Network Security Policy Configuration via Predetermined Command Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring network security systems for OT environments is a time-consuming and labor-intensive process due to the need for manual generation of whitelisting policies, which are prone to errors and require constant updates as new commands are identified.

Innovation Solution

A network security system uses predetermined command groups to automate the generation of whitelisting policies by monitoring data traffic and identifying sets of commands, then applies these groups to the policies, reducing the administrative burden and improving efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual generation of whitelisting policies is used, then security coverage can be comprehensive, but the configuration process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates whitelisting policies by monitoring network traffic and extracting commands autonomously, eliminating the need for manual administrator intervention. The security system serves itself by automatically identifying commands, grouping them, and creating policy rules without human input.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of administrators analyzing services and creating policies is replaced with an automated electronic system that monitors traffic, extracts commands using pattern matching, and generates policies algorithmically, substituting human labor with computational processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If manual configuration of whitelisting policies is performed, then policies can be customized, but human errors increase and constant updates are required

Engineering Contradiction:
Improvepolicy customizationVSAvoiderror rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors network traffic and uses the observed commands as feedback to automatically update and refine whitelisting policies. This closed-loop approach ensures policies remain current with actual network usage while eliminating manual update errors.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system autonomously detects new commands, groups them appropriately, and updates policies without human intervention, maintaining customization adaptability while eliminating human error in policy creation and updates.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated policy generation is implemented, then configuration efficiency improves, but system complexity increases

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated policy generation system is divided into distinct functional modules: network traffic monitoring, command extraction, command grouping, and policy generation. This segmentation manages complexity by organizing the automated process into manageable, independent components with clear interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Command groups serve as an intermediary layer between raw network commands and final security policies. This intermediate structure simplifies the generation process by organizing commands into logical groups before creating policies, reducing the complexity of direct one-to-one mapping.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3451616B1Network security policy configuration based on predetermined command groups
Publication Date: 2020.03.04 GENERAL ELECTRIC CO
  • EP3451616B1 patent drawingFigure 1
  • EP3451616B1 patent drawingFigure 2
  • EP3451616B1 patent drawingFigure 3

AI summary

A network security system 102 monitors, during a time period, data traffic transmitted between devices in a network 104, 106 to identify a plurality of commands transmitted between the devices. The network security system determines, from the plurality of commands, a first set of commands that were transmitted between a first device and a second device in the network. The network security system 102 determines that the first set of commands includes a threshold number of commands from a first predetermined command group of a plurality of predetermined command groups. Each predetermined command group includes a listing of commands. The network security system 102 generates a first policy based on the first predetermined command group.