Dynamic Firewall Mode Adjustment for Network Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures struggle to effectively enhance the operational resilience of computer networks against cyber threats, as they often require trade-offs between security attributes and fail to adapt dynamically to evolving vulnerabilities, leading to potential operational disruptions.

Innovation Solution

A cybersecurity adaptation system that utilizes a matrix representation of networked assets to detect and analyze cybersecurity threats, calculate a criticality score, and transform firewall modes to restrict data flow, thereby improving network resilience through a configurable firewall system and predictive analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures are implemented, then security protection is provided, but operational flexibility and dynamic adaptation to threats are reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoiddynamic adaptation to threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic cybersecurity modes (first mode with normal data flow, second mode with restricted data flow) that can transition based on detected threat levels. The system continuously monitors cybersecurity threats and adapts the operational state of network assets, transforming static security measures into dynamic responses that adjust protection levels in real-time based on actual threat conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If centralized management and control mechanisms are implemented, then security control is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables network assets to automatically detect cybersecurity threats and self-manage their operational states by transitioning between cybersecurity modes. The distributed architecture allows each asset to independently monitor its own security posture and adjust its data flow restrictions without requiring complex centralized coordination, thereby reducing overall system complexity while maintaining effective security control.

Inventive Principle:
Principle #25Self-service

3Reliability

If security restrictions are increased to protect important assets, then security level is improved, but operational efficiency and productivity decrease

Engineering Contradiction:
Improvesecurity levelVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts security restrictions based on actual threat levels rather than maintaining constant high-level protection. When cybersecurity threats are detected, the system transitions to a second mode with restricted data flow to protect assets; when threats are absent, it operates in a first mode with normal data flow, thereby maintaining security while preserving operational efficiency during low-threat periods.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11316883B2Cybersecurity—operational resilience of computer networks
Publication Date: 2022.04.26 BANK OF AMERICA CORP
  • US11316883B2 patent drawing
  • US11316883B2 patent drawing
  • US11316883B2 patent drawing

AI summary

A plurality of communicatively coupled, networked assets may be threatened or attacked by a cybersecurity attack. The operational resiliency of the computer network determines whether the cybersecurity attack leads to a shutdown of one or more assets, or even the entire computer network. A cybersecurity server selectively restricts and controls the data flow over the network and transforms a configurable, networked asset from a low, medium, and high cybersecurity mode. The cybersecurity server may reside on a firewall device or other networked device, and adjusts the cybersecurity mode based on a criticality score that measures the operational resiliency of the computer network. The criticality score changes as cybersecurity threats or attacks are identified and as mitigation strategies are implemented on the networked assets.