Dynamic Security Policy Adaptation via Multi-Parameter Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information system security policies are activated en masse based on correlated alerts, leading to unnecessary activations and lack of deactivation, causing potential harm to users and system performance due to the inability to assess real-time risk and respond effectively to attacks.
Innovation Solution
A method that dynamically activates and deactivates security policies by assessing multiple parameters, including success probability, activation impact, and cost impact of attacks and security policies, using data repositories and attack models to optimize policy deployment and minimize user impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are activated based on correlated alerts, then attack detection coverage is improved, but the number of unnecessary policy activations increases
Solution Approach 1:
The patent changes the decision parameters from simple alert correlation to a multi-parameter assessment including success probability, cost impact, and activation impact. This allows the system to evaluate whether policy activation is truly necessary by considering multiple factors beyond just alert correlation, thereby reducing unnecessary activations while maintaining detection coverage.
Solution Approach 2:
The patent introduces an intermediary assessment layer between alert correlation and policy activation. This intermediary evaluates success probability, cost impact, and activation impact before triggering policy activation, acting as a filter that prevents unnecessary activations while allowing genuine threats to proceed to policy enforcement.
2Reliability
If security policies remain activated continuously, then security coverage is improved, but user impact and system performance deteriorate
Solution Approach 1:
The patent makes security policy activation dynamic rather than static. Policies are activated only when the assessment determines they are necessary based on current system state, success probability, and impact analysis. The system continuously re-evaluates the need for active policies and deactivates them when no longer necessary, adapting to changing conditions in real-time.
Solution Approach 2:
The patent applies partial action by selectively activating only those security policies that are necessary based on the assessment, rather than activating all possible policies. The system determines the minimum necessary intervention by evaluating success probability and impact, applying only the required level of security response.
3Reliability
If multiple security policies are activated in response to attacks, then security response effectiveness is improved, but system complexity and management difficulty increase
Solution Approach 1:
The patent segments the policy management process into distinct assessment components: success probability assessment, cost impact assessment, and activation impact assessment. This segmentation allows the system to evaluate each aspect separately and make informed decisions about which specific policies to activate, reducing management complexity while maintaining comprehensive security response.
4Reliability
If security policies are activated without deactivation capability, then security protection is improved, but system adaptability and performance deteriorate
Solution Approach 1:
The patent implements feedback mechanisms that continuously monitor system state, attack progression, and policy effectiveness. Based on this feedback, the system reassesses success probability and impact parameters, and accordingly activates or deactivates policies. This feedback loop enables the system to adapt to changing conditions and deactivate policies when they are no longer necessary.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention refers to a method for adapting security policies of an information system infrastructure in function of attacks wherein it comprises the steps of: - storing potential attacks and their associated risks in a data repository (125); - storing curative security policies (128) in response of the potential attacks in a data repository; - monitoring (101) entering contents representing data streams of the information system; - detecting (129) at least one attack in the information system; - assessing a success probability parameter (132) of the at least one detected attack and its associated cost impact parameter (133); - assessing an activation impact parameter (136) of at least one curative security policy in response to the at least one detected attack and its associated cost impact parameter; - deciding of the activation or deactivation (134) of a curative security policy in function of the success probability parameter of the, at least one, detected attack, of the activation impact parameter of at least one curative security policy and of the cost impact parameters of both the detected at least one attack and the at least one curative security policy.