Security Analysis System with Segmented Risk Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting security threats in computing systems lack flexibility and fail to account for various aspects such as data, user behavior, and communication channels, making it difficult to visually render and monitor risk levels effectively for risk mitigation.

Innovation Solution

A computer-implemented security analysis method that determines data, endpoint, and channel risk values based on classified files, user behavior, and vulnerabilities, and renders a map showing security risk levels, allowing for flexible threat detection and visualization of risks across a network topology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual events and different combinations of events are coded for threat detection, then threat detection capability is provided, but the method lacks flexibility and does not account for different aspects of the computing system

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidflexibility in threat detection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security analysis into three distinct risk value determinations: data risk value (based on classified files), endpoint risk value (based on user behavior and vulnerabilities), and channel risk value (based on communication channels). This segmentation allows each aspect to be independently analyzed and optimized while maintaining comprehensive threat detection capability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive security analysis covering multiple aspects is implemented, then threat detection accuracy is improved, but the complexity of the system increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

By dividing the security analysis into separate risk value calculations for data, endpoint, and channel aspects, the patent achieves comprehensive threat detection accuracy while managing system complexity through modular, independent analysis components that can be implemented and optimized separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the three independently calculated risk values (data risk, endpoint risk, channel risk) to produce an overall security risk assessment. This combining approach maintains comprehensive analysis capability while allowing each component to remain relatively simple and manageable.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If risk values for data, endpoint, and channel are calculated separately, then independent optimization of each aspect is enabled, but the overall security risk visualization becomes more complex

Engineering Contradiction:
Improveindependent optimization capabilityVSAvoidvisualization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines the three separate risk value calculations into a unified security risk visualization that displays the overall security posture. This merging allows independent optimization of each risk component while presenting a simplified, integrated view through the map interface that shows security risk levels across the network topology.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11321467B2System and method for security analysis
Publication Date: 2022.05.03 BEIJING DIDI INFINITY TECH & DEV CO LTD
  • US11321467B2 patent drawing
  • US11321467B2 patent drawing
  • US11321467B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for security analysis are provided. One of the methods includes: determining a data risk value for data of an endpoint based on a number of classified files within the data and a type of classified files within the data; determining an endpoint risk value for the endpoint based on a user risk value and a cyber security risk value; determining a channel risk value for a set of channels through which the data is conveyable by the endpoint based on a number of channels within the set of channels and a type of channels within the set of channels; and rendering a map showing a security risk level of the endpoint, wherein the security risk level is based on the data risk value, the endpoint risk value, and the channel risk value.