Idempotent Security Policy Enforcement for Configuration Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity systems are inflexible and computationally prohibitive, often failing to effectively identify and remediate security issues across a wide range of devices and applications, as they are limited to specific security standards and require redundant operations, consuming significant processing resources.

Innovation Solution

A configuration management system and agent that enforce security policies by performing idempotent operations, allowing a single software agent to both scan and fix security issues, and implement a policy-driven approach to enforce security policies applicable to multiple standards, reducing processing overhead and improving performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cybersecurity systems perform comprehensive security checks based on multiple security standards, then security coverage is improved, but computing resource consumption increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements a universal security policy framework where a single security policy can address multiple security standards simultaneously. The system maps security requirements from different standards (CIS, STIG, PCI, HIPAA) to a common set of policies, allowing one policy to enforce compliance across multiple standards without running separate checks for each standard, thereby reducing computing resource consumption while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple security standard requirements into unified security policies. Instead of executing separate diagnostic tools for each security standard, the system merges the requirements and implements a single integrated policy enforcement mechanism that checks compliance with all relevant standards in one operation, significantly reducing redundant computing operations.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If conventional cybersecurity systems are tailored to specific security standards, then effectiveness for that standard is improved, but adaptability to other devices and standards deteriorates

Engineering Contradiction:
Improvesecurity check effectivenessVSAvoidapplicability to multiple devices and standards
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security policy framework is designed to be universally applicable across multiple security standards and device types. A single policy can be configured to enforce requirements from CIS, STIG, PCI, or HIPAA standards, or any combination thereof, making the system adaptable to diverse devices and applications while maintaining effectiveness for each specific standard through proper policy configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts to different security standards and device types through configurable security policies. Rather than being fixed to a single standard, the policies can be adjusted and configured to match the specific requirements of different security standards and device categories, enabling the system to effectively serve multiple purposes without sacrificing compliance with any particular standard.

Inventive Principle:
Principle #15Dynamics

3Reliability

If conventional systems perform separate scan and fix operations for security policies, then thoroughness of security remediation is improved, but operational efficiency deteriorates

Engineering Contradiction:
Improvesecurity remediation thoroughnessVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the security scan and security fix operations into a single integrated operation. When a security policy is enforced, the system simultaneously identifies non-compliant configuration settings and remediates them in one action, eliminating the need for separate scan and fix operations. This integrated approach maintains thorough security remediation while significantly improving operational efficiency by reducing redundant operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security policy enforcement mechanism performs self-service by automatically identifying and remediating non-compliant configuration settings without requiring separate manual intervention steps. The system detects security issues and applies fixes autonomously as part of the policy enforcement process, eliminating the need for separate scan and remediation phases that would otherwise require additional operational steps.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11184404B1Performing idempotent operations to scan and remediate configuration settings of a device
Publication Date: 2021.11.23 VMWARE INC
  • US11184404B1 patent drawing
  • US11184404B1 patent drawing
  • US11184404B1 patent drawing

AI summary

The present disclosure relates to systems, methods, and computer-readable media for implementing an efficient and flexible policy-driven approach to securing a computing device. For example, systems disclosed herein can identify any number of security policies including configuration states associated with configuration settings of a client device. The systems disclosed herein can further enforce the security policies by performing an enforcement operation including an idempotent operation that enables a computing device to both diagnose as well as remedy security issues identified by an agent on a computing device. The systems disclosed herein further include features and functionality that enable a computing device to be compliant with multiple security standards without performing redundant enforcement operations.