Zero Trust Engine for Threshold-Based Cyberthreat Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cyberthreat remediation methods are inefficient and resource-intensive, often requiring significant time and resources for frequent remediation actions, making networks and applications susceptible to threats in the intervening periods.
Innovation Solution
A computing platform with a zero trust engine that receives cyberthreat and vulnerability information, generates cyberthreat mappings, and initiates remediation actions only when the cyberthreat level indicator satisfies a threshold, conserving resources by optimizing the frequency of remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional remediation actions are performed frequently to ensure network security, then network security is improved, but resource consumption and time cost increase significantly
Solution Approach 1:
The patent implements dynamic remediation by adjusting the frequency and intensity of security assessments based on real-time threat indicators and vulnerability data. Instead of fixed periodic remediation, the system continuously monitors cyberthreat levels and automatically triggers remediation actions only when thresholds are exceeded, optimizing resource usage while maintaining security.
Solution Approach 2:
The system changes the parameter of remediation frequency from a static value to a dynamic value determined by multiple factors including cyberthreat indicators, vulnerability severity, and risk thresholds. This allows the remediation process to adapt its intensity and timing based on actual security conditions, reducing unnecessary resource consumption during low-risk periods.
2Loss of energy
If remediation actions are performed infrequently to conserve resources, then resource consumption is reduced, but network susceptibility to cyberthreats increases
Solution Approach 1:
The patent implements continuous feedback loops where the system monitors cyberthreat indicators, vulnerability data, and remediation effectiveness in real-time. This feedback mechanism enables the system to detect changes in security conditions and automatically trigger remediation actions when necessary, ensuring resources are used only when actually needed to address genuine security risks.
Solution Approach 2:
The system performs preliminary assessments by continuously collecting and analyzing threat intelligence and vulnerability data before actual remediation actions are required. This advance preparation allows the system to quickly respond to emerging threats without needing to maintain constant high-level remediation activities, optimizing resource allocation.
3Measurement precision
If manual review and penetration testing are conducted on all applications, then identification accuracy of cyberthreat risks is improved, but time consumption and operational complexity increase
Solution Approach 1:
The patent segments the application portfolio into different risk categories based on vulnerability data, cyberthreat indicators, and criticality assessments. This segmentation allows the system to apply different levels of assessment intensity to different applications, focusing manual review and penetration testing only on high-risk segments while using automated assessments for lower-risk applications.
Solution Approach 2:
The system introduces an intermediary automated assessment layer that processes the majority of applications using machine learning models and threat intelligence analysis. This intermediary layer filters out low-risk applications before they reach manual review, significantly reducing the time and complexity burden on security teams while maintaining high identification accuracy for genuine threats.
4Productivity
If automated assessment tools are used to reduce manual effort, then operational efficiency is improved, but measurement precision and detection capability may be reduced
Solution Approach 1:
The patent merges multiple automated assessment tools, machine learning models, and threat intelligence sources into a unified security assessment platform. This combination leverages the strengths of different automated systems while using centralized coordination to maintain high detection accuracy. The unified platform correlates data from multiple sources to reduce false positives and improve overall measurement precision.
Solution Approach 2:
The system uses an intermediary human expert review layer for complex or high-stakes assessments where automated tools may lack sufficient precision. This intermediary approach allows automated tools to handle routine assessments efficiently while reserving human expertise for cases requiring higher measurement precision, thus maintaining both productivity and accuracy.
Data Source
AI summary
Aspects related to cyberthreat remediation using a zero trust engine are provided. A cyberthreat remediation platform may train a zero trust engine to generate cyberthreat mappings comprising vulnerability-cyberthreat pairings based on the information. The platform may generate a cyberthreat level indicator for the application based on the cyberthreat record. The platform may compare the cyberthreat level indicator to a threshold to identify whether remediation actions should be initiated. Based on the comparison, the platform may initiate one or more remediation actions to resolve one or more cyberthreats and may update cybersecurity information. The platform may update the zero trust model based on the cybersecurity information.


