Hierarchical SaaS Risk Scoring for Automated Exposure Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SaaS applications are vulnerable to security threats, leading to data breaches, identity and access management issues, weak encryption, and compliance problems, which can result in financial loss, reputational damage, and legal repercussions, with limited user control over security measures.

Innovation Solution

A scoring system that assigns an exposure metric to cloud-based services by configuring dimensions, identifying resource and policy metrics in a multi-dimensional vector space, aggregating these metrics, and alerting end-user devices about the service's stability or instability, using a scoring server and client/vendor-configured policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users implement resource-intensive security systems for SaaS applications, then security protection is improved, but user control and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a scoring server as an intermediary between users and SaaS applications. This server automatically evaluates security risks by analyzing multiple dimensions (data security, authentication, encryption, compliance) and generates exposure metrics without requiring user intervention. Users simply receive risk scores and recommendations, eliminating the complexity of implementing and managing resource-intensive security systems while maintaining strong security protection through automated assessment and vendor-driven security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If comprehensive security audits and assessments are conducted, then security vulnerabilities are reduced, but time consumption and productivity deteriorate

Engineering Contradiction:
Improvesecurity vulnerabilitiesVSAvoidtime consumption
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary security assessments by pre-configuring multiple security dimensions (data security, authentication, encryption, compliance) and continuously monitoring SaaS applications against these criteria. Rather than conducting time-consuming audits on demand, the scoring server maintains ongoing security evaluations, pre-identifying vulnerabilities and generating exposure metrics before incidents occur. This allows organizations to proactively address security issues without interrupting business operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security audit processes with an automated computational system. The scoring server uses algorithmic evaluation across multiple security dimensions to generate exposure metrics, substituting human analysts and manual assessment procedures with automated data collection, analysis, and scoring mechanisms. This mechanical substitution dramatically reduces time consumption while maintaining comprehensive vulnerability detection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If detailed security metrics and dimensions are tracked, then measurement precision is improved, but device complexity and system architecture worsen

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsystem architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments security assessment into four distinct dimensions: data security (data loss prevention, encryption), authentication (MFA, password policies), compliance (regulatory adherence), and vendor security (vendor assessments). Each dimension is evaluated independently with specific metrics, allowing precise measurement of security posture across different aspects. The scoring server processes each dimension separately and aggregates results into comprehensive exposure metrics, maintaining measurement precision while organizing complexity into manageable segments.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250245348A1Hierarchical risk scoring for security of SAAS applications
Publication Date: 2025.07.31 NETSKOPE INC
  • US20250245348A1 patent drawing
  • US20250245348A1 patent drawing
  • US20250245348A1 patent drawing

AI summary

A scoring system to assign an exposure metric to a service accessed by multiple end-user devices in an application layer of a cloud-based system. The scoring system includes multiple tenants comprising multiple end-user devices and a scoring server. The scoring server configures dimensions that are functions of the service. The scoring server identifies a resource and determines a resource metric that is a weight of the resource in a dimension. The scoring server further receives a policy and calculates a policy metric that is distance of the policy from origin of a vector space, and also aggregates the policies and/or the dimensions, retrieves a dimension metric, and computes the exposure metric for the service. The scoring server stores the exposure metric and determines the status of the service based on the comparison of the exposure matrix with the threshold. And alerts the end-user device about the status of the service.