Dynamic Network Security Policy Assignment by Device Risk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Static security constructs in networks are restrictive and reactive, failing to provide robust, individualized security, especially in dynamic environments like BYOD policies, where devices with varying risk levels require adaptive security measures.
Innovation Solution
A framework that assesses device risk based on threat and harm, dynamically assigning network traffic to customizable security groups, allowing for real-time policy enforcement based on risk levels, using a system comprising a policy engine, group engine, risk assessment engine, assignment engine, action engine, and user interface engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static security policies are applied to all devices, then security enforcement is simplified, but individualized security needs and varying risk levels cannot be addressed
Solution Approach 1:
The patent segments devices into different risk-based groups (e.g., low-risk, medium-risk, high-risk groups) based on assessed risk levels. Each group receives customized security policies tailored to its risk profile, enabling individualized security without manually configuring policies for each device. The system automatically assigns devices to appropriate groups and applies corresponding security measures.
Solution Approach 2:
The system dynamically changes security policy parameters based on risk assessments. Risk levels are calculated using multiple parameters (device type, security posture, behavior patterns), and these parameters are continuously updated. When risk parameters change, the system automatically adjusts the security policy applied to the device, enabling adaptive security response to varying conditions.
2Reliability
If aggressive security policies are applied to all devices, then security protection is enhanced, but legitimate traffic is unnecessarily restricted
Solution Approach 1:
The patent applies different security policy strengths to different devices based on their local risk characteristics. Low-risk devices receive permissive policies that allow legitimate traffic to flow freely, while high-risk devices receive aggressive security policies with strict controls. This local differentiation ensures strong protection where needed while maintaining operational ease for trusted devices.
Solution Approach 2:
Security policies are made dynamic rather than static. The system continuously monitors device behavior and risk factors, automatically adjusting policy aggressiveness in real-time. When a device's risk level changes, the security policy transitions accordingly - becoming more restrictive when risk increases and more permissive when risk decreases, balancing protection and traffic flow dynamically.
3Reliability
If manual updates of security policies are performed, then security can be adjusted, but the process is time-consuming and reactive rather than proactive
Solution Approach 1:
The system performs self-service by automatically assessing device risk levels and updating security policies without administrator intervention. The risk assessment engine continuously monitors devices, calculates risk scores, and triggers automatic policy updates when risk thresholds are crossed. This eliminates manual policy management while maintaining effective security adaptation to changing conditions.
Solution Approach 2:
The system implements continuous feedback loops where device behavior and risk factors are monitored, fed into the risk assessment engine, which then adjusts security policies accordingly. This closed-loop feedback mechanism enables proactive security adjustments - the system detects risk changes and automatically responds by updating policies before threats can exploit vulnerabilities, eliminating the reactive nature of manual updates.
Data Source
AI summary
A security system for a network maintains security policies that each includes a risk level. The security system maintains groups, with each group being associated with a security policy. Assets of the network are assigned to groups according to the risk assessments of the assets. Security policy associated with a group is enforced against network traffic of an asset when the asset is assigned to the group.


