Risk Analysis Method Grouping Components by Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional risk analysis methods are inefficient and lack granularity, failing to group components with similar threats and vulnerabilities together, making it difficult to implement effective risk controls and requiring manual creation of pseudo-assets for complex systems.

Innovation Solution

A risk analysis method that groups components with similar cybersecurity risks and vulnerabilities, allowing for granular analysis by categorizing assets into component categories, properties, and security controls, enabling efficient and accurate risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional risk analysis methods are used to analyze each asset individually, then comprehensive risk coverage is achieved, but the analysis process becomes extremely time-consuming and inefficient

Engineering Contradiction:
Improverisk analysis completenessVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments assets into standardized component categories (e.g., servers, databases, networks, applications) with defined properties. This segmentation allows the risk analysis system to analyze components rather than entire assets, dramatically reducing analysis time while maintaining comprehensive risk coverage through the component-based approach.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal component library that can be applied across multiple assets. Once components are defined and analyzed, they can be reused across different assets, eliminating redundant analysis and significantly reducing the time required for comprehensive risk assessments across an organization's entire IT infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If assets are broken down into constituent parts for detailed analysis, then granular risk identification is improved, but the complexity of the analysis process increases

Engineering Contradiction:
Improverisk identification granularityVSAvoidanalysis process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides assets into standardized component categories with predefined properties, creating a structured framework that simplifies the breakdown process. This segmentation provides clear guidance on what components to analyze and what properties to assess, reducing the perceived complexity while enabling granular risk identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the complex task of asset analysis into a standardized parameter-based evaluation system. By defining specific properties for each component category (e.g., operating system, data type, network exposure), the system converts complex qualitative assessment into structured quantitative parameter evaluation, making the process more manageable and systematic.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If manual creation of pseudo-assets is required for complex systems, then flexibility in representing system relationships is achieved, but the ease of operation deteriorates

Engineering Contradiction:
Improvesystem representation flexibilityVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent eliminates the need for pseudo-assets by segmenting complex systems into their underlying component parts. Instead of creating artificial aggregate assets to represent complex relationships, the system directly models the actual components (servers, databases, networks) and their relationships, providing both flexibility and operational simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent inverts the conventional approach by breaking down assets into components rather than aggregating components into pseudo-assets. This inversion simplifies the modeling process by working with the actual system constituents and their direct relationships, eliminating the need for manual creation of representative pseudo-assets while maintaining adaptability.

Inventive Principle:
Principle #13The other way round (Inversion)

4Ease of operation

If components with different security risks are grouped together, then the ease of operation improves, but the measurement precision of risk analysis deteriorates

Engineering Contradiction:
Improveanalysis efficiencyVSAvoidrisk differentiation accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by allowing different security risk profiles and control measures to be assigned to specific components within the same component category. For example, while all servers share the same component structure, each server can have its own operating system, security controls, and risk profile, enabling both efficient grouping and precise risk differentiation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses parameter changes to differentiate risk profiles within component groups. By varying the values of security-related parameters (e.g., authentication type, encryption status, patch level) for individual components, the system maintains operational efficiency through grouping while achieving precise risk differentiation through parameter variation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10496827B1Risk analysis method and system
Publication Date: 2019.12.03 CLEARWATER COMPLIANCE LLC
  • US10496827B1 patent drawing
  • US10496827B1 patent drawing
  • US10496827B1 patent drawing

AI summary

A risk analysis system and method that groups the attributes or components of assets together if the components face the same threats and vulnerabilities based upon the components, component properties, property values, and security controls of the asset. The risk analysis system and method creates different component groups if the components face different security risks. The risk analysis system and methods provides a more efficient, robust, detailed, and user friendly risk analysis.