Centralized Policy Programming for Distributed Anti-Virus Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enforcing an anti-virus policy across an organization's network is challenging due to constantly changing threats, software updates, and the distribution of host devices, as existing methods are inflexible and require manual reconfiguration for different anti-virus vendors and do not allow for multiple anti-virus products or network policies.

Innovation Solution

A centralized policy programming and distributed policy enforcement system that maintains multiple policy definitions, generates specific configurations, and disseminates them to appropriate networks, enabling efficient management and enforcement of anti-virus policies across various anti-virus products and vendors, with a global policy coordinator and local policy coordinators ensuring compliance and updating of policy configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized system maintains multiple policy definitions for different anti-virus vendors and products, then adaptability and versatility improve, but system complexity increases

Engineering Contradiction:
Improvesupport for multiple anti-virus products and vendorsVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides policy management into separate, modular policy definition components for different vendors and products. Each policy definition is an independent unit that can be maintained separately, allowing the system to support multiple anti-virus solutions without creating a monolithic complex structure. The segmentation enables independent updates and modifications to individual vendor policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized system is designed with a universal policy management framework that can handle multiple types of anti-virus products from different vendors through a common interface. This multi-functional architecture allows the same system infrastructure to enforce policies across diverse anti-virus solutions, reducing the need for separate management systems for each vendor.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If manual reconfiguration of each choke point is required when changing anti-virus vendors, then ease of operation deteriorates, but system control precision improves

Engineering Contradiction:
Improvepolicy update effortVSAvoidreconfiguration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system implements automated policy propagation where the centralized policy server automatically distributes updated policy definitions to all choke points without requiring manual intervention. When a policy definition is updated at the centralized server, the system self-services by automatically detecting changes and pushing updates to the appropriate distributed enforcement points, eliminating manual reconfiguration effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The centralized system pre-configures policy definitions for multiple vendors and products in advance, storing them in a centralized repository. When a vendor change is needed, the administrator simply selects the pre-prepared policy definition from the available options, and the system automatically deploys it. This preliminary preparation eliminates the need for time-consuming on-site configuration work.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a single anti-virus program of a single vendor is enforced, then reliability of policy enforcement improves, but adaptability deteriorates

Engineering Contradiction:
Improvepolicy enforcement consistencyVSAvoidvendor and product flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system allows different quality characteristics for different policy definitions while maintaining overall enforcement consistency. Each vendor-specific policy definition can be optimized for its particular anti-virus product's capabilities and requirements, enabling tailored enforcement strategies for each vendor while maintaining uniformity through the centralized management framework.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The centralized system manages multiple policy definitions with different parameters for various vendors and products. By changing which policy definition is active at the centralized server, the system can switch between different vendors and products without altering the fundamental enforcement mechanism. This parameter-based management allows flexible vendor selection while maintaining consistent policy enforcement reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9426178B1Method and apparatus for centralized policy programming and distributive policy enforcement
Publication Date: 2016.08.23 QUEST SOFTWARE INC
  • US9426178B1 patent drawing
  • US9426178B1 patent drawing
  • US9426178B1 patent drawing

AI summary

A method and apparatus for centralized policy programming and distributive policy enforcement is described. A method comprises centrally maintaining a plurality of policy definitions for one or more subscribers, generating policy configurations using the plurality of policy definitions, each of the policy configurations being specific to one of the plurality of policy definitions, and disseminating the policy configurations to the appropriate ones of the subscribers' networks.