AI Security Configuration Engine for Software Policy Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise organizations face challenges in managing and controlling the security of numerous software applications across various versions and hardware architectures due to the complexity of configuration settings, leading to inconsistent security policies, increased risk of cyber breaches, and high technical debt.

Innovation Solution

An AI configuration engine that translates high-level policy requirements into technical implementation requirements for diverse technology platforms, using machine learning algorithms to identify gaps in security policies and generate uniform configuration settings across software applications and versions, thereby ensuring centralized and consistent security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If brute force methods are used to uniformly configure software applications, then security policies can be applied across applications, but the process becomes time consuming and resource intensive

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical configuration processes with an AI-based automated system. The AI engine analyzes security policies and automatically generates configuration settings for multiple software applications, eliminating the need for manual brute force configuration while maintaining policy consistency across applications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service configuration where the AI engine autonomously processes security policies, identifies required configuration settings, and generates appropriate parameters for different software applications without requiring manual intervention for each application configuration.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If separate configuration policies are developed for each software application, then specific application needs can be addressed, but policy maintenance becomes complex and consistency across applications deteriorates

Engineering Contradiction:
Improveapplication-specific configurationVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal AI engine that can process security policies and generate configuration settings for multiple different software applications from a single unified policy framework. This allows one policy structure to serve multiple applications while maintaining application-specific relevance through AI-generated adaptations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The AI engine acts as an intermediary between high-level security policies and low-level application-specific configuration settings. It translates general policy requirements into concrete configuration parameters for each application, mediating between policy creation and implementation to reduce management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual configuration updates are performed, then security policies can be updated, but changes lag behind security alerts and vulnerabilities

Engineering Contradiction:
Improvesecurity policy updatesVSAvoidupdate speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements continuous automated monitoring where the AI engine continuously scans for security alerts and vulnerability information, automatically triggers policy updates, and generates new configuration settings without interruption. This continuous operation eliminates delays between security events and configuration updates.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary actions by proactively monitoring security landscapes and preparing configuration updates before security breaches occur. The AI engine anticipates security threats and pre-generates configuration changes, ensuring security policies are updated before vulnerabilities can be exploited.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11824900B2Artificial intelligence security configuration engine
Publication Date: 2023.11.21 BANK OF AMERICA CORP
  • US11824900B2 patent drawing
  • US11824900B2 patent drawing
  • US11824900B2 patent drawing

AI summary

Artificial intelligence (“AI”) apparatus and methods are provided for hardening security of software applications. Under the conventional approaches, additional manual investment implementing security policies does not yield proportional increases in combating cyber security threats. Using manual approaches, it is increasingly difficult to consistently apply multiple policies covering different software applications or versions. This results in increased risk and technical debt. Over time, these undesirable consequences exacerbate the likelihood of inadvertently introducing an adverse policy omission or change. As the scale of software application deployed across and organization increases, it becomes even more difficult to ensure that security policies tracked and consistently applied. This may result in ineffective, contradictory or duplicative configuration requirements. AI apparatus and methods provided herein ingest human-readable policy requirements and generate technical configuration settings that implement policy requirements across diverse technology platforms.