Dual Network Security Assessment Engine for Customizable Threat Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in efficiently and timely detecting vulnerabilities due to constant changes in network configurations and emerging threats, making it difficult to manage analysis of security risks effectively.

Innovation Solution

A dual network security assessment engine that executes agent programs on computerized devices to perform security tests, generating both authoritative and configurable security scores based on weighted combinations of test results, allowing for customizable threat analysis and prioritization of remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional single-scoring security assessment systems are used, then the system is simple to operate, but it cannot provide customized threat analysis and prioritization for different organizational needs

Engineering Contradiction:
Improvecustomizability of security assessmentVSAvoidcomplexity of assessment engine
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security assessment into two distinct scoring systems: an authoritative score that reflects overall security posture using standardized weights, and a configurable score that allows organizational customization of threat prioritization. This segmentation enables both standardization and adaptability without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dual scoring system serves multiple functions simultaneously: the authoritative score provides standardized benchmarking and compliance measurement, while the configurable score enables organization-specific threat prioritization and customized security program alignment, making the system universally applicable to diverse organizational needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If comprehensive security tests are executed across the network, then detection precision is improved, but the time required for analysis increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements configurable weightings that allow organizations to emphasize or de-emphasize specific security test categories based on their risk profile and priorities. This partial action approach enables focused analysis on high-priority areas while maintaining comprehensive testing capability, reducing analysis time without sacrificing detection precision in critical areas.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If security test results are weighted equally, then the assessment is straightforward to calculate, but it cannot prioritize threats according to organizational risk profiles

Engineering Contradiction:
Improvesimplicity of score calculationVSAvoidthreat prioritization capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic weightings for security test results that can be configured to reflect organizational risk profiles, threat landscapes, and security program priorities. This dynamic approach allows the same assessment framework to adapt to different organizations and changing conditions while maintaining a straightforward calculation mechanism through systematic weight application.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11799894B2Dual network security assessment engine
Publication Date: 2023.10.24 GEN DIGITAL INC
  • US11799894B2 patent drawing
  • US11799894B2 patent drawing
  • US11799894B2 patent drawing

AI summary

A method of determining the security condition of a network includes executing an agent program on one or more computerized devices coupled to the network. Each executing agent program executes one or more security tests and reports the results of such tests to a network assessment engine, and the network assessment engine determines an authoritative security test score and a configurable security test score for the network based on a weighted combination of the security test results.