Unified Security Management Framework for Enterprise Threat Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems lack comprehensive coverage across an organization's operations, infrastructure, and people-based processes, leading to vulnerabilities and inefficiencies in addressing security threats, particularly in understanding and measuring security posture and compliance with industry-specific regulations.

Innovation Solution

A tailored automated security management framework that integrates real-time monitoring and analysis of both organizational and industry-specific data to provide role-based access management, tailored workflows, and compliance guidance, ensuring comprehensive security coverage and proactive incident management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security management systems are used, then specific security functions (endpoint protection, network access control) are provided, but comprehensive coverage of the organization's overall security posture is lacking

Engineering Contradiction:
Improvesecurity coverageVSAvoidbreadth of monitoring scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security information management system consolidates multiple security components (endpoint protection, network access control, threat monitoring) into a single unified platform that provides comprehensive security management across the entire organization, enabling one system to perform multiple security functions simultaneously

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple limited-scope security systems are deployed, then specific security vulnerabilities are monitored, but the organization lacks ability to measure overall security effectiveness

Engineering Contradiction:
Improvesecurity posture assessmentVSAvoidsecurity data integration
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system aggregates security information from multiple disparate security components and sources into a centralized repository, combining data from endpoint protection, network monitoring, threat intelligence, and other security systems to provide a unified view of the organization's overall security posture and enable comprehensive measurement of security effectiveness

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If security management is manual and fragmented, then specific security tasks can be performed, but the complexity of running a comprehensive security program becomes overwhelming

Engineering Contradiction:
Improvesecurity program efficiencyVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system provides automated security management capabilities including automatic security assessment, threat detection, compliance monitoring, and reporting functions that operate with minimal manual intervention, enabling the security program to self-manage many routine tasks while reducing the complexity burden on security personnel

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9754117B2Security management system
Publication Date: 2017.09.05 NORTHCROSS GRP
  • US9754117B2 patent drawing
  • US9754117B2 patent drawing
  • US9754117B2 patent drawing

AI summary

The invention relates to a system for providing an automated security management framework for an enterprise based on the enterprise's operations, infrastructure, and user-based processes, as well as industry-specific rules and regulations associated with the enterprise. The system is configured to generate recommendations or instructions based on correlation of enterprise's operations, infrastructure, and user-based processes with industry-specific rules and regulations. The recommendations or instructions are then provided to a user associated with the enterprise so as to facilitate actions to be taken to address a potential security threat.