Security Evaluation Device Using Quantitative Threat Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure system design technologies lack the ability to efficiently and quantitatively evaluate the security of system configurations, relying on qualitative assessments that require extensive refinement and do not provide timely detection of vulnerabilities.
Innovation Solution
A security evaluation device and method that calculate threat evaluation values based on probability, execution frequency, and mitigation effectiveness for each threat, enabling a quantitative security evaluation of system configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If qualitative security evaluation based on attack path search is used, then security assessment can be performed, but the evaluation efficiency is low and time consumption is excessive
Solution Approach 1:
The patent transforms the qualitative security evaluation into a quantitative evaluation by introducing numerical parameters. Specifically, it calculates a security evaluation value by aggregating threat evaluation values, where each threat's evaluation value is derived from probability of occurrence, execution frequency, and mitigation effectiveness. This parameter transformation enables efficient numerical comparison and ranking of system configurations without requiring exhaustive qualitative analysis.
2Reliability
If exhaustive search for attack paths is performed to determine security, then comprehensive security assessment is achieved, but the search process is inefficient and time-consuming
Solution Approach 1:
The patent performs preliminary calculations of threat evaluation values by computing probability of occurrence, execution frequency, and mitigation effectiveness for each threat before conducting the full security assessment. This preliminary action prepares the necessary data in advance, allowing the final security evaluation to be computed efficiently by simply aggregating the pre-calculated threat values, thereby reducing the overall assessment time.
3Ease of operation
If only binary secure/unsecure determination is provided, then simple security classification is achieved, but detailed security level comparison and ranking are not possible
Solution Approach 1:
The patent adds a quantitative dimension to the security evaluation by introducing numerical values for probability, frequency, and effectiveness, which are then aggregated into a comprehensive security evaluation value. This dimensional transformation allows systems to be not only classified as secure or unsecure but also ranked according to their relative security levels, providing both simplicity and precision simultaneously.
Data Source
AI summary
A security evaluation device calculates a threat evaluation value for each of all threats present in a system configuration plan based on an evaluation value of a probability of a threat occurring, an evaluation value of an execution frequency of the threat, and an evaluation value of an effectiveness of a mitigation measure for the threat that is possessed by a countermeasure against the threat, which are defined for each type of security threat, and calculates a quantitative security evaluation value for the system configuration plan based on the threat evaluation values calculated for each of all of the threats.


