Endpoint Security AI for Dynamic OS Mismatch Intervention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems fail to effectively identify and address security compromises in endpoint devices due to limited evaluation of changes in operating systems, leading to unresolved security issues and delayed responses.

Innovation Solution

A security alert and intervention system that employs artificial intelligence to monitor and respond to changes in endpoint devices, providing tailored security responses, including immediate interventions and updates based on user interactions, to detect and mitigate potential security threats in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems use predefined malicious file identification, then specific known threats can be detected, but most potential security issues remain unidentified and unresolved

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidcoverage of security issues
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the security evaluation process into multiple independent analysis components: file integrity checking, registry modification monitoring, configuration change detection, and behavior analysis. Each segment focuses on specific aspects of system changes, allowing comprehensive coverage without relying on a single detection method. This segmentation enables the system to identify both known malicious files and previously unrecognized security compromises.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security assessment system is designed as a multi-functional platform that performs diverse security evaluation tasks: comparing current system state against baseline configurations, analyzing modification patterns, evaluating security implications of changes, and generating contextualized alerts. This universal system replaces multiple specialized tools with a single comprehensive security assessment mechanism that adapts to various threat types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security systems implement comprehensive monitoring of all operating system changes, then all security compromises can be identified, but system complexity and processing overhead increase significantly

Engineering Contradiction:
Improvesecurity compromise identificationVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing monitoring intensity on specific critical areas of the operating system rather than uniformly monitoring all changes. High-priority regions such as security configurations, authentication mechanisms, and system binaries receive enhanced scrutiny, while less critical areas use lighter monitoring. This targeted approach maintains high reliability for security-critical detections while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary assessment layer that sits between raw system changes and security conclusions. This intermediary component contextualizes changes by comparing them against baseline configurations, evaluating their security implications, and filtering out benign modifications before generating alerts. This mediation reduces complexity by preprocessing and contextualizing data before final security determination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security responses are delayed for administrator review, then false positives can be avoided, but response time to actual threats increases to hours or days

Engineering Contradiction:
Improvefalse positive reductionVSAvoidsecurity response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic response strategies where the level of automation and speed of intervention adjusts based on threat severity and confidence levels. High-confidence threats trigger immediate automated responses, while lower-confidence cases proceed to administrator review. This dynamic approach optimizes response time for critical threats while maintaining reliability through human review for uncertain cases, eliminating the need for uniform delayed responses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary assessment and classification of security events before they reach the administrator review stage. By pre-evaluating changes against baseline configurations and determining initial risk levels, the system prepares contextualized information for administrators, enabling faster and more informed decision-making. This preliminary action reduces the time administrators need to spend on each alert while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If users are restricted from making changes to the operating system, then security compromise is prevented, but user flexibility and task completion efficiency decrease

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements continuous feedback loops where system changes are monitored, evaluated, and used to update security baselines. When users make legitimate changes, the system assesses their security implications and, if acceptable, updates the baseline to reflect the new legitimate state. This feedback mechanism allows user flexibility while maintaining security protection, as the system learns and adapts to authorized changes rather than rigidly blocking all modifications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security assessment system provides self-service capabilities by automatically evaluating user-initiated changes, comparing them against security policies, and making determination without requiring constant administrator intervention. The system serves itself by maintaining and updating baseline configurations, assessing security risks, and enabling or blocking changes based on automated evaluation. This self-service approach preserves user flexibility while maintaining security protection through automated decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11949696B2Data security system with dynamic intervention response
Publication Date: 2024.04.02 BANK OF AMERICA CORP
  • US11949696B2 patent drawing
  • US11949696B2 patent drawing
  • US11949696B2 patent drawing

AI summary

A system determines baseline deployment properties of operating system deployments stored by a deployment repository and endpoint deployment properties of a deployed operating system executed by an endpoint device. An artificial intelligence model is configured to determine a security response based at least in part on the endpoint deployment properties of the endpoint device. By providing the endpoint deployment properties to the artificial intelligence model, a mismatch value is determined that corresponds to an amount that the endpoint deployment properties are different than the baseline deployment properties. Based on the mismatch value, an action is determined to improve security of the deployed operating system executed by the endpoint device. The determined action is executed to improve security of the deployed operating system.