Digital Identity Risk Prioritization Using Knowledge Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively prioritize and mitigate cyber risks in enterprise networks, particularly focusing on digital identities, due to the lack of automated processes for quantifying and propagating risks across interconnected systems, leading to inadequate defense against cyber-attacks.
Innovation Solution
A system and method for automated prioritization of cyber risk to digital identities, utilizing knowledge graphs to calculate explicit and implicit risks, propagate risks through networks, and generate actionable remedial actions based on risk assessment and tolerance profiles, integrated within an agile security platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security systems monitor and alert all potentially adverse events in the network, then comprehensive security coverage is achieved, but the complexity of managing and prioritizing security alerts increases significantly
Solution Approach 1:
The patent introduces a risk prioritization system that acts as an intermediary between security monitoring systems and security personnel. This system uses knowledge graphs to model relationships between digital identities, assets, and threats, automatically calculating and prioritizing risks based on propagated risk scores. This intermediary layer filters and ranks security alerts, reducing the manual management complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The system implements continuous feedback loops where risk assessments are dynamically updated based on changing network conditions, threat intelligence, and asset criticality. The knowledge graph continuously propagates risk scores across the network model, providing real-time feedback to security personnel about prioritized threats. This automated feedback mechanism reduces the complexity of manual risk assessment while maintaining reliable security monitoring.
2Measurement precision
If knowledge graphs are used to identify vulnerable components and evaluate security fixes, then risk assessment accuracy is improved, but the computational complexity and processing time increase
Solution Approach 1:
The patent pre-computes and stores risk propagation models in the knowledge graph, establishing relationships between digital identities, assets, and potential threats before actual security events occur. Risk scores and propagation paths are pre-calculated and stored, allowing for rapid query and assessment when security events happen. This preliminary action reduces processing time during actual risk assessment while maintaining accurate knowledge graph-based analysis.
Solution Approach 2:
The knowledge graph is segmented into modular components representing different digital identities, assets, and threat types. Each segment can be independently updated and processed, allowing the system to focus computational resources on specific risk areas rather than recalculating the entire network model. This segmentation maintains assessment accuracy while reducing overall processing time through localized computations.
3Productivity
If automated risk propagation and prioritization systems are implemented, then productivity in security operations is improved, but the device complexity and implementation difficulty increase
Solution Approach 1:
The patent implements a universal risk prioritization platform that can be integrated with multiple different security tools, data sources, and network configurations through standardized interfaces. The knowledge graph model is designed to accommodate various asset types, threat models, and organizational structures, allowing the system to serve multiple security functions across different environments. This universality improves productivity across diverse security operations while managing implementation complexity through consistent architectural patterns.
Data Source
AI summary
Implementations are directed to methods, systems, and apparatus for automated prioritization of cyber risk to digital identities. Actions include obtaining graph data defining a knowledge graph including nodes and edges, the nodes representing respective objects of the enterprise network including digital identities and resources, each node being associated with an explicit risk score and properties of the represented object, each edge representing a relation between objects; determining priority scores for the objects, including, for a first object represented by a first node: determining an implicit risk score for the first node; determining a total risk score for the first node; and determining a priority score for the first node based on the total risk score and properties associated with the first node; generating a ranking of the objects according to the priority scores; and providing, for presentation on a display, cyber security risk data indicating the ranking of the objects.


