Cybersecurity Risk Manager with Decay Function
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial process control and automation systems face challenges in managing cyber-security risks due to unaddressed vulnerabilities in networked devices, where operators lack a complete inventory of equipment, making it difficult to quickly identify potential sources of risk and overwhelming them with new maintenance tasks.
Innovation Solution
A risk manager system that evaluates vulnerabilities, prioritizes risks, and guides users to mitigate them by automatically handling cyber-security risk events through a decay function that reduces the risk value of intermittent events over time, allowing users to focus on persistent threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If operators manually monitor and manage cyber-security risk events, then they can identify and address security vulnerabilities, but they become overwhelmed with maintenance tasks and cannot quickly identify potential sources of risk
Solution Approach 1:
The system automatically monitors, evaluates, and manages cyber-security risk events without requiring manual operator intervention. The risk manager system self-services by continuously scanning for vulnerabilities, calculating risk scores, and prioritizing events, thereby reducing operator workload while maintaining reliable security management
Solution Approach 2:
The patent replaces manual mechanical monitoring and analysis operations with an automated computational system. The risk manager system uses algorithms and automated processes to evaluate security events and calculate risk scores, substituting human operators' manual efforts with automated mechanical-computational systems
2Loss of information
If the system displays all cyber-security risk events to operators, then complete security information is provided, but operators are overwhelmed with information and cannot focus on persistent threats
Solution Approach 1:
The system applies different treatment to different types of security events based on their characteristics. Intermittent events receive different risk scoring and display treatment compared to persistent events, allowing the system to highlight locally-relevant persistent threats while still maintaining complete information about all events in the background
Solution Approach 2:
The risk manager system changes the parameter of risk score over time using decay functions. This transforms static security events into dynamic risk assessments, where the displayed priority of events changes based on persistence and recency, helping operators focus on the most critical persistent threats without losing track of other security information
3Reliability
If the system requires manual acknowledgment of all security events, then complete operator awareness is achieved, but intermittent threats consume operator attention unnecessarily
Solution Approach 1:
The system applies partial acknowledgment requirements based on event characteristics. Only persistent and high-risk events require manual operator acknowledgment, while intermittent low-risk events are automatically managed through decay functions. This partial action approach maintains reliable awareness of critical threats without wasting operator time on minor intermittent events
Data Source
Figure 1
Figure 2
AI summary
This disclosure provides an apparatus and method for automatic handling of cyber-security risk events and other risk events. A method includes detecting (205), by a monitoring system (154), a first event associated with a device in a computing system. The method includes initializing (215) a risk item corresponding to the first event, by the monitoring system (154), and setting the risk item to a full risk value, in response to detecting the event. The method includes determining (220) whether a second event, corresponding to the first event, has been detected. The method includes altering (225) the risk value over time in response to determining that no second event has been detected. The method includes determining (230) if the risk value for the risk item has passed a threshold. The method includes clearing (235) the event in response to the risk value passing the threshold