Unified Security Risk Score via Multi-Model Asset Data Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber risk management systems fail to provide a clear and unified view of security risks across multiple assets, leading to inefficient prioritization of security investments and incorrect recommendations, which results in resources being misallocated and opportunities lost due to assets being rendered inoperable by security risks.

Innovation Solution

A monitoring system that integrates data from multiple security systems using models to calculate asset risk likelihood, criticality, and control effectiveness scores, generating a security risk score for each asset, thereby providing a unified view of security risks and optimizing resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data from multiple security systems is integrated using models to generate unified security risk scores, then the clarity and accuracy of security risk prioritization is improved, but the computing and networking resources required are increased

Engineering Contradiction:
Improvesecurity risk score accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the security risk assessment process into multiple specialized models (risk likelihood model, criticality model, control effectiveness model) that process different portions of asset-related data independently. Each model focuses on specific aspects of security risk, allowing parallel processing and reducing the computational burden on a single system while maintaining comprehensive analysis accuracy.

Inventive Principle:
Principle #1Segmentation

2Productivity

If comprehensive security data from multiple systems is processed to generate unified risk scores, then the ability to prioritize security actions is improved, but the complexity of the system architecture is increased

Engineering Contradiction:
Improvesecurity action prioritization efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges data from multiple security systems (vulnerability management, threat intelligence, security controls) into a unified asset-related data structure that feeds into integrated risk assessment models. This consolidation creates a coherent framework that simplifies the overall system architecture by providing a single source of truth for security risk assessment, reducing the complexity of managing multiple separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces asset-related data as an intermediary layer that bridges raw security data from multiple systems and the risk assessment models. This intermediary structure standardizes and contextualizes data before processing, making the system more manageable and easier to maintain while enabling comprehensive risk analysis across diverse data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple specialized models are used to calculate different risk components, then the precision of risk assessment is improved, but the time required for processing is increased

Engineering Contradiction:
Improverisk component calculation accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing and organizing security data into structured asset-related data formats before feeding them into the specialized risk assessment models. This preparation work is done in advance, allowing the models to process only the essential, pre-validated data, thereby reducing their processing time while maintaining high precision in risk component calculations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902314B2Utilizing models to integrate data from multiple security systems and identify a security risk score for an asset
Publication Date: 2024.02.13 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11902314B2 patent drawing
  • US11902314B2 patent drawing
  • US11902314B2 patent drawing

AI summary

A device may receive security data identifying assets of an entity, security issues associated with the assets, and objectives associated with the assets and may utilize a data model to generate, based on the security data, asset related data identifying mapped sets of security data. The device may process a first portion of the asset related data, with a first model, to calculate an asset risk likelihood score for an asset of the assets and may process a second portion of the asset related data, with a second model, to calculate an asset criticality score for the asset. The device may process a third portion of the asset related data, with a third model, to calculate an asset control effectiveness score for the asset and may combine the scores to generate a security risk score for the asset. The device may provide the security risk score for display.