Dynamic Cybersecurity Risk Management for Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity risk management for network connectable devices is inadequate due to challenges in identifying and tracking device vulnerabilities, human-factor-related risks, and timely remediation, leading to increased exposure to cyber-attacks that affect safety, availability, and integrity of data and systems.

Innovation Solution

A dynamic cybersecurity risk management process that creates device risk profiles incorporating technical and human-factor parameters, using network scanning, data collection, gamification, and crowdsourcing to monitor and update risk profiles, and prescribes remediation actions based on role and skill-based decision making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive risk assessment processes are implemented to identify all device vulnerabilities and human-factor risks, then cybersecurity risk management effectiveness is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvecybersecurity risk management effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cybersecurity risk management system into multiple specialized components: device vulnerability assessment modules, human-factor risk evaluation modules, threat indicator analysis modules, and remediation workflow engines. Each module handles specific aspects of risk assessment independently, allowing comprehensive coverage while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary elements such as centralized risk databases, threat intelligence feeds, and automated correlation engines that mediate between various data sources and decision-making processes. These intermediaries aggregate and process information from multiple sources, reducing the complexity burden on individual components while enabling comprehensive risk assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If dynamic monitoring and periodic updating of risk profiles is performed to maintain current risk assessments, then accuracy of risk identification is improved, but time and computational resources are consumed

Engineering Contradiction:
Improveaccuracy of risk identificationVSAvoidtime for monitoring and updating
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements periodic updating mechanisms where risk profiles are reassessed at scheduled intervals rather than continuously. Threat indicators are refreshed periodically from external sources, and device vulnerability assessments are conducted at defined frequencies. This periodic approach maintains accuracy while reducing computational overhead compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent incorporates feedback loops where risk assessment results trigger targeted re-evaluations only when changes are detected. Automated monitoring systems provide feedback on device state changes, threat landscape updates, and human-factor variations, triggering updates only when necessary. This feedback-driven approach maintains precision while minimizing unnecessary time consumption.

Inventive Principle:
Principle #23Feedback

3Quantity of substance

If multiple data collection methods including surveys, gamification, and crowdsourcing are used to obtain human-factor parameters, then completeness of risk profile data is improved, but implementation complexity increases

Engineering Contradiction:
Improvecompleteness of risk profile dataVSAvoidimplementation complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent merges multiple data collection approaches into a unified framework that combines traditional surveys, gamified assessments, and crowdsourced information. These diverse methods are integrated through a central data aggregation layer that harmonizes inputs from different sources, achieving comprehensive human-factor coverage while managing implementation complexity through standardized processing protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent develops multi-functional data collection instruments that serve multiple purposes simultaneously. For example, gamified assessments not only collect human-factor risk data but also engage users, provide security awareness training, and validate device configurations. This universal approach maximizes data completeness while reducing the number of separate implementation components needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If threat indicators from previous cyber-attacks are analyzed and integrated into risk profiles, then ability to predict future attacks is improved, but data processing requirements increase

Engineering Contradiction:
Improveability to predict future attacksVSAvoiddata processing requirements
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts and isolates specific threat indicator elements from historical cyber-attack data that are most relevant to predicting future attacks. Rather than processing entire datasets, the system identifies and extracts key patterns, indicators of compromise, and attack signatures. This extraction approach improves predictive capability while reducing data processing requirements by focusing only on the most critical information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11140193B2Device cybersecurity risk management
Publication Date: 2021.10.05 PATEL JIGAR N
  • US11140193B2 patent drawing
  • US11140193B2 patent drawing
  • US11140193B2 patent drawing

AI summary

A method for implementing cybersecurity risk management for network connectable devices is disclosed. The method involves device vulnerability and risk assessment, risk remediation, compromise detection and incident response. The vulnerability and risk assessment consider both technical and human factors. The method also includes using crowdsourcing methods, such as games and gamification, standalone or in combination with other technologies for inventory development, risk assessment and compromise detection. The risk remediation/mitigation and incident response include prioritized role and skill-based execution of security controls and incident responses, wherein security controls and incident responses can be selected from multiple options based on effectiveness and cost. The method further involves governance of the risk management process in an entity.