Cyber Security Threat Index for Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid increase in digital interactions and content sharing has led to significant security risks in cyber attacks, with users lacking sensors and urgency to assess and remediate threats effectively, as they do in the physical world.

Innovation Solution

A system and method for generating a composite Cyber Security Threat Index (CSTI) that collects, synchronizes, and correlates data from various sources to assess and forecast cyber attack risks, providing users with actionable insights to prevent or mitigate attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data collection and analysis systems are implemented to assess cyber threats, then security awareness and risk assessment capability improve, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity risk assessment capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Cyber Security Threat Index (CSTI) as an intermediary mechanism that mediates between complex security data and user comprehension. The CSTI translates multifaceted security threats into a single comprehensible numerical value, allowing users to assess risks without directly engaging with the underlying complexity of security systems, data sources, and analysis mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms complex security assessment parameters into a simplified single-parameter representation (the CSTI score). By converting multiple security metrics, threat indicators, and risk factors into one composite index value, the system maintains comprehensive security monitoring while presenting results in a simplified form that reduces perceived system complexity for end users.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive security monitoring and data correlation are implemented, then threat detection accuracy improves, but information processing time and computational resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously collecting and pre-processing security data from multiple sources in the background, maintaining synchronized data readiness without requiring intensive processing at the moment of threat assessment. The system proactively prepares security intelligence, correlating data and updating the CSTI in advance, so that when threats need to be assessed, the information is already processed and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuous useful action by implementing ongoing data collection, synchronization, and correlation processes that run continuously in the background. This continuous operation maintains up-to-date security intelligence without requiring periodic intensive processing bursts, thereby improving threat detection accuracy while minimizing interruptions and reducing peak computational resource demands.

Inventive Principle:
Principle #20Continuity of useful action

3Speed

If real-time cyber threat assessment is provided, then user response time to threats improves, but system resource consumption and operational complexity increase

Engineering Contradiction:
Improveuser response timeVSAvoidsystem resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential security information needed for user decision-making by presenting the synthesized CSTI score rather than overwhelming users with raw security data, threat details, and analysis metrics. This extraction approach enables users to quickly grasp the current security posture and respond appropriately while the system maintains comprehensive monitoring in the background with reduced presentation overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a simplified copy or representation of the complex security state through the CSTI index. Instead of requiring users to process the full complexity of security data, the system generates a simplified numerical copy that mirrors the essential security condition, enabling rapid user response while the actual comprehensive security analysis continues separately in the background with minimal user system resource consumption.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10778714B2Method and apparatus for generating cyber security threat index
Publication Date: 2020.09.15 BARRACUDA NETWORKS INC
  • US10778714B2 patent drawing
  • US10778714B2 patent drawing
  • US10778714B2 patent drawing

AI summary

A new approach is proposed to support generating and presenting a single composite Cyber Security Threat Index (CSTI) to a user, wherein the CSTI provides the user with an indication of risk of cyber attacks globally and/or in the context of his/her current networking environment. First, various pools of operational data are collected over networks, systems, and/or products, wherein such data includes files being weaponized in the cyber attacks against computer systems and networks, the surfaces and contexts on which the cyber attacks are launched, and influential factors on these data. The data collected from various pools is then synchronized, correlated, and filtered/cleansed so that it can be used to assess risk of the cyber attacks. The CSTI is calculated based on the correlated data on the cyber attacks and interactively presented to the user, who then takes corresponding remediation actions to prevent a cyber attack from happening or spreading.