Adaptive Network Security Policies for APT Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Single-purpose network security systems with limited context and static policy decisions are ineffective against Advanced Persistent Threats (APTs) that are intermingled with regular network traffic, allowing threats to remain undetected for extended periods.

Innovation Solution

An integrated network security system with a progressive policy engine (PPE) that integrates security intelligence from multiple network security systems, dynamically reassessing and updating security policies through a control plane and data plane architecture, utilizing a dynamic feedback loop to continuously evaluate and adjust security measures based on real-time traffic analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-purpose network security system with static policy decisions is used, then the system is simple to operate and implement, but it is ineffective against Advanced Persistent Threats that are intermingled with regular network traffic

Engineering Contradiction:
Improveeffectiveness against APTsVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple single-purpose network security systems into a single integrated system with a progressive policy engine. This engine dynamically integrates security intelligence from various sources (firewall, intrusion detection, antivirus, etc.) and coordinates their policies to effectively detect and respond to APTs that span multiple security layers, thereby resolving the contradiction between simplicity and effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a progressive policy engine that dynamically adjusts security policies based on real-time analysis of network traffic and threat intelligence. Instead of static policies, the system continuously learns from new threats and adapts its detection and response mechanisms, enabling it to effectively counter APTs while maintaining operational simplicity through automated dynamic adjustment.

Inventive Principle:
Principle #15Dynamics

2Reliability

If static security policies are used, then the system is easy to manage, but threats can remain undetected for extended periods

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidpolicy management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the progressive policy engine continuously monitors network traffic, analyzes security events from multiple security systems, and uses this information to dynamically update security policies. This closed-loop feedback system ensures that policies evolve with emerging threats, maintaining high detection capability while the automation of this process preserves ease of operation by eliminating manual policy updates.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The progressive policy engine operates autonomously, self-managing the analysis of security intelligence and the adjustment of security policies without requiring constant human intervention. This self-service capability allows the system to maintain high threat detection capability through continuous adaptation while keeping policy management simple for operators.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple network security systems are integrated with dynamic policy reassessment, then detection and mitigation of APTs is enhanced, but the system complexity increases

Engineering Contradiction:
ImproveAPT detection and mitigationVSAvoidintegrated system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The progressive policy engine serves as a universal coordinating component that handles multiple security functions (firewall management, intrusion detection, antivirus coordination, etc.) through a single integrated architecture. This multi-functional engine reduces overall system complexity by providing a unified control plane that manages diverse security systems, rather than requiring separate management mechanisms for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The progressive policy engine acts as an intermediary layer between various security systems and the network traffic. It mediates the interaction between different security components, integrating their intelligence and coordinating their responses to APTs. This intermediary architecture simplifies the overall system by providing a centralized point of control that manages the complexity of multiple integrated security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11310285B2Adaptive network security policies
Publication Date: 2022.04.19 TREND MICRO INC
  • US11310285B2 patent drawing
  • US11310285B2 patent drawing
  • US11310285B2 patent drawing

AI summary

Adaptive network security policies can be selected by assigning a number of risk values to security intelligence associated with network traffic, and identifying a number of security policies to implement based on the risk values.