Enterprise Security Simulation for Malware Response Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex enterprises face challenges in analyzing dynamic behavior and achieving optimal production and security due to circular, interlocking relationships among elements, exacerbated by increased remote accessibility and malware threats.

Innovation Solution

A system and method that uses computer simulation to model enterprise elements, evaluate their effectiveness, and determine an information security level by simulating various events and actions, including responses to malware attacks, to maximize effectiveness and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If computerized control systems are made remotely accessible and linked to networks to improve productivity and communication, then ease of operation and productivity are improved, but vulnerability to malware attacks and security threats increases

Engineering Contradiction:
Improveremote accessibilityVSAvoidmalware attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments and simulations before actual malware attacks occur. By pre-evaluating security postures and testing response procedures in advance, the system prepares defense mechanisms ahead of time, enabling faster and more effective response when actual attacks happen, thus resolving the contradiction between remote accessibility and security vulnerability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors security events and uses this feedback to dynamically adjust security measures and response strategies. By analyzing actual attack patterns and simulation results, the system refines its security posture in real-time, allowing the enterprise to maintain remote accessibility while adapting security defenses to counter evolving threats

Inventive Principle:
Principle #23Feedback

2Productivity

If complex enterprise systems are modeled to analyze dynamic behavior and optimize production, then productivity and effectiveness are improved, but device complexity and difficulty of analysis increase

Engineering Contradiction:
Improveproduction effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system creates virtual copies or simulations of complex enterprise systems to analyze their behavior without affecting actual operations. By working with replicated models rather than the complex real systems directly, the system can perform extensive analysis and optimization while maintaining manageable complexity in the simulation environment

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system divides complex enterprise systems into manageable segments or modules for analysis. By breaking down the overall system into smaller, more manageable components that can be simulated and analyzed independently, the system reduces the complexity burden while still capturing the essential dynamics needed for optimization

Inventive Principle:
Principle #1Segmentation

3Reliability

If security measures are increased to protect against malware attacks, then security reliability is improved, but loss of time and productivity decrease

Engineering Contradiction:
Improvesecurity levelVSAvoidtime for security measures
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs security assessments, simulations, and response procedure testing in advance rather than reacting to attacks in real-time. By preparing security measures and response plans beforehand, the system reduces the time needed to respond to actual attacks, thereby maintaining high security reliability without significant productivity loss

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous security monitoring and simulation operations that run alongside business operations rather than interrupting them. This continuous approach allows security measures to be updated and maintained without stopping production, ensuring both high security reliability and minimal time loss

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9178902B1System and method for determining enterprise information security level
Publication Date: 2015.11.03 AO KASPERSKY LAB
  • US9178902B1 patent drawing
  • US9178902B1 patent drawing
  • US9178902B1 patent drawing

AI summary

Disclosed are systems, methods and computer program product for determining information security level for an enterprise. An example method comprising: collecting information relating to a structure of the enterprise, including a plurality of elements of the enterprise; creating a model to correspond to each element of the enterprise based on at least one function of each element; identifying criteria to evaluate an effectiveness of the at least one function of each element; simulating operation of the elements and determining effectiveness of the at least one function of each simulated element, wherein simulating includes determining different sequences of events and actions in response to the events for one or more simulation iterations based on the effectiveness of the at least one function of each element; and determining an information security level for the enterprise by maximizing the effectiveness of functions of the elements in response to events.