Cybersecurity Risk Score Automation via Cyber-Physical Graph

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack the capability to generate comprehensive cybersecurity scores for computer networks using heterogeneous data, and they do not provide automated recommendations for improving cybersecurity or applying changes to enhance security scores.

Innovation Solution

A system and method that utilize a reconnaissance engine to gather data from various sources, evaluate and weight individual vulnerability and risk factors, and generate a comprehensive cybersecurity score. This system can automatically apply recommended changes to improve the cybersecurity score and reassess the risk score for actual impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If comprehensive cybersecurity scoring using heterogeneous data is implemented, then cybersecurity risk assessment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvecybersecurity risk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the cybersecurity assessment process into distinct functional modules: a reconnaissance engine for data gathering, a scoring engine for analysis, and an automated improvement engine for implementation. Each module handles specific aspects of the heterogeneous data processing, making the overall complex system manageable and maintainable while achieving comprehensive risk assessment accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cyber-physical graph as an intermediary data structure that standardizes and integrates heterogeneous cybersecurity data from multiple sources. This graph serves as a mediator between diverse data formats and the scoring engine, enabling accurate risk assessment without requiring the entire system to directly handle all data heterogeneity complexities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated recommendation and change application is implemented, then cybersecurity improvement efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvecybersecurity improvement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service capabilities where the automated improvement engine independently analyzes cybersecurity gaps, generates recommendations, applies changes to the cyber-physical graph, and reassesses risk scores without requiring continuous human intervention. This automation significantly improves cybersecurity improvement efficiency while the modular architecture keeps the complexity manageable

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where the reassessment of cybersecurity risk scores after applying changes provides information back to the improvement engine. This feedback mechanism enables the system to automatically adjust and refine its improvement strategies, increasing efficiency while maintaining a structured approach to complexity management

Inventive Principle:
Principle #23Feedback

3Reliability

If transparent and traceable methodology is used for cybersecurity scoring, then score reliability is improved, but processing time increases

Engineering Contradiction:
Improvescore reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The reconnaissance engine performs preliminary data gathering and validation before the main scoring process. By pre-processing and organizing heterogeneous data into the cyber-physical graph structure in advance, the system ensures reliable and traceable scoring methodology while reducing the processing time required during the actual assessment phase

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12301626B2Automatically computing and improving a cybersecurity risk score
Publication Date: 2025.05.13 QOMPLX INC
  • US12301626B2 patent drawing
  • US12301626B2 patent drawing
  • US12301626B2 patent drawing

AI summary

Automatically computing and managing a cybersecurity risk score. The cybersecurity risk score and cyber-physical graph for a network are retrieved and analyzed to identify potential improvements that can be made to network topography and device configurations, changes are applied automatically and an updated cyber-physical graph reflecting the applied changes is produced, and the updated cyber-physical graph is reassessed to determine the effect of the changes that were applied.