Network Security Policy Compatibility Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security policies in computer networks often struggle to balance security and usability, leading to restrictive settings that hinder software functionality or inadequate security that allows breaches, and require ad hoc adjustments by skilled technicians, which is inefficient and prone to errors as systems become complex.

Innovation Solution

A method that conducts an impact assessment using automated tools like the Erudine Behaviour Engine to determine the effect of security policies on applications, allowing for adjustments to security policies and communications requirements to ensure compatibility and usability, thereby predicting and mitigating potential issues before introducing new applications into the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are made more restrictive to improve security, then security breaches are reduced, but software application functionality is hindered

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary impact assessment before deploying security policies or applications. By simulating the network environment and evaluating potential security impacts in advance, the system identifies suitable security policies that maintain both security and functionality, preventing the need for restrictive post-deployment adjustments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary assessment layer between security policy enforcement and application operation. This intermediary evaluates the compatibility between security policies and application requirements, selecting policies that satisfy both security constraints and functional needs, thus resolving the contradiction without requiring extreme restrictiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security policies are made less restrictive to improve usability, then software functionality is enhanced, but security breaches become more likely

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

By conducting preliminary impact assessments, the system determines the maximum permissive security policies that still maintain adequate security protection. This allows the system to adopt less restrictive policies confidently, knowing that security risks have been evaluated and controlled in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts security policy parameters based on impact assessment results. Instead of using fixed restrictive or permissive policies, the system optimizes policy parameters to achieve the least restrictive configuration that still satisfies security requirements, thereby improving usability without compromising security.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If ad hoc adjustments are made by skilled technicians to resolve security-functionality conflicts, then specific issues are addressed, but efficiency decreases and errors increase as systems become complex

Engineering Contradiction:
Improvesecurity policy adjustmentVSAvoidadjustment efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system performs self-service by automatically conducting impact assessments and determining suitable security policies without requiring skilled technicians. The automated evaluation process analyzes security impacts, application requirements, and policy compatibility, replacing manual ad hoc adjustments with systematic automated decision-making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical process of manual technician analysis and adjustment with an automated computational assessment engine. This substitution eliminates human error, increases efficiency, and scales effectively as system complexity grows, maintaining high productivity regardless of system size.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If comprehensive security assessments are conducted for every new application, then security compatibility is ensured, but time and resources are consumed

Engineering Contradiction:
Improvesecurity compatibilityVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs partial assessments by focusing on the most critical security impact factors rather than conducting exhaustive analyses of every possible scenario. This selective assessment approach identifies the most relevant security considerations, ensuring adequate security compatibility evaluation while significantly reducing assessment time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2232814B1Computer network security
Publication Date: 2019.10.16 AIRBUS DEFENCE AND SPACE LTD
  • EP2232814B1 patent drawingFigure 1
  • EP2232814B1 patent drawingFigure 2
  • EP2232814B1 patent drawingFigure 3

AI summary

A system comprises: a representation of a network; a communications requirements file for an application to be executed by a node of said network; and a security policy file defining a security policy for said node of said network. Said files are processed to determine whether said security policy and said communication requirements are compatible.