Network Security Rule Recommendation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security rules become less effective over time due to changes in the network ecosystem, such as new devices, applications, or user behaviors, requiring manual updates that are time-consuming and inefficient.

Innovation Solution

A system and method that continuously monitors network data to identify changes, generates updated security rules with improved effectiveness, and recommends their implementation to administrators, using a value graph to detect changes and evaluate the effectiveness of new rules compared to existing ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual updating of security rules is performed, then security rules can be updated to reflect network changes, but time consumption and administrative effort increase significantly

Engineering Contradiction:
Improveeffectiveness of security rulesVSAvoidtime for manual rule updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically monitors network changes, generates updated security rules, and recommends them to administrators without requiring manual intervention. The system serves itself by detecting ecosystem changes and autonomously proposing rule updates, reducing administrative burden while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic and ecosystem changes, compares them against existing security rules, and generates feedback in the form of recommended rule updates. This closed-loop feedback mechanism ensures rules remain effective by automatically adapting to network evolution.

Inventive Principle:
Principle #23Feedback

2Reliability

If security rules are updated frequently to match network changes, then security effectiveness is maintained, but system complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomplexity of rule management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs multiple functions within a single unified platform: monitoring network changes, analyzing traffic patterns, generating security rules, evaluating their effectiveness, and recommending updates. This multi-functional approach maintains security effectiveness without requiring separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system acts as an intermediary between network ecosystem changes and security rule updates. It translates complex network variations into standardized rule recommendations, simplifying the management process while maintaining security effectiveness through automated mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If existing security rules are used without updates, then operational simplicity is maintained, but security effectiveness deteriorates over time

Engineering Contradiction:
Improvesimplicity of rule managementVSAvoideffectiveness of security rules
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system proactively monitors network changes and generates rule update recommendations before security gaps can be exploited. By performing preliminary analysis and preparation of updated rules, it maintains both operational simplicity and security effectiveness, eliminating the need for reactive manual updates.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240106867A1Recommending network security rule updates based on changes in the network data
Publication Date: 2024.03.28 CITRIX SYSTEMS INC
  • US20240106867A1 patent drawing
  • US20240106867A1 patent drawing
  • US20240106867A1 patent drawing

AI summary

The present solution provides systems and methods for recommending updated network security rules based on changes in the network data. The present solution can use a rule identifying an entity, an attribute of the entity and a value of the attribute. The solution can detect, responsive to monitoring the network environment, a change in one of the entity, the attribute or the value. The solution can generate, responsive to the detection, an updated rule. The solution can apply the updated rule to previous network traffic to which the rules was applied. In response to determining that effectiveness of the updated rule is greater than that of the prior rule, the solution can provide a recommendation to use the updated rule.