Network Security Hardening via Dynamic Configuration Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network systems face challenges in maintaining security due to manual hardening processes being error-prone and incomplete, especially as network configurations change over time, leading to potential vulnerabilities and cyber threats.

Innovation Solution

A method for automatically improving network security by continuously collecting and analyzing security relevant information from network devices, identifying weak settings, and applying hardened security settings to restrict unnecessary operations while allowing regular system functionality, with periodic monitoring and adaptation to changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual hardening processes are used during commissioning phase, then security settings can be configured, but the process is error-prone and incomplete

Engineering Contradiction:
Improvesecurity settings correctnessVSAvoidhardening process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-hardening by automatically analyzing its own security settings, operational information, and traffic patterns to identify and correct security weaknesses without external intervention, making the hardening process autonomous and error-free

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors security settings and operational information, compares actual behavior against expected patterns, and automatically adjusts security configurations based on feedback from traffic analysis and vulnerability detection, ensuring ongoing correctness

Inventive Principle:
Principle #23Feedback

2Reliability

If initial hardening is performed during commissioning, then security is improved, but the hardening becomes invalid when network system changes occur

Engineering Contradiction:
Improvesecurity settings validityVSAvoidresponse to network changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The hardening system transitions from static initial hardening to dynamic continuous hardening, automatically adapting security configurations as the network system evolves, with real-time monitoring and adjustment capabilities that respond to device additions, configuration changes, and traffic pattern modifications

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs continuous security hardening throughout the network system's operational lifetime, not just during commissioning, by continuously collecting security information, analyzing traffic patterns, and applying hardening measures as needed to maintain validity despite changes

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automated hardening rules are applied, then hardening process is accelerated, but rules may be incorrect or only partially applicable

Engineering Contradiction:
Improvehardening process speedVSAvoidsecurity assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system replaces static automated rules with dynamic machine learning-based analysis that automatically learns optimal security configurations from observed traffic patterns and system behavior, eliminating the need for pre-defined rules while maintaining high speed and accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary learning during a monitoring phase where it collects security information and traffic patterns without applying hardening, then uses this learned knowledge to accurately and quickly apply appropriate hardening measures in subsequent operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3577879B1Automatic communication network system hardening
Publication Date: 2022.05.04 ABB (SCHWEIZ) AG
  • EP3577879B1 patent drawingFigure 1
  • EP3577879B1 patent drawingFigure 2
  • EP3577879B1 patent drawingFigure 3a~3b

AI summary

A method for automatically improving security of a network system (10) comprises: collecting security relevant information (30') from network devices (14) of the network system (10), the security relevant information (30') including security settings (32) and operational information (34) of the network devices (14); analyzing the security relevant information (30') for determining weak security settings (32') of a network device (14), the weak security settings (32') being not necessary for a regular operation of the network system (10); determining hardened security settings (32'') for the network device (14) based on the weak security settings (32'), the hardened security settings (32'') restricting a possible operation of the network device (14) but allow a regular operation of the network system (10); and applying the hardened security settings (32'') to the network device (14).