LLM-Based Security Risk Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assessing security risks from external computing environments are manual, point-in-time, and lack real-time monitoring, making them ineffective for proactive risk management.

Innovation Solution

A computer-implemented method and system that utilize a large language model (LLM) to assess real-time security risks by identifying risk metrics, correlating them with questions, analyzing mismatches, and computing an aggregated security risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual security risk assessment methods are used, then implementation simplicity is maintained, but real-time monitoring capability is lost and assessment timeliness deteriorates

Engineering Contradiction:
Improveassessment timelinessVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising automated data collection modules, risk metric calculation engines, and assessment generation components that mediate between the external computing environment and the target computing environment. This intermediary automatically gathers security data, calculates risk metrics, and generates assessments without requiring manual intervention, thereby achieving real-time monitoring while managing complexity through modular system design.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical assessment processes with automated computational systems. Instead of human analysts manually evaluating security risks, the system uses automated data collection, algorithmic risk metric calculation, and computer-generated assessment reports. This substitution of mechanical human processes with automated computational mechanisms enables real-time continuous assessment without proportionally increasing system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If point-in-time assessment methods are used, then resource consumption is reduced, but monitoring continuity is lost and risk detection capability deteriorates

Engineering Contradiction:
Improverisk detection capabilityVSAvoidassessment frequency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuous automated data collection and risk assessment generation that operates without interruption. The system continuously monitors security events, calculates risk metrics, and updates assessments in real-time, ensuring uninterrupted risk detection capability. This continuous operation improves reliability by maintaining constant surveillance while the automated efficiency maintains productivity through streamlined processing.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs self-service by automatically collecting security data, calculating risk metrics, generating assessments, and updating risk profiles without external intervention. The automated system serves itself by continuously monitoring its own security posture and adjusting assessments based on real-time data, thereby maintaining high assessment frequency and reliable detection capability without proportionally increasing resource consumption.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If automated real-time assessment systems are implemented, then assessment accuracy and timeliness are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem implementation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the automated assessment system into distinct functional modules: data collection modules that gather security events, risk metric calculation engines that compute specific metrics, assessment generation components that synthesize findings, and reporting modules that deliver results. This segmentation allows each component to be developed, tested, and maintained independently, improving overall system accuracy while managing implementation complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universal components that perform multiple functions within the automated assessment system. For example, the risk metric calculation engine can compute various risk metrics using the same underlying framework, and the assessment generation component can produce different types of reports (detailed summaries, alerts, recommendations) from the same data processing pipeline. This multi-functionality improves assessment accuracy through consistent processing while reducing implementation complexity by avoiding redundant components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If comprehensive risk metric analysis is performed, then assessment thoroughness is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveassessment thoroughnessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining risk metric calculation frameworks, assessment templates, and analysis protocols before actual risk assessment occurs. The system pre-configures which security events to monitor, which metrics to calculate, and how to synthesize findings into assessments. This preliminary preparation enables comprehensive thoroughness during actual assessment while reducing processing time by avoiding ad-hoc analysis setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically adjusts analysis parameters based on risk levels, event types, and contextual factors. The system can intensify analysis for high-risk events by calculating more comprehensive metrics while reducing analysis depth for low-risk events. This parameter adjustment allows the system to maintain assessment thoroughness for critical risks while reducing average processing time through selective analysis intensity based on changing risk parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12299139B1Assessment of security risk from an external computing environment
Publication Date: 2025.05.13 LEMA LABS LTD
  • US12299139B1 patent drawing
  • US12299139B1 patent drawing

AI summary

There is provided a computer implemented method of assessing a real time security risk from an external computing environment interfacing with a target computing environment, comprising: identifying a plurality of values of a plurality of risk metrics indicative of a security risk from the external computing environment interfacing with the target computing environment, feeding each of the plurality of values of the plurality of risk metrics into a large language model (LLM), and asking the LLM for which question is correlated with an answer to each value of each risk metric, obtaining a plurality of questions from the LLM, obtaining a plurality of responses to the plurality of questions, analyzing mismatches between the plurality of responses and the plurality of values of the plurality of risk metrics indicative of security risk, and computing the real time security risk according to an aggregation of a plurality of mismatches.