Policy-Based Remediation for Automated Security Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current remediation methods for computer infrastructures are inadequate in automatically determining and implementing necessary security measures to address unauthorized activities and vulnerabilities, as they rely on manual policies and sampling of parameters, which are not comprehensive enough to ensure continuous security and reliability.
Innovation Solution
A method and system for automatically determining and selecting remediations for a device by receiving parameter values, assessing them against defined policies, and implementing appropriate actions to address potential unauthorized activities or manipulations, utilizing a policy-based approach with a server and lightweight sensors to gather and analyze data and deploy remediations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual policies and parameter sampling are used for remediation, then device complexity is reduced, but reliability and security monitoring effectiveness deteriorate
Solution Approach 1:
The system enables automated self-service remediation by having the monitoring system automatically determine and implement remediation actions based on policy evaluations, without requiring manual human intervention for each security incident. The system serves itself by autonomously completing the full remediation workflow from detection to action implementation.
Solution Approach 2:
The system performs preliminary actions by pre-defining multiple remediation options and their associated policies before security incidents occur. When a parameter violation is detected, the system can immediately execute pre-determined remediation actions, eliminating the need for real-time human decision-making and ensuring consistent security responses.
2Productivity
If automated parameter sampling and policy assessment are implemented, then productivity of security response is improved, but device complexity increases
Solution Approach 1:
The system replaces manual mechanical processes of security assessment and remediation decision-making with automated computational processes. The automated determination of remediation based on parameter sampling and policy evaluation substitutes human analysts and manual procedures, dramatically increasing security response productivity while managing complexity through systematic automation.
3Measurement precision
If comprehensive parameter monitoring is implemented, then measurement precision of security state is improved, but use of energy and computational resources increases
Solution Approach 1:
The system applies partial monitoring by selectively sampling specific parameters based on their relevance to security policies, rather than continuously monitoring all possible device parameters. This approach achieves sufficient measurement precision for security assessment while reducing computational resource consumption by focusing only on the most critical parameters needed for policy evaluation.
Data Source
AI summary
A method, of automatically determining one or more remediations for a device that includes a processor, may include: receiving values of a plurality of parameters which collectively characterize an operational state of the device, there being at least one policy associated with at least a given one of the plurality of parameters, policy defining as a condition thereof one or more potential values of, or based upon, the given parameter, satisfaction of the condition potentially being indicative of unauthorized activity or manipulation of the device; automatically determining, from the received parameter values, whether the conditions for any policies are satisfied, respectively; and automatically selecting one or more remediations for the device according to the satisfied policies, respectively.


