Dynamic Misuseability Scoring for IT Infrastructure Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and mitigating cyber-attacks on IT infrastructure are hindered by the need for manual risk analysis, which is time-consuming and fails to account for the dynamic nature of IT assets, and do not effectively assess the misuseability of all IT elements, including servers, routers, and users beyond data leakage.

Innovation Solution

A method and framework that automatically and dynamically derive a misuseability score for each IT element by collecting and analyzing data from these elements, considering parameters like configuration, purpose, activity, and connectivity, to identify potential damage and prioritize protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual risk analysis process is used to identify critical assets, then the organization can focus resources on protecting high-value assets, but the process is time-consuming and fails to reflect dynamic changes in asset value over time

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated self-assessment of IT elements by collecting data directly from the elements themselves and automatically calculating misuseability scores, eliminating the need for manual analyst intervention while continuously tracking dynamic changes in asset value and risk profiles

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of risk analysis with an automated computational system that collects data, analyzes connections between IT elements, and calculates misuseability scores algorithmically, enabling real-time updates without human intervention

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive data collection from all IT elements is performed to assess misuseability, then the organization can identify potential damage from various cyber-attacks, but the amount of data to be analyzed becomes massive and complex

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoiddata analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant parameters needed for misuseability assessment from each IT element (such as configuration, purpose, and activity data), rather than analyzing all possible data, thereby reducing complexity while maintaining assessment reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the overall risk assessment into individual misuseability scores for each IT element, allowing the system to process and analyze each element separately based on its specific parameters, then aggregate the results to provide comprehensive security assessment

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional security solutions are deployed to protect IT infrastructure, then some level of protection is provided, but the variety and costs of security solutions increase without addressing the dynamic nature of threats

Engineering Contradiction:
Improveprotection effectivenessVSAvoidsecurity solution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic security assessment by continuously calculating misuseability scores as IT elements and their connections change, allowing protection strategies to adapt automatically to evolving threats and infrastructure changes rather than relying on static security configurations

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the approach from fixed security parameters to dynamic misuseability parameters that are recalculated based on current data from IT elements, enabling the security system to respond to changing conditions without increasing operational complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10192057B2Misuseability analysis for it infrastructure
Publication Date: 2019.01.29 BG NEGEV TECHNOLOGIES & APPLICATIONS LTD
  • US10192057B2 patent drawing
  • US10192057B2 patent drawing

AI summary

The present invention relates to a method and a framework that automatically and dynamically derives a misuseability score for every IT component (e.g., PC, laptop, server, router, smartphone, and user or any other element that can be connected to organization network or to the internet). The dynamic framework of the present invention supports the risk analysis process. The misuseability score encapsulates the potential damage that can be caused to the organization in case that an asset is compromised and misused, for example, as part of a cyber-attack.