Security Control Selection for Data Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices face challenges in controlling data leakage, unauthorized access, and preventing malicious activities due to vulnerabilities in data storage devices, which are susceptible to various attacks.

Innovation Solution

A system that monitors and adjusts security controls for data storage devices by determining their current security level and applying appropriate security measures, such as software and hardware configurations, to enhance information security before data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security controls are applied to data storage devices to improve information security level, then the device becomes more vulnerable to attacks, but the complexity of device configuration increases

Engineering Contradiction:
Improveinformation security levelVSAvoidsecurity control configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary vulnerability assessment and security level determination before data storage operations. The information security device evaluates the target data storage device's security posture in advance, identifies vulnerabilities, and applies appropriate security controls proactively. This preliminary action ensures that security measures are in place before actual data storage, preventing security issues rather than reacting to them afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables data storage devices to self-assess their security levels and self-configure appropriate security controls. The information security device automatically evaluates vulnerabilities and applies security configurations without requiring manual intervention from system administrators. This self-service approach reduces operational complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

2Reliability

If vulnerability assessment is performed on data storage devices, then the security level can be determined, but the time required for data storage operations increases

Engineering Contradiction:
Improvesecurity level determinationVSAvoiddata storage operation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Vulnerability assessments and security level determinations are performed in advance before actual data storage operations. The information security device evaluates the target data storage device's security posture beforehand, so that when data storage is needed, the assessment is already complete and security controls are pre-configured. This eliminates the time penalty during actual storage operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms where vulnerability assessment results are used to automatically adjust and optimize security control configurations. The information security device monitors security levels and dynamically adjusts controls based on assessed vulnerabilities, creating an efficient feedback loop that minimizes operational overhead while maintaining security.

Inventive Principle:
Principle #23Feedback

3Reliability

If security controls are applied to mitigate vulnerabilities, then information security is improved, but the cost of implementing and maintaining security measures increases

Engineering Contradiction:
Improveinformation securityVSAvoidsecurity resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies security controls locally and specifically tailored to each data storage device's assessed vulnerabilities rather than implementing uniform security measures across all devices. The information security device evaluates each target device's specific security posture and applies only the necessary security controls for that device's identified vulnerabilities. This targeted approach optimizes security resource allocation by avoiding unnecessary security measures on already-secure devices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11438364B2Threat analysis for information security
Publication Date: 2022.09.06 BANK OF AMERICA CORP
  • US11438364B2 patent drawing
  • US11438364B2 patent drawing
  • US11438364B2 patent drawing

AI summary

A device configured to receive a data storage request that identifies a target data storage device for a data element. The device is further configured to determine a security level associated with the target data storage device. The device is further configured to determine a protection level range based on the determined security level and to identify one or more security controls within the protection level range. Each security control comprises a hardware configuration for data storage devices that are associated with mitigating one or more vulnerability types. The device is further configured to output the identified one or more security controls.