IoT Network Security Compliance Using ML Policy Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security compliance checking for IoT networks is inefficient, ad-hoc, and time-consuming, particularly due to the manual process of identifying relevant security standards and policies, which limits reusability and overlooks critical deployment considerations, and regular updates to security standards and policies are not scalable and adaptable to evolving security landscapes.

Innovation Solution

A computer-implemented method using trained machine learning models to extract and process contextual data from IoT infrastructure and data to determine compliance with security policies, contextual data from the network infrastructure, and determine compliance with security standards by extracting security policies from various sources, including official standards and local regulations, and providing automated compliance checking and risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual auditing and validation of deployment settings is performed to ensure compliance with security requirements, then compliance accuracy is improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvecompliance checking accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical auditing processes with automated machine learning models that extract security policies from standards and validate deployment settings automatically. The NLP-based policy extraction model and compliance validation model eliminate the need for manual review while maintaining high accuracy through automated contextual analysis and comparison against security requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces machine learning models as intermediaries between security standards and deployment configurations. These models act as intelligent mediators that automatically interpret security policies, extract relevant requirements, and validate compliance without requiring manual intervention, thus reducing time consumption while preserving compliance checking accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If comprehensive security standards and policies are manually identified and validated, then compliance coverage is improved, but operational complexity and resource requirements increase

Engineering Contradiction:
Improvecompliance coverageVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal automated compliance validation system that can handle multiple security standards and policies simultaneously through a single machine learning model framework. The system is designed to be multi-functional, accommodating various security requirements and deployment configurations without requiring separate manual validation processes for each standard, thus reducing operational complexity while expanding compliance coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the operational parameters from manual processes to automated computational processes. By transforming the compliance validation from a manual, step-by-step procedure to an automated machine learning-based system, the patent reduces operational complexity while maintaining or expanding compliance coverage through efficient parameter-driven validation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If regular updates to security standards are performed manually, then compliance currency is improved, but productivity and time efficiency deteriorate

Engineering Contradiction:
Improvecompliance currencyVSAvoidupdate efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables continuous automated monitoring and validation of security compliance through machine learning models that can process updates to security standards in real-time. The system maintains continuous compliance currency by automatically detecting changes in security policies and re-validating deployment configurations without interruption to operational productivity, unlike manual update processes that require significant time and resources.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent implements a self-updating compliance validation system where the machine learning models automatically adapt to new security standards and policies without requiring manual reconfiguration. The system performs self-service by autonomously detecting changes in security requirements, updating its validation criteria, and re-assessing compliance status, thereby maintaining compliance currency while preserving productivity.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If detailed contextual data is extracted from each component for compliance validation, then compliance precision is improved, but data processing complexity and computational resources increase

Engineering Contradiction:
Improvecompliance validation precisionVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the relevant contextual data from each network component that is necessary for compliance validation, using NLP-based policy extraction to identify and isolate specific security-related parameters. This selective extraction approach maintains compliance validation precision by focusing on critical data points while reducing overall data processing complexity by eliminating unnecessary information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the compliance validation process into distinct analytical stages, where machine learning models process different aspects of contextual data separately. By dividing the complex validation task into manageable segments—such as policy extraction, contextual data analysis, and compliance comparison—the system achieves high precision validation while reducing the computational complexity of processing detailed component data.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260025402A1Method and device for determining security compliance of network infrastructure
Publication Date: 2026.01.22 CISCO SYSTEMS AUSTRALIA PTY LTD
  • US20260025402A1 patent drawing
  • US20260025402A1 patent drawing
  • US20260025402A1 patent drawing

AI summary

Computer-implemented methods, instructions and systems for determining the compliance of a network infrastructure with a security policy. The network infrastructure includes a plurality of components. A method includes extracting, by applying a first trained machine learning model to a security standard, at least one security policy of the security standard, and obtaining, from each component of the plurality of components of the network infrastructure, contextual data defining the security configurations and security capabilities of the component. The method further includes processing the contextual data and the security policy of the security standard, by a second trained machine learning model, the second trained machine learning model configured to output an indication of whether the network infrastructure satisfies the security policy of the security standard.