Runtime Adaptive Security via Fuzzy Causal Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security technologies fail to adapt security configurations in real-time to changes in assets and contextual factors, leading to ineffective protection and increased risk, as they do not consider the variability of assets and their values during software development and operation.
Innovation Solution
A method and system using a fuzzy causal network to analyze changes in assets and context, updating security controls to ensure the security configuration aligns with the total risk of harm and satisfies security goals, by propagating values through causal links and selecting the most appropriate security configuration to implement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static security configuration is used, then implementation cost is reduced and system complexity is simplified, but security effectiveness deteriorates when assets or context change
Solution Approach 1:
The patent implements dynamic security configuration that automatically adapts to changes in assets and contextual factors. The system continuously monitors asset states and contextual conditions, then dynamically adjusts security controls and parameters without requiring manual reconfiguration, thereby maintaining security effectiveness while managing complexity through automation.
Solution Approach 2:
The system employs feedback mechanisms where security configurations are continuously evaluated based on current asset states and contextual factors. The feedback loop enables automatic detection of security gaps and triggers adaptive reconfiguration, ensuring security effectiveness improves in response to changing conditions without proportional increase in complexity.
2Reliability
If security configuration is adapted to every change in assets and context, then security effectiveness is improved, but system complexity and computational overhead increase
Solution Approach 1:
The system changes security parameters adaptively based on asset criticality and contextual risk factors. Instead of reconfiguring entire security architectures, the system adjusts specific security parameters such as authentication requirements, encryption levels, and access control policies, thereby improving protection while minimizing the complexity burden of full system reconfiguration.
Solution Approach 2:
The patent applies partial adaptation by selectively adjusting security controls only for affected assets or contexts rather than reconfiguring the entire security system. This partial action approach maintains adequate security protection for changed elements while avoiding the excessive complexity of comprehensive system-wide reconfiguration.
3Reliability
If strong authorization and authentication mechanisms are applied, then asset protection is improved, but system usability and operational efficiency deteriorate
Solution Approach 1:
The system applies different authorization and authentication mechanisms locally based on asset criticality and contextual risk. High-value assets receive stronger security measures while lower-value assets use lighter mechanisms, thereby improving overall asset security without uniformly degrading system usability across all operations.
Solution Approach 2:
Strong authorization and authentication are applied partially only when and where asset risk requires it, rather than universally. This partial application of security measures protects critical assets effectively while maintaining ease of operation for routine, low-risk activities, thus resolving the contradiction between security strength and usability.
Data Source
AI summary
A method of adapting a security configuration of a data processing application at runtime, and a system, together with its computing architecture, are disclosed. The system stores a causal network comprising a plurality of nodes and a plurality of incoming and outgoing causal links associated therewith, wherein each node of the causal network is associated with a security concern or a requirement that can be affected by any configuration of the security controls. The current value of assets nodes, as well as those of the security concerns that can be affected by monitored contextual factors, are updated. The control nodes corresponding to the security controls is updated according to the security configuration whose utility is evaluated by the causal network. The node corresponding to the at least one variable is updated with the determined current value, which is propagated through the causal network through the causal links associated with the updated node. The security configuration with the highest utility is selected and replaces the actual configuration by activating and/or deactivating the security functions corresponding to security control nodes enabled/disabled in the selected security configuration.


