Automated Compliance Remediation Agent for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current compliance systems rely heavily on manual intervention and generate extensive information burdens for IT personnel, requiring them to audit and remediate non-compliant computer systems, which is inefficient and time-consuming.

Innovation Solution

A flexible compliance system with a deployable system health agent that automates remediation based on configurable compliance rules, allowing administrators to define conditions and actions, thereby reducing manual intervention and enabling IT personnel to focus on other tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual auditing and remediation of non-compliant systems is performed, then compliance can be verified and enforced, but IT personnel workload and time consumption increase significantly

Engineering Contradiction:
Improvecompliance verificationVSAvoidIT personnel time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the compliance management system automatically performs auditing, generates reports, and executes remediation actions without requiring manual IT personnel intervention for each compliance check or fix

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (IT personnel manually auditing and remediating systems) with automated computational processes (software agents that automatically detect, report, and remediate compliance issues)

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If extensive compliance reporting is generated, then comprehensive compliance information is available, but information burden on IT personnel increases

Engineering Contradiction:
Improvecompliance information availabilityVSAvoidinformation processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments compliance information into organized categories and structures reports in a hierarchical manner, breaking down complex compliance data into manageable sections that are easier to process and understand

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary automated system that processes and filters compliance information between the compliance checking mechanisms and IT personnel, presenting information in a standardized, digestible format rather than raw data

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If non-compliant systems are isolated from compliant systems, then security risks are reduced, but service access for users may be restricted

Engineering Contradiction:
Improvesecurity riskVSAvoidservice accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically adjusts system isolation status based on compliance state - non-compliant systems are isolated when detected, but automatically re-integrated once compliance is restored, making the isolation temporary and condition-based rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback loops where the system continuously monitors compliance status and automatically adjusts isolation measures - when compliance issues are detected, isolation is applied; when issues are remediated, isolation is removed, creating a responsive security mechanism

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8019857B2Flexible system health and remediation agent
Publication Date: 2011.09.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8019857B2 patent drawing
  • US8019857B2 patent drawing
  • US8019857B2 patent drawing

AI summary

A flexible compliance system is described herein that provides a deployable system health agent and automated remediation of computer system compliance failures based on configurable compliance rules. An administrator defines rules that represent compliance elements that the flexible compliance system will enforce. The flexible compliance system reads the rules defined by the administrator like a flexible set of conditions to check, and checks client computer systems based on the rules. The flexible compliance system generates a statement of health that indicates whether the computer system satisfies or violates each rule. In response to the statement of health, the flexible compliance system may take various actions with respect to a computer system in violation of a rule, including attempting to resolve the violation or quarantining the computer system to avoid interaction with other computer systems.