Application Security Event Assessment With Dual Policy Entities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber security solutions, such as firewalls and antivirus tools, fail to manage insider risks due to the lack of context in common identity management tools, which cannot prevent malicious insiders from performing damaging actions, and traditional agents can be disabled or removed, rendering them ineffective in detecting suspicious activities.
Innovation Solution
Implementing a dual policy assessment entity system, where a first entity monitors and assesses activity against a set of policies within an application's runtime environment, and a second entity operates independently to further evaluate and perform security actions, ensuring continuous monitoring even if the first entity is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single policy assessment entity (agent) is deployed on a computing device to monitor and assess security events, then the device can detect and respond to suspicious activities, but the agent may be maliciously removed or disabled, rendering the security system ineffective
Solution Approach 1:
The patent divides the policy assessment functionality into two separate entities: a first policy assessment entity deployed within the application's runtime environment and a second policy assessment entity operating independently. This segmentation ensures that if one entity is compromised or removed, the other can continue to provide security monitoring, thereby resolving the contradiction between reliability and the vulnerability of single-point failure.
2Object-affected harmful factors
If traditional security tools (firewalls, antivirus) are used to protect against cyber threats, then network security can be maintained, but they cannot prevent insider risks or contextualize user behavior
Solution Approach 1:
The patent implements a feedback mechanism where the first policy assessment entity continuously monitors application activity and assesses it against security policies, then transmits assessment results to the second entity. This closed-loop feedback system enables real-time detection of insider threats by analyzing actual user behavior patterns and contextual information, going beyond traditional security tools' static rule-based approaches.
3Measurement precision
If a security agent operates within the application runtime environment to monitor activity, then it can detect suspicious events, but it becomes vulnerable to being disabled by malicious insiders
Solution Approach 1:
The patent introduces the second policy assessment entity as an intermediary that operates independently of the application runtime environment. This intermediary receives and further assesses activity indications from the first entity, creating a layered defense where the independent second entity cannot be easily disabled by insiders who can only affect the application environment, thus protecting operational continuity while maintaining detection precision.
Data Source
AI summary
Systems and methods for assessment of raised security events at an application are provided. In one example, first and second policy assessment entities are executed by a computing device. The first policy assessment entity is operable in a runtime environment of an application running on the computing device and monitors activity of the application, assesses that activity against a first set of policies and, in response to a determination that such an assessment meets certain criteria, transmits an indication of that activity to the second policy assessment entity. The second policy assessment entity is operable independent of the application and receives an indication of activity from the first policy assessment entity, assesses that activity against a second set of policies and, in response to a determination that an assessment of that activity against the second set of policies meets certain, performs a security action.


