Cyber Security Threat Index for Monetary Impact Estimation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing cyber attack risks and estimating monetary impact are inadequate, as they fail to accurately predict future attacks, account for potential security holes that may not lead to monetary or customer data loss, and rely on static data that does not reflect actual attack frequencies or previous successful attacks.

Innovation Solution

A system and method for generating a composite Cyber Security Threat Index (CSTI) that collects and synchronizes data from various sources to provide a real-time indication of cyber attack risks, predicts future threats, and calculates the monetary impact of cyber attacks by correlating historical and real-time data using predictive models, allowing for personalized and global risk assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current risk assessment methods scan for potential security issues using static data, then security vulnerabilities can be identified, but the potential monetary impact and frequency of cyber attacks cannot be estimated

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidmonetary impact estimation
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent transitions from static security scanning to dynamic risk assessment by continuously collecting and analyzing historical cyber attack data, security control effectiveness, and real-time threat intelligence to generate updated monetary impact estimates and attack frequency predictions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where collected cyber attack data and security control performance metrics are continuously fed back into the risk assessment model to refine and update monetary impact estimates, creating a self-improving evaluation system

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive data collection and analysis systems are implemented to predict future attacks, then predictive capability improves, but system complexity increases

Engineering Contradiction:
Improvecyber attack prediction accuracyVSAvoiddata collection and analysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex risk assessment system into distinct functional modules: data collection module, data processing module, risk calculation module, and reporting module. Each module handles specific tasks independently, making the overall system more manageable and maintainable while achieving comprehensive predictive capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as standardized data processing pipelines and centralized risk calculation engines that mediate between diverse data sources and the final risk assessment output, simplifying the integration of multiple data sources and analysis methods

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If static security scanning is performed, then potential security holes can be identified, but it cannot determine if attacks will actually occur or their frequency

Engineering Contradiction:
Improvesecurity vulnerability identificationVSAvoidattack frequency prediction capability
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The patent performs preliminary risk assessment by analyzing historical data and security control effectiveness before actual cyber attacks occur, enabling organizations to proactively identify high-risk areas and implement preventive measures ahead of potential attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical security scanning with an intelligent system that uses data-driven analytics, machine learning models, and predictive algorithms to assess risk and predict attack frequency based on patterns in historical cyber attack data

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11356469B2Method and apparatus for estimating monetary impact of cyber attacks
Publication Date: 2022.06.07 BARRACUDA NETWORKS INC
  • US11356469B2 patent drawing
  • US11356469B2 patent drawing
  • US11356469B2 patent drawing

AI summary

A new approach is proposed to support generating and presenting to a user cyber attack monetary impact estimation of a current or future cyber attack, which is used to stop monetary losses or to mitigate monetary impacts. First, both historic data and real time data on monetary impact of current and/or potential cyber attacks is continuously collected from a plurality of data pools. The collected data is then synchronized, correlated and filtered/cleansed once the data is available to create fidelity among the data from the plurality of data pools. The cyber attack monetary impact is calculated based on the correlated and cleansed data, and is presented to the user along with one or more suggested applications by the user in response to the cyber attack monetary impact, to mitigate the monetary impact of the current or future cyber attack.