Endpoint Security Scoring via Segmented Risk Dimensions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures fail to effectively evaluate and prioritize the biggest threats to distributed systems, which are often the end users and system configurations, necessitating a method to quantify and rank endpoint user security risk across large networks.

Innovation Solution

A lightweight software application is deployed across endpoints to generate a Relative Score based on various dimensions such as user hygiene, forensic readiness, defense, and other security metrics, allowing for centralized ranking and resource allocation to high-risk users and machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security assessment services are provided to evaluate all aspects of enterprise distributed systems, then security coverage is improved, but device complexity and resource requirements increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive security assessment into multiple independent dimensions (user hygiene, forensic readiness, defense, insider threat, spear phishing, exfiltration, physical security). Each dimension is evaluated separately through specific software instructions that collect and analyze data for that particular aspect, allowing the overall assessment to be built from modular, manageable components rather than a single complex assessment system.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed security metrics are collected and analyzed across all endpoints, then measurement precision is improved, but loss of time and computational resources increase

Engineering Contradiction:
Improveendpoint risk assessment precisionVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by deploying software instructions on endpoints that continuously collect and pre-process security-relevant data in the background. Dimensions such as user hygiene metrics, forensic readiness status, and defense configurations are monitored and prepared in advance, so that when assessment is needed, the data is already organized and ready for analysis, eliminating the need for time-consuming on-demand data collection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating a virtual representation of the endpoint's security state through software instructions that replicate security metrics and characteristics. Instead of analyzing the actual complex system state directly, the assessment system works with copied data representations (scores and metrics) that capture the essential security posture, enabling faster analysis without requiring deep inspection of the actual endpoint systems.

Inventive Principle:
Principle #26Copying

3Ease of operation

If quantitative scoring and ranking of endpoints is implemented, then ease of operation for resource allocation is improved, but manufacturing precision of security metrics decreases

Engineering Contradiction:
Improveresource allocation easeVSAvoidsecurity metric accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent applies parameter changes by transforming complex, multi-dimensional security data into simplified numerical scores with standardized ranges (e.g., 0-100 scales for each dimension). The raw security metrics from various sources are converted into comparable quantitative parameters through normalization and weighting schemes, enabling straightforward ranking and comparison while maintaining the essential security information through carefully designed scoring algorithms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11683332B2Method and apparatus for measuring information system device integrity and evaluating endpoint posture
Publication Date: 2023.06.20 SIX ENGINES LLC
  • US11683332B2 patent drawing
  • US11683332B2 patent drawing

AI summary

Methods, devices, and systems disclosed herein measure endpoint user security event susceptibility (e.g., a malware infection) and provide information for endpoint/user posture evaluation. A relatively small software application may be installed using, for example, a systems management push system where the software runs on each endpoint system and reports back to a central repository or base system. The software runs on machines that it is pushed to and generates a score for that endpoint. That score is a quantification of endpoint user security risk, i.e., the likelihood that a particular endpoint is likely to be the source of a security event at some point in the future. This information may be used to generate a Relative Score for each endpoint so that the endpoints can be ranked from most secure to least secure and an Absolute Score so that a given distributed system can be compared to other distributed systems.