Intelligent Security Platform Automating Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in implementing effective computer security strategies due to the complexity of existing security solutions and a shortage of skilled professionals, compounded by the rapidly evolving nature of computer security threats and varying network architectures.

Innovation Solution

A centralized intelligent computer security platform that includes multi-factor authentication, a security engine with machine learning capabilities, threat intelligence feeds, and a user interface, which collects and analyzes security data to generate entity-specific security configurations and policies, simplifying the configuration process for network administrators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complicated security solutions are implemented to address security concerns, then security effectiveness is improved, but implementation difficulty increases and requires teams of professionals

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security platform performs self-configuration and self-optimization by automatically analyzing the computing environment, identifying security vulnerabilities, and implementing security policies without requiring manual intervention from security professionals. The system serves itself by continuously monitoring and adjusting security configurations based on detected threats and environment characteristics.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes of security configuration with automated computational processes. Machine learning algorithms and automated analysis tools substitute for the manual work of security professionals in dissecting and implementing security solutions, transforming a labor-intensive process into an automated computational task.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If skilled security professionals are deployed to implement security solutions, then security strategy deployment is improved, but resource availability deteriorates due to shortage of professionals

Engineering Contradiction:
Improvesecurity strategy deploymentVSAvoidavailability of skilled professionals
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The security platform enables organizations to independently configure and implement security strategies without relying on external security professionals. The automated system performs tasks that would traditionally require skilled human operators, allowing organizations to deploy security strategies using their own internal resources.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the expertise and knowledge of security professionals into an automated platform. The system captures and codifies security professional knowledge into algorithms and automated processes, making this expertise accessible without requiring the physical presence of skilled professionals.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If security configurations are customized for each entity's specific network architecture, then security adaptability is improved, but configuration complexity increases

Engineering Contradiction:
Improvesecurity configuration adaptabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security platform analyzes the specific characteristics of each entity's computing environment and applies tailored security configurations localized to that environment. The system identifies unique network architecture features, device types, and threat profiles, then customizes security policies to match local conditions rather than applying uniform configurations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent replaces the manual process of analyzing and configuring security for each unique environment with automated computational analysis. Machine learning algorithms automatically assess environment characteristics and generate appropriate configurations, eliminating the need for manual analysis while maintaining customization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If manual security configuration processes are used, then security policy implementation is improved through expert judgment, but time consumption increases

Engineering Contradiction:
Improvesecurity policy implementation qualityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security platform performs preliminary analysis of the computing environment and pre-generates security configurations before they are needed. The system continuously monitors threats and pre-configures security responses, so when threats are detected, implementations can proceed immediately without time-consuming manual analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent substitutes manual expert judgment processes with automated machine learning models that can rapidly analyze environments and generate security configurations. The computational processes execute much faster than human analysis while maintaining or improving implementation quality through consistent application of security best practices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10412113B2Systems and methods for intelligently configuring computer security
Publication Date: 2019.09.10 CISCO TECHNOLOGY INC
  • US10412113B2 patent drawing
  • US10412113B2 patent drawing
  • US10412113B2 patent drawing

AI summary

A system and method that enables the configuration of computer security of a subject entity at a computer security platform includes collecting a corpus of security data relating to one or more security configurations of the network maintained by the subject entity, analyzing the corpus of security data to determine one or more vulnerability factors and one or more security behaviors relating to the subject entity, generating a security assessment for the subject entity based on the analysis of the corpus of security data, generating a computer security policy for the security environment based on the security assessment, and providing, to the subject entity, a security policy recommendation incorporating at least a subset of the generated computer security policy.