Network Security Risk Assessment via Virtual Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in effectively assessing and improving their security strategies to protect against web-based attacks and malware, as existing methods lack comprehensive risk assessment and simulation of mitigation strategies.
Innovation Solution
A risk assessment system that models external threat environments, internal protections, and web browsing behavior patterns, running simulations to evaluate security risks and test the effectiveness of mitigation strategies, including the construction of a web infection model and simulation of browsing activities with internal protection mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations implement security strategies to protect against web-based attacks, then security protection capability is improved, but the ability to effectively assess and evaluate these security strategies deteriorates
Solution Approach 1:
The patent creates a virtual copy of the organization's IT infrastructure, security strategies, and threat environment through modeling. This virtual model allows for safe simulation and evaluation of security strategies without affecting the actual system, enabling precise risk assessment while maintaining strong security protection.
Solution Approach 2:
The patent performs risk assessment and strategy evaluation in advance through simulations before actual threats occur. By preliminarily testing security strategies against modeled threats, organizations can identify weaknesses and improve their security posture before real attacks, enhancing both protection capability and assessment precision.
2Reliability
If organizations assess security risks of their security strategies, then security strategy effectiveness is improved, but the complexity of the assessment system increases
Solution Approach 1:
Instead of creating complex assessment procedures for the actual system, the patent creates a simplified virtual copy that replicates essential characteristics. This model can be manipulated and analyzed with relative ease while still providing meaningful insights into security strategy effectiveness.
Solution Approach 2:
The simulation model is designed to automatically assess security strategies by incorporating the organization's own security configurations, threat environments, and infrastructure characteristics. The system self-evaluates without requiring complex external assessment tools or procedures.
3Measurement precision
If simulations are run to test mitigation strategies, then decision support quality is improved, but computational resources and time consumption increase
Solution Approach 1:
The patent implements progressive simulation testing, starting with partial scenarios and key critical paths rather than exhaustive testing of all possible threats and configurations. This approach provides sufficient decision support quality by focusing on the most impactful scenarios while significantly reducing computation time.
Solution Approach 2:
The system pre-calculates and stores baseline security metrics, threat probabilities, and vulnerability data before running simulations. This preliminary preparation allows simulations to proceed more quickly by avoiding repeated calculations of common parameters, thus improving decision support quality while reducing time consumption.
Data Source
AI summary
A security risk of a computer network is assessed by simulating a threat environment of the computer network, wherein the threat environment includes a vulnerability and a website, simulating a protection environment of the computer network and a computer system in the computer network, and simulating network activity of the computer system. The security risk of the computer network is assessed based at least in part on the simulated threat environment, the simulated protection environment, and the simulated network activity of the computer system.


