Network Asset Prioritization via Security Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for prioritizing assets in a network based on security metrics are inefficient, prone to errors, and unable to adapt to real-time changes in network traffic, especially in large enterprises with thousands of assets.
Innovation Solution
A method that calculates a security metric for assets by analyzing network data, including the number of hosts and users accessing the asset, and adjusts security policies based on these metrics, independent of vulnerability assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual asset prioritization is performed by security analysts, then security management can be performed on assets, but the process becomes time-consuming, error-prone, and inconsistent across multiple analysts
Solution Approach 1:
The system enables assets to self-report their operational status, performance metrics, and security events through embedded agents. This automated self-service approach eliminates manual assessment by security analysts, providing consistent, real-time data collection across all assets without human intervention or time constraints.
Solution Approach 2:
The patent replaces the mechanical manual process of security analysts assessing and prioritizing assets with an automated computational system. The system uses algorithms to process security metrics, vulnerability data, and operational statistics, substituting human judgment with consistent machine-based analysis that operates continuously without fatigue or inconsistency.
2Reliability
If vulnerability-based methods are used to prioritize assets, then security risks can be identified, but the computational complexity increases significantly when analyzing millions of application vulnerabilities
Solution Approach 1:
The patent segments the vulnerability analysis process by categorizing assets into different types (infrastructure assets, application assets, data assets) and applying type-specific metrics and analysis methods. This segmentation allows the system to handle millions of vulnerabilities by processing them in manageable categories rather than as a monolithic complex problem.
Solution Approach 2:
The system dynamically changes analysis parameters based on asset type, risk level, and current security context. Instead of applying uniform complex analysis to all assets, the system adjusts the depth and scope of vulnerability analysis parameters, focusing computational resources on high-priority assets while using streamlined assessment for lower-priority ones.
3Adaptability or versatility
If traditional security monitoring methods are used, then security events can be detected, but the system cannot adapt to real-time changes in network traffic and asset importance
Solution Approach 1:
The system implements continuous monitoring and calculation of security metrics without interruption. Agents continuously collect data, and the system continuously updates asset priority rankings in real-time, ensuring uninterrupted security oversight and immediate detection of changing conditions in the network environment.
Solution Approach 2:
The system incorporates feedback loops where security metrics, vulnerability assessments, and operational data continuously inform and adjust asset prioritization. This feedback mechanism enables real-time adaptation to network changes, with the system automatically re-ranking assets based on updated information about security events, traffic patterns, and emerging threats.
Data Source
AI summary
This disclosure describes techniques for identifying the criticality of an asset in a network. In an example method, a first security metric of a first asset in a network, as well as network data that identifies data flows associated with a second asset in the network are identified. The second asset is a nearest neighbor of the first asset in the network. The method includes determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period and generating a second security metric of the second asset based on the first security metric and the number of hosts. A security policy of the second asset is adjusted based on the security metric.


