Automated Policy Audit System for Proactive Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security audit systems lack the ability to proactively audit for policy violations and vulnerabilities before an attack occurs, relying on manual and inefficient remediation processes, and provide limited compliance with enterprise or regulatory policies, with vulnerability analysis tools only detecting known vulnerabilities and offering inaccurate assessments for large networks.

Innovation Solution

A system and method for automated policy audits that include configuring network audits, storing configuration information, automatically gathering network data, applying network policies, determining compliance, generating remediation tasks, and monitoring task status, using a server with a user interface, data store, and engines for automated initiation and compliance determination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time intrusion detection systems are used to detect attacks after they occur, then defensive security monitoring is improved, but the ability to proactively protect the network before an attack occurs deteriorates

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidproactive security protection capability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary actions by conducting vulnerability scans and policy audits before attacks occur. The audit system proactively identifies security weaknesses, policy violations, and compliance issues in advance, allowing organizations to remediate problems before they can be exploited by attackers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by implementing policy-based security controls and remediation tasks that prevent potential security issues before they materialize. The automated policy audit system proactively enforces security policies and generates remediation tasks to address vulnerabilities before attacks can occur.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If manual remediation processes are used for each attacked device, then individual device security is improved, but efficiency and cost-effectiveness deteriorate as network size increases

Engineering Contradiction:
Improveindividual device securityVSAvoidremediation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies universality by implementing centralized automated policy audit and remediation management that serves multiple devices simultaneously. The policy audit system can assess security compliance across entire networks rather than individual devices, and automated remediation tasks can be deployed universally across multiple systems at once.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service through automated remediation task generation and tracking. The policy audit system automatically generates remediation tasks based on detected policy violations and vulnerabilities, assigns them to appropriate personnel or systems, and tracks their completion status without requiring manual intervention for each individual device.

Inventive Principle:
Principle #25Self-service

3Reliability

If vulnerability analysis tools search only for known vulnerabilities, then detection of documented vulnerabilities is improved, but accuracy of overall network vulnerability assessment deteriorates

Engineering Contradiction:
Improveknown vulnerability detectionVSAvoidnetwork vulnerability assessment accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements feedback mechanisms where policy audit results continuously inform and refine vulnerability assessments. The automated policy audit system provides ongoing feedback about security compliance status, which feeds into broader vulnerability assessment processes, enabling more accurate overall network security evaluation that combines known vulnerability data with policy compliance information.

Inventive Principle:
Principle #23Feedback

4Loss of time

If consultants perform penetration testing on sampled nodes only, then cost and time requirements are reduced, but accuracy of network-wide vulnerability assessment deteriorates

Engineering Contradiction:
Improveaudit timeVSAvoidnetwork vulnerability assessment accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The system replaces manual mechanical consulting processes with automated electronic policy audit systems. The automated policy audit system can assess security compliance across entire networks without requiring manual sampling by consultants, eliminating the trade-off between audit scope and resource requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system applies parameter changes by transforming the audit approach from manual sampling to automated comprehensive assessment. The policy audit system changes key parameters including audit scope (from sample to complete network), audit speed (from manual to automated), and data collection methods (from manual observation to automated scanning), enabling accurate network-wide assessment without consultant time constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8561175B2System and method for automated policy audit and remediation management
Publication Date: 2013.10.15 MAGENTA SECURITY HOLDINGS LLC
  • US8561175B2 patent drawing
  • US8561175B2 patent drawing
  • US8561175B2 patent drawing

AI summary

A prevention-based network auditing system includes a central compliance server providing a user interface allowing a user to schedule and configure a network audit. The configured audit is stored in an audit repository until its scheduled time. At such a time, the compliance server automatically invokes one or more audit servers to gather information about the network. The compliance server receives the gathered information and electronically applies a network policy to the information for determining compliance with the policy. A remediation task may be generated if the policy has been violated, and the task monitored until its completion.