Holistic Cyber Security Risk Assessment System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cyber security threat assessments for network-connected systems are inadequate as they lack a granular and holistic approach, failing to provide comprehensive insights into the vulnerability and likelihood of attacks across the entire enterprise network.
Innovation Solution
A method and system for predicting cyber security risk that involves collecting network parameters and threat intelligence data, performing Extract, Transform, and Load (ETL) processes, and analyzing this data to generate a holistic cyber security risk score, incorporating vulnerability scoring and exploit severity data to determine component threat scores and a comprehensive risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional vulnerability data collection and analysis methods are used, then vulnerability data can be gathered, but the approach lacks granular and holistic insights into the entire enterprise network
Solution Approach 1:
The patent segments the enterprise network into discrete technological components and assets, assessing each individually for vulnerabilities and threats. This segmentation enables granular measurement precision at the component level while maintaining an organized structure that avoids overwhelming complexity in the overall assessment system.
Solution Approach 2:
The patent introduces a holistic enterprise-level dimension to traditional vulnerability assessment by combining component-level technical data with enterprise-wide contextual factors. This multi-dimensional approach provides comprehensive insights across both granular and aggregate levels without proportionally increasing system complexity.
2Reliability
If comprehensive network parameters and threat intelligence data are collected from multiple sources, then a holistic threat assessment can be achieved, but the data processing and analysis complexity increases
Solution Approach 1:
The patent merges multiple data sources including network parameters, vulnerability data, threat intelligence, and exploit information into a unified assessment framework. This consolidation improves reliability by integrating comprehensive data while managing processing complexity through a structured methodology that combines these elements systematically.
Solution Approach 2:
The patent creates a multi-functional assessment system that handles diverse data types (network parameters, vulnerability scores, threat intelligence, exploit data) through a single integrated framework. This universal approach improves assessment reliability across different data sources while avoiding the need for separate complex processing systems for each data type.
3Measurement precision
If detailed component threat scores are calculated based on vulnerability scoring and exploit severity data, then granular vulnerability identification is improved, but the computational requirements and processing time increase
Solution Approach 1:
The patent performs preliminary calculations of component threat scores by pre-processing vulnerability scoring data and exploit severity data before the main assessment execution. This preliminary action enables rapid generation of detailed vulnerability identifications during actual assessment while reducing real-time processing time and computational burden.
Data Source
AI summary
Embodiments of the disclosure provide a system and method for developing rich data for holistic metrics for gauging an enterprise cyber security posture to enable proactive and preventative measures in order to minimize the enterprise's exposure to a cyberattack. By taking an enterprise-wide holistic approach to cyber security, the enterprise will have information needed to identify areas of its network systems for remediation that will result in making the enterprise a less attractive target for cyber threat actors.


