Cyber Security Risk Assessment Using Digital Asset Entity Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack an efficient method to track and assess cyber security risks associated with digital assets across various entities, as existing technologies struggle to accurately map and update relationships between digital assets and their owners or managers, particularly in complex internet service provider environments.
Innovation Solution
A system that receives customer account data from service providers, processes it to update a database with mappings of digital assets to entities, and evaluates security risks based on changes in these mappings, using digital asset identifiers like IP addresses and domain names, and merges information from multiple sources to determine events such as IP address allocations and changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If customer account data is collected and processed to map digital assets to entities, then the accuracy of entity maps and security risk assessment is improved, but the system complexity and data processing requirements increase
Solution Approach 1:
The system segments the complex task of entity mapping into distinct processing stages: data collection from service providers, data preprocessing and validation, entity identification and matching, digital asset mapping, and security risk evaluation. Each stage handles specific aspects of the data, reducing overall system complexity while maintaining mapping accuracy.
Solution Approach 2:
The patent introduces intermediary components including data preprocessing modules that standardize incoming account data, entity resolution services that match entities across different data sources, and mapping databases that store standardized relationships. These intermediaries simplify the core mapping function by handling data normalization and validation.
2Loss of information
If digital asset mappings are updated frequently to track changes, then the depth and timeliness of security risk assessment is improved, but the data processing time and computational resources increase
Solution Approach 1:
The system implements periodic updates of entity maps by scheduling regular processing cycles that collect account data from service providers at predetermined intervals. Changes in digital asset mappings are detected and processed during these periodic cycles, ensuring up-to-date security assessments without continuous processing overhead.
Solution Approach 2:
The patent applies preliminary filtering and validation to incoming account data before full processing. Changes in digital asset mappings are pre-identified and validated against existing entity maps, allowing the system to process only relevant updates rather than reprocessing all data, thus reducing processing time while maintaining depth of information.
3Loss of information
If multiple data sources are merged to enhance entity maps, then the comprehensiveness of security risk information is improved, but the difficulty of data integration and preprocessing increases
Solution Approach 1:
The system employs universal data schemas and standardized formats that can accommodate multiple data sources including service provider account data, public records, and security databases. The entity resolution service is designed to handle various data types and formats, enabling comprehensive information integration without requiring separate processing pipelines for each source.
Solution Approach 2:
The patent transforms data from different sources into a common parameter structure during preprocessing. Entity identifiers, digital asset associations, and security attributes are normalized to standardized parameters, allowing seamless integration of multiple data sources while simplifying subsequent processing and analysis operations.
4Reliability
If security risk evaluation is performed based on detailed mapping changes, then the reliability of security assessment is improved, but the computational resources and processing power required increase
Solution Approach 1:
The system performs security risk evaluation selectively based on the type and significance of mapping changes detected. High-priority changes such as new entity creations, significant digital asset allocations, or changes involving previously assessed entities trigger comprehensive security evaluations, while minor updates use streamlined assessment procedures, optimizing resource usage while maintaining assessment reliability.
Data Source
AI summary
Among other things, customer account data is received from a service provider. The customer account data is representative of relationships that exist at successive times between digital assets provided by the service provider and respective entities to whom the digital assets are provided by the service provider. The received data is used to update a database to represent mappings of digital assets to respective entities to whom the digital assets are provided at one of the successive times, changes in the mappings between successive times, or both.


