Policy-Based Network Security Threat Response Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems often rely on external sources for threat response strategies, which may not align with a company's policies, potentially leading to inappropriate or prohibited actions.
Innovation Solution
A system and method that detect network threats, select appropriate response actions from a set of available actions, and filter them based on a company's policies to ensure compliance, allowing only permitted actions to be executed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a company uses external security vendors or researchers for threat response strategies, then up-to-date threat mitigation information is obtained, but the response actions may violate company policies or be inappropriate for the specific organization
Solution Approach 1:
The patent introduces a policy filtering mechanism as an intermediary component between the threat response selection module and the execution module. This filter receives threat response actions from external sources, evaluates them against company-specific policies, and selectively allows or blocks actions based on policy compliance. This resolves the contradiction by enabling the system to access external threat intelligence while ensuring only policy-compliant actions are executed.
Solution Approach 2:
The system dynamically adjusts the set of executable response actions by filtering parameters (actions) based on policy conditions. When a threat response action is evaluated against company policies, the system modifies the actionable parameter set to include only compliant responses. This allows the system to maintain access to comprehensive external threat intelligence while adapting the executable actions to match organizational policy requirements.
2Object-affected harmful factors
If aggressive counterattacking responses are implemented, then threat neutralization is enhanced, but company policies may be violated
Solution Approach 1:
The policy filter serves as a mediator that receives aggressive counterattacking responses from the threat response library and evaluates them against company policies. If a counterattack action violates policy (e.g., retaliatory measures prohibited by corporate governance), the filter blocks that action while allowing compliant alternatives. This enables the system to maintain strong threat neutralization capability while ensuring policy adherence through the intermediary filtering layer.
Solution Approach 2:
The system extracts and removes prohibited actions from the set of available threat responses. By identifying and extracting actions that violate company policies (such as unauthorized counterattacks), the system creates a filtered subset of permissible responses. This maintains the effectiveness of threat neutralization through allowed actions while eliminating policy-violating options from execution.
Data Source
AI summary
A method includes, responsive to detecting network activity indicative of a threat, selecting a threat mitigation scheme corresponding to a set of response actions. The method also include filtering the set of response actions based on a policy to generate a set of allowed response actions and executing one or more response actions of the set of allowed response actions.


