ML Database Command Security Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in managing and monitoring database commands across various databases due to complexity, frequent changes, and the need for timely and searchable information, which affects resource utilization, security compliance, and efficient operations.

Innovation Solution

A machine learning-based computing platform that retrieves, identifies, and classifies database commands, determines security scores, and provides them through an interactive interface, enabling monitoring and querying for vulnerabilities, and associating commands with security scores for efficient management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring and tracking of database commands is performed, then security compliance can be ensured, but time consumption and labor requirements increase significantly

Engineering Contradiction:
Improvesecurity complianceVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by automatically monitoring, identifying, and classifying database commands without requiring manual intervention. The machine learning model autonomously analyzes command patterns, detects vulnerabilities, and generates security scores, allowing the system to monitor itself and its own operations continuously without human labor.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical monitoring processes with an automated machine learning-based system. The machine learning model processes database commands, identifies patterns, and assesses security risks automatically, substituting human analysts and manual review processes with an intelligent automated system that operates continuously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive monitoring of all database commands is implemented, then security coverage is improved, but system complexity and resource utilization increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and focuses on the most critical aspects of database command monitoring by using machine learning to identify and prioritize commands based on vulnerability patterns. Instead of treating all commands equally, the system extracts and analyzes only the relevant features and patterns that indicate security risks, reducing complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameters of command analysis by transforming raw database commands into structured representations with security scores, vulnerability levels, and classification categories. This parameter transformation allows the system to handle comprehensive monitoring data in an organized, manageable format that reduces system complexity while improving security coverage.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If database command information is made searchable and accessible, then operational efficiency is improved, but data management complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoiddata management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-processing and indexing database commands before they are needed for search operations. The machine learning model automatically classifies commands, generates security scores, and organizes them in a searchable repository in advance, so that when users need to search for information, the data is already structured and ready for quick retrieval, improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer in the form of a searchable repository that mediates between raw database commands and user queries. This intermediary structure organizes and presents command information in a user-friendly format, making the system accessible and easy to use while managing the complexity of data storage and retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If machine learning models are trained to identify similar commands, then classification accuracy is improved, but computational resources and training time increase

Engineering Contradiction:
Improveclassification accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by training the machine learning model to identify and analyze only the most relevant patterns and features in database commands that are indicative of security vulnerabilities. Instead of analyzing every possible aspect of every command, the model focuses on the critical patterns that matter for security classification, improving accuracy while reducing computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11574217B2Machine learning based identification and classification of database commands
Publication Date: 2023.02.07 BANK OF AMERICA CORP
  • US11574217B2 patent drawing
  • US11574217B2 patent drawing
  • US11574217B2 patent drawing

AI summary

Aspects of the disclosure relate to a machine learning based identification and classification of database commands. A computing platform may retrieve, by a computing device and from a first database of a plurality of databases, a database command. Subsequently, the computing platform may identify, by the computing device and for the database command and based on a machine learning model, one or more database commands from the plurality of databases, wherein the one or more database commands perform operations similar to the database command. Then, the computing platform may determine, by the computing device and for the database command, a security score indicative of a level of vulnerability associated with the database command. Subsequently, the computing platform may provide, via an interactive graphical user interface, the database command and the security score.