Automated Configuration Violation Remediation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security administrators face challenges in managing and triaging a large volume of security violation alerts, as well as tracking dynamic states of detected violations, due to the complexity and volume of alerts generated by computer-related security violations.

Innovation Solution

A remediation system that detects configuration-related violations by comparing actual configurations against prescribed settings, determines severity, and performs either automatic or manual remediation, while maintaining an audit log to track events, using a remediation server that communicates with data source servers and client devices to address discrepancies and security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual triage and management of security violation alerts is performed, then security administrators can address violations, but the workload becomes unmanageable due to large volume of alerts

Engineering Contradiction:
Improveease of managing security violationsVSAvoidvolume of security alerts
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The system enables self-service automation where the remediation server automatically performs triage, severity determination, and remediation actions without requiring manual security administrator intervention for each alert. The system serves itself by autonomously managing the security violation workflow from detection to resolution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of security administrators reviewing and managing alerts with an automated computer-based system. The remediation server uses automated algorithms to perform triage, determine severity, select remediation plans, and execute fixes, substituting human manual operations with automated computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security administrators manually track dynamic states of violations, then they can monitor remediation progress, but tracking becomes difficult due to large number of alerts

Engineering Contradiction:
Improvetracking accuracy of violation statesVSAvoidcomplexity of tracking multiple violations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements continuous feedback mechanisms where the remediation server automatically monitors and tracks the state of each security violation throughout the remediation process. The system provides feedback on remediation progress, updates violation states in real-time, and notifies stakeholders of status changes, enabling reliable tracking without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The remediation server performs multiple functions including violation detection, triage, severity determination, remediation plan selection, execution, and state tracking all through a single automated system. This multi-functional approach simplifies the complexity of tracking multiple violations by consolidating all tracking operations within one universal system rather than requiring separate manual processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automatic remediation is performed for high-severity violations, then resolution time is reduced, but automation extent increases

Engineering Contradiction:
Improveremediation speedVSAvoidlevel of automated remediation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system applies different levels of automation to different severity levels of violations. High-severity violations receive automatic remediation with full automation, while lower-severity violations may use manual or semi-automated processes. This localized quality approach optimizes remediation speed for critical issues while maintaining appropriate human oversight for less severe matters.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of automation extent based on the severity parameter of the violation. When severity exceeds a threshold, the system transitions from manual to automatic remediation mode. This dynamic parameter adjustment allows the system to optimize productivity for high-severity cases while maintaining controlled automation levels overall.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11418393B1Remediation of detected configuration violations
Publication Date: 2022.08.16 APPOMNI INC
  • US11418393B1 patent drawing
  • US11418393B1 patent drawing
  • US11418393B1 patent drawing

AI summary

Remediation of detected configuration violations is disclosed, including: detecting a violation associated with a configuration at a data source server; providing a remediation corresponding to the violation; and storing an audit log that includes one or more events associated with the remediation corresponding to the violation.