Network Asset Prioritization via Security Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for prioritizing assets in a network based on security metrics are inefficient, prone to errors, and unable to adapt to real-time changes in network traffic, especially in large enterprises with thousands of assets.

Innovation Solution

A method that calculates a security metric for assets by analyzing network data, including the number of hosts and users accessing the asset, and adjusts security policies based on these metrics, independent of vulnerability assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual asset prioritization is performed by security analysts, then security management can be performed on assets, but the process becomes time-consuming, error-prone, and inconsistent across multiple analysts

Engineering Contradiction:
Improveconsistency of asset prioritizationVSAvoidtime required for manual asset assessment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables assets to self-report their operational status, performance metrics, and security events through embedded agents. This automated self-service approach eliminates manual assessment by security analysts, providing consistent, real-time data collection across all assets without human intervention or time constraints.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of security analysts assessing and prioritizing assets with an automated computational system. The system uses algorithms to process security metrics, vulnerability data, and operational statistics, substituting human judgment with consistent machine-based analysis that operates continuously without fatigue or inconsistency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If vulnerability-based methods are used to prioritize assets, then security risks can be identified, but the computational complexity increases significantly when analyzing millions of application vulnerabilities

Engineering Contradiction:
Improveaccuracy of security risk assessmentVSAvoidcomputational complexity of vulnerability analysis
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability analysis process by categorizing assets into different types (infrastructure assets, application assets, data assets) and applying type-specific metrics and analysis methods. This segmentation allows the system to handle millions of vulnerabilities by processing them in manageable categories rather than as a monolithic complex problem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes analysis parameters based on asset type, risk level, and current security context. Instead of applying uniform complex analysis to all assets, the system adjusts the depth and scope of vulnerability analysis parameters, focusing computational resources on high-priority assets while using streamlined assessment for lower-priority ones.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If traditional security monitoring methods are used, then security events can be detected, but the system cannot adapt to real-time changes in network traffic and asset importance

Engineering Contradiction:
Improvereal-time adaptation to network changesVSAvoidefficiency of security metric calculation
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements continuous monitoring and calculation of security metrics without interruption. Agents continuously collect data, and the system continuously updates asset priority rankings in real-time, ensuring uninterrupted security oversight and immediate detection of changing conditions in the network environment.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system incorporates feedback loops where security metrics, vulnerability assessments, and operational data continuously inform and adjust asset prioritization. This feedback mechanism enables real-time adaptation to network changes, with the system automatically re-ranking assets based on updated information about security events, traffic patterns, and emerging threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12244616B2Prioritizing assets using security metrics
Publication Date: 2025.03.04 CISCO TECHNOLOGY INC
  • US12244616B2 patent drawing
  • US12244616B2 patent drawing
  • US12244616B2 patent drawing

AI summary

This disclosure describes techniques for identifying the criticality of an asset in a network. In an example method, a first security metric of a first asset in a network, as well as network data that identifies data flows associated with a second asset in the network are identified. The second asset is a nearest neighbor of the first asset in the network. The method includes determining, based on the network data, a number of hosts in the network that exchanged data traffic with the second asset during a time period and generating a second security metric of the second asset based on the first security metric and the number of hosts. A security policy of the second asset is adjusted based on the security metric.