Cybersecurity Risk Assessment for Remote Office Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transition to work-from-home arrangements has introduced cybersecurity risks for entities as employees use personal devices on remote networks outside of the entity's direct control, making it challenging to assess and manage the overall cybersecurity state.

Innovation Solution

A system and method to assess the cybersecurity state of entities by characterizing extended computer network characteristics, including identifying devices accessing the entity's networks, determining Work From Home Remote Office (WFH-RO) networks, and evaluating security characteristics associated with these networks, while excluding shared or service provider networks to provide an accurate security rating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employee devices are allowed to access remote networks outside entity control, then employee flexibility and convenience are improved, but cybersecurity risk exposure increases

Engineering Contradiction:
Improveemployee flexibilityVSAvoidcybersecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary assessment system that evaluates remote networks before allowing employee device access. This intermediary layer analyzes network security characteristics and provides risk assessments, enabling flexible remote work while mitigating cybersecurity risks through informed decision-making.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all accessed networks are included in cybersecurity assessment, then comprehensive risk evaluation is achieved, but assessment accuracy deteriorates due to skewing from shared/public networks

Engineering Contradiction:
Improverisk evaluation completenessVSAvoidsecurity rating accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent extracts and excludes shared or public networks from the cybersecurity assessment dataset. By removing these networks that would skew results, the system achieves more accurate security ratings while maintaining comprehensive evaluation of relevant private remote networks through selective data extraction.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security characteristics of WFH-RO networks are evaluated, then cybersecurity state determination is improved, but device complexity increases due to extended network characterization requirements

Engineering Contradiction:
Improvecybersecurity state determinationVSAvoidnetwork characterization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network characterization process into distinct components: identifying remote networks, evaluating their security characteristics, and integrating results into overall cybersecurity state determination. This segmentation manages complexity by breaking down the extended assessment into manageable, modular steps.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240362342A1Systems and methods for assessing cybersecurity risk in a work from home environment
Publication Date: 2024.10.31 BITSIGHT TECH
  • US20240362342A1 patent drawing
  • US20240362342A1 patent drawing
  • US20240362342A1 patent drawing

AI summary

Methods and systems are provided for assessing the cybersecurity state of entities based on extended-computer network characteristics. A method can include obtaining, for a plurality of computer networks associated with an entity and not associated with the entity, a first and second network dataset. The first and second network datasets can be combined. A plurality of Internet Protocol (IP) addresses associated with the entity and associated with a plurality of entities can be obtained, where the entity and the plurality of entities each associated with a unique identifier (UID). The method can include determining whether each of the plurality of computer networks not associated with the entity comprises a remote office network. A cybersecurity state of the entity can be determined based on an evaluation of security characteristics of the IP addresses associated with the entity and of one or more IP addresses attributed to the remote office networks.