Crowdsourced Security Policy Server for Dynamic Network Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and maintaining effective security policies in dynamic and rapidly changing wireless computer network environments is challenging due to the variety of threats, devices, and communication protocols.

Innovation Solution

A system that includes a crowdsourcing security policy server integrated with a threat management system, allowing users to share and rate security policies, providing a user interface for displaying ranked security policies, and suggesting policy templates based on network data, to facilitate the management and application of security rules and protocols across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security policy implementation methods are used, then security policies can be enforced, but the complexity of managing and maintaining effective security policies in dynamic network environments increases

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to automatically contribute security policies through their own network configurations and threat experiences. The crowdsourcing mechanism allows policies to be generated and shared without requiring manual creation by system administrators, reducing the management burden while maintaining policy effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates rating mechanisms where users can evaluate and rate security policies based on their effectiveness. This feedback loop allows the system to learn from user experiences and improve policy selection, making the complex policy management process more intelligent and adaptive.

Inventive Principle:
Principle #23Feedback

2Reliability

If security policies are manually created and distributed, then policies can be implemented, but the time required for development and distribution increases

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidpolicy development and distribution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses template-based policy generation where successful security policies are replicated and adapted for different network environments. Users can copy proven policies from the crowdsourced repository rather than creating them from scratch, significantly reducing development time while maintaining effectiveness.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Security policies are pre-generated and stored in a crowdsourced repository before they are needed. When a user needs security protection, the system retrieves pre-validated policies from the repository rather than creating them in real-time, accelerating the policy implementation process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a centralized security policy system is implemented, then policy management is simplified, but the adaptability to dynamic and rapidly changing network environments decreases

Engineering Contradiction:
Improvepolicy management easeVSAvoidnetwork environment adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system maintains a dynamic crowdsourced policy repository that continuously updates with new policies and ratings from users across different network environments. This dynamic approach allows the centralized system to adapt to changing network conditions while maintaining the organizational benefits of centralized management through a unified policy interface.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The crowdsourced policy templates are designed to be universally applicable across different network types and configurations. A single policy template can serve multiple network environments, enhancing both the ease of centralized management and the adaptability to diverse network scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11683350B2System and method for providing and managing security rules and policies
Publication Date: 2023.06.20 SOPHOS LTD
  • US11683350B2 patent drawing
  • US11683350B2 patent drawing
  • US11683350B2 patent drawing

AI summary

Methods, systems, and computer readable media for providing and managing security rules and policies are described. In some implementations, a method may include receiving, at a crowdsourcing security policy server, a security policy from a first user account, and providing a crowdsourced security policy user interface including a section corresponding to the security policy configured to make the security policy available for use by other user accounts. The method may also include receiving from one or more of the other user accounts, a security policy rating corresponding to the security policy, and receiving, from one or more of the other user accounts, a user account rating corresponding to the first user account.