Application Consolidation With AI-Based Shadow App Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in monitoring and managing shadow applications, which are software applications used without official approval, leading to cybersecurity threats, data exposure, compliance issues, and operational inefficiencies due to varied naming conventions across audit logs.

Innovation Solution

A computing system and method utilizing Graph analytics and generative AI to identify and manage shadow applications by creating and linking app IDs, performing similarity searches, and updating security policies for known and new applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations monitor all entities' activity to verify sanctioned apps, then security compliance is improved, but system complexity and monitoring overhead increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between organizational resources and the monitoring process. This system consolidates application identification and policy application, reducing the complexity burden on the overall monitoring infrastructure while maintaining security compliance through centralized management of sanctioned applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is designed to perform multiple functions: identifying applications, determining if they are sanctioned, and applying policies automatically. This multi-functional approach reduces the need for separate systems for each task, thereby reducing overall system complexity while maintaining comprehensive security oversight.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If organizations allow diverse applications, then operational flexibility is improved, but security risks and compliance issues increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts application access based on real-time identification and policy evaluation. Rather than static allow/deny lists, the system continuously monitors and adapts its security posture, enabling flexible operation with sanctioned applications while automatically blocking or restricting unauthorized applications, thus maintaining both operational flexibility and security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The monitoring system implements feedback mechanisms where application usage data is continuously collected, analyzed, and used to update security policies. This closed-loop approach allows the system to learn from actual usage patterns, adjusting its security posture to permit legitimate diverse applications while blocking security risks, thereby balancing flexibility and security.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If manual application verification is performed, then policy accuracy is improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvepolicy application accuracyVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service automated verification where applications are automatically identified, classified as sanctioned or unsanctioned, and have policies applied without manual intervention. This automated self-verification process maintains high policy accuracy through consistent rule application while eliminating the time loss and operational overhead associated with manual verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical verification processes with automated computational systems. Instead of human operators manually checking each application against policy lists, the system uses automated identification and classification mechanisms that rapidly process applications with consistent accuracy, dramatically reducing verification time while maintaining or improving policy application precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If shadow applications are permitted, then user autonomy is improved, but cybersecurity threats and data exposure increase

Engineering Contradiction:
Improveuser autonomyVSAvoidcybersecurity threats
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary identification and classification of applications before they can cause harm. By proactively detecting shadow applications and automatically applying appropriate policies, the system prevents cybersecurity threats and data exposure before they occur, while still allowing users autonomous access to sanctioned applications without restriction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the potentially harmful presence of shadow applications into a benefit by using their detection data to improve overall security posture. Unauthorized applications are identified and blocked, preventing threats, while the same detection capability continuously monitors and protects the organization, turning what could be a security vulnerability into an enhanced security mechanism that preserves user autonomy for legitimate uses.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS20250307292A1Systems and methods for consolidating applications used in an organization
Publication Date: 2025.10.02 RECOLABS LTD
  • US20250307292A1 patent drawing
  • US20250307292A1 patent drawing
  • US20250307292A1 patent drawing

AI summary

A computing system for consolidating software services, the system comprises a memory and a processor configured to collecting data records from computer applications, each record includes a name of a software service, for each data record, search on a database using a search query that includes the software service name, converting text from search results into a numeric vector, performing a similarity comparison between the numeric vector and vectors stored in a service database, the vectors represent description of known software services, creating a candidate list including candidate software services having a similarity score higher than a threshold, inputting information on the candidate software services into a model that determines whether one of the candidate software services matches the software service of the data record, enabling or disabling use of the software service based on policies on the selected candidate software service.