Network Security Policy Analysis via Device Adapter Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of determining and managing the overall security policy in computer networks is exacerbated by independently configured devices, making it challenging to assess and represent the existing security policy in a meaningful way for users.
Innovation Solution
A method and system that collect and analyze security configuration settings from multiple network nodes, graphically display network topology, and generate a security policy for communications between nodes, allowing users to reorder criteria and visualize the policy as a hierarchy, using device adapters, a network simulator, and a user interface module to derive and display the security policy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If each device is configured independently from others, then each device can be managed autonomously, but the overall security policy becomes complicated and difficult to determine
Solution Approach 1:
The patent introduces a security analysis program as an intermediary system that collects security configuration information from multiple network devices, analyzes the settings, and determines the effective security policy. This mediator consolidates the independent device configurations into a unified security policy representation, resolving the complexity issue while preserving independent device management.
Solution Approach 2:
The system implements feedback by analyzing the security settings of each device and providing information about the overall effective security policy. This feedback mechanism allows administrators to understand how individual device configurations contribute to the network-wide security policy, making it easier to manage independent devices while maintaining policy coherence.
2Reliability
If multiple devices enforce security rules, then network security is enhanced, but determining the existing security policy becomes challenging
Solution Approach 1:
The security analysis program acts as an intermediary that systematically collects security configuration information from multiple devices, analyzes the settings, and determines the effective security policy. This intermediary approach simplifies the detection and measurement of the overall security policy by consolidating information from multiple devices into a unified analysis.
3Measurement precision
If security policy is represented in detail for all devices, then accuracy is improved, but usability for users deteriorates
Solution Approach 1:
The patent extracts the essential elements of security policy from detailed device configurations and presents them in a simplified format. The security analysis program identifies and extracts the effective security policy characteristics that are relevant to users, separating the essential policy information from the detailed device-specific configurations, thereby improving usability while maintaining accuracy.
Data Source
AI summary
Described herein are a method and system for analyzing the security of a computer network. According to various implementations, there is a device adapter associated with each device that has a significant impact on the security of the network (e.g., routers, switches, gateways, or “significant hosts”). The device adapter, which may be implemented as a piece of software executing remotely from the device, queries the device to determine what its security settings are (e.g., its firewall rules). The device adapter conducts the query using whichever form of communication the device requires (e.g., telnet, HTTP) and using whichever command set the device requires. Each type of device on the network has a software model associated with it. For example, there may be a router model, a switch model, a firewall model, and a gateway model. The model is made up of a series of rule sets. Each rule set includes rules that are derived from the configuration of the device (obtained by the device adapter). The rules are expressed in a canonical rule set language. A global view of the security policy of the network is generated based on the modeled behaviors of the security devices (i.e., devices that have an impact on security) of the network, and is displayed on a user interface.


