Dynamic Website Access Control via Machine Learning Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of applications increases in an organization, cybersecurity risks associated with security vulnerabilities rise, particularly when members access compromised websites, posing a threat of malicious exploitation. Existing methods lack effective means to assess and mitigate these risks dynamically.

Innovation Solution

A method utilizing a machine-learning algorithm to determine the impact level and security breach probability of unblocking a website, based on website gateway data and threat data, to decide whether to modify access lists and allow user devices to access the website, thereby mitigating potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations block access to websites to prevent security breaches, then security reliability is improved, but network accessibility and productivity deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidnetwork accessibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic website blocking decisions by continuously analyzing multiple data sources including threat intelligence, website reputation, and security metrics. The system automatically adjusts blocking status based on real-time risk assessment, transitioning from static blocking lists to dynamic, context-aware access control that adapts to changing security conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system evaluates multiple parameters including threat level, website reputation score, security vulnerability data, and business criticality to make informed blocking decisions. By changing the parameters considered for blocking decisions and weighting them appropriately, the system achieves both security reliability and network accessibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If organizations use comprehensive website blocking lists to prevent malicious sites, then security protection is improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where the system automatically updates blocking lists, adjusts security policies, and makes blocking decisions without requiring manual intervention. The automated system monitors threat intelligence sources, evaluates website safety, and dynamically updates access control rules, reducing administrative burden while maintaining comprehensive security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops that continuously monitor security outcomes, user access patterns, and threat landscape changes. This feedback drives automatic adjustments to blocking lists and security policies, enabling the system to adapt to new threats while maintaining manageable complexity through data-driven decision making.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If organizations manually review and unblock websites to allow access, then access control precision is improved, but time consumption and operational efficiency worsen

Engineering Contradiction:
Improveaccess control precisionVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-evaluating websites against multiple security criteria and maintaining updated blocking lists before access requests occur. The system proactively identifies safe websites and prepares access decisions in advance, so when users need access, the system can quickly retrieve pre-made decisions rather than requiring time-consuming manual reviews.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual mechanical review processes with automated electronic analysis using machine learning algorithms, threat intelligence databases, and security scanning tools. This substitution maintains high precision in access control decisions while eliminating the time consumption associated with manual human review of each website request.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11711393B2Methods and systems for managing website access through machine learning
Publication Date: 2023.07.25 SAUDI ARABIAN OIL CO
  • US11711393B2 patent drawing
  • US11711393B2 patent drawing
  • US11711393B2 patent drawing

AI summary

A method may include obtaining a request to unblock a predetermined website in a network and that is associated with a predetermined list. The predetermined list may be used to determine whether a respective user device among various user devices can access one or more websites. The method may further include determining an impact level of the predetermined website for an organization using a machine-learning algorithm and website gateway data. The method may further include determining a probability of a security breach using the machine-learning algorithm and threat data. The method may further include determining whether to unblock the predetermined website based on the impact level and the probability of a security breach. The method may further include transmitting, in response to determining that the predetermined website should be unblocked, a command that modifies the predetermined list to enable the respective user device to access the predetermined website.