Dynamic Network Asset Classification for Threat Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems fail to effectively identify, prevent, and rectify security threats in computing devices due to their inability to dynamically adapt to shifting conditions and compromise vectors within a network environment.

Innovation Solution

A system that dynamically classifies computing assets based on characteristics like geographic location, operating system, and hardware configuration, identifies compromise vectors, and generates remediation steps, including isolation and antivirus updates, to mitigate threats by dynamically updating classifications and implementing recommended actions in response to changing conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional static classification methods are used for network assets, then system complexity is reduced, but the system cannot adapt to changing security threats and environments

Engineering Contradiction:
Improveadaptability to changing conditionsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic classification of network assets by continuously monitoring asset characteristics, geographic locations, and threat environments. Classification labels are automatically updated in real-time based on changing conditions, allowing the system to adapt to new security threats without manual intervention. This dynamic approach resolves the contradiction by making the system flexible and responsive while managing complexity through automated processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that continuously monitor asset states, threat vectors, and classification accuracy. This feedback mechanism enables the system to learn from emerging threats and adjust classifications accordingly, improving adaptability while maintaining manageable complexity through iterative refinement of security policies based on observed conditions.

Inventive Principle:
Principle #23Feedback

2Loss of time

If dynamic classification and continuous monitoring are implemented, then security response time is reduced, but computational resources and system complexity increase

Engineering Contradiction:
Improveresponse time to threatsVSAvoidcomputational resources
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The patent applies partial monitoring and classification actions by focusing computational resources on assets and threat vectors that pose the highest risk. Rather than continuously analyzing all assets equally, the system dynamically prioritizes monitoring based on threat levels and asset criticality, reducing overall computational overhead while maintaining rapid response times for high-priority security events.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes monitoring parameters dynamically based on threat conditions. During low-threat periods, monitoring intensity is reduced to conserve computational resources. During high-threat periods or when suspicious activity is detected, monitoring frequency and depth increase automatically, enabling rapid response when needed while optimizing resource usage during normal operations.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive asset classification and threat analysis are performed, then security coverage is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network security system into distinct functional modules: asset classification components, threat vector identification components, classification label assignment components, and remediation recommendation components. Each module handles specific aspects of security analysis independently, improving comprehensive coverage while managing complexity through modular architecture that allows independent development, testing, and maintenance of each security function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11741228B2System for generating computing network segmentation and isolation schemes using dynamic and shifting classification of assets
Publication Date: 2023.08.29 BANK OF AMERICA CORP
  • US11741228B2 patent drawing
  • US11741228B2 patent drawing

AI summary

A system is provided for generating computing network segmentation and isolation schemes using dynamic and shifting classification of assets. In particular, the system may comprise various components that may identify and classify assets (e.g., computing devices) within a network, network topology, and vectors that may compromise one or more assets. The system may further comprise a component for mitigating and rectifying the effects of such vectors. Each asset within the network may be assigned a classification which may be dynamically modified and/or shifted by the system based on changing requirements and/or environments. In this way, the system may provide a more comprehensive way to protect the integrity and security of computing devices and/or electronic data.