Policy-Vulnerability Mapping for Correlated Security Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current risk assessment methods fail to accurately integrate policy compliance with vulnerability management, leading to incomplete evaluations of an environment's security posture due to the lack of correlation between vulnerabilities and mitigation measures.
Innovation Solution
Implement machine learning models to classify mitigation techniques and weakness types, mapping these to attack techniques, and adjust risk assessments based on existing policies and vulnerabilities, using datasets like CVE and CWE to enhance accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual threat monitoring and analysis is performed, then security analysts can review and respond to threats, but the process is time-consuming and inefficient due to the need to search through wide ranges of data sources
Solution Approach 1:
The patent replaces manual mechanical analysis processes with automated machine learning models. The policy machine learning model automatically classifies mitigation techniques, and the vulnerability machine learning model automatically classifies weakness types, eliminating the need for manual searching through data sources and significantly reducing analysis time while improving productivity
Solution Approach 2:
The system enables self-service through automated risk assessment. The machine learning models automatically perform risk evaluations by mapping mitigation techniques and weakness types to attack techniques, allowing the system to assess risks independently without requiring manual intervention from security analysts for each assessment
2Measurement precision
If current risk assessment methods are used, then vulnerabilities can be identified, but the assessment is incomplete due to lack of correlation between vulnerabilities and mitigation measures
Solution Approach 1:
The patent merges policy compliance assessment with vulnerability management by combining the policy machine learning model (which classifies mitigation techniques) with the vulnerability machine learning model (which classifies weakness types). This integration allows the system to correlate vulnerabilities with their corresponding mitigation measures, providing complete and accurate risk assessments that include both vulnerability information and policy compliance status
Solution Approach 2:
The patent introduces attack techniques as an intermediary concept that bridges vulnerabilities and mitigation measures. Both the vulnerability machine learning model and policy machine learning model map their respective classifications (weakness types and mitigation techniques) to attack techniques, creating a common reference framework that enables accurate correlation and complete risk assessment
Data Source
AI summary
An apparatus, a method, and a computer program product are provided that combine policy compliance with vulnerability management to provide a more accurate risk assessment of an environment. The method includes training a policy machine learning model using a first training dataset to generate a policy machine learning model to produce mitigation technique classifications and training a vulnerability machine learning model using a second training dataset to generate a vulnerability machine learning model to produce weakness type classifications. The method also includes mapping the mitigation technique classifications to attack techniques to produce a policy mapping and mapping the weakness type classifications to the attack techniques to produce a vulnerability mapping. The method further includes producing a risk assessment of a vulnerability based on the policy mapping and the vulnerability mapping.


