Network Security Volatility Assessment via Temporal Thresholding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As networks grow larger and operate over longer periods, evaluating and contextualizing network security metrics becomes increasingly difficult due to the sheer volume of records, making it challenging to determine trends and implement effective security measures.
Innovation Solution
A system that chronologically orders and compares values of network security metrics against thresholds to assess volatility, determining when controls should be implemented to mitigate breaches and fraudulent transactions, and potentially redesigning processes or adjusting thresholds based on these assessments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security metrics are collected and stored over long periods, then security assessment capability is improved, but data volume and evaluation difficulty increase
Solution Approach 1:
The patent segments the large volume of security metric records by organizing them into time-based periods (e.g., first time period, second time period, third time period) and further dividing them into individual time points within each period. This segmentation allows the system to manage and evaluate extensive data without being overwhelmed by the total volume, as each segment can be processed independently and systematically.
Solution Approach 2:
The patent introduces a time dimension to organize security metric data, transforming the evaluation from a static analysis to a dynamic temporal analysis. By chronologically ordering values and comparing them across different time periods, the system adds a temporal dimension that structures the data in a manageable way, enabling trend analysis without being paralyzed by data volume.
2Measurement precision
If more security metrics are evaluated, then security monitoring accuracy is improved, but difficulty in determining trends increases
Solution Approach 1:
The patent applies preliminary action by pre-ordering security metric values chronologically and pre-comparing them against thresholds before full analysis. This preliminary organization and comparison work is done in advance, creating a structured foundation that makes subsequent trend determination much easier. The system prepares the data by establishing temporal sequences and initial threshold comparisons, reducing the complexity of later trend analysis.
Solution Approach 2:
The patent implements feedback mechanisms by comparing security metric values against thresholds and using the results to determine volatility and trigger control implementations. The system continuously monitors whether values exceed thresholds, feeds this information back into the volatility calculation, and uses the volatility assessment to determine when controls should be implemented. This feedback loop simplifies trend determination by providing clear decision criteria based on threshold comparisons rather than requiring complex manual analysis of all metric relationships.
3Productivity
If volatility assessment is performed frequently, then control implementation timing is improved, but computational overhead increases
Solution Approach 1:
The patent applies partial action by performing volatility assessment at selected time points rather than continuously analyzing every single metric value. The system divides time into periods and selects specific points within those periods for volatility calculation. This partial assessment approach provides sufficient information for timely control implementation decisions without requiring exhaustive computational analysis of every data point, thereby reducing computational overhead while maintaining effective security response.
Data Source
AI summary
A network security assessment apparatus includes a memory and a processor. The memory stores first, second, and third values of a metric. The metric indicates one or more of a number of network security breaches and a number of fraudulent transactions. The processor chronologically orders the first, second, and third values for the metric over a period of time and compares the first, second, and third values against a threshold to produce first, second, and third results. If the first result is different from the second result or if the second result is different from the third result, the processor increments a volatility count. The processor determines, based on the volatility count, that a control should be implemented to mitigate one or more of the number of network security breaches and the number of fraudulent transactions and in response to that determination, the processor implements the control.


