Network Security System for Risky Resource Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in timely and effective identification and prioritization of risky computing resources within complex computer networks, leading to potential unaddressed security risks exploitable by threat actors.
Innovation Solution
A network security solution that analyzes network-internal, open source intelligence (OSINT), and network-external domain information to identify and prioritize risky computing resources, determining a ranking weight based on recency, risk, relevancy, reconnaissance, and rationality factors, and applies targeted penetration testing or remediation solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive multi-domain information analysis is performed to identify and prioritize risky computing resources, then identification accuracy and risk prioritization effectiveness are improved, but system complexity and analysis time increase
Solution Approach 1:
The system segments the complex security analysis task into three distinct domain modules: network-internal domain analysis (analyzing network traffic, device configurations, and internal threats), OSINT domain analysis (gathered public intelligence from external sources), and network-external domain analysis (examining external network threats and vulnerabilities). Each domain is analyzed independently by specialized components, then results are integrated to produce comprehensive risk prioritization. This segmentation improves identification accuracy while managing system complexity through modular design.
2Measurement precision
If comprehensive multi-domain information analysis is performed to identify and prioritize risky computing resources, then identification accuracy and risk prioritization effectiveness are improved, but analysis time increases
Solution Approach 1:
The system performs preliminary actions by continuously gathering and pre-processing information from all three domains (network-internal, OSINT, and network-external) before a specific risk assessment is needed. Risk indicators, vulnerability data, and threat intelligence are collected and organized in advance, allowing the system to quickly prioritize risky computing resources when assessment is required. This reduces analysis time while maintaining high identification accuracy.
3Reliability
If targeted penetration testing and remediation solutions are applied to prioritized risky computing resources, then security risk mitigation effectiveness is improved, but resource allocation complexity increases
Solution Approach 1:
The system applies local quality by directing penetration testing and remediation resources specifically to the computing resources identified as highest risk based on the multi-domain analysis. Instead of uniformly applying security measures across all resources, the system concentrates expertise and tools on prioritized targets where they will have maximum impact. This improves mitigation effectiveness while managing resource allocation complexity through focused, risk-based deployment.
Data Source
AI summary
A system, a method, and a computer program for identifying and prioritizing a risky computing resource for security evaluation and remediation in a computer network that has a plurality of computing resources, comprising analyzing network-internal domain information to identify the risky computing resource in the computer network, generating a keyword for a cyberattack risk, analyzing open source intelligence domain information using the keyword, analyzing network-external domain information to identify additional risk attributes for the cyberattack risk, determining a ranking weight for the cyberattack risk, prioritizing the risky computing resource with respect to one or more computing resources based on the ranking weight, targeting the risky computing resource for penetration testing in accordance with the prioritization, and evaluating a threat risk of the risky computing resource to the computer network.


