Network Security Assessment Using Best Practice Templates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Assessing firewall security policies in corporate networks is challenging due to the complexity of rule sets and the difficulty in determining compliance with security requirements, as simple inspections of firewall rules are insufficient to ensure that insecure services are properly blocked.

Innovation Solution

A method and system using Best Practice Templates (BPTs) to assess network security by evaluating compliance across multiple targets, providing a composite compliance result, and displaying or storing the outcome, which includes a device adapter querying security settings, modeling devices, and analyzing policies to ensure adherence to security best practices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If simple inspection of firewall rules is performed, then the assessment process is fast and easy, but the accuracy of determining compliance with security requirements deteriorates

Engineering Contradiction:
Improveassessment speedVSAvoidcompliance determination accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary analysis layer that sits between simple rule inspection and compliance determination. This intermediary performs deep analysis of firewall rules, network traffic patterns, and security policies to bridge the gap between quick inspection and accurate compliance assessment, enabling both speed and precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual or simple mechanical inspection methods with automated intelligent analysis systems that use algorithms and machine learning to evaluate firewall compliance. This substitution enables rapid automated assessment while maintaining high accuracy through sophisticated analysis capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If deep analysis of firewall rules is performed, then the accuracy of compliance determination improves, but the complexity and time required for assessment increases

Engineering Contradiction:
Improvecompliance determination accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the firewall assessment process into multiple independent modules: rule parsing module, traffic analysis module, policy evaluation module, and compliance determination module. Each module handles a specific aspect of the analysis, reducing overall system complexity while enabling comprehensive deep analysis through coordinated operation of specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic analysis capabilities that adapt the depth and scope of firewall rule analysis based on detected risks, network traffic patterns, and compliance requirements. The system dynamically adjusts its analysis intensity, performing deeper analysis only where necessary, thereby managing complexity while maintaining accuracy.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive firewall policy analysis is performed, then the reliability of security assessment improves, but the time required for assessment increases

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-compiling firewall rules into optimized data structures, pre-analyzing network traffic baselines, and pre-evaluating security policies before the actual compliance assessment. This preliminary preparation enables rapid comprehensive analysis during the actual assessment, improving reliability without proportionally increasing assessment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic action by conducting comprehensive firewall policy analysis at scheduled intervals and using continuous monitoring to detect changes. This approach maintains high reliability through regular comprehensive assessments while minimizing time loss by using lighter-weight continuous monitoring between periodic deep analyses.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8176561B1Assessing network security risk using best practices
Publication Date: 2012.05.08 SOLARWINDS WORLDWIDE LLC
  • US8176561B1 patent drawing
  • US8176561B1 patent drawing
  • US8176561B1 patent drawing

AI summary

A method and appertaining system for implementing the method are provided that utilize predefined Best Practice Templates that are rules/criteria for assessing the security of a particular network and devices on the network. A value is determined for each object and connection within a network as to whether it passes or fails one of the Best Practice criteria, and a pass ratio is determined for a particular Best Practice. Numerous Best Practice tests may be run, and an overall total value based on the collective sum of the Best Practice measurements is determined. This value can be utilized to provide a user with information that relates to the overall security of a network and can be used in compliance determinations and network architecture design.