Policy Analysis Tool for Distributed Network Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networked systems face challenges in ensuring compliance with global security policies due to complex interactions among distributed access control mechanisms, leading to subtle errors and security vulnerabilities, as misconfigurations in firewalls and other access control elements can mask problems and result in noncompliance.

Innovation Solution

The Access Policy Tool (APT) analyzes security policy implementations for conformance with global security specifications by integrating policy rules from various sources, providing a graphical front-end for usability and performing both offline and online analysis, including dynamic detection of policy implementation holes, using a multi-layered rule graph and statistical techniques for efficient compliance checking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed access control mechanisms are deployed throughout the network system, then security coverage and control granularity are improved, but system complexity and difficulty of compliance verification worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the distributed access control system into multiple layers (network layer, host layer, application layer) and represents each layer's policy rules as separate nodes in a rule graph. This segmentation allows comprehensive security coverage while managing complexity by organizing policies in a structured, hierarchical manner that can be systematically analyzed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy analysis tool as an intermediary that automatically collects, integrates, and analyzes policy rules from distributed access control mechanisms. This intermediary system verifies compliance with global security policies without requiring manual inspection of each distributed component, thus maintaining security coverage while reducing the operational complexity burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple layered access control mechanisms are implemented, then access control precision and security enforcement are improved, but difficulty of diagnosing misconfigurations worsens

Engineering Contradiction:
Improveaccess control precisionVSAvoiddiagnosis difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the policy analysis tool automatically analyzes the multi-layered rule graph, detects policy violations and misconfigurations, and provides diagnostic information about root causes. This feedback loop enables precise access control enforcement while making misconfiguration diagnosis tractable through automated analysis and reporting of specific violation paths.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms the multi-layered access control problem into a graphical dimension by representing policy rules as nodes and relationships as edges in a rule graph. This dimensional transformation allows precise access control across multiple layers while enabling visualization and systematic analysis of policy interactions, making misconfiguration diagnosis significantly easier through graph traversal and path analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If comprehensive policy analysis is performed across distributed systems, then compliance detection accuracy is improved, but computational resources and analysis time worsen

Engineering Contradiction:
Improvecompliance detection accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by collecting and integrating policy rules from distributed access control mechanisms before conducting compliance analysis. The system pre-processes policy data, builds the multi-layered rule graph structure, and organizes policy information in advance, which enables accurate compliance detection while reducing computational resources required during the actual analysis phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic analysis capabilities that can adapt the depth and scope of policy analysis based on system state and compliance requirements. The policy analysis tool can dynamically adjust its analysis intensity, focusing computational resources on critical policy violations and high-risk areas while maintaining comprehensive coverage, thus achieving high detection accuracy with optimized resource utilization.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8209738B2Analysis of distributed policy rule-sets for compliance with global policy
Publication Date: 2012.06.26 THE BOARD OF TRUSTEES OF THE UNIV OF ILLINOIS
  • US8209738B2 patent drawing
  • US8209738B2 patent drawing
  • US8209738B2 patent drawing

AI summary

A method for analysis of distributed device rule-sets for compliance with global policies includes enabling an administrator to specify a network topology with intercommunicating elements and parameters required to secure the intercommunication with access control elements of the network topology; establishing connections to the access controls elements to capture a snapshot configuration of device rule-sets of the access control elements; enabling the administrator to specify a set of global access constraints with reference to the access control elements; enabling the administrator to select between exhaustive analysis and statistical analysis; conducting the selected analysis to determine violations by the device rule-sets that fail to comply with the set of global access constraints, wherein statistical analysis quantitatively characterizes a level of compliance without conducting analysis of all potential network paths; and providing results of the selected analysis to the administrator through a graphical user interface (GUI) as the results are obtained.