Security Policy Selection via Uncertainty and Resource Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing IT security policies in dynamic IT environments is challenging due to the complexity of identifying security issues and the lack of understanding about the impact of changing security settings, leading to resource-intensive and time-consuming processes that may not align with business needs.

Innovation Solution

A computer-implemented method using trained machine learning models to analyze IT information and compute a recommended security policy based on calculated uncertainty and predicted resource consumption, outputting the policy for display on a user device dashboard.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods are used to implement IT security policies, then security coverage can be comprehensive, but the process becomes resource-intensive and time-consuming

Engineering Contradiction:
Improvesecurity coverageVSAvoidimplementation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transforms security policy selection from a manual, comprehensive review process to an automated decision process by changing key parameters: using machine learning models to predict resource consumption, calculating uncertainty scores, and automatically ranking policies. This parameter transformation maintains security coverage while dramatically improving implementation efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system enables self-service security policy implementation by automatically analyzing IT environment data, predicting resource consumption for different policies, calculating uncertainty, and recommending optimal policies without requiring extensive manual security expert intervention. This self-service approach maintains comprehensive security coverage while reducing implementation overhead.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual analysis is used to evaluate security policy impacts, then understanding of security effects can be thorough, but the time and resources required increase significantly

Engineering Contradiction:
Improveeffect understandingVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with automated computational systems. Machine learning models predict resource consumption, algorithms calculate uncertainty scores, and automated systems rank policies. This substitution maintains thorough understanding of security effects while reducing analysis time from weeks to minutes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary actions by pre-training machine learning models on historical security data and pre-calculating resource consumption predictions for multiple potential policies. When a security policy decision is needed, the pre-prepared models and predictions enable rapid evaluation without requiring time-consuming manual analysis at the moment of decision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security policies are implemented, then security risks are minimized, but business operations may be impacted due to resource consumption

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidbusiness operation continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies partial action by recommending security policies that provide sufficient protection against identified risks without implementing every possible security measure. The system calculates uncertainty and predicts resource consumption to determine the optimal level of security intervention, balancing risk mitigation with business operation continuity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts security policy recommendations based on real-time analysis of the IT environment, calculated uncertainty levels, and predicted resource consumption. This dynamic approach ensures security policies are tailored to actual risk levels and resource availability, preventing excessive security measures from impacting business operations while maintaining adequate protection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12192243B2Security policy selection based on calculated uncertainty and predicted resource consumption
Publication Date: 2025.01.07 KYNDRYL INC
  • US12192243B2 patent drawing
  • US12192243B2 patent drawing
  • US12192243B2 patent drawing

AI summary

A computer-implemented method according to one embodiment includes receiving a request to perform a security policy implementation analysis for a first deployment associated with a first client in an IT environment. IT information associated with the first deployment is collected. The method further includes applying trained machine learning models to analyze the IT information of the first client to compute a security policy for the first deployment. The security policy is computed based on a calculated uncertainty of effects that applying the security policy to the first deployment is capable of causing, and a predicted amount of resources of the first deployment that applying the security policy to the first deployment would consume. An indication of the security policy is output for display in a dashboard on a display of a user device of the first client.