Cyber Threat Intelligence Supply Chain Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack an effective method to assess and mitigate cyber security risks within an organization's supply chain, as they primarily focus on internal network monitoring without adequately accounting for vulnerabilities in connected organizations.

Innovation Solution

A method and system that utilize cyber-threat intelligence infrastructure to process and summarize network data, identifying service suppliers and their vulnerability exposure, which is then weighted to determine an organization's overall vulnerability exposure, incorporating enrichment data and session summaries to generate risk scores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network monitoring focuses only on internal organization traffic, then internal security threats can be detected, but supply chain vulnerabilities remain undetected

Engineering Contradiction:
Improveinternal security detectionVSAvoidsupply chain vulnerability exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security assessment into two distinct components: internal organization network monitoring and external service supplier chain monitoring. By separating these functions, the system can independently assess internal security posture while simultaneously evaluating external supply chain risks, thereby detecting both internal threats and supply chain vulnerabilities without conflating the two assessment domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that connects internal network monitoring with external service supplier assessment. This intermediary enables the flow of security intelligence between the organization's internal network and its external service suppliers, allowing threats from the supply chain to be detected and correlated with internal security events, thus bridging the gap between internal and external security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive supply chain assessment is implemented, then overall cybersecurity risk understanding improves, but system complexity increases

Engineering Contradiction:
Improvecybersecurity risk assessment accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal assessment framework that serves multiple functions simultaneously: it monitors internal network traffic, evaluates external service suppliers, identifies vulnerabilities, and generates risk scores all through a single integrated system. This multi-functional approach enables comprehensive supply chain assessment without proportionally increasing system complexity, as the same infrastructure performs diverse security assessment tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes by dynamically adjusting assessment weights and risk scoring parameters based on the specific characteristics of each service supplier and organizational context. By changing assessment parameters rather than creating entirely separate assessment systems for different suppliers, the patent achieves precise, customized risk measurement while maintaining system efficiency and avoiding unnecessary complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10812519B2Cyber threat intelligence threat and vulnerability assessment of service supplier chain
Publication Date: 2020.10.20 BCE
  • US10812519B2 patent drawing
  • US10812519B2 patent drawing
  • US10812519B2 patent drawing

AI summary

Determining the cyber threat risk and vulnerability of an organization may be determined taking in to account the chain of service suppliers to the organization.