External Cybersecurity Risk Scoring via Network Prefix Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing cybersecurity breach risk in organizations are subjective and lack a robust, generic measure, relying on fine-grained network traffic data that is challenging to convert into a comprehensive risk score.

Innovation Solution

A computer-implemented predictive analytics system that assesses cybersecurity breach risk by scoring individual network prefixes and combining scores to generate an overall organization score, using externally visible data and features indicative of cybersecurity posture, such as DNS resolvers, SSL/TLS configurations, and reputation blacklists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fine-grained network traffic data is used for risk assessment, then measurement precision is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improverisk assessment precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the most critical security features from fine-grained network traffic data (e.g., DNS resolver configuration, SSL/TLS certificate validity, port openness) rather than analyzing all available data points. This extraction approach maintains measurement precision for risk assessment while significantly reducing system complexity by focusing on a curated subset of externally-visible features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer of pre-defined security features that act as mediators between raw network traffic data and final risk scores. These features serve as a simplified interface, translating complex network observations into standardized security indicators that are easier to process and interpret without losing essential risk information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If fine-grained network traffic data is collected, then measurement precision is improved, but ease of operation worsens

Engineering Contradiction:
Improverisk assessment precisionVSAvoiddata collection ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent extracts only the most critical security features from fine-grained network traffic data (e.g., DNS resolver configuration, SSL/TLS certificate validity, port openness) rather than analyzing all available data points. This extraction approach maintains measurement precision for risk assessment while significantly reducing system complexity by focusing on a curated subset of externally-visible features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer of pre-defined security features that act as mediators between raw network traffic data and final risk scores. These features serve as a simplified interface, translating complex network observations into standardized security indicators that are easier to process and interpret without losing essential risk information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If subjective expert assessments are used, then ease of operation is improved, but measurement precision deteriorates

Engineering Contradiction:
Improveassessment easeVSAvoidrisk score objectivity
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent replaces the mechanical system of subjective expert judgment with an automated computational system that objectively calculates risk scores based on observable network features. The system uses algorithmic processing of security features (DNS configuration, SSL certificates, port scans) to generate standardized risk assessments, eliminating human subjectivity while maintaining operational simplicity through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms subjective expert assessments into objective parameter-based measurements by defining specific, quantifiable security features (e.g., number of open ports, certificate validity status, DNS resolver responses). This parameterization allows risk assessment to be performed through automated comparison of measurable attributes rather than subjective evaluation, improving both objectivity and consistency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10791136B2System and method for empirical organizational cybersecurity risk assessment using externally-visible data
Publication Date: 2020.09.29 INSTITUTIONAL SHAREHOLDER SERVICES
  • US10791136B2 patent drawing
  • US10791136B2 patent drawing
  • US10791136B2 patent drawing

AI summary

A system and method for assessing the cybersecurity breach risk associated with a given organization is disclosed. The system and method assume no internal visibility into any organizational network. A taxonomy of possible data sources is defined and motivated. The system and method are both purely empirical and robust against common difficulties in scoring organizational networks, such as the raw number of network assets owned by the organization.