Policy-Based Remediation for Automated Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remediation methods for computer infrastructures are inadequate in automatically determining and implementing necessary security measures to address unauthorized activities and vulnerabilities, as they rely on manual policies and sampling of parameters, which are not comprehensive enough to ensure continuous security and reliability.

Innovation Solution

A method and system for automatically determining and selecting remediations for a device by receiving parameter values, assessing them against defined policies, and implementing appropriate actions to address potential unauthorized activities or manipulations, utilizing a policy-based approach with a server and lightweight sensors to gather and analyze data and deploy remediations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual policies and parameter sampling are used for remediation, then device complexity is reduced, but reliability and security monitoring effectiveness deteriorate

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidautomated remediation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service remediation by having the monitoring system automatically determine and implement remediation actions based on policy evaluations, without requiring manual human intervention for each security incident. The system serves itself by autonomously completing the full remediation workflow from detection to action implementation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining multiple remediation options and their associated policies before security incidents occur. When a parameter violation is detected, the system can immediately execute pre-determined remediation actions, eliminating the need for real-time human decision-making and ensuring consistent security responses.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated parameter sampling and policy assessment are implemented, then productivity of security response is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity response speedVSAvoidautomated determination system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system replaces manual mechanical processes of security assessment and remediation decision-making with automated computational processes. The automated determination of remediation based on parameter sampling and policy evaluation substitutes human analysts and manual procedures, dramatically increasing security response productivity while managing complexity through systematic automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive parameter monitoring is implemented, then measurement precision of security state is improved, but use of energy and computational resources increases

Engineering Contradiction:
Improveoperational state characterization accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by selectively sampling specific parameters based on their relevance to security policies, rather than continuously monitoring all possible device parameters. This approach achieves sufficient measurement precision for security assessment while reducing computational resource consumption by focusing only on the most critical parameters needed for policy evaluation.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7665119B2Policy-based selection of remediation
Publication Date: 2010.02.16 FORTINET INC
  • US7665119B2 patent drawing
  • US7665119B2 patent drawing
  • US7665119B2 patent drawing

AI summary

A method, of automatically determining one or more remediations for a device that includes a processor, may include: receiving values of a plurality of parameters which collectively characterize an operational state of the device, there being at least one policy associated with at least a given one of the plurality of parameters, policy defining as a condition thereof one or more potential values of, or based upon, the given parameter, satisfaction of the condition potentially being indicative of unauthorized activity or manipulation of the device; automatically determining, from the received parameter values, whether the conditions for any policies are satisfied, respectively; and automatically selecting one or more remediations for the device according to the satisfied policies, respectively.