Threat-Evaluated Cyber Defense for Proactive Vulnerability Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security technologies are inefficient and unreliable due to reliance on manual vulnerability evaluations and reactive responses to completed vulnerability events, failing to proactively manage emerging threats and vulnerabilities in rapidly changing technology environments.

Innovation Solution

A threat-evaluated cyber defense framework that includes a process for adjusting cyber defense based on detailed evaluations of anticipated events, using a security defense system to improve vulnerability detection, analysis, and prevention, and facilitating proactive responses by considering various threat sources and employing a threat-level approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vulnerability evaluations are used, then flexibility in assessment can be maintained, but efficiency and reliability of vulnerability detection deteriorate

Engineering Contradiction:
Improvereliability of vulnerability detectionVSAvoidefficiency of vulnerability detection
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical evaluation processes with automated computer-based systems that use algorithms, machine learning models, and data processing to assess vulnerabilities. This substitution eliminates human error and inconsistency while processing vulnerabilities at machine speed, simultaneously improving both reliability through consistent automated assessment and efficiency through rapid automated scanning and analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service vulnerability assessment where the automated system independently identifies, evaluates, and prioritizes vulnerabilities without requiring manual intervention for each assessment. The system serves itself by automatically updating vulnerability databases, re-assessing affected assets, and adjusting risk scores based on new information, thereby improving efficiency while maintaining reliable standardized evaluation criteria.

Inventive Principle:
Principle #25Self-service

2Reliability

If reactive responses to completed vulnerability events are used, then response actions are taken based on actual incidents, but the ability to proactively manage emerging threats deteriorates

Engineering Contradiction:
Improvereliability of threat responseVSAvoidtime to respond to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by proactively identifying and assessing vulnerabilities before they are exploited by attackers. The system continuously scans for known vulnerabilities, evaluates affected assets, and prioritizes remediation efforts in advance of actual attacks. This preliminary assessment enables organizations to address security gaps before incidents occur, reducing response time while maintaining reliable incident response capabilities when threats do materialize.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback loops that continuously monitor vulnerability landscapes, update threat intelligence, and adjust risk assessments in real-time. When new vulnerabilities are discovered or threats evolve, the system automatically re-evaluates affected assets and updates prioritization, ensuring that response actions remain reliable and up-to-date. This continuous feedback enables both proactive threat management and reliable reactive response to actual incidents.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive evaluation of multiple threat sources is performed, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvecomprehensive security coverageVSAvoidcomplexity of defense system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal vulnerability management platform that consolidates multiple assessment functions into a single system. The system performs vulnerability scanning, asset inventory, risk assessment, and remediation tracking across diverse threat sources and asset types through a unified interface and standardized processes. This multi-functional approach achieves comprehensive security coverage while reducing overall system complexity by eliminating the need for multiple separate tools and processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity through parameter changes by dynamically adjusting assessment depth, scope, and criteria based on risk priorities and resource constraints. The platform can modify evaluation parameters such as scanning frequency, vulnerability thresholds, and asset criticality weights to balance comprehensive coverage with operational feasibility. This flexible parameter adjustment enables the system to maintain thorough security assessment capabilities while adapting complexity levels to match organizational needs and resources.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12169559B2Threat-evaluated cyber defense
Publication Date: 2024.12.17 BANK OF AMERICA CORP
  • US12169559B2 patent drawing
  • US12169559B2 patent drawing
  • US12169559B2 patent drawing

AI summary

A system for improving data security for computing devices receives a data input stream indicating changes to data security threats posed to the computing devices. The system detects, based at least in part on the changes to the data security threats, a new data security threat posed to the computing devices. The system determines one or more available data security controls that align with the new data security threat. The one or more available data security controls comprise security countermeasures available to the computing devices for resolving the new data security threat. After determining that a security vulnerability rating is greater than a threshold value, at least one of the one or more available data security controls may be automatically implemented at the computing devices.