Network Risk Assessment via Segmented Node Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity practices are inefficient and ineffective in securing 'crown jewel' data due to a lack of clear identification of sensitive data, inadequate understanding of data access points, and insufficient targeted protection measures, leading to increased risks from sophisticated attacks and data breaches.
Innovation Solution
A method and system for determining and distributing a network security risk assessment that involves a risk assessment server and viewer application, which evaluates software applications and organizational nodes within a network, assigning scores based on accessibility and interconnection weights, and provides notifications when predefined thresholds are exceeded, allowing for focused protection of critical data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all data is secured in the same manner as crown jewel data, then data security is improved, but cost and computing resource efficiency deteriorate
Solution Approach 1:
The patent implements differentiated security measures by identifying crown jewel data and applying enhanced security protocols specifically to those data elements, while using standard security measures for other data. This local quality approach ensures that computing resources are concentrated where most needed (on critical data) rather than uniformly applied across all data, thereby maintaining high security for sensitive information while improving overall resource efficiency.
2Measurement precision
If comprehensive data inventory and analysis are performed, then identification of crown jewel data is improved, but time and computational overhead increase
Solution Approach 1:
The patent performs preliminary automated analysis of data assets, security controls, and risk factors to pre-identify potential crown jewel data before a formal risk assessment is initiated. This preliminary action includes automated discovery of data repositories, classification of data sensitivity, and pre-calculation of risk metrics, which significantly reduces the time required for comprehensive analysis while maintaining high identification accuracy.
Solution Approach 2:
The patent replaces manual, mechanical processes of data inventory and risk assessment with automated computational systems that continuously monitor and analyze data assets. This substitution uses algorithms to automatically classify data, evaluate security controls, and calculate risk scores, thereby maintaining precise identification of crown jewel data while dramatically reducing the time and human resources required compared to traditional manual assessment methods.
3Reliability
If detailed risk assessment of all software applications and organizational nodes is performed, then security risk identification is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent segments the risk assessment process into distinct modular components: software application risk assessment, organizational node risk assessment, and overall organization risk assessment. Each component evaluates specific properties independently (e.g., application security controls, node access rights), and results are aggregated to determine overall risk. This segmentation maintains high risk identification accuracy while reducing system complexity by breaking down the assessment into manageable, reusable modules.
Data Source
AI summary
Network security risk assessment systems and methods are provided. The system has a remote subscriber computer, a risk assessment viewer application, and a risk assessment server that receives a list of software applications operating within the subscriber organization network and a plurality of properties for each of the software applications, and receives a list of organizational nodes within the subscriber organization and a plurality of properties for each of the organizational nodes, determines one or more risk assessment scores and transmits a notification to the remote subscriber computer when a predefined reporting threshold is exceeded.


