Service Dependency Mapping for Network Domain Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations relying on third-party IT services for network domain functionality face challenges in managing and mitigating service failures, such as cyberattacks, due to a lack of comprehensive understanding of the services utilized by their domains, which can lead to inefficient risk assessment and security measures.

Innovation Solution

A computer-implemented method and system for mapping services utilized by network domains, involving receiving requests for risk assessments, querying databases for records linking network resources to service types and providers, generating service maps, and facilitating security measures based on risk assessments, including the use of DNS databases and cached query logs to identify and categorize service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If organizations rely on third-party IT services for network domain functionality, then service costs and infrastructure management are reduced, but the ability to assess and mitigate service failures is weakened due to lack of comprehensive understanding of service dependencies

Engineering Contradiction:
Improveservice management easeVSAvoidservice failure assessment capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary mapping of service dependencies before failures occur. By proactively querying DNS databases and cached query logs to identify and categorize service providers, the system creates a service map that enables future risk assessment and security measure facilitation, resolving the contradiction by preparing information in advance rather than reacting to failures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary system that sits between organizations and third-party service providers. This intermediary automatically queries DNS databases and cached query logs to map service dependencies, translating complex service relationships into actionable risk assessments. This intermediary resolves the contradiction by providing comprehensive service understanding without requiring organizations to directly manage or understand each third-party service

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If vendors provide services to a very large number of clients, then service coverage and scalability are improved, but the impact of service outages increases and becomes harder to manage

Engineering Contradiction:
Improveservice coverageVSAvoidoutage impact scope
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments the broad service provider landscape into specific categories (CDN, hosting, mail service, cloud services) by querying DNS databases and cached query logs. This segmentation allows for targeted risk assessment and security measures for each service type, resolving the contradiction by making manageable the otherwise overwhelming scope of service dependencies across large numbers of clients

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If complete picture of services utilized by domain is obtained, then risk assessment accuracy is improved, but data collection complexity and processing requirements increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata collection system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses cached query logs as copies of DNS query data, avoiding the need to continuously query live DNS databases. By working with cached copies of service dependency information, the system achieves accurate risk assessment without the ongoing complexity of real-time data collection, resolving the contradiction between measurement precision and device complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10547633B1Systems and methods for mapping services utilized by network domains
Publication Date: 2020.01.28 GEN DIGITAL INC
  • US10547633B1 patent drawing
  • US10547633B1 patent drawing
  • US10547633B1 patent drawing

AI summary

The disclosed computer-implemented method for mapping services utilized by network domains may include (i) receiving a request to perform a risk assessment on a domain, (ii) querying a database for records associated with the domain, where each record links to a network resource that enables functionality of the domain, (iii) generating a service map that matches each network resource to a corresponding service type and service provider, (v) performing the risk assessment of the domain, and (vi) facilitating a security measure for the domain based on a result of the risk assessment. Various other methods, systems, and computer-readable media are also disclosed.