Risk-Based Computer System Scanning for Confidential Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in monitoring and identifying computer systems that pose a higher risk of compromising confidential information due to the sheer volume of data and numerous ways information can be disseminated across various devices within their networks.

Innovation Solution

A system and method for compiling a list of user computer systems at risk, determining their availability for scanning, and scanning them to identify potential or actual threats, while rating their risk levels and remediating incidents through a coordinated effort involving remediation and escalation teams.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive scanning of all computer systems is performed, then security monitoring coverage is improved, but system resources and time consumption increase significantly

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating scanning intensity and frequency based on risk ratings. High-risk systems receive more frequent and thorough scanning, while low-risk systems receive less intensive monitoring. This resolves the contradiction by concentrating security resources where they are most needed rather than applying uniform scanning across all systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of scanning frequency and depth based on dynamically calculated risk ratings. Systems are re-rated periodically, and scanning parameters are adjusted accordingly. This allows the organization to maintain high security coverage for critical systems while reducing scanning overhead for lower-risk systems, thereby managing time consumption effectively.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If frequent scanning of computer systems is performed, then threat detection capability is improved, but system performance and user productivity deteriorate

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiduser productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements local quality by applying different scanning frequencies to different systems based on their risk profiles. High-risk systems are scanned more frequently to maintain high threat detection capability, while low-risk systems are scanned less frequently to minimize impact on user productivity. This differentiated approach resolves the contradiction between detection precision and productivity.

Inventive Principle:
Principle #3Local quality

3Productivity

If risk-based prioritization of scanning is implemented, then scanning efficiency is improved, but complexity of system management increases

Engineering Contradiction:
Improvescanning efficiencyVSAvoidsystem management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the computer system population into risk-based groups (high, medium, low risk). Each group receives appropriate scanning frequency and intensity. This segmentation improves scanning efficiency by focusing resources on high-risk systems while simplifying management through clear categorization and automated risk-based routing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8613086B2Ping and scan of computer systems
Publication Date: 2013.12.17 BANK OF AMERICA CORP
  • US8613086B2 patent drawing
  • US8613086B2 patent drawing
  • US8613086B2 patent drawing

AI summary

Embodiments of the present invention provide apparatuses and methods for identifying computer systems that pose a threat for potential dissemination of confidential information, and thereafter, scanning the computer systems for unauthorized activity related to potential dissemination of confidential information. Embodiments of the invention comprise compiling a list of user computer systems that are at risk of accessing, using, or disseminating confidential information; determining whether the computer systems on the list are available for scanning; and scanning the computer systems on the list to identify an incident related to potential or actual threats or breaches of confidential information.