Distributed Security Agent Policy Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability assessment languages, such as OVAL, are inflexible and unable to effectively evaluate unknown or dynamic vulnerability and compliance issues in computing environments, as they only describe known security threats and policies.

Innovation Solution

The use of policy descriptions in XML files distributed to computing devices, where agents evaluate criteria defined in these policies by performing tests on device objects, storing state values for comparison, and reporting changes to improve policy definitions and enable dynamic security automation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If standardized vulnerability assessment languages like OVAL are used, then interoperability and policy evaluation capability are improved, but flexibility and adaptability to unknown or dynamic security threats deteriorate

Engineering Contradiction:
Improveadaptability to unknown security threatsVSAvoidpolicy definition complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments security assessment into two distinct layers: standardized policy definitions (OVAL) for known threats and adaptive machine learning models for unknown threats. This segmentation allows each layer to specialize - the standardized layer ensures interoperability while the adaptive layer provides flexibility, resolving the contradiction between standardization and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary adaptive assessment layer that sits between the standardized vulnerability assessment language and the actual security evaluation. This intermediary uses machine learning to bridge the gap between rigid standardized definitions and dynamic unknown threats, enabling the system to handle both known and unknown security issues effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive policy definitions are enforced to ensure security compliance, then security reliability is improved, but system productivity and ease of operation deteriorate due to rigid constraints

Engineering Contradiction:
Improvesecurity compliance reliabilityVSAvoidsystem operation productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system transitions from static, rigid policy enforcement to dynamic adaptive assessment. The adaptive layer continuously learns from new threat patterns and adjusts assessments in real-time, allowing security compliance to be maintained reliably while adapting to changing conditions without requiring constant manual policy updates, thus preserving productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms where assessment results from both standardized and adaptive layers are continuously analyzed to improve future assessments. This feedback loop enables the system to maintain high security reliability by learning from actual security events while automating the process, reducing manual intervention and maintaining productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10599850B1Distributed security agent technology
Publication Date: 2020.03.24 TRIPWIRE INC
  • US10599850B1 patent drawing
  • US10599850B1 patent drawing
  • US10599850B1 patent drawing

AI summary

Apparatus and methods are disclosed for identifying differences in objects of a computing device using definitions expressed in vulnerability assessment languages such as Open Vulnerability and Assessment Language (OVAL). In one example of the disclosed technology, a method includes receiving criteria for evaluating the computing device using an agent. The criteria specify object tests used to generate associated state values based on states or status of the tested objects. The criteria are evaluated and first state values generated by performing the object tests are stored as expected values for object tests. The criteria are then evaluated by re-performing the object tests, and second state values thereby generated are compared to the first state values. One or more differences between the first and second state values can be identified and reported to, for example, a monitor server.