Cybersecurity Maturity Assessment via Hardware and Software Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity assessment methods are often subjective and labor-intensive, relying on human assessors to evaluate cybersecurity maturity and compliance with standards, which can lead to incomplete and inconsistent results due to human intervention and judgment.

Innovation Solution

A system and method utilizing hardware and software probes to autonomously collect and analyze network data, determining cybersecurity maturity scores based on established maturity models, and transmitting remediation commands to adjust configuration settings, thereby reducing human subjectivity and providing a comprehensive and repeatable assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If human assessors are used to evaluate cybersecurity maturity, then subjective judgment and flexibility are introduced, but labor intensity and inconsistency increase

Engineering Contradiction:
Improveassessment flexibilityVSAvoidhuman intervention complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables automated self-assessment of cybersecurity maturity through probes that autonomously collect data, apply maturity models, and generate scores without human intervention. The cybersecurity maturity manager automatically performs assessments by collecting data from hardware and software probes, applying maturity models, and generating maturity scores, eliminating the need for human assessors while maintaining assessment capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of human assessment with an automated electronic system. Human assessors are substituted by a cybersecurity maturity manager comprising hardware probes, software probes, and a computer processor that automatically collect data, analyze it against maturity models, and determine cybersecurity maturity scores, thereby eliminating labor-intensive manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If automated probes are used to collect cybersecurity data, then objectivity and repeatability improve, but system complexity increases

Engineering Contradiction:
Improveassessment objectivityVSAvoidprobe system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The assessment system is segmented into specialized components: hardware probes for collecting infrastructure data, software probes for collecting configuration data, and a cybersecurity maturity manager for analysis. This segmentation allows each component to perform its specific function efficiently, with hardware probes handling network traffic analysis and software probes handling configuration file analysis, thereby managing complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cybersecurity maturity manager serves multiple functions: it manages hardware probes, manages software probes, collects data from both probe types, applies maturity models, and generates maturity scores. This multi-functionality consolidates complex operations into a single coordinated system, reducing the need for separate specialized systems while maintaining assessment objectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive data collection from multiple probes is performed, then assessment completeness improves, but data processing time increases

Engineering Contradiction:
Improveassessment completenessVSAvoidassessment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary data collection by deploying hardware probes and software probes to continuously gather cybersecurity data before the actual maturity assessment. Hardware probes continuously monitor network traffic, and software probes continuously monitor configuration files, so that when an assessment is needed, the data is already collected and ready for analysis, reducing processing time while maintaining completeness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The probes operate continuously to collect cybersecurity data, maintaining an ongoing stream of information about network traffic and configuration settings. This continuous data collection ensures that the most current and complete information is available for maturity assessment, eliminating the need for repeated data gathering cycles and improving assessment speed without sacrificing completeness.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11451575B2Method and system for determining cybersecurity maturity
Publication Date: 2022.09.20 SAUDI ARABIAN OIL CO
  • US11451575B2 patent drawing
  • US11451575B2 patent drawing
  • US11451575B2 patent drawing

AI summary

A method may include obtaining first cybersecurity data using a hardware probe disposed within a network. The first cybersecurity data may correspond to an analysis of the hardware probe regarding network data that is transmitted through the network. The method may further include obtaining second cybersecurity data using a software probe operating on a network element within the network. The second cybersecurity data may correspond to an analysis of the software probe regarding one or more configuration settings of the network element. The method may further include determining a cybersecurity maturity score using the first cybersecurity data and the second cybersecurity data. The cybersecurity maturity score may be based on a maturity model. The method may further include transmitting, based on the cybersecurity maturity score, a remediation command that adjusts a configuration setting of the network.