Network Security Assessment Engine for Multitenant Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques fail to accurately identify and communicate security risks within local networks, despite the importance of network security due to threats from malware and other vulnerabilities.

Innovation Solution

A network security assessment engine that executes security tests on various properties of computing devices and networks, receives and analyzes test results, determines security scores, and presents an overall network security score along with contributing factors, enabling effective risk communication and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional monitoring services are used to track network performance and activity, then basic network management is achieved, but security risks cannot be identified or communicated

Engineering Contradiction:
Improvenetwork security assessmentVSAvoidsecurity risk identification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the security assessment process into multiple independent security tests, each evaluating specific properties (firewall configuration, encryption, authentication, etc.). Each test operates independently and contributes to the overall security score, allowing comprehensive assessment without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary assessment engine that collects data from multiple security tests and synthesizes it into a comprehensive security evaluation. This intermediary layer translates raw test results into actionable security insights and risk communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple security tests are executed on network properties, then comprehensive security assessment is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity risk detection accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal assessment engine that handles multiple types of security tests through a single unified system. The engine can execute diverse security tests (firewall, encryption, authentication, malware detection) using the same underlying infrastructure, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of assessment from qualitative security evaluations to quantitative security scores. By converting various security test results into standardized numerical scores, the system simplifies complexity while maintaining measurement precision.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If detailed security test results are collected from all computing devices, then accurate security scoring is achieved, but data processing requirements increase

Engineering Contradiction:
Improvesecurity score accuracyVSAvoidsecurity data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security-relevant data from comprehensive device information. The assessment engine selectively collects and processes only those properties that directly impact security scoring, filtering out unnecessary data to reduce processing requirements while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by not processing all possible device data, but only the critical security-related subset. This approach achieves sufficient measurement precision without the excessive data processing burden of analyzing every device parameter.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11546365B2Computer network security assessment engine
Publication Date: 2023.01.03 GEN DIGITAL INC
  • US11546365B2 patent drawing
  • US11546365B2 patent drawing
  • US11546365B2 patent drawing

AI summary

A network security assessment engine can assess security on a remote computer network. Agent programs on computing devices on the remote network can execute security tests. The network security assessment engine receives security test results produced by the security tests. The network security assessment engine can determine security test scores based, at least in part, on the security test results. The network security assessment engine can determine an overall network security score based, at least in part, on the security test scores and present the overall network security score. As an example, a network services provider can utilize the network security assessment engine to provide an adaptive, expressive scoring mechanism, allowing the network services provided to more efficiently digest, assess, and report network anomalies within a multitenant context.