Vulnerability Score Quantification via Control Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise organizations face challenges in determining overall vulnerability measures and identifying specific assets vulnerable to attacks due to the large number of attack vectors and varying security controls, making it difficult to quantify vulnerabilities effectively.
Innovation Solution
A computing platform determines vulnerability scores by mapping attack vectors to controls, calculating compliance and effectiveness scores, and transmitting these scores to identify vulnerabilities and recommend additional controls for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security controls are implemented to protect against various attack vectors, then security coverage is improved, but determining overall vulnerability measures becomes challenging
Solution Approach 1:
The system segments the overall vulnerability assessment into individual control-level assessments. Each security control is evaluated separately against its mapped attack vectors, producing discrete compliance scores and effectiveness scores. This segmentation transforms the complex overall vulnerability determination into manageable control-specific evaluations, resolving the contradiction between comprehensive security coverage and determination complexity.
Solution Approach 2:
The system introduces quantifiable parameters (compliance scores and effectiveness scores) to transform qualitative security control evaluations into measurable metrics. By changing the assessment from subjective judgment to parameter-based scoring, the system enables automated calculation of overall vulnerability measures, reducing determination complexity while maintaining comprehensive security coverage.
2Measurement precision
If comprehensive vulnerability assessment is performed across all assets and attack vectors, then measurement precision is improved, but the difficulty of detecting and measuring vulnerabilities increases
Solution Approach 1:
The system divides the comprehensive vulnerability assessment task into discrete control-level evaluations. Each control is assessed independently against its specific attack vectors, producing precise compliance and effectiveness scores. This segmentation maintains measurement precision by evaluating each control thoroughly while reducing detection difficulty through automated, standardized scoring procedures.
Solution Approach 2:
The system introduces an intermediary mapping relationship between controls and attack vectors that facilitates systematic assessment. This mapping structure serves as a mediator that organizes the complex relationships between security controls and attack vectors, enabling precise measurement through standardized evaluation procedures while reducing the difficulty of comprehensive vulnerability detection.
3Adaptability or versatility
If security controls are customized for different assets and attack vectors, then adaptability is improved, but device complexity increases
Solution Approach 1:
The system implements a universal mapping framework that can accommodate different security controls, assets, and attack vectors through a common structure. The mapping relationship and scoring mechanism serve universal purposes across diverse security scenarios, enabling customized control-asset-vector associations without increasing management complexity. This universality allows adaptable control customization while maintaining systematic, manageable complexity.
Data Source
AI summary
Aspects of the disclosure relate to quantification of attack surfaces in an enterprise computing system. A computing platform may receive indications of usage of a plurality of controls associated with an enterprise computing system. The computing platform may determine, based on a mapping between the plurality of controls and a plurality of attack vectors, one or more controls of the plurality of controls that are mapped to an attack vector. The computing platform may determine respective compliance scores of the one or more controls, and determine, based on the respective compliance scores, a vulnerability score associated with the attack vector. The computing platform may transmit an indication of the determined vulnerability score associated with the attack vector.


