Security Metric Analysis Identifying Key Performance Indicators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
System administrators face difficulties in obtaining a comprehensive view of system security due to the large number of security metrics and restrictions imposed by security monitoring products, making it challenging to identify key performance indicators that provide the best overall picture of system security.
Innovation Solution
A method that involves receiving security information data from multiple sources, calculating scores using metric definitions, comparing scores to identify relationships, and selecting key performance indicators that are indicative of other metrics, allowing for a graphical representation of these relationships to be presented to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If system administrators use multiple security metrics to quantify overall risk, then the comprehensiveness of security view is improved, but the complexity of analysis and interpretation increases
Solution Approach 1:
The patent extracts and identifies key performance indicators from a large set of security metrics by analyzing relationships between metrics. The system automatically selects a subset of metrics that provide the most comprehensive security view, extracting only the essential indicators needed for effective security monitoring and analysis.
Solution Approach 2:
The patent introduces an intermediary system that analyzes relationships between security metrics and identifies key performance indicators. This intermediary layer processes the complex metric data and presents simplified, relationship-based insights to administrators, mediating between the raw metrics and the user's understanding.
2Ease of operation
If security monitoring products restrict which security metrics administrators can view, then the ease of operation is improved, but the ability to develop comprehensive security view is worsened
Solution Approach 1:
The patent implements a dynamic approach where the system automatically adapts to different security environments by analyzing relationships between available metrics and identifying key performance indicators tailored to each specific system. This dynamic adaptation allows the system to work effectively with restricted metric sets while maintaining comprehensive security monitoring capabilities.
3Adaptability or versatility
If system administrators can use any security metric they want, then the adaptability to system requirements is improved, but the difficulty of identifying best metrics increases
Solution Approach 1:
The patent implements feedback mechanisms where the system continuously monitors security metrics and their relationships, automatically identifying key performance indicators based on observed patterns and relationships. The system provides feedback to administrators about which metrics are most valuable for their specific security context, enabling informed selection without requiring administrators to manually evaluate all available metrics.
Data Source
AI summary
A security metrics system receives security information data for a network system of computers and metric definitions from metric sources. Each metric definition defines a heuristic for calculating a score for the network system from one or more security signal values at a time in the plurality of times, wherein the score quantifies a security metric for the network system. The system calculates each metric definition for a plurality of times and selecting metric definitions that are related to the performance of and are indicative of one or more other metric definitions as candidates to be key performance indicators.


