Cognitive Engine Network Security Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security systems require frequent and laborious updates to manage network traffic flow, often only occurring after vulnerabilities are exposed, necessitating a more efficient method for identifying and addressing rule vulnerabilities.

Innovation Solution

An automated network security system utilizing a cognitive engine and robotic process automation to continuously monitor traffic, analyze behavioral data, generate virtual testing environments, and simulate rule changes to identify and rectify vulnerabilities before they are exposed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updates to network security rules are performed, then security vulnerabilities can be addressed, but the process is time-consuming and laborious

Engineering Contradiction:
Improvesecurity vulnerability remediationVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring network traffic and proactively identifying security vulnerabilities before they can be exploited. The cognitive engine analyzes behavioral data in real-time to detect potential threats, allowing security rules to be updated before actual breaches occur, thus reducing both time loss and improving reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network security system performs self-service through automated vulnerability detection and rule generation. The cognitive engine independently analyzes network traffic patterns, identifies security gaps, and generates updated security rules without requiring manual intervention. This automation eliminates the time-consuming manual update process while maintaining high reliability in vulnerability remediation.

Inventive Principle:
Principle #25Self-service

2Reliability

If frequent updates to network security rules are performed, then security coverage is improved, but the complexity of managing and testing rules increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cognitive engine serves as an intermediary between network traffic monitoring and security rule management. It processes raw network traffic data, identifies vulnerabilities, and generates candidate security rules. The robotic process automation system then acts as another intermediary to test these rules in a virtual environment before deployment. This intermediary layering manages complexity by breaking down the rule management process into automated, manageable stages while improving security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of the network environment to test security rules before deploying them to production. The robotic process automation system generates virtual testing environments that replicate real network conditions, allowing frequent rule updates to be tested safely without affecting actual network operations. This copying approach enables frequent updates while managing complexity through isolated testing.

Inventive Principle:
Principle #26Copying

3Manufacturing precision

If manual testing of security rule changes is performed, then rule accuracy can be verified, but the process is laborious and slow

Engineering Contradiction:
Improverule accuracyVSAvoidrule update speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system replaces manual mechanical testing processes with automated robotic process automation. The robotic process automation system systematically tests security rule changes in virtual environments, eliminating the need for manual testing while maintaining high rule accuracy. This substitution of automated systems for manual operations verifies rule precision without sacrificing update speed, directly resolving the contradiction between manufacturing precision and productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The robotic process automation system changes testing parameters by executing multiple test scenarios with varying network traffic patterns, threat types, and rule configurations. This systematic variation of test parameters comprehensively verifies rule accuracy across different conditions, ensuring high manufacturing precision while maintaining fast update speeds through automated execution of extensive test suites.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10958691B2Network security system with cognitive engine for dynamic automation
Publication Date: 2021.03.23 BANK OF AMERICA CORP
  • US10958691B2 patent drawing
  • US10958691B2 patent drawing
  • US10958691B2 patent drawing

AI summary

Embodiments of the present invention provide an automated network security system for dynamically managing network security rules. The system uses a cognitive engine to capture network traffic and analyze behavioral data about said network traffic. Based on analysis of the behavioral data, the system may identify one or more vulnerabilities in the network security system and determine one or more changes to the network security rules to remedy the one or more vulnerabilities. The system further uses a robotic process automation system to test and simulate the one or more changes.