Network Security Data Models for Unmanaged Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to identify all existing relationships within an entity, leading to difficulties in identifying unmanaged devices consuming confidential data, which poses a risk of exposure.

Innovation Solution

A system generates solution data models by integrating authentication, human resources, and asset management information to identify relationships between asset systems, users, and logical assets, allowing for the identification and mitigation of unmanaged devices by automatically applying security patches, disconnecting access to confidential data, or disconnecting from the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems are used to manage devices in a network, then system simplicity is maintained, but the ability to identify all existing relationships and unmanaged devices is insufficient

Engineering Contradiction:
Improveidentification accuracy of relationships and unmanaged devicesVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources including authentication systems, asset management systems, and human resources systems into a unified data model. This integration allows the system to identify all existing relationships within an entity and detect unmanaged devices by comparing expected versus actual device states across these merged data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments the identification process into distinct components: generating a data model from multiple sources, identifying relationships between assets and users, detecting unmanaged devices through comparison, and mitigating exposures. This segmentation allows each component to be optimized independently while maintaining overall system manageability.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If comprehensive data integration is performed to identify all relationships, then identification completeness is improved, but data processing complexity increases

Engineering Contradiction:
Improvecompleteness of relationship informationVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-generating comprehensive data models that incorporate authentication, asset management, and human resources information before actual device identification is needed. These pre-computed models establish expected device states and relationships in advance, enabling faster and simpler real-time detection of unmanaged devices without processing all raw data during the identification phase.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If unmanaged devices are identified and exposed, then security risk is increased, but automated mitigation capability is needed to reduce exposure

Engineering Contradiction:
Improvesecurity exposure riskVSAvoidautomated mitigation capability
Core Design Contradiction:
Object-affected harmful factorsVSExtent of automation

Solution Approach 1:

The system implements self-service automated mitigation capabilities that automatically respond to identified unmanaged devices without requiring manual intervention. When unmanaged devices are detected, the system autonomously executes mitigation actions such as isolating devices from the network, revoking access credentials, or alerting appropriate personnel, thereby reducing security exposure risk through automated self-correction.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10970406B2System for mitigating exposure associated with identified unmanaged devices in a network using solution data modelling
Publication Date: 2021.04.06 BANK OF AMERICA CORP
  • US10970406B2 patent drawing
  • US10970406B2 patent drawing
  • US10970406B2 patent drawing

AI summary

Embodiments of the present invention provide a system for mitigating exposures associated with identified unmanaged devices in a network using solution data modelling. The system is typically configured for generating one or more solution data models comprising a plurality of asset systems and a plurality of users, storing the one or more solution data models in a model database, receiving an input from a user to identify unmanaged devices in a network, accessing a first solution data model associated with the network from the model database, identifying the unmanaged devices in the network based on the first solution data model, and displaying information associated with the unmanaged devices to the user.