Interactive Confidence-Based Graph for Internet Asset Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The vast amount of information on the Internet makes it difficult for enterprises to efficiently monitor and manage their Internet-facing assets, leading to challenges in compliance, security, and identifying potential threats, as existing solutions do not provide a complete view of an organization's attack surface.

Innovation Solution

An asset discovery platform that uses a network analytic system and discovery and inventory system to generate a digital footprint of Internet assets, applying policies to determine ownership and relationships, and providing an interactive graphical interface to visualize and manage these assets, enabling better risk management and security decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises expose more computer assets to the Internet to provide services, then service capability and business reach are improved, but the attack surface increases and security risk increases

Engineering Contradiction:
Improveservice capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary discovery and inventory of Internet-facing assets before threats can exploit them. By continuously crawling and identifying assets in advance, the system enables proactive security measures rather than reactive responses to breaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback loops that track asset exposure, ownership, and security status. This feedback mechanism allows enterprises to adjust their security posture dynamically based on real-time information about their attack surface.

Inventive Principle:
Principle #23Feedback

2Reliability

If enterprises use traditional security tools like firewalls and endpoint devices, then basic security protection is provided, but a complete view of the attack surface is not achieved

Engineering Contradiction:
Improvesecurity protectionVSAvoidvisibility of attack surface
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system provides a universal platform that combines asset discovery, inventory management, ownership determination, and security monitoring in one integrated solution. This multi-functional approach replaces multiple separate tools and provides comprehensive visibility that traditional specialized tools cannot achieve alone.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system acts as an intermediary between various security tools and enterprise assets, providing a centralized view that connects firewalls, endpoint devices, and other security infrastructure to a unified attack surface model, enabling coordinated security operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the number of Internet assets increases, then business capability expands, but tracking and identifying assets becomes difficult

Engineering Contradiction:
Improvebusiness capabilityVSAvoidasset tracking
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system segments the complex landscape of Internet assets into manageable units organized by ownership, asset type, and relationship. By dividing the asset inventory into discrete, categorizable segments, the system makes large-scale asset tracking feasible and intuitive despite the growing number of assets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses visual indicators and color-coding to represent different asset ownership states, security statuses, and risk levels. This visual encoding transforms complex asset data into easily interpretable graphical representations, maintaining ease of operation as asset numbers grow.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11765197B2Interactive display of a confidence-based graph of internet related assets
Publication Date: 2023.09.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11765197B2 patent drawing
  • US11765197B2 patent drawing
  • US11765197B2 patent drawing

AI summary

An inventory of Internet-facing assets related to a target domain is generated using network data gathered from network data sources. Using data sources of known threats, such as malware, phishing attempts, scam pages, blacklisted sites, and so on, a network analytic system generates analytical information about domains, sub-domains, and components that are owned, managed, and/or controlled by a target entity. A confidence score of ownership is generated based on a recursive rule engine. A visual representation of the inventory of Internet-facing assets is generated in a graphical user interface.