Network Security via Inter-Application Data Flow Diagrams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise organizations face challenges in real-time monitoring and managing network activity across complex networks with numerous devices and users, making it difficult to detect anomalies and optimize resources, which can lead to insufficient security and increased costs.

Innovation Solution

A computing platform that monitors data transmissions through application programming interfaces, generates a structured database to identify structural patterns, and uses machine learning to detect potential security vulnerabilities, providing real-time visual representations and predictive analytics for mitigating threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time monitoring of data transmissions is implemented across a complex enterprise network, then network security detection capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex network monitoring task into modular components: data transmission monitoring modules at API level, structured database generation modules, machine learning model training modules, and visual representation modules. Each component handles a specific aspect of security analysis, reducing overall system complexity while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces structured databases as intermediary structures that organize raw transmission data into standardized formats with defined schemas. These structured databases serve as intermediaries between raw data and machine learning analysis, simplifying the complexity of processing unstructured network data while enabling effective security detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive data flow analysis is performed to identify security anomalies, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining structured database schemas and data organization structures before actual security analysis occurs. Transmission attributes are pre-categorized into structured formats with predetermined relationships, enabling faster processing during actual security monitoring without sacrificing detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes parameters by transforming raw transmission data into structured database formats with optimized schemas designed for efficient querying and analysis. This parameter transformation enables the system to maintain high detection accuracy while reducing processing time through optimized data organization and access patterns.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If machine learning models are trained on structured database patterns, then security vulnerability detection is improved, but computational resources increase

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent creates simplified copies of transmission data in structured database format that preserve essential security patterns while reducing data complexity. These structured copies enable machine learning models to train on representative data with reduced computational requirements while maintaining vulnerability detection effectiveness.

Inventive Principle:
Principle #26Copying

4Reliability

If the structured database is updated in real-time to reflect network changes, then security monitoring effectiveness is improved, but system performance overhead increases

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuous but optimized database updates that maintain security monitoring effectiveness without excessive performance overhead. The structured database schema enables efficient incremental updates by maintaining predefined relationships and indexes, allowing the system to continuously adapt to network changes while preserving overall system performance.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12132753B2Enhanced network security based on inter-application data flow diagrams
Publication Date: 2024.10.29 BANK OF AMERICA CORP
  • US12132753B2 patent drawing
  • US12132753B2 patent drawing
  • US12132753B2 patent drawing

AI summary

Aspects of the disclosure relate to enhanced network security based on inter-application data flows. A computing platform may monitor, via application programming interfaces, data transmissions between applications. Subsequently, the computing platform may retrieve one or more of a time of the data transmission, a source of the data transmission, and a destination of the data transmission. Then, the computing platform may generate a structured database where a pair of components of the database are dynamically linked to one another when the pair of components corresponds to a source and a destination for a data transmission. Subsequently, the computing platform may train a machine learning model to detect structural patterns within the structured database. Then, the computing platform may generate clusters indicative of similar application profiles. Then, the computing platform may predict an impact of a change in an application profile of an application of the plurality of applications.