Network Perimeter Security Assessment Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security assessments are limited in providing a comprehensive review of the perimeter security, focusing on specific disciplines rather than a broad framework, and lack integration of multiple security disciplines to ensure a secure environment.

Innovation Solution

A method that combines network architecture review, component review, application review, policy review, and vulnerability review to assess the security of network perimeters, incorporating tools and processes to identify vulnerabilities and ensure compliance with corporate and industry standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security review disciplines (architecture, component, application, policy, vulnerability) are integrated into a comprehensive assessment framework, then the comprehensiveness and reliability of network perimeter security assessment is improved, but the device complexity and difficulty of operation increase

Engineering Contradiction:
Improvecomprehensiveness of security assessmentVSAvoidcomplexity of assessment framework
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security assessment into five distinct review disciplines (architecture review, component review, application review, policy review, and vulnerability review), each handled by separate review modules. This segmentation allows comprehensive coverage while managing complexity through modular organization, where each module can be independently configured and executed based on specific assessment needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The assessment framework is designed as a universal system that can perform multiple types of security reviews across different disciplines. The framework accommodates various review types (architecture, component, application, policy, vulnerability) within a single integrated platform, making it adaptable to different network environments and security assessment requirements without requiring separate specialized tools for each review type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If a comprehensive multi-disciplinary security review framework is implemented, then the security coverage and measurement precision are improved, but the ease of operation deteriorates

Engineering Contradiction:
Improveprecision of security assessmentVSAvoidease of conducting security review
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent merges five separate review disciplines into a single integrated assessment framework that operates as a unified system. The framework combines architecture review, component review, application review, policy review, and vulnerability review into one coordinated process, allowing comprehensive security assessment while presenting a unified interface to users, thereby improving ease of operation despite the multi-disciplinary nature of the assessment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The framework introduces an intermediary assessment engine that coordinates between different review modules and synthesizes their findings. This intermediary layer manages the complexity of multiple review disciplines by providing a standardized interface and automated coordination, reducing the operational burden on users while maintaining comprehensive and precise security assessment across all five review areas.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If manual architecture review processes are vendor-specific and product-focused, then the ease of manufacture and adaptability to specific products are improved, but the adaptability to broad network frameworks deteriorates

Engineering Contradiction:
Improveease of developing review processVSAvoidversatility of security assessment framework
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent designs the assessment framework with universal applicability across multiple network vendors and product types. Rather than creating vendor-specific review processes, the framework implements discipline-based review modules (architecture, component, application, policy, vulnerability) that can assess networks regardless of the specific vendors or products used, thereby achieving broad versatility while maintaining ease of implementation through standardized review criteria.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The framework employs configurable parameters and adjustable review criteria that can be modified to suit different network environments, vendors, and products. By making the review parameters changeable rather than fixed, the system maintains ease of manufacture through standardized processes while achieving high adaptability to various network architectures and vendor-specific implementations through parameter customization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8561154B2Method for providing network perimeter security assessment
Publication Date: 2013.10.15 KYNDRYL INC
  • US8561154B2 patent drawing
  • US8561154B2 patent drawing
  • US8561154B2 patent drawing

AI summary

A method for providing network perimeter security assessment that involves a combination of perimeter security assessment disciplines is disclosed. A security review of a network perimeter architecture is performed along with a review of the security of data processing devices that transfer data across the perimeter of the network, a review of the security of applications that transfer data across said perimeter and a review of the vulnerability of applications or data processing devices within said perimeter from computers or users outside of said perimeter. Each of the reviews may be performed by comparison to a security policy of an enterprise that owns or controls the network.