Dynamic Security Policy via Risk Profile Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security policies for computer systems are often static and fail to adapt to dynamic environments and user behaviors, leading to security compromises or productivity hindrances.

Innovation Solution

A method that logs risk factors over time to dynamically generate and update a risk profile, which is used to set and adjust security policies accordingly, ensuring security policy aggressiveness aligns with the current risk environment and user behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a static security policy is used, then the security policy is simple to implement, but it cannot adapt to dynamic environments and user behaviors

Engineering Contradiction:
Improveadaptability to dynamic environmentsVSAvoidsecurity policy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on real-time risk assessments. The system continuously monitors user behavior, system state, and security events to dynamically modify policy parameters, transitioning from static to adaptive security control without requiring complex manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where security events and risk assessments feed back into policy adjustments. The risk assessment module continuously evaluates security conditions and feeds this information back to the policy enforcement mechanism, enabling automatic adaptation to changing threats and behaviors.

Inventive Principle:
Principle #23Feedback

2Reliability

If a static security policy is used, then the implementation is straightforward, but it leads to security compromises or productivity hindrances

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically changes security parameters such as access control levels, monitoring intensity, and policy strictness based on real-time risk assessments. When risk is low, policies become more permissive to maintain productivity; when risk increases, policies automatically tighten to ensure security reliability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent enables security policies to dynamically adjust their strictness based on current risk conditions, allowing the system to balance security and productivity automatically rather than requiring fixed, overly restrictive policies that hinder operations.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If risk factors are logged and analyzed over time, then the risk profile becomes more accurate, but the data processing complexity increases

Engineering Contradiction:
Improverisk profile accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-defining risk factor categories, weighting schemes, and assessment models before actual security events occur. This preparation work structures the data collection and analysis process, making real-time risk profiling more efficient despite the volume of data being processed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The risk assessment system operates autonomously, automatically collecting, analyzing, and interpreting security data without requiring manual intervention. The system self-manages the complexity of data processing through automated algorithms and machine learning models that continuously refine risk profiles based on accumulated data.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7647622B1Dynamic security policy through use of empirical security events
Publication Date: 2010.01.12 CA TECH INC
  • US7647622B1 patent drawing
  • US7647622B1 patent drawing
  • US7647622B1 patent drawing

AI summary

Risk events occurring on a computer system are logged over time and a risk profile is dynamically generated and updated based on the logged risk events. In one embodiment, a security policy is dynamically set and updated based on the risk profile.