Cybersecurity Scoring Engine Using Graph Analysis for Insurance Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity assessment methods lack a comprehensive and holistic approach to evaluate network threats and security capabilities, failing to accurately score organizations' cybersecurity posture due to heterogeneous data sources and inadequate use of time-graphs and machine learning for insurance purposes.

Innovation Solution

A system comprising sensors, multi-dimensional time-series databases, and a cybersecurity scoring engine that crawls internet resources and public databases to gather and analyze data from diverse sources, generating a weighted cybersecurity rating by assessing vulnerabilities, patching frequency, and other factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple data sources are gathered to improve cybersecurity assessment comprehensiveness, then the accuracy and completeness of security profiles improve, but the complexity of data collection and processing increases due to heterogeneous data formats and sources

Engineering Contradiction:
Improvecybersecurity assessment accuracyVSAvoiddata collection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs intermediate processing layers including web crawlers, data normalization services, and standardized data models that act as mediators between heterogeneous data sources and the analysis engine. These intermediaries transform diverse data formats into a unified structure, enabling comprehensive security assessment without directly managing the complexity of multiple sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms heterogeneous data by changing its parameters and format through normalization processes. Data from different sources is converted to standardized schemas with consistent data types, time formats, and structural representations, allowing the analysis engine to process diverse information uniformly while maintaining assessment accuracy.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If time-graphs and machine learning are implemented to analyze cybersecurity trends, then the ability to detect patterns and predict threats improves, but the computational resources and processing time required increase

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary data processing and feature extraction before applying machine learning algorithms. Time-graphs are pre-computed from historical data, and relevant features are extracted and stored in optimized formats. This preliminary action reduces the computational burden during actual threat analysis, enabling reliable pattern detection with lower real-time resource consumption.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If comprehensive reconnaissance is performed to establish full security profiles, then the completeness of cybersecurity information improves, but the time and computational effort required for data collection increases

Engineering Contradiction:
Improvesecurity information completenessVSAvoiddata collection time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system implements a tiered reconnaissance approach that performs partial comprehensive scans at different intervals. Critical security parameters are monitored continuously with high frequency, while less critical parameters are assessed periodically. This partial action strategy maintains information completeness for essential security metrics while reducing overall data collection time and resource expenditure.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20220263852A1System and method for cybersecurity analysis and score generation for insurance purposes
Publication Date: 2022.08.18 QOMPLX INC
  • US20220263852A1 patent drawing
  • US20220263852A1 patent drawing
  • US20220263852A1 patent drawing

AI summary

A system for comprehensive cybersecurity analysis and rating based on heterogeneous data and reconnaissance is provided, comprising a multidimensional time-series data server configured to create a dataset with at least time-series data gathered from passive or active network reconnaissance of a client or target; and a cybersecurity scoring engine configured to retrieve the dataset from the multidimensional time-series data server, process the dataset using at least computational graph analysis, and generate an aggregated cybersecurity score based at least on results of processing the dataset.