Holistic Cyber Security Risk Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security threat assessments for network-connected systems are inadequate as they lack a granular and holistic approach, failing to provide comprehensive insights into the vulnerability and likelihood of attacks across the entire enterprise network.

Innovation Solution

A method and system for predicting cyber security risk that involves collecting network parameters and threat intelligence data, performing Extract, Transform, and Load (ETL) processes, and analyzing this data to generate a holistic cyber security risk score, incorporating vulnerability scoring and exploit severity data to determine component threat scores and a comprehensive risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional vulnerability data collection and analysis methods are used, then vulnerability data can be gathered, but the approach lacks granular and holistic insights into the entire enterprise network

Engineering Contradiction:
Improvethreat assessment precisionVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into discrete technological components and assets, assessing each individually for vulnerabilities and threats. This segmentation enables granular measurement precision at the component level while maintaining an organized structure that avoids overwhelming complexity in the overall assessment system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a holistic enterprise-level dimension to traditional vulnerability assessment by combining component-level technical data with enterprise-wide contextual factors. This multi-dimensional approach provides comprehensive insights across both granular and aggregate levels without proportionally increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive network parameters and threat intelligence data are collected from multiple sources, then a holistic threat assessment can be achieved, but the data processing and analysis complexity increases

Engineering Contradiction:
Improvethreat assessment reliabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple data sources including network parameters, vulnerability data, threat intelligence, and exploit information into a unified assessment framework. This consolidation improves reliability by integrating comprehensive data while managing processing complexity through a structured methodology that combines these elements systematically.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a multi-functional assessment system that handles diverse data types (network parameters, vulnerability scores, threat intelligence, exploit data) through a single integrated framework. This universal approach improves assessment reliability across different data sources while avoiding the need for separate complex processing systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed component threat scores are calculated based on vulnerability scoring and exploit severity data, then granular vulnerability identification is improved, but the computational requirements and processing time increase

Engineering Contradiction:
Improvevulnerability identification precisionVSAvoidassessment processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary calculations of component threat scores by pre-processing vulnerability scoring data and exploit severity data before the main assessment execution. This preliminary action enables rapid generation of detailed vulnerability identifications during actual assessment while reducing real-time processing time and computational burden.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11522900B2System and method for cyber security threat assessment
Publication Date: 2022.12.06 CYBETA LLC
  • US11522900B2 patent drawing
  • US11522900B2 patent drawing
  • US11522900B2 patent drawing

AI summary

Embodiments of the disclosure provide a system and method for developing rich data for holistic metrics for gauging an enterprise cyber security posture to enable proactive and preventative measures in order to minimize the enterprise's exposure to a cyberattack. By taking an enterprise-wide holistic approach to cyber security, the enterprise will have information needed to identify areas of its network systems for remediation that will result in making the enterprise a less attractive target for cyber threat actors.