Software and Hardware Component Risk Scoring for Early Cyber-Tech Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations lack proactive methods to identify and monitor the inherent cyber-tech risks of software and hardware components, leading to resource overhead and unwanted cyber-risk exposures due to late integration of cyber-risk considerations in the Software Development Life Cycle (SDLC).

Innovation Solution

A system and method for proactively monitoring cyber-tech risk involves identifying proposed components, retrieving vulnerability information, generating risk scores based on factors like vulnerability density and threat intelligence, and providing risk assessments and recommendations using a product/version risk assessment computer program and a trained machine learning engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If cyber-risk considerations are integrated late in the Software Development Life Cycle (SDLC), then resource overhead is reduced, but unwanted cyber-risk exposures occur

Engineering Contradiction:
Improveresource overheadVSAvoidcyber-risk exposure
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent applies preliminary action by performing risk assessment activities before components are fully integrated into the software product. The system proactively identifies and evaluates cyber-tech risks of proposed components during the selection phase, rather than waiting until later SDLC stages. This allows organizations to make informed decisions about component selection while minimizing both resource overhead and cyber-risk exposure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If proactive risk assessment is implemented, then cyber-risk exposures are reduced, but resource overhead increases

Engineering Contradiction:
Improvecyber-risk exposureVSAvoidresource overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements self-service by enabling the risk assessment system to automatically evaluate components using pre-configured criteria, vulnerability databases, and scoring algorithms. Once the system is initially set up with risk parameters and data sources, it autonomously performs assessments without requiring extensive manual intervention for each component evaluation, thereby reducing ongoing resource overhead while maintaining proactive risk detection capabilities.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive vulnerability information is retrieved for all proposed components, then measurement precision of risk assessment is improved, but device complexity increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the risk assessment process into distinct functional modules: component identification, vulnerability information retrieval, risk scoring calculation, and assessment reporting. Each module handles a specific aspect of the assessment, allowing the system to comprehensively evaluate components while managing complexity through modular architecture. This segmentation enables precise risk measurement without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250267164A1Systems and methods for proactively monitoring the inherent cyber-tech risk of software and hardware components
Publication Date: 2025.08.21 JPMORGAN CHASE BANK NA
  • US20250267164A1 patent drawing
  • US20250267164A1 patent drawing
  • US20250267164A1 patent drawing

AI summary

Systems and methods for proactively monitoring the inherent cyber-tech risk of software and hardware components are disclosed. In one embodiment, a method for proactively monitoring a cyber risk of a computer program may include: (1) receiving, by a product/version risk assessment computer program executed by an electronic device and from a user computer program executed by a use electronic device, an identification of a plurality of proposed components to include in the computer program; (2) retrieving, by the product/version risk assessment computer program, vulnerability information for each of the plurality of proposed components, wherein the vulnerability information identifies a security vulnerability for the proposed component; (3) generating, by a product/version risk scoring computer program, a risk score for the computer program under development based on the vulnerability information; and (4) returning, by the vulnerability assessment computer program, the risk score to the user computer program.