Automated Security Architecture Design Using Directed Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions for large networks are cumbersome, prone to errors, and difficult to implement due to the complexity of scaling and decentralized updates, making it impractical to manually identify and modify security architectures based on constraints such as cost, time, and security requirements.

Innovation Solution

A system and method that includes an interface to access remote data sources for security information, a processor to identify user-based constraints, and automatically generate a security architecture model that complies with these constraints by comparing and modifying existing models, using directed graphs to represent network architectures and incorporating data from various sources to ensure accuracy and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to identify and modify security architectures, then human expertise and flexibility can be applied, but the process becomes cumbersome, error-prone, and difficult to scale for large networks

Engineering Contradiction:
Improveaccuracy of security architecture identificationVSAvoidcomplexity of security architecture modification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical analysis methods with automated computer-based systems that use algorithms to identify security architectures, analyze constraints, and generate modification recommendations. This substitution eliminates human error while handling large-scale network complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables security architectures to be self-analyzed and self-modified through automated constraint satisfaction algorithms that independently evaluate security requirements and generate compliance solutions without continuous human intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If security solutions are implemented on large-scale networks with thousands of computers, then comprehensive security coverage is achieved, but implementation becomes cumbersome and latency increases

Engineering Contradiction:
Improvesecurity coverage completenessVSAvoidspeed of security implementation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments large-scale networks into manageable components represented as directed graphs, allowing security analysis and modification to be performed on modular sections. This segmentation enables parallel processing and reduces overall implementation latency while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security parameters and constraints based on network scale and characteristics, optimizing the balance between comprehensive security coverage and implementation speed for different network sizes and configurations.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If decentralized rapid updates are executed to maintain current security architectures, then adaptability to changing threats is improved, but accurate schematic tracking becomes impossible

Engineering Contradiction:
Improveresponsiveness to security threatsVSAvoidaccuracy of network architecture schematic
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements automated feedback mechanisms that continuously monitor and track network architecture changes through algorithmic analysis of network data. This feedback loop maintains accurate schematics despite decentralized updates by automatically detecting and recording configuration changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary automated analysis of network architectures before changes are made, establishing baseline schematics and predicting potential modification paths. This preliminary action ensures accurate tracking even as decentralized updates occur.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple security architecture models are generated to meet different constraints, then solution versatility is improved, but computational complexity increases

Engineering Contradiction:
Improvenumber of constraint-compliant solutionsVSAvoidcomputational complexity of model generation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent generates security architecture models with varying degrees of completeness based on constraint satisfaction requirements. Rather than exhaustively generating all possible models, the system produces sufficient solutions that meet the specified constraints, reducing computational complexity while maintaining versatility.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11115439B2Automated security solutions identification and architecture design
Publication Date: 2021.09.07 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11115439B2 patent drawing
  • US11115439B2 patent drawing
  • US11115439B2 patent drawing

AI summary

Systems, apparatuses, and methods directed to security enhancement. One or more remote data sources may be accessed to retrieve remote data associated with security for a computing architecture. An input model of an input network security architecture may be identified. One or more user-based constraints may be identified. An output model may be automatically generated based on the input model, the remote data and the one or more user-based constraints. The output model is an output network security architecture that complies with the one or more user-based constraints.