LLM-Based Security Risk Assessment System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for assessing security risks from external computing environments are manual, point-in-time, and lack real-time monitoring, making them ineffective for proactive risk management.
Innovation Solution
A computer-implemented method and system that utilize a large language model (LLM) to assess real-time security risks by identifying risk metrics, correlating them with questions, analyzing mismatches, and computing an aggregated security risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If manual security risk assessment methods are used, then implementation simplicity is maintained, but real-time monitoring capability is lost and assessment timeliness deteriorates
Solution Approach 1:
The patent introduces an intermediary system comprising automated data collection modules, risk metric calculation engines, and assessment generation components that mediate between the external computing environment and the target computing environment. This intermediary automatically gathers security data, calculates risk metrics, and generates assessments without requiring manual intervention, thereby achieving real-time monitoring while managing complexity through modular system design.
Solution Approach 2:
The patent replaces manual mechanical assessment processes with automated computational systems. Instead of human analysts manually evaluating security risks, the system uses automated data collection, algorithmic risk metric calculation, and computer-generated assessment reports. This substitution of mechanical human processes with automated computational mechanisms enables real-time continuous assessment without proportionally increasing system complexity.
2Reliability
If point-in-time assessment methods are used, then resource consumption is reduced, but monitoring continuity is lost and risk detection capability deteriorates
Solution Approach 1:
The patent implements continuous automated data collection and risk assessment generation that operates without interruption. The system continuously monitors security events, calculates risk metrics, and updates assessments in real-time, ensuring uninterrupted risk detection capability. This continuous operation improves reliability by maintaining constant surveillance while the automated efficiency maintains productivity through streamlined processing.
Solution Approach 2:
The system performs self-service by automatically collecting security data, calculating risk metrics, generating assessments, and updating risk profiles without external intervention. The automated system serves itself by continuously monitoring its own security posture and adjusting assessments based on real-time data, thereby maintaining high assessment frequency and reliable detection capability without proportionally increasing resource consumption.
3Measurement precision
If automated real-time assessment systems are implemented, then assessment accuracy and timeliness are improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent segments the automated assessment system into distinct functional modules: data collection modules that gather security events, risk metric calculation engines that compute specific metrics, assessment generation components that synthesize findings, and reporting modules that deliver results. This segmentation allows each component to be developed, tested, and maintained independently, improving overall system accuracy while managing implementation complexity through modular architecture.
Solution Approach 2:
The patent implements universal components that perform multiple functions within the automated assessment system. For example, the risk metric calculation engine can compute various risk metrics using the same underlying framework, and the assessment generation component can produce different types of reports (detailed summaries, alerts, recommendations) from the same data processing pipeline. This multi-functionality improves assessment accuracy through consistent processing while reducing implementation complexity by avoiding redundant components.
4Measurement precision
If comprehensive risk metric analysis is performed, then assessment thoroughness is improved, but processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary actions by pre-defining risk metric calculation frameworks, assessment templates, and analysis protocols before actual risk assessment occurs. The system pre-configures which security events to monitor, which metrics to calculate, and how to synthesize findings into assessments. This preliminary preparation enables comprehensive thoroughness during actual assessment while reducing processing time by avoiding ad-hoc analysis setup.
Solution Approach 2:
The patent dynamically adjusts analysis parameters based on risk levels, event types, and contextual factors. The system can intensify analysis for high-risk events by calculating more comprehensive metrics while reducing analysis depth for low-risk events. This parameter adjustment allows the system to maintain assessment thoroughness for critical risks while reducing average processing time through selective analysis intensity based on changing risk parameters.
Data Source
AI summary
There is provided a computer implemented method of assessing a real time security risk from an external computing environment interfacing with a target computing environment, comprising: identifying a plurality of values of a plurality of risk metrics indicative of a security risk from the external computing environment interfacing with the target computing environment, feeding each of the plurality of values of the plurality of risk metrics into a large language model (LLM), and asking the LLM for which question is correlated with an answer to each value of each risk metric, obtaining a plurality of questions from the LLM, obtaining a plurality of responses to the plurality of questions, analyzing mismatches between the plurality of responses and the plurality of values of the plurality of risk metrics indicative of security risk, and computing the real time security risk according to an aggregation of a plurality of mismatches.

