Security Measure Evaluation Using Threat-Effectiveness Indexing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures lack a systematic method to evaluate the effectiveness of multiple security measures against cyber threats, leading to inefficiencies in resource allocation and risk management.

Innovation Solution

A computer system that utilizes configuration management information, threat management information, and evaluation rule management information to analyze threats, generate security measures, and calculate an index indicating the effectiveness of these measures, enabling the presentation of high-effectiveness security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security measures are implemented to address multiple threats, then the security coverage is improved, but the complexity of evaluating and prioritizing these measures increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidevaluation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the evaluation of security measures by changing parameters from simple risk values to effectiveness indices. The effectiveness index is calculated by aggregating risk values across multiple threats and security measures, allowing for standardized comparison and prioritization. This parameter transformation resolves the contradiction by providing a quantitative metric that simplifies the evaluation complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements a feedback mechanism where the effectiveness of security measures is continuously evaluated and used to prioritize implementation. The calculated effectiveness indices provide feedback on which measures deliver the greatest risk reduction, enabling iterative improvement and optimized resource allocation. This feedback loop resolves the evaluation complexity by providing actionable insights from the multi-measure security framework.

Inventive Principle:
Principle #23Feedback

2Reliability

If all identified security measures are implemented, then the security effectiveness is maximized, but the time and cost resources required increase significantly

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an effectiveness index parameter that aggregates the impact of each security measure across multiple threats. By calculating and comparing these indices, the system identifies which measures provide the greatest security improvement per unit of resource invested. This parameter enables prioritization that maximizes security effectiveness while minimizing implementation time and cost.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Rather than requiring implementation of all security measures, the system applies partial action by selecting and prioritizing only the most effective measures based on their effectiveness indices. This approach achieves sufficient security improvement without the excessive time and cost investment required to implement every possible measure, resolving the contradiction between security effectiveness and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If risk-based prioritization is used to implement security measures, then the resource allocation is optimized, but the effectiveness evaluation of multiple measures becomes difficult

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoideffectiveness evaluation accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent resolves this contradiction by introducing a new effectiveness index parameter that is specifically designed to measure the impact of security measures across multiple threats. This index aggregates risk values and provides a precise quantitative metric for evaluating effectiveness, enabling both optimized resource allocation through prioritization and accurate measurement of security improvement through the effectiveness index.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260010638A1Computer system and security measures evaluation method
Publication Date: 2026.01.08 HITACHI SYST LTD
  • US20260010638A1 patent drawing
  • US20260010638A1 patent drawing
  • US20260010638A1 patent drawing

AI summary

A computer system holds configuration management information for managing an element constituting an object to be analyzed for a security risk, and evaluation rule management information for managing an evaluation rule for calculating an index indicating effectiveness of a security measure to avoid a threat. The computer system identifies a threat to each element by using the configuration management information, stores an evaluation pair in which the element and the threat are associated, generates a security measure for the evaluation pair, aggregates evaluation pairs having the same generated security measure, calculates an index for each security measure by using the evaluation pair associated with the security measure and the evaluation rule management information, and generates display information for presenting the security measure and the index.