Dynamic Risk Score for Threat Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security systems face challenges in efficiently mitigating growing numbers of information security threats, such as vulnerabilities and malware, which require significant resources and often necessitate costly downtimes for countermeasures, making it difficult to prioritize and address threats effectively.

Innovation Solution

A system and method that analyze data from various sources to identify threat events, generate threat timelines, extract features using correlation, and calculate a dynamic risk score using machine learning models to prioritize risk mitigation based on estimated threat levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive threat analysis and mitigation measures are implemented, then information security reliability is improved, but system productivity deteriorates due to required downtimes

Engineering Contradiction:
Improveinformation securityVSAvoidsystem operation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of threat data, vulnerability information, and security events to proactively identify and prioritize threats before they can cause harm. By pre-calculating risk scores and preparing mitigation strategies in advance, the system enables security improvements without requiring system shutdowns, thus maintaining productivity while enhancing reliability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If extensive resources are allocated to threat mitigation, then information security reliability is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies local quality by allocating security resources selectively based on the specific characteristics and risk levels of different threats. Rather than uniformly distributing resources across all potential threats, the system identifies high-risk areas and concentrates mitigation efforts where they will have the greatest impact, improving reliability while minimizing overall resource consumption

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the parameter of resource allocation based on evolving threat landscapes, vulnerability assessments, and security event data. By adjusting risk scores and mitigation priorities in real-time, the system optimizes resource utilization to maintain high security reliability without excessive resource consumption

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If manual threat prioritization is performed, then measurement precision is improved, but productivity deteriorates

Engineering Contradiction:
Improvethreat risk assessmentVSAvoidthreat mitigation speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system introduces an intermediary automated analysis layer that processes threat data, vulnerability information, and security events to generate risk scores and prioritization recommendations. This intermediary system combines automated data processing with expert-derived assessment criteria, achieving both high measurement precision in threat risk assessment and high productivity in mitigation speed by eliminating manual analysis bottlenecks

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11748488B2Information security risk management
Publication Date: 2023.09.05 SIXGILL LTD
  • US11748488B2 patent drawing
  • US11748488B2 patent drawing
  • US11748488B2 patent drawing

AI summary

A method, system and computer program product for facilitating risk mitigation of information security threats. Data obtained from at least one tracked data source is analyzed for identifying at least one event related to a threat, to be stored in a database comprising date and time of each event identified, enabling generation of threat timeline comprising temporally ordered sequence of each event related to respective threat identified. Features selected using correlation between features from threat timelines in the database and labeling assigned using records of threat usage incidents are extracted from events in threat timeline for the threat which the at least one event related thereto being identified and based thereon a dynamic score indicating an estimated level of risk posed by the threat is calculated using at least one machine learning model for predicting threat usage during a time window defined, enabling risk mitigation based on outputted indication thereof.