Cyber Security Risk Model Quantifying Asset Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional analytical techniques for calculating cyber security risks in information handling systems, such as those in maritime environments, are largely qualitative and do not adequately address the quantifiable assessment of risks across diverse and complex asset environments with numerous access points, failing to provide an efficient and accurate risk mitigation strategy.

Innovation Solution

A cyber security risk model and index are developed to quantify cyber security risks by assessing virtual asset security attributes, including functions, connections, and identities, using a model that calculates a relative cyber security risk score to facilitate modifications and adjustments in system configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional qualitative analytical techniques are used to assess cyber security risks, then understanding of risk characteristics is improved, but quantifiability and measurement precision of risks deteriorate

Engineering Contradiction:
Improveunderstanding of risk characteristicsVSAvoidquantifiability of risks
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent transforms qualitative cyber security risk assessment into quantitative assessment by introducing measurable parameters including risk probability (P), risk impact (I), and risk exposure (E). The risk probability is calculated based on vulnerability data and threat intelligence, risk impact is quantified using asset criticality and potential damage metrics, and risk exposure is computed as the product of probability and impact. This parameter transformation enables precise measurement and comparison of cyber security risks across different systems and scenarios.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive risk assessment across diverse asset environments is performed, then coverage and reliability of risk evaluation is improved, but system complexity and difficulty of assessment increase

Engineering Contradiction:
Improvecoverage of risk assessmentVSAvoidcomplexity of assessment system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cyber security risk assessment system into distinct functional modules: asset identification module that catalogs digital assets and their criticality, vulnerability assessment module that evaluates system weaknesses, threat intelligence module that incorporates external threat data, risk calculation module that computes probability and impact metrics, and prioritization module that ranks risks. This segmentation allows comprehensive coverage of diverse asset environments while managing complexity through modular design, where each module handles specific aspects of the assessment independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent standardizes complex risk assessment by transforming diverse security attributes into uniform quantitative parameters. All assets are evaluated using consistent metrics for risk probability (based on vulnerability severity and threat likelihood), risk impact (based on asset criticality and potential damage), and risk exposure (calculated as probability multiplied by impact). This parameter standardization enables reliable comparison across heterogeneous systems while simplifying the assessment process through a unified computational framework.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If detailed security attributes of virtual assets are assessed, then measurement precision of risk evaluation is improved, but ease of operation and implementation difficulty increase

Engineering Contradiction:
Improveprecision of risk evaluationVSAvoidease of implementation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent achieves precise risk evaluation by transforming detailed security attributes into standardized quantitative parameters. Security attributes such as vulnerability severity, asset criticality, and threat likelihood are converted into numerical values for risk probability and risk impact. The risk exposure is then calculated using the straightforward formula E = P × I, where P is risk probability and I is risk impact. This parameter transformation maintains high measurement precision while enabling automated computation and simplifying the assessment process.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements automated risk assessment that reduces manual intervention. The system automatically collects security attribute data from various sources, computes risk metrics using predefined algorithms, and generates prioritized risk lists without requiring extensive manual analysis. This self-service approach maintains high measurement precision through consistent application of calculation formulas while significantly improving ease of operation and reducing implementation complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10791139B2Cyber security risk model and index
Publication Date: 2020.09.29 AMERICAN BUREAU OF SHIPPING
  • US10791139B2 patent drawing
  • US10791139B2 patent drawing
  • US10791139B2 patent drawing

AI summary

A cyber security risk model mitigates cyber security risks for an asset environment (including a virtual asset) by utilizing a functions, connections and identities to determine a cyber security risk index (CSRI). An asset environment may comprise one or more functions where each function has one or more connections associated with any one or more of the functions and one or more identities associated with the virtual asset. A CSRI may be determined for each function based on the cyber security risk model that takes into account the cyber security risks or attributes associated with each function, connection and identity associated with the virtual environment or virtual asset. The asset environment may be adjusted, reconfigured, or otherwise altered based on the CSRI for any given function or for an overall CSRI. An alert may also be triggered based, at least in part, on a determined CSRI.