Network Vulnerability Risk Indicator Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying network vulnerabilities is a time-consuming and costly process, especially in dynamically changing networks, as network engineers must analyze each device individually to identify potential attack points and mitigate risks, which becomes more challenging with the addition of new devices.

Innovation Solution

A method and system for analyzing network elements by assigning values to vulnerabilities, generating risk indicators, and providing a user interface for monitoring network devices, allowing for efficient identification and prioritization of vulnerabilities through a network monitoring system that includes scanners, intrusion detection, and databases for asset and ownership information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network engineers analyze each network device individually to identify vulnerabilities, then vulnerability identification completeness is improved, but analysis time and cost increase significantly

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables network devices to self-assess their own vulnerabilities through automated vulnerability scanning and risk calculation. Each device independently evaluates its security posture based on configured parameters, eliminating the need for manual engineer analysis of each device while maintaining comprehensive vulnerability identification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms vulnerability assessment from qualitative manual analysis to quantitative parameter-based calculation. By assigning numerical risk values to vulnerabilities and using configurable risk parameters, the system automatically calculates risk indicators for each device, replacing time-consuming manual engineering analysis with automated computational assessment.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If network engineers manually assess vulnerabilities in dynamically changing networks, then assessment accuracy is maintained, but the process becomes more time consuming and costly

Engineering Contradiction:
Improveassessment accuracyVSAvoidassessment efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system continuously monitors network changes and automatically updates vulnerability assessments. When network configuration changes occur, the system receives feedback about these changes and recalculates risk indicators accordingly, maintaining assessment accuracy without requiring re-analysis by engineers and improving overall productivity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements preliminary configuration of risk parameters and vulnerability thresholds before actual assessment occurs. By pre-configuring assessment criteria and risk calculation parameters, the system enables rapid automated evaluation of network changes without requiring engineers to re-assess everything from scratch, thus maintaining accuracy while improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7962960B2Systems and methods for performing risk analysis
Publication Date: 2011.06.14 EBATES PERFORMANCE MARKETING INC DBA RAKUTEN REWARDS
  • US7962960B2 patent drawing
  • US7962960B2 patent drawing
  • US7962960B2 patent drawing

AI summary

A method for analyzing a network element may include assigning values to each of a plurality of vulnerabilities. The method may also include identifying a vulnerability associated with the network element and generating a risk indicator for the network element based on the assigned value associated with the identified vulnerability.