Multi-Source Cybersecurity Policy Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Data Loss Prevention (DLP) platforms face challenges in balancing security with employee productivity, often resulting in false positives, inefficiencies, and increased complexity due to the rise of remote work and cloud adoption, leading to blind spots in data protection.

Innovation Solution

A system and method that normalize multiple cybersecurity policies stored in different data formats, using a generative artificial intelligence model to generate policies in various formats, allowing for unified application across multiple cybersecurity platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple cybersecurity policies in different data formats are applied across various platforms, then comprehensive data protection coverage is improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvedata protection coverageVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple cybersecurity policies from different sources and formats into a single unified policy. The system ingests policies from various platforms (Cloudflare, AWS, Azure, etc.) in different data formats, normalizes them, and merges them into one comprehensive policy that provides holistic data protection across all platforms, thereby reducing management complexity while maintaining comprehensive coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified cybersecurity policy serves multiple functions across different platforms simultaneously. A single policy can be applied to protect data across cloud services, endpoints, networks, and other environments, making the system universal and multi-functional rather than requiring separate policies for each platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If strict cybersecurity policies are enforced to enhance security, then data protection is improved, but employee productivity and workflow efficiency deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidemployee workflow efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts policy parameters based on context, user roles, and risk levels. Instead of applying uniform strict policies everywhere, it modifies policy parameters to allow legitimate business activities while maintaining security, thereby reducing false positives and improving employee productivity without compromising overall security protection

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple cybersecurity platforms are deployed to cover all security needs, then comprehensive protection is improved, but false positives and system overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The unified policy acts as an intermediary layer between multiple cybersecurity platforms. It receives inputs from various platforms, processes them through a single policy framework, and coordinates their actions, thereby reducing conflicts and false positives that arise when multiple platforms operate independently with overlapping or conflicting rules

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12316686B1System and method for applying multi-source cybersecurity policy on computing environments
Publication Date: 2025.05.27 CYERA LTD
  • US12316686B1 patent drawing
  • US12316686B1 patent drawing
  • US12316686B1 patent drawing

AI summary

A system and method for generating multi-source cybersecurity policies is presented. The method includes receiving a plurality of cybersecurity policies, wherein a first cybersecurity policy is stored in a first data format, and a second cybersecurity policy is stored in a second data format; generating a normalized cybersecurity policy based on each received cybersecurity policy, including a normalized first cybersecurity policy and a normalized second cybersecurity policy; generating a first generated cybersecurity policy based on the normalized first cybersecurity policy, utilizing the second data format; generating a second generated cybersecurity policy based on the normalized second cybersecurity policy, utilizing the first data format; and applying each of the generated cybersecurity policies on a respective cybersecurity platform.