Network Security Policy Generator for Automated Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security configuration verification methods for network devices are time-consuming and require significant manufacturer intervention, especially when multiple devices with different configurations need to be verified, leading to increased costs and efforts.

Innovation Solution

A security configuration verification device and method that generate a new scanning policy based on preconfigured policies, allowing network administrators to select and modify security check items according to specific network devices and environments, enabling self-defined verification policies without manufacturer intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security configuration verification is performed on multiple network devices using traditional methods, then security verification can be accomplished, but the time consumption increases significantly due to repeated manufacturer intervention

Engineering Contradiction:
Improvesecurity verification completenessVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring scanning policies for different network device types before actual verification. The scanning policy configuration is performed in advance and stored in a database, so when verification is needed, the pre-configured policies can be directly selected and applied without requiring manufacturer intervention each time, thus reducing verification time while maintaining completeness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating scanning policy templates for different network device types. Once a scanning policy is configured for a particular device type, it can be copied and reused for other devices of the same type, eliminating the need to reconfigure each device individually and significantly reducing the time required for verifying multiple devices

Inventive Principle:
Principle #26Copying

2Measurement precision

If custom scanning policies are created for each network device type, then verification accuracy improves, but the complexity of the verification system increases due to multiple preconfigured policies

Engineering Contradiction:
Improveconfiguration verification accuracyVSAvoidscanning policy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing scanning policies into distinct templates based on network device types (routers, switches, firewalls, etc.). Each device type has its own dedicated scanning policy template with specific verification items tailored to that device type. This segmentation allows for precise verification of each device while managing complexity through organized categorization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by creating a unified scanning policy management system that handles multiple device types through standardized templates. The system provides universal functions for policy creation, storage, selection, and execution that work across all network device types, reducing management complexity while maintaining verification accuracy through type-specific policy templates

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security manufacturers customize scanning schemes for each verification task, then verification thoroughness is ensured, but the cost and effort increase significantly

Engineering Contradiction:
Improveverification thoroughnessVSAvoidpolicy configuration effort
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling network administrators to independently select and apply pre-configured scanning policy templates without requiring security manufacturer intervention. The system provides self-service capabilities for policy selection, configuration application, and verification execution, eliminating the need for external manufacturer support while maintaining thorough verification through specialized templates

Inventive Principle:
Principle #25Self-service

4Reliability

If comprehensive security check items are included in scanning policies, then verification completeness improves, but the time required for each verification increases

Engineering Contradiction:
Improvesecurity check completenessVSAvoidverification throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by tailoring the scope and depth of security check items to match the specific requirements of each network device type. Each scanning policy template includes only the verification items relevant to that device type, avoiding unnecessary checks. This localized approach ensures comprehensive verification for each device while reducing overall verification time by eliminating redundant checks across different device types

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8978134B2Security configuration verification device and method and network system employing the same
Publication Date: 2015.03.10 NSFOCUS INFORMATION TECHNOLOGY CO LTD
  • US8978134B2 patent drawing
  • US8978134B2 patent drawing
  • US8978134B2 patent drawing

AI summary

The invention discloses a security configuration verification device for performing a security configuration verification on a network device, which comprises: one or more preconfigured scanning policies; a scanning policy generator, which selects a scanning policy from the one or more preconfigured scanning policies to generate a new scanning policy corresponding to the network device; and a scanner, which performs the security scanning on the network device with the generated new scanning policy and thereby performs the security configuration verification. The invention also discloses a corresponding security configuration verification method and a network system employing the verification device.