Fragility Handling in Compliance Checking Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Compliance checking and remediation systems in enterprises are fragile, leading to potential network access restrictions and productivity losses due to failures in components or connectivity, which existing systems fail to adequately handle.
Innovation Solution
Implementing fragility detection and configurable fragility alleviation measures, including built-in fragility handling, error categorization, and customizable mitigation rules to manage failures in compliance checking systems, allowing for flexible security level adjustments to maintain business continuity and user productivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If compliance checking is implemented to ensure security, then security level is improved, but network access reliability deteriorates due to component failures
Solution Approach 1:
The system implements fragility detection mechanisms that anticipate potential compliance checking failures before they impact network access. By detecting fragility conditions (component failures, connectivity issues) in advance, the system can apply mitigation rules to cushion the impact and maintain network access availability while preserving security requirements.
Solution Approach 2:
The patent introduces an intermediary fragility detection and mitigation layer between the compliance checking system and network access control. This intermediary detects compliance checking failures, categorizes them by fragility type, and applies mitigation rules to determine appropriate network access decisions, thereby preventing compliance failures from directly blocking network access.
2Reliability
If strict compliance checking is enforced to maintain security policies, then security administration reliability is improved, but business continuity deteriorates due to access restrictions
Solution Approach 1:
The system dynamically adjusts network access decisions based on detected fragility conditions. When compliance checking failures are detected and categorized as fragile (rather than indicative of actual non-compliance), the system dynamically modifies access permissions through mitigation rules, allowing continued business operations while maintaining security oversight.
Solution Approach 2:
The patent changes the parameter of network access permission based on fragility detection results. By identifying that a compliance failure is due to system fragility rather than actual policy violation, the system adjusts the access parameter from restricted to permitted, thereby maintaining business continuity while preserving security administration integrity.
3Reliability
If compliance checking infrastructure is made highly redundant to prevent failures, then system reliability is improved, but device complexity increases
Solution Approach 1:
Rather than increasing infrastructure redundancy, the patent introduces an intermediary fragility detection layer that works with the existing compliance checking infrastructure. This intermediary detects and mitigates the impact of failures without requiring duplicate compliance checking components, thereby improving effective reliability without proportionally increasing infrastructure complexity.
Data Source
AI summary
A method is provided for handling failures in a computer system including a compliance checking system in a computer network. In response to a client computer failing to obtain a compliance check, a determination is made as to a category of an error that at least partially caused the failure in obtaining the compliance check. As a result, the method includes performing an action to at least partially based on the determined category of the error. In some instances, the action can include allowing the client computer to connect to the network. Another method includes receiving a definition of a configurable mitigation rule, where the configurable mitigation rule describes an action to perform at least partially based on the category of an error. Yet another method includes receiving a selection of a security level of operation of the compliance checking system.


