Service Dependency Mapping for Network Domain Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations relying on third-party IT services for network domain functionality face challenges in managing and mitigating service failures, such as cyberattacks, due to a lack of comprehensive understanding of the services utilized by their domains, which can lead to inefficient risk assessment and security measures.
Innovation Solution
A computer-implemented method and system for mapping services utilized by network domains, involving receiving requests for risk assessments, querying databases for records linking network resources to service types and providers, generating service maps, and facilitating security measures based on risk assessments, including the use of DNS databases and cached query logs to identify and categorize service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If organizations rely on third-party IT services for network domain functionality, then service costs and infrastructure management are reduced, but the ability to assess and mitigate service failures is weakened due to lack of comprehensive understanding of service dependencies
Solution Approach 1:
The system performs preliminary mapping of service dependencies before failures occur. By proactively querying DNS databases and cached query logs to identify and categorize service providers, the system creates a service map that enables future risk assessment and security measure facilitation, resolving the contradiction by preparing information in advance rather than reacting to failures
Solution Approach 2:
The patent introduces an intermediary system that sits between organizations and third-party service providers. This intermediary automatically queries DNS databases and cached query logs to map service dependencies, translating complex service relationships into actionable risk assessments. This intermediary resolves the contradiction by providing comprehensive service understanding without requiring organizations to directly manage or understand each third-party service
2Productivity
If vendors provide services to a very large number of clients, then service coverage and scalability are improved, but the impact of service outages increases and becomes harder to manage
Solution Approach 1:
The system segments the broad service provider landscape into specific categories (CDN, hosting, mail service, cloud services) by querying DNS databases and cached query logs. This segmentation allows for targeted risk assessment and security measures for each service type, resolving the contradiction by making manageable the otherwise overwhelming scope of service dependencies across large numbers of clients
3Measurement precision
If complete picture of services utilized by domain is obtained, then risk assessment accuracy is improved, but data collection complexity and processing requirements increase
Solution Approach 1:
The system uses cached query logs as copies of DNS query data, avoiding the need to continuously query live DNS databases. By working with cached copies of service dependency information, the system achieves accurate risk assessment without the ongoing complexity of real-time data collection, resolving the contradiction between measurement precision and device complexity
Data Source
AI summary
The disclosed computer-implemented method for mapping services utilized by network domains may include (i) receiving a request to perform a risk assessment on a domain, (ii) querying a database for records associated with the domain, where each record links to a network resource that enables functionality of the domain, (iii) generating a service map that matches each network resource to a corresponding service type and service provider, (v) performing the risk assessment of the domain, and (vi) facilitating a security measure for the domain based on a result of the risk assessment. Various other methods, systems, and computer-readable media are also disclosed.


