Network Risk Assessment via Active Scanning and Logistic Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network risk management technologies rely on passive analysis, which is inadequate for real-time vulnerability detection and lacks flexibility to provide custom assessments based on specific risk profiles, often resulting in inaccurate and stale data.

Innovation Solution

A method involving active scanning and flexible definitions for network risk management, including sampling networks, assessing security features, ranking them based on risk, transforming factors into categorized elements, and building a logistic model that blends these factors into a likelihood of breach, with real-time configurability and customization options through a graphical user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If passive analysis is used to determine network risk, then system complexity is reduced, but measurement precision and timeliness of vulnerability detection deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidvulnerability detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent replaces passive mechanical analysis with active automated scanning systems that use software agents to proactively detect vulnerabilities. This substitution enables real-time, precise vulnerability identification without manually increasing system complexity, as the automation handles the complexity internally.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces risk assessment models and scoring systems as intermediaries between raw scan data and risk decisions. These models process and interpret vulnerability data, providing precise risk measurements while keeping the overall system architecture manageable through modular design.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If fixed analysis approaches are used, then device complexity is reduced, but adaptability to specific risk profiles deteriorates

Engineering Contradiction:
Improveanalysis approach complexityVSAvoidcustomization to risk profiles
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic risk assessment models that can be configured and adjusted based on specific organizational risk profiles. The system allows users to modify assessment parameters, weights, and criteria through graphical interfaces, enabling adaptability without requiring complex custom development for each scenario.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables customization by allowing users to change parameters such as risk weights, assessment criteria, and scanning configurations. These parameter adjustments let organizations tailor the risk assessment to their specific needs while maintaining the underlying system structure.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If historical data is used for risk assessment, then data collection complexity is reduced, but measurement precision and timeliness deteriorate

Engineering Contradiction:
Improvedata collection complexityVSAvoidrisk assessment accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent performs vulnerability scans and risk assessments proactively before breaches occur, rather than relying on historical breach data. This preliminary action ensures current, accurate risk measurements by detecting vulnerabilities in real-time before they can be exploited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and recurring scanning capabilities that maintain up-to-date risk assessments. This continuous action ensures risk data remains current and accurate without requiring complex manual updates or relying on stale historical information.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240356984A1Systems and methods for network risk management, cyber risk management, security ratings, and evaluation systems and methods of the same
Publication Date: 2024.10.24 FORTIFYDATA INC
  • US20240356984A1 patent drawing
  • US20240356984A1 patent drawing
  • US20240356984A1 patent drawing

AI summary

A method of building a risk management model, the method including: sampling a plurality of organization networks; assessing identified security features; ranking the identified security features based on security risk; transforming ranked features into categorized factors; building logistic model to blend the categorized factors into a likelihood of breach; and transforming the logistics model from a multiplicative model to an additive model by scaling the logistics model.