Multi-layer Risk Model for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security breach prevention methods are inadequate in identifying and mitigating unique, customized malware targeting specific enterprise networks, as they rely on recognizing previously encountered malware traits and patterns, which are ineffective against rapidly mutating or newly designed threats.

Innovation Solution

A comprehensive approach that models and mitigates security risk vulnerabilities by systematically identifying and analyzing all connected devices within an enterprise network, generating a risk heat map, and developing an enterprise risk model to predict and address potential breaches through a multi-layered risk assessment and mitigation strategy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus software and firewalls rely on recognizing previously encountered malware traits and patterns, then they can effectively identify known threats, but they fail to detect unique, customized malware designed to breach specific enterprise network defenses

Engineering Contradiction:
Improvesecurity breach prevention effectivenessVSAvoidability to detect unique customized malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by proactively identifying and classifying all devices within the enterprise network before threats occur. The system creates a comprehensive risk model that pre-establishes security baselines, device categories, and risk profiles for all network components. This preliminary characterization enables the system to detect anomalies and unique malware behaviors that deviate from established patterns, rather than relying on recognition of previously encountered threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements parameter changes by dynamically adjusting risk scores and security parameters based on real-time network conditions, device characteristics, and threat intelligence. The system continuously updates the enterprise risk model by modifying parameters such as device vulnerability ratings, exposure levels, and risk priorities. This dynamic parameter adjustment allows the system to adapt to new threats and customized malware without requiring pre-existing pattern recognition rules.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive risk modeling and mitigation strategies are implemented across the entire enterprise network, then security coverage and detection capability are improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity risk identification accuracyVSAvoidrisk modeling system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the enterprise network into distinct device categories and risk groups based on functional characteristics, vulnerability profiles, and exposure levels. The system segments the network into core infrastructure devices, endpoint devices, network infrastructure, and cloud-based resources. This segmentation allows for targeted risk assessment and mitigation strategies for each category, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different risk assessment methodologies, security policies, and mitigation strategies tailored to specific device types, network segments, and risk profiles. Rather than using a uniform approach across the entire network, the system customizes security parameters and monitoring intensity based on local characteristics of each device and segment. This localized approach optimizes resource allocation and reduces complexity by focusing detailed analysis only where necessary.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10250631B2Risk modeling
Publication Date: 2019.04.02 BALBIX INC
  • US10250631B2 patent drawing
  • US10250631B2 patent drawing
  • US10250631B2 patent drawing

AI summary

Approaches for modeling a risk of security breaches to a network. Agents gather, from multiple sources across the network, analysis data that identifies observed characteristics of habitable nodes and opaque nodes. Using the analysis data a multi-layer risk model for the network is generated that comprises a first layer that models an inherent risk of security breaches to assets of the network based on the observed characteristics. The model also comprises a second layer that models a present state of the inherent risk to the assets caused by global and temporal events. The model also comprises a third layer that models a change to the risk of security breaches in response to potential mitigative actions. The model may be used to understand how risk of a security breach is distributed and interdependent upon the nodes of the network so as to allow the most valuable preventive measures to be taken.