Third-Party Risk Assessment via Dark Web Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional risk assessment methods fail to account for unforeseen events like 'acts of God' and cyber-attacks, which are driven by specific objectives and resources, necessitating a more sophisticated approach to modeling and predicting threats, especially in cyber environments.

Innovation Solution

A computer-implemented system that leverages machine learning to assess third-party risks by crawling and analyzing data from the dark web and deep web, using predetermined keywords to filter and preprocess hacker conversations, and applying anomaly detection and feature extraction techniques to generate predictive models for cyber insurance and other assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional risk assessment methods are used, then traditional insurance risk analysis is maintained, but unforeseen events like cyber-attacks and acts of God cannot be assessed

Engineering Contradiction:
Improverisk assessment coverageVSAvoidprediction accuracy for unforeseen events
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adapts its risk assessment model by integrating multiple data sources (dark web monitoring, news feeds, social media) and adjusting predictions based on emerging threats. The machine learning model continuously learns from new data patterns, enabling it to assess unforeseen events like cyber-attacks and natural disasters that were not part of traditional static insurance models.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The risk assessment system is designed to evaluate multiple types of risks simultaneously - cyber threats, natural disasters, and traditional insurance risks - through a unified platform. It processes diverse data types including text from dark web forums, news articles, and social media posts, making it universally applicable to various unforeseen events beyond conventional assessment scope.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If dark web and deep web data crawling is implemented, then hacker conversation analysis capability is improved, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata processing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant features from vast amounts of dark web and deep web data using natural language processing and machine learning techniques. It identifies and isolates key indicators of cyber threats from unstructured text, filtering out noise and focusing computational resources on high-value signals that indicate actual risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces intermediary processing layers including data crawling agents, natural language processing modules, and feature extraction components that mediate between raw dark web data and the core risk assessment engine. These intermediaries transform unstructured text into structured risk indicators, simplifying the integration of complex data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If machine learning models are trained on diverse data sources, then risk prediction comprehensiveness is improved, but data processing time and computational resources increase

Engineering Contradiction:
Improverisk assessment comprehensivenessVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary processing of data from multiple sources including crawling, cleaning, and feature extraction before feeding data into the machine learning model. By pre-processing and structuring data in advance, it reduces the computational burden during actual risk assessment, enabling faster predictions while maintaining comprehensive analysis of diverse data sources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different processing techniques and levels of analysis to different data sources based on their specific characteristics. For example, dark web forum posts may undergo more intensive natural language processing compared to structured news feeds, optimizing computational resources while maintaining comprehensive risk coverage across all data types.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11336673B2Systems and methods for third party risk assessment
Publication Date: 2022.05.17 THE ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIV OF ARIZONA
  • US11336673B2 patent drawing
  • US11336673B2 patent drawing
  • US11336673B2 patent drawing

AI summary

Embodiments for systems and methods for third party assessment related to the evaluation of risks associated with third parties in which hacker conversations on websites are filtered and analyzed using keywords as input to uncover relevant forum and marketplace discussions are disclosed herein.