System Under Test Cybersecurity Evaluation for Asset Vulnerability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems face challenges in evaluating their hardware and software components for proper functionality and cybersecurity, often leading to inefficiencies and vulnerabilities that can be exploited by cyber-attacks, which are difficult for in-house IT departments or third-party providers to address effectively.

Innovation Solution

An analysis system is employed to evaluate computer systems, assessing their understanding, implementation, and operation, identifying deficiencies, and auto-correcting issues through a comprehensive evaluation process that includes data gathering, analysis, and rating metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive cybersecurity evaluation is implemented, then system security is improved, but evaluation complexity and resource requirements increase

Engineering Contradiction:
Improvesystem securityVSAvoidevaluation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cybersecurity evaluation system divides the evaluation process into distinct modules: data gathering module, analysis module, and rating metrics module. Each module handles specific aspects of the evaluation, making the complex task manageable and systematic. The system further segments evaluation into different categories (understanding, implementation, operation) with specific metrics for each.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary analysis system that acts as a mediator between the system under test and the evaluation criteria. This intermediary automatically collects data, applies analysis algorithms, and generates security ratings, reducing the need for direct complex human analysis while maintaining comprehensive evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If automated evaluation and auto-correction are implemented, then system self-healing capability is improved, but system complexity increases

Engineering Contradiction:
Improveself-healing capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The evaluation system incorporates auto-correction capabilities that allow the system under test to self-heal identified vulnerabilities. The system automatically generates remediation recommendations and can implement corrections without human intervention, enabling self-service security maintenance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where evaluation results are fed back to the system under test, which then applies corrections. This feedback mechanism enables adaptive self-improvement, where the system learns from evaluations and automatically adjusts to strengthen its security posture.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250298708A1Cybersecurity threat evaluation of a system under test or portion thereof
Publication Date: 2025.09.25 UNCOMMONX INC
  • US20250298708A1 patent drawing
  • US20250298708A1 patent drawing
  • US20250298708A1 patent drawing

AI summary

A method includes identifying, by an analysis computing entity, a system sector of a system under test for an analysis regarding the system sector's vulnerability to cybersecurity threats. The method further includes analyzing the system sector to determine a plurality of system assets of the system sector. The method further includes evaluating the plurality of system assets from a cybersecurity operation perspective to identify a cybersecurity status of the plurality of system assets. The method further includes when a system asset of the plurality of system assets has an unfavorable cybersecurity status, determining a level of vulnerability to business operations of the system sector, determining a level of threat to business operations of the system sector based on the level of vulnerability and the plurality of system assets, and outputting the level of vulnerability and the level of threat.