Application Security Event Assessment With Dual Policy Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security solutions, such as firewalls and antivirus tools, fail to manage insider risks due to the lack of context in common identity management tools, which cannot prevent malicious insiders from performing damaging actions, and traditional agents can be disabled or removed, rendering them ineffective in detecting suspicious activities.

Innovation Solution

Implementing a dual policy assessment entity system, where a first entity monitors and assesses activity against a set of policies within an application's runtime environment, and a second entity operates independently to further evaluate and perform security actions, ensuring continuous monitoring even if the first entity is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single policy assessment entity (agent) is deployed on a computing device to monitor and assess security events, then the device can detect and respond to suspicious activities, but the agent may be maliciously removed or disabled, rendering the security system ineffective

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidmonitoring system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the policy assessment functionality into two separate entities: a first policy assessment entity deployed within the application's runtime environment and a second policy assessment entity operating independently. This segmentation ensures that if one entity is compromised or removed, the other can continue to provide security monitoring, thereby resolving the contradiction between reliability and the vulnerability of single-point failure.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traditional security tools (firewalls, antivirus) are used to protect against cyber threats, then network security can be maintained, but they cannot prevent insider risks or contextualize user behavior

Engineering Contradiction:
Improveinsider threat protectionVSAvoidcontextual information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the first policy assessment entity continuously monitors application activity and assesses it against security policies, then transmits assessment results to the second entity. This closed-loop feedback system enables real-time detection of insider threats by analyzing actual user behavior patterns and contextual information, going beyond traditional security tools' static rule-based approaches.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If a security agent operates within the application runtime environment to monitor activity, then it can detect suspicious events, but it becomes vulnerable to being disabled by malicious insiders

Engineering Contradiction:
Improveactivity detection accuracyVSAvoidagent operational continuity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces the second policy assessment entity as an intermediary that operates independently of the application runtime environment. This intermediary receives and further assesses activity indications from the first entity, creating a layered defense where the independent second entity cannot be easily disabled by insiders who can only affect the application environment, thus protecting operational continuity while maintaining detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250284822A1Assessment of raised security events at an application
Publication Date: 2025.09.11 FORTINET INC
  • US20250284822A1 patent drawing
  • US20250284822A1 patent drawing
  • US20250284822A1 patent drawing

AI summary

Systems and methods for assessment of raised security events at an application are provided. In one example, first and second policy assessment entities are executed by a computing device. The first policy assessment entity is operable in a runtime environment of an application running on the computing device and monitors activity of the application, assesses that activity against a first set of policies and, in response to a determination that such an assessment meets certain criteria, transmits an indication of that activity to the second policy assessment entity. The second policy assessment entity is operable independent of the application and receives an indication of activity from the first policy assessment entity, assesses that activity against a second set of policies and, in response to a determination that an assessment of that activity against the second set of policies meets certain, performs a security action.