Diversity Analysis for Cyber Risk Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively determine and mitigate cyber security risk diversity among entities, leading to increased risk due to similarity in attributes, which can result in cascading losses during cyber events.

Innovation Solution

A method and system that analyze sets of variables indicative of entity attributes, compare them to identify clusters of similar variables, calculate probable maximum loss, and provide actionable feedback to end users to decrease this risk by diversifying attributes and infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If entities share similar attributes and infrastructure, then operational efficiency and cost-effectiveness are improved, but cyber security risk and potential losses increase due to correlated vulnerabilities

Engineering Contradiction:
Improvecost-effectivenessVSAvoidcyber security risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system segments entities into clusters based on shared attributes and infrastructure characteristics. By identifying groups of entities with similar vulnerabilities (e.g., same cloud provider, CDN, or technology stack), the system enables targeted risk management strategies for each segment while maintaining cost-effective operations within segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of risk assessment by calculating probable maximum loss (PML) values that reflect correlated cyber risk across entities with shared attributes. This transforms traditional independent risk assessment into a correlated risk model that accounts for shared vulnerabilities, enabling better-informed decisions about maintaining vs. diversifying entity attributes.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If entities diversify their attributes and infrastructure, then cyber security risk is reduced, but operational efficiency and cost-effectiveness may decrease

Engineering Contradiction:
Improvecyber security riskVSAvoidoperational efficiency
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The system provides actionable feedback to entities by calculating their PML values and identifying specific shared attributes that contribute to correlated risk. This feedback loop enables entities to make informed decisions about which shared attributes to maintain (for operational efficiency) and which to diversify (for risk reduction), optimizing the balance between efficiency and security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary risk assessment by calculating probable maximum loss values before cyber events occur. By identifying vulnerable clusters and shared attributes in advance, entities can proactively make strategic decisions about diversification versus consolidation, rather than reacting to losses after events occur.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If traditional independent risk assessment methods are used, then simplicity and ease of calculation are maintained, but accuracy in assessing aggregate cyber risk is reduced

Engineering Contradiction:
Improveassessment complexityVSAvoidrisk assessment accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system merges traditional independent risk assessment with correlation analysis by combining entity-specific vulnerability data with shared attribute information. This integration creates a comprehensive PML calculation that accounts for both individual entity risks and correlated risks across entities with shared infrastructure, providing more accurate aggregate risk assessment.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20160189301A1Diversity Analysis with Actionable Feedback Methodologies
Publication Date: 2016.06.30 GUIDEWIRE SOFTWARE INC
  • US20160189301A1 patent drawing
  • US20160189301A1 patent drawing
  • US20160189301A1 patent drawing

AI summary

Various embodiments of the present technology relate to diversity and similarity analysis. In some exemplary embodiments, a method includes, for each of a plurality of entities, receiving a set of variables that are indicative of attributes of an entity. The exemplary method also includes comparing the sets of variables for the plurality of entities to each other, locating clusters of similar variables shared between two or more of the plurality of entities, determining a probable maximum loss for the plurality of entities that share the clusters, the probable maximum loss being a loss value attributed to a cyber event against one or more of the shared variables, receiving feedback from an end user in response to providing the probable maximum loss to the end user, and updating the probable maximum loss in response to the feedback.