Security Assessment Unit Normalizing Multi-Tool Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security tools provide disparate and incompatible methods for evaluating and reporting system security, leading to fragmented and difficult-to-analyze results, as each tool uses its own approach and format, making comprehensive assessment and reporting challenging.

Innovation Solution

A system comprising a server device with a security assessment unit that imports, combines, and normalizes data from various security tools, allowing for comprehensive viewing, editing, and reporting of findings, including a database for storing and managing vulnerabilities, and user interfaces for tracking and presenting security data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different security tools are used to evaluate system security, then comprehensive security assessment coverage is improved, but data compatibility and analysis difficulty worsen due to disparate formats and approaches

Engineering Contradiction:
Improvesecurity assessment coverageVSAvoiddata integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security assessment system implements a universal data model that can accommodate multiple security tools and evaluation approaches. The normalized data structure includes standardized fields for vulnerability information, risk assessments, and remediation recommendations, allowing diverse tool outputs to be integrated into a single comprehensive view without losing tool-specific capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a normalization layer that acts as an intermediary between various security tools and the central assessment system. This layer transforms tool-specific data formats into a standardized structure, enabling seamless integration while preserving the original tool methodologies and evaluation approaches

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If each security tool uses its own evaluation approach and format, then tool-specific precision is improved, but comprehensive analysis capability worsens due to fragmented results

Engineering Contradiction:
Improvetool-specific evaluation precisionVSAvoidcomprehensive security information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system segments security assessment data into distinct, standardized components including vulnerability identifiers, severity ratings, affected systems, and remediation steps. This segmentation allows each tool's precise evaluation to be preserved in its own segment while enabling comprehensive analysis through the organized assembly of all segments

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms tool-specific evaluation parameters into a standardized parameter set that maintains the precision of original assessments. By mapping diverse tool metrics to common security parameters such as CVSS scores, vulnerability categories, and risk levels, the system preserves measurement precision while enabling cross-tool comparison and aggregation

Inventive Principle:
Principle #35Parameter changes

3Productivity

If data from multiple security tools is imported and combined, then comprehensive reporting capability is improved, but data processing time and system complexity worsen

Engineering Contradiction:
Improvereporting efficiencyVSAvoiddata processing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary normalization and validation of security tool data during the import process rather than during report generation. By pre-processing data into the standardized format and identifying inconsistencies early, the system reduces processing time during actual reporting operations and enables faster comprehensive security assessments

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9118706B2Using imported data from security tools
Publication Date: 2015.08.25 ATLASSIAN US INC
  • US9118706B2 patent drawing
  • US9118706B2 patent drawing
  • US9118706B2 patent drawing

AI summary

A device may create a new project that includes criteria, import findings from a group of different network security tools into the new project based on the criteria, normalize the imported findings, and store the normalized findings.