Security Control Selection for Attack-Path Risk Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security threat analysis and risk assessment methods lack efficient mechanisms for matching security controls to attack steps and optimizing their implementation based on cost and feasibility, leading to suboptimal security measures.

Innovation Solution

A security threat treatment method that receives risk analysis information, matches security controls to attack steps, and outputs optimized security control lists considering expenditure and feasibility, utilizing a system comprising a management subsystem, control association, and optimization subsystems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security controls are implemented to cover all attack steps, then security coverage is improved, but implementation cost and complexity increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes parameters by evaluating security controls based on multiple dimensions including effectiveness, cost, and feasibility. It transforms the security control selection from a binary comprehensive approach to a parameterized optimization problem where controls are selected based on their effectiveness-to-cost ratio and feasibility scores, allowing comprehensive coverage where valuable while avoiding unnecessary complexity elsewhere

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies local quality by tailoring security control implementation to specific attack steps and assets rather than uniformly applying all controls everywhere. Each security control is matched to specific attack steps based on effectiveness, and the implementation plan is customized for each asset's risk profile, implementing comprehensive controls only where they provide meaningful security improvement

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple security controls are matched to each attack step, then security effectiveness is improved, but selection and implementation time increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidselection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system transforms the control selection process by introducing feasibility scores and effectiveness ratings as parameters. Instead of manually evaluating multiple controls against each attack step, the system automatically scores controls based on their ability to reduce attack feasibility and their implementation feasibility, enabling rapid selection of optimal controls without sacrificing effectiveness

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system enables self-service by automatically matching security controls to attack steps based on pre-defined effectiveness criteria and feasibility assessments. The automated matching process eliminates manual review time while ensuring that selected controls are both effective at reducing attack feasibility and practical to implement, allowing security teams to quickly generate implementation plans

Inventive Principle:
Principle #25Self-service

3Reliability

If security controls are selected based on highest effectiveness, then risk reduction is improved, but implementation cost increases

Engineering Contradiction:
Improverisk reductionVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system changes the selection criterion from pure effectiveness to an optimized balance of effectiveness, cost, and feasibility parameters. It calculates risk reduction benefits against implementation costs and feasibility scores, selecting controls that provide adequate risk reduction at reasonable cost rather than always choosing the most effective but most expensive options

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies partial action by selecting a subset of security controls that provide sufficient risk reduction rather than implementing all potentially effective controls. It identifies the minimum necessary controls to achieve acceptable risk levels, avoiding unnecessary expenditure on controls that would provide marginal additional security beyond what is needed

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12488118B2Security control system and method
Publication Date: 2025.12.02 C2A SEC LTD
  • US12488118B2 patent drawing
  • US12488118B2 patent drawing
  • US12488118B2 patent drawing

AI summary

A security control method, constituted of: receiving risk analysis information comprising data regarding a plurality of threats, each of the plurality of threats associated with a respective asset; loading a control database comprising data regarding a plurality of security controls; for each of the plurality of threats, matching one or more of the plurality of security controls to one or more attack steps of one or more attack paths associated with the respective threat; for each of the plurality of threats, selecting at least a subset of the matched security controls; and for each of the plurality of threats, outputting information regarding the selected security controls.