Automated Security Scoring Ontology for Third-Party Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing large computer networks against third-party risks is challenging despite the availability of security ratings and tools, as network administrators face difficulties in detecting and assessing risks in real-time and understanding the underlying factors contributing to these risks.

Innovation Solution

A computer security monitoring method and system that continuously aggregates risk scores for monitored entities by gathering machine-readable facts, deriving risk profiles, and using an ontology to associate entities, providing visual and interactive reports to users, and issuing alerts when predetermined criteria are met, allowing for real-time risk assessment and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security ratings and tools are used to evaluate third-party risks, then security assessment capability is improved, but the difficulty of detecting and measuring risks in real-time increases

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidreal-time risk detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments risk assessment into multiple components: entity-level risk scores, relationship-level risk scores, and aggregated organizational risk scores. This segmentation allows real-time detection of individual entity risks while maintaining comprehensive organizational security assessment capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk score mechanism that translates complex security facts into standardized risk profiles. These risk profiles serve as intermediaries between raw security data and final risk assessments, enabling real-time detection while maintaining assessment reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If continuous monitoring and aggregation of risk scores is implemented, then real-time risk detection speed is improved, but device complexity increases

Engineering Contradiction:
Improvereal-time risk detection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system merges multiple risk assessment functions into a unified continuous monitoring process. By combining entity risk scoring, relationship risk scoring, and aggregation operations into a single coordinated system, real-time detection speed is improved without proportionally increasing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The risk profile structure serves multiple functions: it stores entity-level risks, enables relationship mapping, supports aggregation operations, and provides the basis for alert generation. This multi-functionality reduces overall system complexity while maintaining real-time detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If detailed ontological relationships and triggering conditions are disclosed to users, then ease of operation and understanding is improved, but loss of information increases

Engineering Contradiction:
Improveuser understanding of risk factorsVSAvoidinformation disclosure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system extracts only the necessary ontological relationship details and triggering conditions when users request explanations for risk scores. This selective extraction provides ease of operation and understanding while minimizing information loss by only disclosing relevant details on demand.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The information disclosure mechanism is dynamic, adapting the level of detail based on user needs. The system can provide high-level summaries or detailed ontological relationships depending on user interaction, balancing ease of operation with information preservation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20200401961A1Automated organizational security scoring system
Publication Date: 2020.12.24 RECORDED FUTURE
  • US20200401961A1 patent drawing
  • US20200401961A1 patent drawing
  • US20200401961A1 patent drawing

AI summary

Computer security systems and methods are disclosed. In one general aspect, a computer security monitoring method is disclosed that includes continuously gathering machine-readable facts relating to a number of topics and continuously deriving and storing risk profiles for a plurality of monitored entities based on at least some of the facts. This method also includes providing an ontology that associates a different subset of the monitored entities to each of a plurality of organizational entities possessing digital assets, aggregating the risk scores for the scored entities for each of the organizational entities based on the associations in the ontology to derive an aggregated risk score, and electronically reporting the aggregated risk score to an end user.