Automated Security Risk Assessment for Networked Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in efficiently assessing and prioritizing IT security risks across numerous networked systems and assets, especially when outsourcing services to third-party providers, due to the complexity of maintaining effective security configurations and vulnerabilities.

Innovation Solution

A method and system for assessing and monitoring network asset security risks by inferring the content and security control features of systems and assets using machine learning models, regular expressions, and text analysis to determine a 'value at risk' ranking, which prioritizes security monitoring and resource allocation based on network proximity and security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated assessment systems are deployed to evaluate security risks across numerous networked systems, then security resource allocation efficiency is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity resource allocation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables automated self-assessment of security risks by having the assessment system itself collect data from, and evaluate, the networked systems without requiring extensive manual configuration or intervention. The systems under assessment provide the necessary information through automated data collection mechanisms, effectively serving themselves in the assessment process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The assessment system is designed to evaluate multiple types of networked systems across various organizations and service providers using a unified approach. It can assess different asset types (hardware, software, data) and apply consistent security risk evaluation methodologies across diverse environments, making the system universally applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security monitoring is implemented across all network assets, then security coverage is improved, but resource consumption and processing overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies differentiated assessment strategies based on the specific characteristics, sensitivity, and risk profile of each network asset. High-value or sensitive assets receive more comprehensive monitoring and assessment, while lower-risk assets receive streamlined evaluation, optimizing resource allocation across the network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs security assessments at appropriate levels of detail rather than uniformly exhaustive analysis across all assets. It focuses computational resources on assets where deeper assessment provides the most value, performing partial assessments where full comprehensiveness is not necessary for effective security management.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If detailed data collection is performed to accurately assess security risks, then assessment accuracy is improved, but data privacy concerns and security exposure increase

Engineering Contradiction:
Improveassessment accuracyVSAvoiddata privacy risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The assessment system acts as an intermediary that collects and processes security-related data without requiring direct access to or exposure of sensitive information. It uses automated data collection mechanisms that gather necessary security metrics while maintaining appropriate data protection, serving as a neutral mediator between security assessment needs and data privacy requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts only the specific security-relevant information needed for assessment while leaving sensitive data behind. It collects metadata, configuration information, and security control status without accessing or storing actual sensitive data, separating the assessment function from exposure of protected information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240232767A1Systems and methods for monitoring information security effectiveness
Publication Date: 2024.07.11 RISKRECON INC
  • US20240232767A1 patent drawing
  • US20240232767A1 patent drawing
  • US20240232767A1 patent drawing

AI summary

Systems and methods for automatically assessing and monitoring information security effectiveness using collected indicia of sensitive content and indicia of security measure information for a plurality of networked organizational assets/systems to provide respective asset/system value at risk ratings. Elements of the system include automated asset discovery, automated hosting provider and location discovery, collection of information harvested from public sources and, optionally non-public sources, analysis of the collected information against public, non-public, and proprietary sources, and/or mathematical models used to infer broader security program conclusions and to rank asset/system values at risk. Estimates of values at risk are used to prioritize allocation of security measures.