Information Processing for Security-Policy-Aligned Operation Procedures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems lack support for constructing configurations that align with security policies, despite advancements in IT technology making systems increasingly complex.
Innovation Solution
An information processing apparatus and method that includes a policy analysis unit to analyze security policies, a dataflow information analysis unit to analyze system dataflow, and an operation procedure construction unit to integrate these analyses to construct operation procedures aligned with security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing apparatuses for network visualization and dataflow analysis are used, then network path detection and system overview are improved, but security policy compliance is not achieved
Solution Approach 1:
The system segments the security analysis process into three distinct functional modules: network configuration analysis unit, dataflow analysis unit, and security policy compliance determination unit. Each module handles a specific aspect of the analysis, allowing comprehensive security verification while maintaining clear functional boundaries and improving overall system reliability.
Solution Approach 2:
The patent introduces an intermediary information processing apparatus that acts as a mediator between the target system and security policy requirements. This apparatus receives network configuration and dataflow information, performs intermediate analysis, and determines compliance with security policies, thereby bridging the gap between system operation and security requirements.
2Manufacturing precision
If comprehensive security analysis is performed, then security policy compliance is improved, but system complexity increases
Solution Approach 1:
The information processing apparatus is designed with multi-functional capabilities, serving as a universal system that can perform network configuration analysis, dataflow analysis, and security policy compliance determination all through a single integrated platform. This reduces overall system complexity by consolidating multiple analysis functions into one apparatus.
Solution Approach 2:
The system performs preliminary analysis of network configurations and dataflows before final security policy compliance determination. By pre-processing and organizing information in advance, the system simplifies the subsequent compliance checking process and reduces the complexity of real-time analysis.
3Reliability
If detailed dataflow analysis is conducted, then security vulnerability detection is improved, but processing time increases
Solution Approach 1:
The system performs preliminary organization and classification of network configuration information and dataflow information before conducting detailed security analysis. This pre-processing step structures the data in advance, enabling faster and more efficient vulnerability detection without compromising analysis depth.
Solution Approach 2:
The analysis process is segmented into distinct phases: network configuration analysis, dataflow analysis, and compliance determination. Each phase processes specific information independently, allowing parallel processing and reducing overall analysis time while maintaining comprehensive security checking.
Data Source
AI summary
An information processing apparatus includes: a policy analysis unit that analyzes a security policy of operation of a target system; a dataflow information analysis unit that analyzes dataflow information of the target system; and an operation procedure construction unit that searches operation procedures registered in advance, using a result of analysis of the security policy, to specify a corresponding operation procedure, and applies a result of analysis of the dataflow information to the specified operation procedure to construct an operation procedure of the target system.


