Statistical Classifier for Security Improvement Plan Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for generating security improvement plans for entities rely on brittle rules or summary statistics, leading to crude or unrealistic plans due to the large and complex space of possible improvement plans.

Innovation Solution

The system and method utilize statistical modeling and data from similar entities to generate a feasible security improvement plan by training a statistical classifier based on static and modifiable parameters, focusing on achievable goals that can realistically improve the entity's security rating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If conventional methods use brittle rules or summary statistics to generate improvement plans, then the planning process is simple and fast, but the resulting plans are crude or unrealistic

Engineering Contradiction:
Improveplan qualityVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces a statistical classifier as an intermediary between the input data and improvement plan generation. This classifier is trained on historical data from multiple entities and serves as a mediator to transform complex data relationships into actionable improvement recommendations, resolving the contradiction by adding computational complexity that produces higher quality plans

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by training the statistical classifier in advance using historical security data from multiple entities. This pre-computation allows the system to quickly generate realistic improvement plans during operation without sacrificing plan quality, as the complex pattern recognition work is done beforehand

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the system considers a large space of possible improvement plans, then more comprehensive solutions can be found, but determining achievable plans becomes difficult

Engineering Contradiction:
Improveplan coverageVSAvoidachievable plan identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The statistical classifier provides feedback by learning from historical data what improvement plans were actually achievable for similar entities. The system uses past outcomes to inform future recommendations, automatically filtering out unachievable plans based on patterns observed in real-world data from multiple entities

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system copies successful improvement patterns from similar entities that have already achieved security improvements. By replicating proven strategies from peer entities with comparable characteristics, the system identifies achievable plans without having to evaluate the entire space of possibilities

Inventive Principle:
Principle #26Copying

3Reliability

If statistical modeling based on similar entities is used, then realistic and achievable goals are identified, but data processing and model training are required

Engineering Contradiction:
Improveplan achievabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs the computationally intensive statistical modeling and classifier training in advance, before actual improvement plan generation is needed. This preliminary action ensures that when improvement plans are requested, the system can quickly query pre-computed models rather than performing complex analysis in real-time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adapts between offline model training phases and online query phases. During offline phases, comprehensive statistical modeling is performed to build reliable predictors. During online operation, the system efficiently queries these models to provide rapid recommendations, balancing reliability with responsiveness

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250124138A1Systems and methods for generating security improvement plans for entities
Publication Date: 2025.04.17 BITSIGHT TECH
  • US20250124138A1 patent drawing
  • US20250124138A1 patent drawing
  • US20250124138A1 patent drawing

AI summary

A computer-implemented method is provided for statistical modeling of entities of a particular type. The method can include obtaining entity data including a plurality of entity data sets, each entity data set associated with a respective entity and including values for one or more static parameters indicative of a type of the entity. Each entity data set can include (i) values for input parameter(s) indicative of a security profile of the entity and (ii) a value of a security class parameter indicative of a security class of the entity based on the values of the input parameters. The method can include training a statistical classifier to infer a value of the security class parameter indicative of the security class of a particular entity of the particular type based on values of one or more of the input parameters indicative of a security profile of the particular entity.