Cybersecurity Risk Remediation via Zone Rating Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions are inadequate in effectively assessing and remediating cybersecurity risks in large computer networks with diverse resources, as they lack the ability to accurately identify critical risks and require manual, framework-specific calculations, making it challenging to prioritize and address vulnerabilities in a timely manner.

Innovation Solution

A cybersecurity solution that includes a system, method, and computer program capable of receiving data from computing resources, selecting a risk framework (such as OWASP, CVSS, or TRIKE), calculating risk scores, and remediating risks by assigning resources based on calculated risk ratings, allowing for automated and tailored remediation within each network zone.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual framework-specific risk calculations are performed, then measurement precision of risk assessment is improved, but loss of time and productivity deteriorate

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidtime for risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically selecting appropriate risk frameworks and executing calculations without requiring manual intervention. The risk assessment system autonomously processes computing resources, selects frameworks based on resource types, and computes risk scores automatically, eliminating the need for manual framework-specific calculations while maintaining measurement precision.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters by dynamically selecting different risk frameworks (OWASP, CVSS, TRIKE, OCTAVE) based on the type of computing resource being assessed. This parameter change allows the system to adapt the assessment methodology to match the specific characteristics of each resource type, maintaining accuracy while standardizing the process to reduce time consumption.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If automated risk assessment is implemented, then productivity is improved, but measurement precision of risk scoring deteriorates

Engineering Contradiction:
Improverisk assessment efficiencyVSAvoidrisk score accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where risk scores are calculated, stored in a scoreboard, and used to determine remediation priorities. The feedback loop ensures that automated calculations are continuously refined and validated, maintaining measurement precision while achieving high productivity through automation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system achieves universality by supporting multiple risk frameworks (OWASP, CVSS, TRIKE, OCTAVE) within a single automated platform. This multi-functionality allows the system to maintain measurement precision across different assessment methodologies while achieving productivity improvements through unified automated processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If zone risk ratings are applied to override individual risk ratings, then reliability of risk management is improved, but device complexity increases

Engineering Contradiction:
Improverisk management consistencyVSAvoidrisk rating comparison logic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network into zones, each with its own risk rating, and compares individual resource risk ratings against their respective zone ratings. This segmentation approach improves reliability by ensuring consistent risk management at the zone level while managing complexity through modular, hierarchical comparison logic that processes each zone independently.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If multiple risk frameworks are supported, then adaptability to different computing resources is improved, but device complexity increases

Engineering Contradiction:
Improveframework selection capabilityVSAvoidrisk framework management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamics by automatically selecting the appropriate risk framework based on the type of computing resource being assessed. The framework selection is not static but adapts dynamically to the resource characteristics, improving versatility while managing complexity through automated, context-aware selection rather than manual configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11799917B2System, method, and computing medium to remediate cybersecurity risks based on a risk rating
Publication Date: 2023.10.24 SAUDI ARABIAN OIL CO
  • US11799917B2 patent drawing
  • US11799917B2 patent drawing
  • US11799917B2 patent drawing

AI summary

A system, a method, and a computer program remediate a risk of a computing resource located in a computer network that has a plurality of other computing resource assets each having an associated risk. Data associated with a first computing resource is received, and a first risk framework is selected from among a plurality of risk frameworks. A risk score is calculated based on the received data and the selected first risk framework, and a first risk rating is determined based on the risk score. The first risk rating is compared against a zone risk rating to determine whether the first risk rating is greater than the zone risk rating, and the first risk rating is replaced by the zone risk rating when the zone risk rating is greater than the first risk rating. The cybersecurity risk of the first computing resource is remediated according to the first risk rating.