Cybersecurity Assessment Segmentation for Private Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public computer networks, commonly used by entities to accommodate guests, are often poorly secured, posing a higher risk of security breaches due to their minimal security characteristics compared to private networks.

Innovation Solution

A system and method for assessing the cybersecurity state of entities by characterizing their computer networks, distinguishing between public and private networks based on service set identifiers (SSIDs), user device activity, and email-related data, and evaluating security characteristics to determine a security rating that excludes public network security traits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public networks are included in cybersecurity assessment, then comprehensive network coverage is achieved, but assessment accuracy deteriorates due to poor security characteristics of public networks

Engineering Contradiction:
Improvecybersecurity state assessment accuracyVSAvoidsecurity risk from public networks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the entity's networks into public and private categories based on network characteristics and access patterns. By dividing the assessment into separate segments, the system can evaluate private networks with higher security expectations independently from public networks that have inherently lower security, thus improving overall assessment accuracy without being skewed by public network vulnerabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and excludes public network security characteristics from the overall cybersecurity state assessment. By removing the harmful influence of public network security traits (which are typically weaker) from the evaluation, the system focuses on assessing the security posture of private networks that are more critical to the entity's core operations and security posture

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If public networks are excluded from cybersecurity assessment, then assessment accuracy improves by focusing on private networks, but network coverage completeness deteriorates

Engineering Contradiction:
Improvecybersecurity state measurement accuracyVSAvoidnetwork assessment coverage
Core Design Contradiction:
Measurement precisionVSArea of stationary object

Solution Approach 1:

The patent segments the network assessment into distinct public and private components, allowing comprehensive coverage of all networks while maintaining measurement precision for private networks. The segmentation enables the system to process and evaluate different network types with appropriate criteria, ensuring both completeness and accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary classification mechanism that identifies and categorizes networks as public or private based on various characteristics. This intermediary step allows the system to maintain comprehensive network coverage while selectively applying different assessment criteria, thereby preserving measurement precision for private networks without sacrificing coverage completeness

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If network security characteristics are evaluated without distinguishing public and private networks, then assessment process is simplified, but security rating accuracy deteriorates

Engineering Contradiction:
Improveassessment process simplicityVSAvoidsecurity rating precision
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent segments the assessment process into distinct phases: network identification and classification, followed by differentiated evaluation. This segmentation maintains operational simplicity by providing a clear workflow while improving rating precision through tailored assessment criteria for public versus private networks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the assessment parameters dynamically based on network type. By adjusting evaluation criteria, weighting, and security expectations according to whether a network is public or private, the system maintains a unified assessment process structure while achieving precise security ratings that reflect the different security postures of different network types

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11050779B1Systems and methods for assessing cybersecurity state of entities based on computer network characterization
Publication Date: 2021.06.29 BITSIGHT TECH
  • US11050779B1 patent drawing
  • US11050779B1 patent drawing
  • US11050779B1 patent drawing

AI summary

Computer-implemented methods are provided for assessing the cybersecurity state of entities based on computer network characterization. The exemplary method can include obtaining, for one or more computer networks of a plurality of computer networks associated with an entity, a network dataset including a service set identifier (SSID); and obtaining a plurality of Internet Protocol (IP) addresses associated with the entity. The method can further include determining whether each of the plurality of computer networks includes a public network or a private network based on the network dataset; and assessing a cybersecurity state of the entity based on an evaluation of security characteristics of the IP addresses attributed to the private network, excluding security characteristics of the IP addresses attributed to the public network.