Cybersecurity Assessment Segmentation for Private Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public computer networks, commonly used by entities to accommodate guests, are often poorly secured, posing a higher risk of security breaches due to their minimal security characteristics compared to private networks.
Innovation Solution
A system and method for assessing the cybersecurity state of entities by characterizing their computer networks, distinguishing between public and private networks based on service set identifiers (SSIDs), user device activity, and email-related data, and evaluating security characteristics to determine a security rating that excludes public network security traits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public networks are included in cybersecurity assessment, then comprehensive network coverage is achieved, but assessment accuracy deteriorates due to poor security characteristics of public networks
Solution Approach 1:
The patent segments the entity's networks into public and private categories based on network characteristics and access patterns. By dividing the assessment into separate segments, the system can evaluate private networks with higher security expectations independently from public networks that have inherently lower security, thus improving overall assessment accuracy without being skewed by public network vulnerabilities
Solution Approach 2:
The patent extracts and excludes public network security characteristics from the overall cybersecurity state assessment. By removing the harmful influence of public network security traits (which are typically weaker) from the evaluation, the system focuses on assessing the security posture of private networks that are more critical to the entity's core operations and security posture
2Measurement precision
If public networks are excluded from cybersecurity assessment, then assessment accuracy improves by focusing on private networks, but network coverage completeness deteriorates
Solution Approach 1:
The patent segments the network assessment into distinct public and private components, allowing comprehensive coverage of all networks while maintaining measurement precision for private networks. The segmentation enables the system to process and evaluate different network types with appropriate criteria, ensuring both completeness and accuracy
Solution Approach 2:
The patent introduces an intermediary classification mechanism that identifies and categorizes networks as public or private based on various characteristics. This intermediary step allows the system to maintain comprehensive network coverage while selectively applying different assessment criteria, thereby preserving measurement precision for private networks without sacrificing coverage completeness
3Ease of operation
If network security characteristics are evaluated without distinguishing public and private networks, then assessment process is simplified, but security rating accuracy deteriorates
Solution Approach 1:
The patent segments the assessment process into distinct phases: network identification and classification, followed by differentiated evaluation. This segmentation maintains operational simplicity by providing a clear workflow while improving rating precision through tailored assessment criteria for public versus private networks
Solution Approach 2:
The patent changes the assessment parameters dynamically based on network type. By adjusting evaluation criteria, weighting, and security expectations according to whether a network is public or private, the system maintains a unified assessment process structure while achieving precise security ratings that reflect the different security postures of different network types
Data Source
AI summary
Computer-implemented methods are provided for assessing the cybersecurity state of entities based on computer network characterization. The exemplary method can include obtaining, for one or more computer networks of a plurality of computer networks associated with an entity, a network dataset including a service set identifier (SSID); and obtaining a plurality of Internet Protocol (IP) addresses associated with the entity. The method can further include determining whether each of the plurality of computer networks includes a public network or a private network based on the network dataset; and assessing a cybersecurity state of the entity based on an evaluation of security characteristics of the IP addresses attributed to the private network, excluding security characteristics of the IP addresses attributed to the public network.


