Network Compliance Server Traversing Policy Breaches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large managed information networks, identifying and tracking the causes of rule violations deviating from established policies is cumbersome due to the lack of effective notification categorization and correlation of breaches, making it difficult to maintain network compliance and prevent vulnerabilities from becoming violations.

Innovation Solution

A compliance server and integrated graphical user interface (GUI) are introduced to traverse and correlate notifications, organize breaches by severity and recurrence, and identify related network entities and rules, allowing for efficient analysis and remediation of policy breaches across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple policies with numerous rules are implemented to ensure network compliance, then network security and best practices are improved, but the complexity of identifying and verifying compliance increases

Engineering Contradiction:
Improvenetwork complianceVSAvoidcompliance verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the compliance verification process by organizing rules into multiple policy files with hierarchical structures. Each policy file contains specific rule sets that can be independently processed and verified, reducing the complexity of handling numerous rules across multiple policies simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a compliance verification system that acts as an intermediary between network elements and policies. This system automatically traverses the network, collects configuration data, evaluates it against rules, and generates compliance reports, eliminating the need for manual verification of each rule across multiple policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual monitoring of network rules is performed, then compliance can be verified, but the time required for identification and correction of violations increases

Engineering Contradiction:
Improvepolicy complianceVSAvoidbreach identification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-service compliance verification mechanism where the system automatically monitors network elements, evaluates their configurations against defined rules, and identifies violations without human intervention. The system continuously traverses the network, collects data, and generates compliance reports in real-time, eliminating manual monitoring delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes a feedback loop where compliance violations are automatically detected and reported to administrators. The system provides real-time feedback on policy breaches, enabling rapid response and correction. Compliance reports are generated and made available for review, allowing administrators to address issues promptly rather than discovering them through manual checks.

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If comprehensive network monitoring is implemented to track all network events, then breach detection capability is improved, but the difficulty of pinpointing causes of rule violations increases

Engineering Contradiction:
Improvebreach detection capabilityVSAvoidcause analysis complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts relevant information from comprehensive network monitoring by selectively collecting only the data needed for compliance verification. The system filters network events to identify those related to policy violations, extracting specific configuration parameters and network element states that are relevant to rule evaluation, thereby reducing the complexity of analyzing vast amounts of monitoring data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments network monitoring into discrete functional components: configuration data collection, rule evaluation, violation detection, and report generation. Each component handles specific aspects of monitoring independently, making the overall system more manageable and easier to analyze. The segmented architecture allows traceability from network events to specific rule violations without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9282005B1IT infrastructure policy breach investigation interface
Publication Date: 2016.03.08 EMC IP HLDG CO LLC
  • US9282005B1 patent drawing
  • US9282005B1 patent drawing
  • US9282005B1 patent drawing

AI summary

In a large network, it can be difficult to pinpoint and track down the causes of breaches of established policies. A policy compliance server allows traversal of notifications according to breaches, organizes the breaches (vulnerabilities and violation) according to severity and recurrence, and identifies related rules, network entities and configuration changes, which may be related to the breach. An integrated graphical user interface (GUI) provides efficient, timely traversal and analysis of rule breaches across the network to allow quick, efficient identification of the underlying cause or condition of the rule breach. A discoverer gathers configuration data including notifications of changes, alerts, and conditions in the network that are pertinent to the rule breaches. A compliance engine evaluates the configuration data against the rules to identify breaches. Therefore, the compliance engine identifies breaches (rule violations and vulnerabilities) across the network to be addressed for compliance with the policies in effect in the network.