4D Threat Mapping for Cybersecurity Assurance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity verification processes typically involve limited steps, which may not provide sufficient assurance for critical security controls, leading to potential vulnerabilities.

Innovation Solution

The implementation of a four-dimensional (4D) threat mapping technique for critical cyber assets, using a computer-implemented method that generates scores for people, process, and technology elements, and visualizes these in a 3D graph over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one or two step verification processes are used, then the process is simple and quick to execute, but the level of assurance for critical security controls is insufficient

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into three distinct dimensions (People, Process, Technology) with multiple questionnaire items within each dimension. This segmentation allows comprehensive assessment of security controls while maintaining structured evaluation, resolving the contradiction between thorough verification and process simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional one or two-step verification to a three-dimensional assessment framework (People, Process, Technology). This dimensional expansion enables more comprehensive security assurance by evaluating multiple aspects simultaneously, addressing the insufficiency of traditional approaches while providing a structured methodology.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive security verification is implemented, then the level of assurance improves, but the time and resources required increase

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The questionnaire framework is prepared in advance with all necessary items categorized by dimension. Organizations can conduct self-assessments using this pre-structured framework, reducing the time required for verification by eliminating the need to design assessment protocols during the verification process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a scoring mechanism that transforms qualitative security assessments into quantitative metrics. By converting security control evaluations into measurable scores across three dimensions, the system enables efficient comparison and tracking of security posture over time, reducing the time needed for comprehensive verification.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If detailed security assessments are conducted, then visibility of compliance and security trends improves, but manpower overheads increase

Engineering Contradiction:
Improvevisibility of security trendsVSAvoidmanpower efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent implements a scoring system that provides immediate feedback on security posture across three dimensions. By calculating scores for People, Process, and Technology dimensions and providing overall security maturity assessments, the system enables automated tracking of compliance trends without requiring manual analysis, thereby improving visibility while maintaining manpower efficiency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The questionnaire framework enables organizations to conduct self-assessments of their security controls. By providing a structured self-evaluation mechanism, the system reduces the need for external verification resources while maintaining comprehensive assessment capabilities, thereby improving productivity and reducing manpower overheads.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12316665B2Cyber security assurance using 4D threat mapping of critical cyber assets
Publication Date: 2025.05.27 SAUDI ARABIAN OIL CO
  • US12316665B2 patent drawing
  • US12316665B2 patent drawing

AI summary

Systems and methods include a computer-implemented method for presenting a model of cybersecurity. Questionnaire answers corresponding to individual components of each of three elements contributing to cybersecurity risk and maturity for a computer system are received by a four-dimensional cybersecurity assurance model application. Three scores corresponding to dimensions of cybersecurity assurance for the computer system are generated by the four-dimensional cybersecurity assurance model application using the questionnaire answers. A three-dimensional graph presenting a four-dimensional model of cybersecurity assurance for the computer system is generated by the four-dimensional cybersecurity assurance model application using the three scores and temporal information.