Flexible Risk Analyzer for Communication Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security risk management tools for communication networks lack the ability to consolidate risk impacts at the network and service levels, are inflexible, and rely on proprietary, fixed risk calculation formulas that fail to account for the complexity of modern security scenarios, making it difficult to assess vulnerabilities and prioritize risk mitigation effectively.

Innovation Solution

A risk analysis system and method that includes a risk analyzer to assess security risks specific to features of a communication network, such as services or missions, using a flexible security model and customizable risk calculation formulas, which consider physical and logical assets, vulnerabilities, and their relationships to provide a comprehensive and realistic risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary and fixed risk calculation formulas are used, then the system has a defined calculation method, but the system lacks flexibility and cannot adapt to complex security scenarios

Engineering Contradiction:
Improveflexibility of security modelVSAvoidcomplexity of risk calculation system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic risk calculation by allowing the system to adaptively select and adjust risk calculation formulas based on different security scenarios, asset types, and vulnerability characteristics. The risk analysis engine can dynamically modify calculation parameters and choose appropriate formulas rather than relying on fixed proprietary methods, enabling the system to respond flexibly to changing security conditions while maintaining manageable complexity through structured decision logic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables parameter changes by allowing customization of risk calculation inputs including asset values, vulnerability severities, threat levels, and contextual factors. Users can modify these parameters based on specific security assessments, and the system recalculates risk metrics accordingly. This approach provides flexibility in adapting to different security scenarios without requiring a complete redesign of the calculation framework.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If network-wide security analysis is performed on all assets, then comprehensive coverage is achieved, but the analysis becomes too broad and loses focus on specific services or missions

Engineering Contradiction:
Improveprecision of risk assessmentVSAvoidscope of analysis
Core Design Contradiction:
Measurement precisionVSArea of stationary object

Solution Approach 1:

The patent implements segmentation by dividing the network into service-specific or mission-specific segments for targeted risk analysis. Instead of analyzing all assets uniformly, the system allows users to define specific scopes (e.g., particular services, missions, or network segments) and performs risk assessments focused on those selected areas. This segmentation maintains comprehensive coverage capabilities while enabling precise, focused analysis when needed, improving both precision and operational efficiency.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive security assessment of all assets is conducted, then complete risk picture is obtained, but the assessment takes too much time to complete

Engineering Contradiction:
Improvecompleteness of security assessmentVSAvoidtime for vulnerability assessment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by enabling users to perform risk assessments on selected subsets of assets rather than requiring complete analysis of all network assets. The risk analysis engine can focus on specific services, missions, or high-priority assets based on user selection or automated prioritization criteria. This approach provides timely security insights for critical areas while maintaining the option to expand assessment scope as needed, balancing completeness with time efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements preliminary action by performing preliminary risk assessments and prioritization before conducting detailed analysis. The risk analysis engine can quickly evaluate assets to identify high-risk areas that require immediate attention, allowing operators to focus comprehensive assessment efforts on the most critical assets. This preliminary triage approach ensures that time-sensitive security decisions can be made based on the most important risks while maintaining the option to conduct fuller assessments later.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1724990B1Communication network security risk exposure management systems and methods
Publication Date: 2022.11.23 HUAWEI TECH CO LTD
  • EP1724990B1 patent drawingFigure 1
  • EP1724990B1 patent drawingFigure 2
  • EP1724990B1 patent drawingFigure 3

AI summary

Communication network security risk exposure management systems and methods are disclosed. Risks to a communication network are determined by analyzing assets of the communication network and vulnerabilities affecting the assets. Assets may include physical assets such as equipment or logical assets such as software or data. Risk analysis may be adapted to assess risks to a particular feature of a communication network by analyzing assets of the communication network which are associated with that feature and one or more of vulnerabilities which affect the feature and vulnerabilities which affect the assets associated with the feature. A feature may be an asset itself or a function or service offered in the network and supported by particular assets, for example.