Policy Enforcement via Hidden Logging and False Responses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computing environments, ensuring the security and visibility control of policies is challenging, especially as the complexity of resource access grows, with users potentially exploiting access logs to avoid detection.
Innovation Solution
Implementing a system that allows users to author and manage policies with visibility restrictions, where certain policies are hidden from users who would otherwise detect their execution, using a policy management system that encrypts logs and provides false responses to requests, preventing users from knowing that certain actions are being taken.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators have great control over computing resources to ensure security, then security monitoring capability is improved, but users can detect and avoid detection through careful planning of their actions
Solution Approach 1:
The patent introduces an intermediary mechanism where policy enforcement is separated from visibility. The system uses an indirect detection method where users cannot directly observe policy enforcement actions, but the system still monitors and enforces policies through hidden logging and tracking mechanisms. This intermediary layer prevents users from detecting and avoiding policy enforcement while maintaining security monitoring capability.
Solution Approach 2:
The patent applies the concept of changing visibility states by making policy enforcement actions invisible to users. The system dynamically controls what users can see regarding policy enforcement - actions are taken but not displayed or logged in a visible manner to end users, effectively changing the visibility state from visible to hidden while maintaining the enforcement capability.
2Loss of information
If policies are made visible to users for transparency, then user awareness of security measures is improved, but users can plan actions to avoid detection
Solution Approach 1:
The patent inverts the traditional approach by making policy enforcement hidden rather than visible. Instead of displaying policy actions to users for transparency, the system secretly enforces policies without user knowledge. This inversion maintains user awareness that policies exist (through indirect means) while preventing them from detecting specific enforcement actions that could be avoided.
3Reliability
If comprehensive logging of user actions is implemented, then security monitoring is improved, but users with access to logs can avoid detection
Solution Approach 1:
The patent applies local quality by differentiating visibility for different user roles. Administrative users can access comprehensive logs for security monitoring, while regular users cannot see enforcement actions in the logs. This localized visibility control ensures that log secrecy is maintained for regular users while preserving security monitoring capability for administrators who need full visibility.
Data Source
AI summary
A request to access one or more computing resources is received by a system. The system performs one or more operations in response to the request according to one or more security polices, the one or more operations selected according to a substantially random selection process. A response to the request is caused based at least in part on the one or more operations.


