Network Security Assessment System Using Segmented Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to rapidly assess and enhance the security status of computer networks, especially those connected to unsecured or externally unverified networks, due to the complexity of threats and the need for continuous updates.

Innovation Solution

A process that collects and parses network configuration and environment information to identify security risks, assigns cumulative security scores, and provides suggested changes to improve security, utilizing AI for real-time security assessments and filter set generation for Network Access Control platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a customized Zero-Trust security approach is implemented, then security assessment capability is improved, but system complexity and implementation burden increase

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security assessment system segments the network into multiple assessment zones (e.g., critical assets, sensitive data, general infrastructure) and applies different assessment criteria and depths to each segment. This allows comprehensive security evaluation without requiring uniform complex assessment of every network component, thereby improving reliability while managing system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security assessments using automated scanning and configuration analysis before full Zero-Trust implementation. This preliminary action identifies baseline security posture, critical vulnerabilities, and high-risk areas, enabling prioritized remediation and reducing the overall complexity of the implementation process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If continuous security monitoring and updates are performed, then security posture is improved, but time and operational burden increase

Engineering Contradiction:
Improvesecurity postureVSAvoidtime for updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic security assessments at scheduled intervals (e.g., daily, weekly, monthly) rather than continuous monitoring. Critical security parameters are monitored continuously with automated alerting, while comprehensive assessments occur periodically. This balances security posture improvement with reduced operational burden and time investment.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The security assessment system performs self-service operations including automated vulnerability scanning, configuration analysis, and risk calculation without requiring constant human intervention. The system automatically updates security databases, re-assesses risks after changes, and generates reports, significantly reducing the time and operational burden on security personnel.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security assessment of external networks is attempted, then security coverage is improved, but assessment accuracy decreases due to unavailable security information

Engineering Contradiction:
Improvesecurity coverageVSAvoidassessment accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system applies different assessment qualities to different network regions: internal networks receive comprehensive deep assessments with high precision, while external networks receive focused assessments of critical entry points and known vulnerabilities. This local differentiation maintains high assessment accuracy for internal assets while still providing meaningful security coverage of external networks despite limited information availability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system proactively identifies and addresses known external threats, vulnerability patterns, and common attack vectors before they can exploit unknown weaknesses. By pre-configuring protection against documented external risks and using intelligence from threat feeds, the system compensates for the inability to perform deep assessments of external networks, maintaining both coverage and effective accuracy.

Inventive Principle:
Principle #9Preliminary anti-action

4Adaptability or versatility

If manual security configuration updates are performed frequently, then security adaptability is improved, but operational efficiency decreases

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidoperational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system continuously monitors security configurations, vulnerability databases, and threat intelligence, then automatically feeds this information back to update security policies and controls. This closed-loop feedback mechanism ensures security adaptability to new threats and configurations while eliminating manual update processes, thereby maintaining high adaptability with improved operational efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces manual mechanical processes of security configuration updates with automated computational processes. Scripts and automation frameworks systematically apply security updates, policy changes, and configuration modifications across the network infrastructure, dramatically improving operational efficiency while maintaining full security adaptability through automated response to emerging threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250055873A1Process for enhancing network security
Publication Date: 2025.02.13 HURRY RONALD D

AI summary

A process for enhancing network security includes collecting network configuration and network environment information from users, including the identification of suppliers of goods and services. The collected information is parsed to identify individual security risks and a value is assigned to each security risk identified. A cumulative security score is calculated for each user using the values assigned to each security risk, and suggestions are offered to improve security.