Electronic Device Audit Rule Segmentation for Security and Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices face inefficiencies in auditing processes due to the need to analyze logs generated by numerous predefined rules, leading to increased overhead and potential security vulnerabilities when the number of rules is high, or compromised security when the number of rules is low.
Innovation Solution
An electronic device and method that skip audits for security-verified applications by generating specific rules to identify and verify applications, allowing only unreliable processes to undergo full audits, thereby reducing unnecessary log analysis and maintaining system security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the number of predefined audit rules is increased, then security coverage is improved, but system overhead and log analysis time increase
Solution Approach 1:
The patent segments the audit process into two distinct paths: a fast path for security-verified applications that skips detailed rule auditing, and a normal path for unverified applications that undergoes full audit scrutiny. This segmentation allows the system to maintain comprehensive security rules while avoiding the overhead of applying all rules to every application, thereby resolving the contradiction between security coverage and system overhead.
Solution Approach 2:
The system performs preliminary security verification of applications before they are subjected to full audit processing. By pre-identifying and verifying the security status of applications, the system can subsequently skip the time-consuming rule-matching process for trusted applications, thus maintaining high security coverage without incurring proportional overhead costs.
2Reliability
If the number of predefined audit rules is increased, then security coverage is improved, but log analysis time increases
Solution Approach 1:
The patent segments the audit process into two distinct paths: a fast path for security-verified applications that skips detailed rule auditing, and a normal path for unverified applications that undergoes full audit scrutiny. This segmentation allows the system to maintain comprehensive security rules while avoiding the overhead of applying all rules to every application, thereby resolving the contradiction between security coverage and system overhead.
Solution Approach 2:
The system performs preliminary security verification of applications before they are subjected to full audit processing. By pre-identifying and verifying the security status of applications, the system can subsequently skip the time-consuming rule-matching process for trusted applications, thus maintaining high security coverage without incurring proportional overhead costs.
3Device complexity
If the number of predefined audit rules is decreased, then system overhead is reduced, but security vulnerability increases
Solution Approach 1:
The patent implements a dynamic audit rule selection mechanism that adjusts the number of applied rules based on the security verification status of each application. For security-verified applications, the system dynamically reduces the number of applied rules to minimize overhead, while for unverified applications, the full set of security rules is applied to ensure comprehensive protection, thus adapting the system complexity to the actual security needs.
Solution Approach 2:
The patent applies different audit scrutiny levels to different applications based on their security verification status. Security-verified applications receive a simplified audit treatment with fewer rules applied, while unverified applications undergo comprehensive auditing with all rules applied. This local differentiation allows the system to reduce overall overhead without compromising the security of applications that need rigorous inspection.
4Reliability
If security verification is performed for all applications, then system security is improved, but processing overhead increases
Solution Approach 1:
The patent segments the audit process into two distinct paths: a fast path for security-verified applications that skips detailed rule auditing, and a normal path for unverified applications that undergoes full audit scrutiny. This segmentation allows the system to maintain comprehensive security rules while avoiding the overhead of applying all rules to every application, thereby resolving the contradiction between security coverage and system overhead.
Solution Approach 2:
The system performs preliminary security verification of applications before they are subjected to full audit processing. By pre-identifying and verifying the security status of applications, the system can subsequently skip the time-consuming rule-matching process for trusted applications, thus maintaining high security coverage without incurring proportional overhead costs.
Data Source
AI summary
Provided in the present disclosure are an electronic device and a control method therefor. An electronic device of the present disclosure comprises a memory in which a kernel and at least one application are stored, and a processor, which generates a first rule for determining a time at which the application calls a system in order to execute a process, determines, on the basis of the first rule, whether the application corresponds to an application for which security is verified, and generates a second rule for skipping an audit on the basis of a plurality of pre-defined rules, if the application corresponds to the application for which security is verified.


