Security Evaluation Device Using Quantitative Threat Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure system design technologies lack the ability to efficiently and quantitatively evaluate the security of system configurations, relying on qualitative assessments that require extensive refinement and do not provide timely detection of vulnerabilities.

Innovation Solution

A security evaluation device and method that calculate threat evaluation values based on probability, execution frequency, and mitigation effectiveness for each threat, enabling a quantitative security evaluation of system configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If qualitative security evaluation based on attack path search is used, then security assessment can be performed, but the evaluation efficiency is low and time consumption is excessive

Engineering Contradiction:
Improvesecurity evaluation precisionVSAvoidevaluation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent transforms the qualitative security evaluation into a quantitative evaluation by introducing numerical parameters. Specifically, it calculates a security evaluation value by aggregating threat evaluation values, where each threat's evaluation value is derived from probability of occurrence, execution frequency, and mitigation effectiveness. This parameter transformation enables efficient numerical comparison and ranking of system configurations without requiring exhaustive qualitative analysis.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If exhaustive search for attack paths is performed to determine security, then comprehensive security assessment is achieved, but the search process is inefficient and time-consuming

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidsearch time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary calculations of threat evaluation values by computing probability of occurrence, execution frequency, and mitigation effectiveness for each threat before conducting the full security assessment. This preliminary action prepares the necessary data in advance, allowing the final security evaluation to be computed efficiently by simply aggregating the pre-calculated threat values, thereby reducing the overall assessment time.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If only binary secure/unsecure determination is provided, then simple security classification is achieved, but detailed security level comparison and ranking are not possible

Engineering Contradiction:
Improveevaluation simplicityVSAvoidsecurity level differentiation
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent adds a quantitative dimension to the security evaluation by introducing numerical values for probability, frequency, and effectiveness, which are then aggregated into a comprehensive security evaluation value. This dimensional transformation allows systems to be not only classified as secure or unsecure but also ranked according to their relative security levels, providing both simplicity and precision simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250258926A1Security evaluation device, secure system automatic design device, security, and evaluation method
Publication Date: 2025.08.14 NEC CORP
  • US20250258926A1 patent drawing
  • US20250258926A1 patent drawing
  • US20250258926A1 patent drawing

AI summary

A security evaluation device calculates a threat evaluation value for each of all threats present in a system configuration plan based on an evaluation value of a probability of a threat occurring, an evaluation value of an execution frequency of the threat, and an evaluation value of an effectiveness of a mitigation measure for the threat that is possessed by a countermeasure against the threat, which are defined for each type of security threat, and calculates a quantitative security evaluation value for the system configuration plan based on the threat evaluation values calculated for each of all of the threats.