticated scan patterns, eliminating the need for credential management while recovering information completeness
Data Source
AI summary
Techniques, methods and/or apparatuses are disclosed that enable prediction of cyber risks of assets of networks. Through the disclosed techniques, a cyber risk prediction model, which may be a form of a machine learning model, may be trained to predict cyber risks. The cyber risk model may be provided to a cyber risk predictor two predict cyber risks of an asset, without the need to scan the asset at a very deep scan level.


