ML Security Governance Recommendations for Secured-by-Design Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid evolution of technological advancements and complex cybersecurity threats pose challenges for companies to timely and consistently secure their computing environments, as consultants and companies may lack knowledge on relevant security controls and solutions, leading to difficulties in identifying and deploying necessary security measures.

Innovation Solution

The development of machine learning (ML) systems and methods that access threat and security solution knowledge data to analyze current and future security states, using trained ML models to generate security governance recommendations for secured-by-design computing environments, which can be displayed on computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security assessment methods are used, then security expertise is required to identify threats and solutions, but the complexity and speed of identifying and responding to security threats increases due to the rapid evolution of cyber threats

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidtime to identify and respond to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated security assessment where the computing environment self-evaluates its security state by collecting security state data from various components and analyzing it through trained ML models, eliminating the need for manual expert intervention in continuous monitoring

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual security assessment processes are replaced with machine learning models that automatically analyze security state data, threat patterns, and solution effectiveness, substituting human expert analysis with automated intelligent systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive security controls are implemented, then security coverage is improved, but the device complexity and cost of implementing and maintaining security solutions increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity solution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts security controls based on analyzed risk levels and threat patterns, changing security parameters such as monitoring intensity, control strictness, and resource allocation rather than maintaining fixed maximum-security configurations

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies security controls selectively based on risk assessment, implementing comprehensive controls only where needed rather than uniformly across all systems, reducing overall complexity while maintaining adequate coverage

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If manual security assessment processes are used, then security expertise knowledge is required, but the scalability and consistency of security recommendations across different computing environments decreases

Engineering Contradiction:
Improvesecurity recommendation qualityVSAvoidscalability to different environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The ML models are trained on diverse security state data from multiple computing environments and threat patterns, enabling them to provide consistent security recommendations across different environments, architectures, and scales without requiring environment-specific customization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11811797B2Machine learning methods and systems for developing security governance recommendations
Publication Date: 2023.11.07 MCKINSEY & CO INC
  • US11811797B2 patent drawing
  • US11811797B2 patent drawing
  • US11811797B2 patent drawing

AI summary

Machine learning methods and systems for developing security governance recommendations are disclosed. An example method includes: accessing threat assessment knowledge data representative of security threats and threat patterns; accessing security solution knowledge data representative of security solutions; obtaining first security state data representing a current security state of a current computing environment; obtaining second security state data representing a future security state for a future secured-by-design computing environment; analyzing, using one or more first trained machine learning (ml) models, one or more of (i) the threat assessment knowledge data, (ii) the security solution knowledge data, (iii) the first security state data, or (iv) the second security state data to develop one or more aspects of a security governance recommendation for the future secured-by-design computing environment; and causing the one or more aspects of the security governance to be displayed on a computing device.