Security Assessment Method Using Error Tradeoff Plots
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for assessing the security of information access systems lack objectivity, providing only subjective measures such as 'low', 'medium', or 'high' security levels and fail to balance trade-offs between different security aspects, resulting in incomplete vulnerability assessments.
Innovation Solution
A method involving user-definable verification mechanisms, error tradeoff plots, and calculations to determine false acceptance and rejection rates, which are combined to assess intrusion and denial protection, ultimately providing an objective security assessment of the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If subjective security levels (low, medium, high) are used to assess information access systems, then the assessment is simple to provide, but the measurement precision and objectivity are insufficient
Solution Approach 1:
The patent transforms subjective security levels into objective mathematical parameters by calculating false acceptance rates and false rejection rates from verification mechanism performance data. This converts qualitative assessments into quantitative metrics that can be precisely measured and compared.
Solution Approach 2:
The patent replaces subjective human judgment with an automated mathematical model that calculates security metrics based on verification mechanism performance data, eliminating the need for subjective categorization while maintaining ease of operation through algorithmic processing.
2Difficulty of detecting and measuring
If vulnerability scanning methods are used to identify security weaknesses, then the system can detect vulnerability aspects, but it produces only tables of configurations without objective security measures
Solution Approach 1:
The patent incorporates feedback mechanisms by calculating false acceptance and false rejection rates from actual verification mechanism performance data, creating a closed-loop system that objectively measures security based on observed behavior rather than static configuration tables.
Solution Approach 2:
The patent transforms vulnerability detection results from qualitative configuration tables into quantitative security metrics by calculating objective measures based on verification mechanism performance, enabling precise comparison and assessment.
3Measurement precision
If verification mechanisms are evaluated using error tradeoff plots, then objective security metrics can be derived, but the complexity of the assessment method increases
Solution Approach 1:
The patent segments the security assessment into distinct components: false acceptance rate calculation, false rejection rate calculation, and combination to determine intrusion and denial protection. This modular approach manages complexity by breaking down the overall assessment into manageable steps.
Solution Approach 2:
The patent adds mathematical dimensions to the assessment by introducing error tradeoff plots and calculating multiple security metrics (intrusion protection, denial protection, security magnitude, security direction), transforming the assessment from simple categorization to multi-dimensional quantitative analysis.
4Adaptability or versatility
If only vulnerability aspects are listed for remote systems, then the assessment covers multiple systems, but it provides no objective security measure or trade-off analysis
Solution Approach 1:
The patent creates a universal assessment framework that can be applied to multiple information access systems using the same mathematical model and verification mechanism evaluation process, enabling consistent objective measurement across different systems while maintaining the ability to customize verification mechanisms.
Data Source
AI summary
A method of assessing security of an information access system by selecting at least one verification mechanism, estimating an error tradeoff plot showing false acceptance rate versus false rejection rate for each verification mechanism, selecting a corresponding false acceptance rate and false rejection rate pair from each error plot, combining the false acceptance rates to determine intrusion protection, combining the false rejection rates to determine denial protection, and combining intrusion protection and denial protection as the assessment of the information access system.


