Dynamic Security Posture Scoring for Network Resource Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex network computing systems face increased risks from malicious attacks and unforeseen failures, requiring efficient allocation of limited cyber security resources to optimize cost/performance tradeoffs while minimizing service disruptions.

Innovation Solution

A security posture scoring system that collects behavior data from network entities, calculates risk scores using a classification model, and allocates cyber security resources based on these scores to mitigate perceived risks, employing a risk analysis server and data aggregation points to dynamically assess and respond to potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cyber security resources are allocated to all network entities uniformly, then security coverage is comprehensive, but resource efficiency deteriorates due to limited resources and varying risk levels

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by allocating different levels of security resources to different network entities based on their individual risk scores. High-risk entities receive intensive security scrutiny and resource allocation, while low-risk entities receive minimal or no additional security resources, optimizing the overall security posture without wasting resources on already secure entities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the allocation parameter of security resources based on calculated risk scores. The risk score serves as a parameter that determines the level of security resources allocated to each entity, allowing flexible adjustment of security investment according to actual threat levels rather than uniform distribution.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If extensive security monitoring and resource allocation are applied to all entities, then security detection capability is improved, but service disruption increases due to resource constraints and monitoring overhead

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidservice disruption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing security monitoring and resource allocation only for network entities that exceed a certain risk threshold. Rather than monitoring all entities equally, the system focuses security efforts on those with high risk scores, reducing overall monitoring overhead and associated service disruptions while maintaining adequate detection capability for critical threats.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If security resources are concentrated on high-risk entities identified through risk scoring, then resource utilization effectiveness is improved, but security coverage may be reduced for low-risk entities

Engineering Contradiction:
Improveresource utilization effectivenessVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where security outcomes and new threat intelligence continuously update risk scores for all network entities. This allows the system to dynamically adjust security resource allocation, ensuring that entities transitioning to higher risk levels receive appropriate attention while maintaining overall security coverage through continuous monitoring and re-assessment.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10284588B2Dynamic selection of security posture for devices in a network using risk scoring
Publication Date: 2019.05.07 CISCO TECHNOLOGY INC
  • US10284588B2 patent drawing
  • US10284588B2 patent drawing

AI summary

In one embodiment, a method for assessing security posture for entities in a computing network is implemented on a computing device and includes: receiving behavior data from one or more of the entities, where the behavior data is associated with at least activity on the computing network by the one or more entities, calculating a risk score for at least one of the entities by comparing the behavior data with a classification model, where the classification model represents at least a baseline for normative network behavior by the entities in a computing network, assessing a security posture for the at least one the entities based on the risk score, and allocating network security resources to the at least one of the entities at least in accordance with the security posture.