Enterprise Network Security Risk Modeling via Asset Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital security approaches are inadequate in preventing customized malware and computerized attacks, as they rely on recognizing previously encountered malware traits and patterns, which are ineffective against unique or mutated malware, leading to increased frequency and severity of security breaches.

Innovation Solution

A programmatic mechanism for analyzing and modeling network security, which identifies and mitigates risks by systematically assessing all connected devices, generating an enterprise risk model to predict and address potential security breaches, and segmenting the network to enhance security through restrictive subnetworks and advanced access controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional anti-virus software and firewalls rely on recognizing previously encountered malware traits and patterns, then they can effectively identify known malware, but they fail to detect customized or mutated malware that has different digital signatures

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcapability against customized malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by systematically identifying and categorizing all network assets before an attack occurs, establishing a complete inventory with risk ratings. This proactive asset discovery and classification enables the system to detect and respond to unknown malware by analyzing network behavior patterns rather than relying on pre-existing malware signatures, thus resolving the contradiction between detecting known malware and adapting to customized threats

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where security agents monitor network traffic and asset interactions in real-time, feeding this information back to the risk model. This dynamic feedback mechanism allows the system to adapt to new and mutated malware by learning from observed network behaviors and updating risk assessments continuously, rather than relying on static malware databases

Inventive Principle:
Principle #23Feedback

2Reliability

If the enterprise network maintains a comprehensive inventory of all connected devices and assets, then security monitoring coverage is improved, but the complexity of managing and analyzing this data increases significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by categorizing different network assets according to their specific characteristics, functions, and risk profiles rather than treating all assets uniformly. Each asset receives localized security policies and risk ratings based on its specific attributes, enabling effective monitoring without overwhelming complexity in managing diverse asset types

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system transforms the complex asset inventory data into simplified risk ratings and priority levels through parameter changes. By converting detailed asset information into standardized risk metrics, the system maintains comprehensive monitoring coverage while reducing the complexity of data analysis and decision-making processes

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If security measures are strengthened across the entire network perimeter, then external attack prevention is improved, but internal security vulnerabilities and weakest links remain exposed

Engineering Contradiction:
Improveexternal attack resistanceVSAvoidinternal security posture
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements segmentation by dividing the network into discrete asset categories and applying differentiated security controls to each segment. This granular segmentation allows the system to identify and strengthen protection at specific internal weak points rather than applying uniform perimeter security, thus addressing internal vulnerabilities while maintaining external defense capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by assigning specific security measures and risk mitigation strategies to individual assets or asset categories based on their unique characteristics and risk profiles. This localized approach ensures that internal security weaknesses are addressed with targeted controls rather than generic perimeter defenses

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10320829B1Comprehensive modeling and mitigation of security risk vulnerabilities in an enterprise network
Publication Date: 2019.06.11 BALBIX INC
  • US10320829B1 patent drawing
  • US10320829B1 patent drawing
  • US10320829B1 patent drawing

AI summary

Approaches for analyzing risk of security breaches to a network. Agents gather, from multiple sources across the network, analysis data that identifies one or more habitable nodes and one or more opaque nodes. Habitable nodes each possess a computing environment conducive to installation of at least one of agent, while opaque nodes do not. An enterprise risk model is generated for the network using the analysis data. The enterprise risk model models a risk of security breaches to assets of the network from both authorized and unauthorized users of the network based on attributes of the habitable nodes and the opaque nodes of the network. The enterprise risk model may model both the present and the future risk to the enterprise, enabling, resources, such as time and money, to be best allocated in a scientific and methodical manner to improve the risk profile of the enterprise network.