Reversible Security Risk Remediation via Credential Vaulting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cloud computing security systems lack the ability to reversibly remediate security risks, often requiring manual intervention to restore access after risk mitigation, which is inefficient and inconvenient for users.

Innovation Solution

A computer-implemented system and method for reversibly remediating security risks by determining and implementing policies for mitigation, monitoring for indicators of security risks, and automatically reversing remedial actions once the risk is mitigated, utilizing APIs and serverless services like AWS Lambda to provide automated and dynamic security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional systems delete user passwords to remediate security risks, then security is improved, but user access is permanently lost requiring manual customer service intervention

Engineering Contradiction:
ImprovesecurityVSAvoiduser access restoration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by capturing and storing user credentials (passwords, authentication factors) in a secure vault before they are deleted during remediation. This preliminary capture enables automatic restoration later without requiring manual customer service intervention, thus maintaining both security and ease of access restoration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system discards user credentials securely during remediation (deleting passwords to fix security risks) and then recovers them automatically from the secure vault when the security issue is resolved. This cycle of discarding and recovering enables temporary security measures to be reversed automatically, eliminating the need for permanent access loss or manual intervention.

Inventive Principle:
Principle #34Discarding and recovering

2Reliability

If manual customer service intervention is required to restore access, then security control is maintained, but time and operational efficiency are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess restoration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by automatically restoring user credentials without requiring customer service representative involvement. The remediation system monitors security conditions, and when risks are resolved, it automatically retrieves stored credentials from the secure vault and restores user access, eliminating manual intervention and reducing time loss.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback mechanisms to monitor security risk conditions continuously. When the feedback indicates that security risks have been resolved, the system automatically triggers credential restoration. This closed-loop feedback control enables automatic decision-making for access restoration, reducing both time loss and maintaining security control.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated remediation is implemented, then operational efficiency is improved, but the ability to reversibly restore access is lost

Engineering Contradiction:
Improveremediation efficiencyVSAvoidreversibility of remediation
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary capture and storage of credentials in a secure vault before automated remediation deletes them. This preliminary action enables the automated system to reverse its own actions later, maintaining both high remediation efficiency and the adaptability to restore access when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamic remediation where the level of security restriction can change automatically based on current risk conditions. Credentials can be temporarily deleted during high-risk periods and automatically restored when risks subside, making the remediation process adaptable and reversible while maintaining high operational efficiency through automation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11665201B2Computer implemented system and method, and computer program product for reversibly remediating a security risk
Publication Date: 2023.05.30 SECUREWORKS CORP
  • US11665201B2 patent drawing
  • US11665201B2 patent drawing
  • US11665201B2 patent drawing

AI summary

Systems and methods for reversibly remediating security risks, which monitor a network or system for security risks, and upon detection of one or more of risks, apply a remedial action applicable to at least partially remedy or mitigate the one or more detected risk. The network or system is monitored for a change to the detected risk(s), and upon detection of a change to the detected risk(s), the applied remediation action is automatically reversed.