Network Security Policy Analysis via Device Adapter Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of determining and managing the overall security policy in computer networks is exacerbated by independently configured devices, making it challenging to assess and represent the existing security policy in a meaningful way for users.

Innovation Solution

A method and system that collect and analyze security configuration settings from multiple network nodes, graphically display network topology, and generate a security policy for communications between nodes, allowing users to reorder criteria and visualize the policy as a hierarchy, using device adapters, a network simulator, and a user interface module to derive and display the security policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If each device is configured independently from others, then each device can be managed autonomously, but the overall security policy becomes complicated and difficult to determine

Engineering Contradiction:
ImproveIndependent device configurationVSAvoidOverall security policy complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a security analysis program as an intermediary system that collects security configuration information from multiple network devices, analyzes the settings, and determines the effective security policy. This mediator consolidates the independent device configurations into a unified security policy representation, resolving the complexity issue while preserving independent device management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by analyzing the security settings of each device and providing information about the overall effective security policy. This feedback mechanism allows administrators to understand how individual device configurations contribute to the network-wide security policy, making it easier to manage independent devices while maintaining policy coherence.

Inventive Principle:
Principle #23Feedback

2Reliability

If multiple devices enforce security rules, then network security is enhanced, but determining the existing security policy becomes challenging

Engineering Contradiction:
ImproveNetwork securityVSAvoidExisting security policy determination
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The security analysis program acts as an intermediary that systematically collects security configuration information from multiple devices, analyzes the settings, and determines the effective security policy. This intermediary approach simplifies the detection and measurement of the overall security policy by consolidating information from multiple devices into a unified analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If security policy is represented in detail for all devices, then accuracy is improved, but usability for users deteriorates

Engineering Contradiction:
ImproveSecurity policy accuracyVSAvoidUser understanding
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent extracts the essential elements of security policy from detailed device configurations and presents them in a simplified format. The security analysis program identifies and extracts the effective security policy characteristics that are relevant to users, separating the essential policy information from the detailed device-specific configurations, thereby improving usability while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7849497B1Method and system for analyzing the security of a network
Publication Date: 2010.12.07 SOLARWINDS WORLDWIDE LLC
  • US7849497B1 patent drawing
  • US7849497B1 patent drawing
  • US7849497B1 patent drawing

AI summary

Described herein are a method and system for analyzing the security of a computer network. According to various implementations, there is a device adapter associated with each device that has a significant impact on the security of the network (e.g., routers, switches, gateways, or “significant hosts”). The device adapter, which may be implemented as a piece of software executing remotely from the device, queries the device to determine what its security settings are (e.g., its firewall rules). The device adapter conducts the query using whichever form of communication the device requires (e.g., telnet, HTTP) and using whichever command set the device requires. Each type of device on the network has a software model associated with it. For example, there may be a router model, a switch model, a firewall model, and a gateway model. The model is made up of a series of rule sets. Each rule set includes rules that are derived from the configuration of the device (obtained by the device adapter). The rules are expressed in a canonical rule set language. A global view of the security policy of the network is generated based on the modeled behaviors of the security devices (i.e., devices that have an impact on security) of the network, and is displayed on a user interface.