Automated Security Threat Remediation via Risk Certainty

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat management systems lack efficient automation and analytics for predicting and responding to security threats, particularly in assessing and mitigating risks for managed assets, as they often rely on manual processes and lack adaptive response capabilities.

Innovation Solution

A method and system that utilize a risk assessment engine to calculate risk values and certainty factors based on security control criteria, enabling automated remediation actions by integrating advanced automation, machine learning, and adaptive response mechanisms, aligning with standardized formats like OSCAL and SCAP for comprehensive threat management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual processes are used for threat assessment and remediation, then system complexity is reduced, but productivity and response efficiency deteriorate

Engineering Contradiction:
Improvethreat assessment and remediation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs self-assessment of security controls and automated remediation without requiring manual intervention. The risk assessment engine automatically evaluates control effectiveness, calculates risk values, and triggers remediation actions based on predefined policies, enabling the system to serve itself in threat management operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures security control criteria, risk assessment parameters, and remediation policies before threats occur. By establishing these frameworks in advance using standardized formats like OSCAL and SCAP, the system can rapidly respond to threats without requiring complex real-time decision-making structures.

Inventive Principle:
Principle #10Preliminary action

2Speed

If automated remediation actions are implemented, then response speed improves, but reliability may deteriorate due to potential false actions

Engineering Contradiction:
Improveresponse speedVSAvoidremediation action reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system continuously monitors security control effectiveness and threat conditions, using this feedback to adjust risk assessments and remediation decisions. By incorporating feedback loops that verify actual control performance against expected outcomes, the system reduces false remediation actions while maintaining rapid response capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual mechanical decision-making processes with computational algorithms that calculate risk values and certainty factors. This substitution eliminates human error and inconsistency in remediation decisions, improving reliability while maintaining speed through automated computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive security control assessment is performed, then measurement precision improves, but loss of time increases

Engineering Contradiction:
Improverisk assessment precisionVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system changes the parameters of assessment by calculating a certainty factor that quantifies the confidence level of risk assessments. This parameter transformation allows the system to identify high-certainty threats requiring detailed assessment while quickly processing low-certainty threats, thereby maintaining precision for critical issues while reducing overall assessment time.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs partial assessment by focusing comprehensive security control evaluation only on threats that exceed predefined risk thresholds. By applying full assessment rigor only when necessary and using streamlined evaluation for lower-risk threats, the system maintains measurement precision for critical issues while minimizing time loss across the entire threat landscape.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12034755B2Computationally assessing and remediating security threats
Publication Date: 2024.07.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12034755B2 patent drawing
  • US12034755B2 patent drawing
  • US12034755B2 patent drawing

AI summary

Computer software that assesses risks for security threat events by that performing the following operations: (i) receiving information pertaining to a managed asset; (ii) identifying, based, at least in part, on the received information: a threat to the managed asset and, one or more corresponding security controls for mitigating the threat, the security controls having associated control criteria; (iii) utilizing a risk assessment engine to calculate a risk value for the threat based, at least in part, on the received information; (iv) calculating a certainty factor for the threat based, at least in part, on a measure of belief associated with the control criteria; and (v) performing a computer-based remediation action based, at least in part, on the risk value and the certainty factor.