Cyber Security Model Framework for Access Path Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems lack effective mechanisms to monitor and control access to internal computing devices within a network, leading to vulnerabilities that can result in unauthorized access and data breaches, causing potential loss and impact on entities and customers.

Innovation Solution

A model framework and system that utilizes a distributed network of servers to determine access paths, controls, and tools to regulate access, detect unauthorized access, and incorporate tools to monitor and prohibit access, thereby reducing exposure scores and mitigating potential losses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures are adopted to protect technology resources, then data security is improved, but the system lacks effective monitoring and control mechanisms leading to unauthorized access vulnerabilities

Engineering Contradiction:
Improvedata securityVSAvoidmonitoring and control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cybersecurity system into multiple specialized modules including access path determination module, control capability determination module, tool identification module, and exposure score calculation module. Each module handles a specific aspect of security monitoring, making the complex system manageable and effective without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary cybersecurity system that acts as a mediator between internal computing devices and external access attempts. This intermediary system monitors access paths, evaluates control capabilities, and coordinates security responses without requiring direct modification of protected devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If comprehensive access monitoring is implemented to detect unauthorized access, then security detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveunauthorized access detectionVSAvoidsecurity system structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent creates a universal cybersecurity system that performs multiple functions through integrated modules: determining access paths, evaluating control capabilities, identifying appropriate tools, calculating exposure scores, and coordinating security responses. This multi-functional approach improves detection capability while avoiding the complexity of separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors access attempts, evaluates control effectiveness, and adjusts security measures based on detected threats. The exposure score calculation provides quantitative feedback to prioritize security interventions and measure improvement effectiveness

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple security tools are incorporated to regulate access controls, then access control effectiveness is improved, but implementation complexity and deployment time increase

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidsystem implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a dynamic tool identification and selection mechanism that adapts to specific security needs and contexts. The system evaluates control capabilities and identifies appropriate tools based on real-time requirements rather than deploying fixed comprehensive toolsets, reducing implementation complexity while maintaining effectiveness

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary analysis of access paths and control capabilities before deploying security tools. By pre-evaluating security requirements and identifying appropriate controls in advance, the system simplifies implementation and reduces deployment time while ensuring effective access control

Inventive Principle:
Principle #10Preliminary action

4Reliability

If the system monitors all access paths to internal computing devices, then security coverage is improved, but computational resources and processing time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by focusing security monitoring resources on specific high-risk access paths and vulnerable internal computing devices rather than uniformly monitoring all paths. The system evaluates and prioritizes access paths based on their security significance, concentrating computational resources where they provide maximum security coverage with minimum energy consumption

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10003598B2Model framework and system for cyber security services
Publication Date: 2018.06.19 BANK OF AMERICA CORP
  • US10003598B2 patent drawing
  • US10003598B2 patent drawing
  • US10003598B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for a model framework and system for cyber security services. The present invention is configured to determine one or more access paths to the internal computing device from an external computing device; determine one or more controls associated with each access path; determine one or more types of access that may be made via one or more of the access paths by the external computing device to access the internal computing device; determine whether the one or more controls associated with the at least one of the one or more access paths is capable of detecting the access; determine one or more tools configured to regulate the one or more controls; and incorporate the one or more tools within the network to regulate the one or more controls to detect and monitor the access.