Network Component Exception Rolling Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing and remediating vulnerabilities in network components due to the large number of devices and the complexity of identifying and addressing potential security threats efficiently.

Innovation Solution

A system and method for monitoring network components to identify vulnerabilities, implementing remediation plans, and allowing for remediation suppression and rolling exceptions based on custom criteria, enabling remote monitoring and control to improve security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring and management of network components is performed, then security control can be exercised, but the time and resources required increase significantly due to the large number of network components

Engineering Contradiction:
Improvesecurity controlVSAvoidtime required for monitoring
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-monitoring of network components where the monitoring system automatically detects vulnerabilities, assesses risks, and implements remediation actions without requiring manual intervention for each component, thereby maintaining security control while eliminating time consumption

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical monitoring processes with an automated electronic monitoring system that continuously scans network components, automatically identifies vulnerabilities, and executes remediation plans, substituting human time and effort with automated computational processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If remediation actions are taken for all identified vulnerabilities, then security is improved, but unnecessary actions are performed on acceptable vulnerabilities causing inefficiency

Engineering Contradiction:
ImprovesecurityVSAvoidefficiency of remediation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different quality levels of remediation based on local conditions of each vulnerability by assessing risk factors and determining whether each specific vulnerability requires remediation or can be accepted, allowing selective application of remediation actions only where necessary rather than uniform treatment of all vulnerabilities

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of remediation application from a binary always-on approach to a conditional approach based on risk assessment parameters, where remediation is applied only when risk thresholds are exceeded, thereby eliminating unnecessary remediation actions while maintaining security for critical vulnerabilities

Inventive Principle:
Principle #35Parameter changes

3Reliability

If exceptions are manually reviewed and approved, then control over acceptable vulnerabilities is maintained, but the process becomes complex and time-consuming

Engineering Contradiction:
Improvecontrol over vulnerabilitiesVSAvoidexception management process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual exception review processes with automated risk assessment algorithms that evaluate vulnerabilities against predefined criteria and organizational policies, automatically determining whether exceptions are warranted, thereby maintaining control while eliminating process complexity and time consumption

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If comprehensive monitoring of all network components is implemented, then all vulnerabilities are detected, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvevulnerability detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into modular functional components including vulnerability scanning modules, risk assessment modules, remediation planning modules, and exception management modules, allowing the system to maintain comprehensive monitoring capabilities while reducing overall complexity through organized functional separation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal monitoring platform that can detect multiple types of vulnerabilities across diverse network components using standardized protocols and assessment criteria, enabling comprehensive detection without proportionally increasing system complexity through reusable and scalable detection mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10819731B2Exception remediation logic rolling platform
Publication Date: 2020.10.27 BANK OF AMERICA CORP
  • US10819731B2 patent drawing
  • US10819731B2 patent drawing
  • US10819731B2 patent drawing

AI summary

The invention relates generally to monitoring and managing network components, such as monitoring the network components to determine the vulnerabilities of network components, implementing remediation plans for the vulnerabilities, instituting remediation suppression for acceptable uses, instituting network component exceptions and rolling exceptions to other network components automatically, and taking consequence actions for the vulnerabilities. A network component exception may be implemented for a network component when the network component data meets custom criteria. When the custom criteria is met, the network component is automatically rolled into the network component exception process to automatically associate network component exceptions with network components that have data that meets the custom criteria. The network component exceptions prevent vulnerability actions from being taken with respect to the associated network components.