Cybersecurity Awareness Assessment via Network Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assessing cybersecurity awareness are subjective, require user participation, and are difficult to implement for large numbers of users, as they rely on questionnaires that may not accurately reflect knowledge or behavior and are not continuously up-to-date.

Innovation Solution

A system that automatically monitors network traffic to compute a cybersecurity awareness score using a machine-learned model, which maps features to a characteristic vector of coefficients, allowing for objective and continuous assessment without user participation, using network probes and software agents to extract relevant features and simulate attacks to verify responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If questionnaires are used to assess cybersecurity awareness, then user participation is required, but the assessment becomes subjective and not continuously up-to-date

Engineering Contradiction:
Improveassessment accuracyVSAvoidautomation level
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The system automatically monitors network traffic and computes cybersecurity awareness scores without requiring active user participation. The monitoring agent continuously observes user behavior patterns, and the processor automatically calculates scores based on predefined criteria, eliminating the need for users to manually complete questionnaires or provide self-assessments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual questionnaire-based assessment with automated network traffic analysis. Instead of relying on users to manually respond to security awareness questions, the system uses network probes to automatically capture traffic data and processes this information to generate objective awareness scores, substituting mechanical user input with automated digital observation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If questionnaires are used to assess cybersecurity awareness, then user participation is required, but the assessment does not continuously reflect current knowledge or behavior

Engineering Contradiction:
Improveassessment reliabilityVSAvoidtime lag
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The monitoring agent continuously monitors network traffic and updates cybersecurity awareness scores in real-time. Instead of conducting periodic assessments, the system operates continuously, capturing user behavior patterns as they occur and immediately processing this data to maintain an up-to-date profile of each user's security awareness level.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary monitoring and analysis of network traffic patterns to predict and identify security awareness issues before they manifest as actual security breaches. By continuously observing behavior patterns in advance, the system can detect emerging risks and update assessments proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If network traffic monitoring is implemented, then objective and continuous assessment is achieved, but device complexity increases

Engineering Contradiction:
Improveautomation levelVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system divides the cybersecurity awareness assessment into separate functional modules: a monitoring agent that collects network traffic data, a processor that analyzes the data and computes scores, and a feedback mechanism that delivers results. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by assigning specific responsibilities to distinct elements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a monitoring agent as an intermediary component between network traffic and the assessment system. This agent acts as a mediator that collects, pre-processes, and forwards traffic data to the processor, simplifying the interaction between complex system components and reducing the complexity burden on the main assessment system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If comprehensive network monitoring is implemented, then comprehensive assessment is achieved, but implementation difficulty increases for large numbers of users

Engineering Contradiction:
Improveassessment comprehensivenessVSAvoidimplementation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The monitoring agent is designed as a universal solution that can be deployed across diverse network environments and user types. The same agent handles different network traffic patterns, device types, and user behaviors through a single unified architecture, making the system scalable and easy to implement for large numbers of users without requiring custom configurations for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11601452B2System and method for assessing cybersecurity awareness
Publication Date: 2023.03.07 BG NEGEV TECHNOLOGIES & APPLICATIONS LTD
  • US11601452B2 patent drawing
  • US11601452B2 patent drawing

AI summary

Described embodiments include a system that includes a monitoring agent, configured to automatically monitor usage of a computing device by a user, and a processor. The processor is configured to compute, based on the monitoring, a score indicative of a cyber-security awareness of the user, and to generate an output indicative of the score.