Rule-Based Criticality Scoring for Network Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assigning criticality scores to assets in a management system are manual, subjective, and labor-intensive, leading to outdated scores that do not reflect the changing security landscape.

Innovation Solution

A rule-based method for assigning criticality scores to assets using a criticality rules table that maps individual or group attributes to corresponding criticality scores, with the ability to update these rules using machine learning and operator feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to assign criticality scores to assets, then the scoring process allows for subjective evaluation and customization, but it becomes labor-intensive, expensive, and outdated quickly

Engineering Contradiction:
Improvecriticality score accuracyVSAvoidscoring speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables assets to self-assess their own criticality by automatically evaluating their own attributes and comparing them against the criticality rules table. This eliminates the need for manual scoring while maintaining accuracy, as each asset independently determines its own criticality level based on current attributes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of human evaluation with an automated computational system. The management system automatically assigns criticality scores by processing asset attributes through the criticality rules table, substituting human judgment with algorithmic evaluation that is both faster and consistently accurate.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If manual criticality scoring is performed infrequently to reduce labor costs, then costs are reduced, but the criticality scores become outdated and do not reflect the current security landscape

Engineering Contradiction:
Improvescoring frequencyVSAvoidscore relevance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements continuous automatic re-evaluation of asset criticality scores whenever asset attributes change. This ensures that criticality scoring is not performed infrequently but rather continuously, maintaining score relevance without incurring manual labor costs, as the automation runs on-demand based on attribute changes.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The management system continuously monitors asset attributes and automatically triggers re-evaluation when changes are detected. This feedback mechanism ensures that criticality scores remain current and relevant by responding to attribute changes in real-time, eliminating the need for scheduled manual updates.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated rule-based assignment is implemented, then near real-time criticality scores are achieved, but the system requires a structured rules table and machine learning components

Engineering Contradiction:
Improvescoring speedVSAvoidsystem structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system divides the criticality assessment into discrete rules within the criticality rules table, where each rule evaluates specific asset attributes independently. This segmentation allows the complex automated system to process assets through manageable, modular rule evaluations, reducing the perceived complexity while maintaining high-speed automated scoring.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12212597B2Rule-based assignment of criticality scores to assets and generation of a criticality rules table
Publication Date: 2025.01.28 TENABLE INC
  • US12212597B2 patent drawing
  • US12212597B2 patent drawing
  • US12212597B2 patent drawing

AI summary

In an embodiment, a management system obtains a criticality rules table that includes a plurality of rules mapped to corresponding criticality scores indicative of a level of risk in the event that an associated asset of a managed network is compromised by a third party. The one embodiment, the criticality rules table is updated based upon machine learning and/or feedback from an operator of the managed network. In another embodiment, the criticality rules table is used to assign one or more criticality scores to one or more assets based on one or more attributes of one or more assets, and the criticality rules table.