Computing Environment Risk Model for Consistent Security Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security risk assessment methods for distributed computing environments are inconsistent, arbitrary, and fail to prioritize mitigation efforts effectively, leading to inaccurate risk evaluations and potential disastrous consequences.

Innovation Solution

A Threat and Vulnerability Management Security System (TVMSS) that computes an overall risk score using a flexible risk model, incorporating individual and composite risk factors, and automatically initiates mitigation actions when the score exceeds a threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual risk assessment methods are used, then flexibility in evaluation is maintained, but consistency and reliability of risk scores deteriorate due to human variability and subjectivity

Engineering Contradiction:
Improveconsistency of risk assessmentVSAvoidcomplexity of assessment system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual human assessment with an automated computational risk assessment system. The system automatically calculates risk scores by processing input data through defined algorithms, eliminating human variability and subjectivity while maintaining consistent, reliable risk evaluations across different assessors and time periods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms qualitative risk assessment parameters into quantitative measurements. By converting risk factors into numerical scores and using mathematical operations to compute overall risk, the system achieves consistent and reproducible results while reducing the complexity of manual evaluation processes.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If manual risk assessment is performed, then adaptability to specific contexts is maintained, but productivity and efficiency deteriorate due to time-consuming evaluations

Engineering Contradiction:
Improvespeed of risk assessmentVSAvoidaccuracy of risk evaluation
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The automated system rapidly processes risk assessments by executing computational algorithms, dramatically increasing productivity compared to manual methods. The system maintains measurement precision through structured calculation frameworks that ensure accurate risk evaluations while reducing the time required for assessment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary processing of risk factors and prepares calculation frameworks in advance, enabling rapid and accurate risk assessments. Pre-defined algorithms and processing steps allow the system to quickly evaluate risks without sacrificing precision, as the computational logic is already established and optimized.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual risk assessment methods are used, then ease of operation is maintained, but reliability and consistency of results deteriorate due to arbitrariness and subjectivity

Engineering Contradiction:
Improveaccuracy of risk scoreVSAvoidsimplicity of assessment process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The automated system eliminates the arbitrariness and subjectivity inherent in manual assessments by using objective computational algorithms. The system reliably calculates risk scores based on consistent mathematical operations, ensuring accurate and reproducible results while maintaining operational simplicity through automated processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically processing and evaluating risk factors without requiring manual intervention. The automated algorithms independently calculate risk scores, ensuring reliability and accuracy while simplifying the operational process for users who simply need to input data and receive results.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If manual risk assessment is performed, then flexibility in customization is maintained, but measurement precision and consistency deteriorate due to lack of standardized approaches

Engineering Contradiction:
Improveconsistency of risk measurementVSAvoidcomplexity of risk model
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms risk assessment into a standardized quantitative process by converting qualitative factors into measurable parameters. The system uses consistent mathematical operations and defined algorithms to calculate risk scores, achieving precise and reproducible measurements while managing model complexity through structured, modular design.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The risk assessment model is segmented into distinct, manageable components that can be independently processed and combined. This modular approach maintains measurement precision by allowing standardized evaluation of individual risk factors while reducing overall model complexity through systematic organization and separation of concerns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260039680A1Assessing security risk at scale for a computing environment
Publication Date: 2026.02.05 ORACLE INT CORP
  • US20260039680A1 patent drawing
  • US20260039680A1 patent drawing
  • US20260039680A1 patent drawing

AI summary

Techniques for assessing security risk at scale for a computing environment are disclosed. In an example method, a computing system accesses a risk model specified for a computing environment including at least a set of individual risk factors, a set of composite risk factors, and a final composite function for computing an overall risk score. The computing system receives a set of one or more inputs. The computing system computes an individual risk score for each individual risk factor using at least one input. The computing system computes a composite risk score for each composite risk factor. The computing system computes the overall risk score using the final composite function using at least two composite risk scores and outputs the overall risk score.