Synthetic Diversity Analysis to Complete Cyber Risk Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively manage and mitigate cyber risk by ensuring diversity among entities, leading to increased similarity and potential cascading risks in cyber security failures.
Innovation Solution
A system and method for determining and enhancing diversity among entities by synthesizing missing data, analyzing shared attributes, and providing actionable feedback to reduce similarity, using a computing architecture with modules for attribute analysis, comparison, clustering, and recommendation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cyber risk analysis is performed on entities with incomplete data, then productivity is improved by enabling analysis without complete information, but measurement precision deteriorates due to missing entity data portions
Solution Approach 1:
The system creates synthetic copies of missing entity data by selecting and copying attributes from similar entities within the same portfolio. This allows the risk analysis to proceed with synthesized data that mimics the structure and characteristics of complete entity profiles, maintaining measurement precision while improving productivity.
Solution Approach 2:
The system introduces an intermediary synthesis process that bridges the gap between incomplete entity data and complete risk analysis requirements. By synthesizing missing portions through comparison with similar entities, the system acts as a mediator that enables accurate risk assessment without requiring complete original data.
2Manufacturing precision
If entity data is synthesized from similar entities, then manufacturing precision is improved by creating complete data profiles, but loss of information occurs when original entity attributes differ from synthesized ones
Solution Approach 1:
The system applies local quality by selectively synthesizing only the missing portions of entity data rather than replacing entire profiles. Each missing attribute is synthesized independently from similar entities, preserving the local characteristics and unique qualities of the original entity while achieving overall data completeness.
Solution Approach 2:
The system performs partial synthesis by only generating the specific missing data portions needed for risk analysis rather than creating complete duplicate profiles. This partial action approach maintains the original entity's unique information while filling only the necessary gaps.
3Reliability
If diversity analysis is performed across all portfolio entities, then reliability is improved by identifying aggregate cyber risk patterns, but device complexity increases due to comprehensive data processing requirements
Solution Approach 1:
The system segments the diversity analysis process into distinct modules: data synthesis, attribute comparison, clustering, and risk assessment. Each module handles a specific aspect of the analysis independently, reducing overall system complexity while maintaining comprehensive portfolio-wide risk assessment reliability.
Solution Approach 2:
The system performs preliminary data synthesis and attribute standardization before conducting the main diversity analysis. By preparing and organizing entity data in advance, the system reduces the complexity of the subsequent risk assessment processes while ensuring reliable and consistent results across the entire portfolio.
Data Source
AI summary
Various embodiments disclosed include, for each entity in a portfolio, receiving entity data indicative of attributes of an entity, determining the received entity data for at least some entities is missing a portion of the entity data required to perform a cyber risk analysis; and synthesizing the missing portion. The method may further include comparing the received entity data and synthesized missing portion for each of the entities to each other; locating clusters of similar entity data shared between two or more of the entities; and calculating a cyber risk score representing how different the entities are to one another based on the entity data that are not shared between entities. Some embodiments include comparing entities that are missing some entity data to entities which have complete entity data, and generating a synthesized portfolio by selecting entities having complete entity data to replace the entities that are missing entity data.


