Vulnerability Score Quantification via Control Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in determining overall vulnerability measures and identifying specific assets vulnerable to attacks due to the large number of attack vectors and varying security controls, making it difficult to quantify vulnerabilities effectively.

Innovation Solution

A computing platform determines vulnerability scores by mapping attack vectors to controls, calculating compliance and effectiveness scores, and transmitting these scores to identify vulnerabilities and recommend additional controls for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security controls are implemented to protect against various attack vectors, then security coverage is improved, but determining overall vulnerability measures becomes challenging

Engineering Contradiction:
Improvesecurity coverageVSAvoidvulnerability determination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the overall vulnerability assessment into individual control-level assessments. Each security control is evaluated separately against its mapped attack vectors, producing discrete compliance scores and effectiveness scores. This segmentation transforms the complex overall vulnerability determination into manageable control-specific evaluations, resolving the contradiction between comprehensive security coverage and determination complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces quantifiable parameters (compliance scores and effectiveness scores) to transform qualitative security control evaluations into measurable metrics. By changing the assessment from subjective judgment to parameter-based scoring, the system enables automated calculation of overall vulnerability measures, reducing determination complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive vulnerability assessment is performed across all assets and attack vectors, then measurement precision is improved, but the difficulty of detecting and measuring vulnerabilities increases

Engineering Contradiction:
Improvevulnerability quantification precisionVSAvoidvulnerability detection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system divides the comprehensive vulnerability assessment task into discrete control-level evaluations. Each control is assessed independently against its specific attack vectors, producing precise compliance and effectiveness scores. This segmentation maintains measurement precision by evaluating each control thoroughly while reducing detection difficulty through automated, standardized scoring procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mapping relationship between controls and attack vectors that facilitates systematic assessment. This mapping structure serves as a mediator that organizes the complex relationships between security controls and attack vectors, enabling precise measurement through standardized evaluation procedures while reducing the difficulty of comprehensive vulnerability detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security controls are customized for different assets and attack vectors, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvecontrol customization adaptabilityVSAvoidcontrol management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal mapping framework that can accommodate different security controls, assets, and attack vectors through a common structure. The mapping relationship and scoring mechanism serve universal purposes across diverse security scenarios, enabling customized control-asset-vector associations without increasing management complexity. This universality allows adaptable control customization while maintaining systematic, manageable complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11570198B2Detecting and quantifying vulnerabilities in a network system
Publication Date: 2023.01.31 BANK OF AMERICA CORP
  • US11570198B2 patent drawing
  • US11570198B2 patent drawing
  • US11570198B2 patent drawing

AI summary

Aspects of the disclosure relate to quantification of attack surfaces in an enterprise computing system. A computing platform may receive indications of usage of a plurality of controls associated with an enterprise computing system. The computing platform may determine, based on a mapping between the plurality of controls and a plurality of attack vectors, one or more controls of the plurality of controls that are mapped to an attack vector. The computing platform may determine respective compliance scores of the one or more controls, and determine, based on the respective compliance scores, a vulnerability score associated with the attack vector. The computing platform may transmit an indication of the determined vulnerability score associated with the attack vector.