Dynamic Network Security Policy Assignment by Device Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Static security constructs in networks are restrictive and reactive, failing to provide robust, individualized security, especially in dynamic environments like BYOD policies, where devices with varying risk levels require adaptive security measures.

Innovation Solution

A framework that assesses device risk based on threat and harm, dynamically assigning network traffic to customizable security groups, allowing for real-time policy enforcement based on risk levels, using a system comprising a policy engine, group engine, risk assessment engine, assignment engine, action engine, and user interface engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security policies are applied to all devices, then security enforcement is simplified, but individualized security needs and varying risk levels cannot be addressed

Engineering Contradiction:
Improveadaptability to varying risk levelsVSAvoidsecurity policy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments devices into different risk-based groups (e.g., low-risk, medium-risk, high-risk groups) based on assessed risk levels. Each group receives customized security policies tailored to its risk profile, enabling individualized security without manually configuring policies for each device. The system automatically assigns devices to appropriate groups and applies corresponding security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes security policy parameters based on risk assessments. Risk levels are calculated using multiple parameters (device type, security posture, behavior patterns), and these parameters are continuously updated. When risk parameters change, the system automatically adjusts the security policy applied to the device, enabling adaptive security response to varying conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If aggressive security policies are applied to all devices, then security protection is enhanced, but legitimate traffic is unnecessarily restricted

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidnetwork traffic flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different security policy strengths to different devices based on their local risk characteristics. Low-risk devices receive permissive policies that allow legitimate traffic to flow freely, while high-risk devices receive aggressive security policies with strict controls. This local differentiation ensures strong protection where needed while maintaining operational ease for trusted devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Security policies are made dynamic rather than static. The system continuously monitors device behavior and risk factors, automatically adjusting policy aggressiveness in real-time. When a device's risk level changes, the security policy transitions accordingly - becoming more restrictive when risk increases and more permissive when risk decreases, balancing protection and traffic flow dynamically.

Inventive Principle:
Principle #15Dynamics

3Reliability

If manual updates of security policies are performed, then security can be adjusted, but the process is time-consuming and reactive rather than proactive

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidpolicy update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically assessing device risk levels and updating security policies without administrator intervention. The risk assessment engine continuously monitors devices, calculates risk scores, and triggers automatic policy updates when risk thresholds are crossed. This eliminates manual policy management while maintaining effective security adaptation to changing conditions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where device behavior and risk factors are monitored, fed into the risk assessment engine, which then adjusts security policies accordingly. This closed-loop feedback mechanism enables proactive security adjustments - the system detects risk changes and automatically responds by updating policies before threats can exploit vulnerabilities, eliminating the reactive nature of manual updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10554691B2Security policy based on risk
Publication Date: 2020.02.04 TREND MICRO INC
  • US10554691B2 patent drawing
  • US10554691B2 patent drawing
  • US10554691B2 patent drawing

AI summary

A security system for a network maintains security policies that each includes a risk level. The security system maintains groups, with each group being associated with a security policy. Assets of the network are assigned to groups according to the risk assessments of the assets. Security policy associated with a group is enforced against network traffic of an asset when the asset is assigned to the group.