Security Policy Sandbox Analysis for Faster Root Cause Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT operations face significant challenges in identifying and remediating application connectivity issues in large network infrastructures, particularly for Software as a Service (SaaS) and private applications, due to the complexity and vastness of domains requiring thorough check and analysis, leading to increased mean time to detect and resolve issues.
Innovation Solution
An Application Access Analyzer (AAA) provides an interface for operators to detect and auto-remediate application reachability, connectivity, and access/permission issues, utilizing artificial intelligence and machine learning to analyze user authentication, network health, DNS servers, and security policies, and automatically discover network topology, reducing the mean time to resolve issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual troubleshooting methods are used in large network infrastructures, then domain knowledge expertise is required for thorough analysis, but the mean time to detect and resolve issues increases significantly
Solution Approach 1:
The system enables self-service troubleshooting by automatically discovering network topology, analyzing security policies, and identifying root causes without requiring human domain knowledge expertise. The automated analysis engine performs comprehensive checks across multiple domains (network connectivity, DNS resolution, authentication, security policies) and provides actionable remediation recommendations, allowing operators to resolve issues without specialized knowledge while maintaining thorough analysis.
Solution Approach 2:
The patent replaces manual mechanical troubleshooting processes with automated computational analysis. The system uses machine learning models and automated analysis engines to substitute human experts' cognitive processes, automatically gathering data, analyzing security policies, discovering network topology, and identifying root causes, thereby eliminating the time constraint while preserving analysis thoroughness.
2Measurement precision
If comprehensive security policy analysis is performed across all network domains, then accurate root cause identification is achieved, but the complexity of the analysis process increases
Solution Approach 1:
The system segments the complex analysis process into distinct modular components: network connectivity analysis, DNS resolution analysis, authentication analysis, security policy analysis, and topological correlation analysis. Each module handles a specific domain independently, analyzing relevant data and security policies within that domain, then integrating results to identify root causes. This segmentation reduces overall complexity while maintaining comprehensive analysis accuracy.
Solution Approach 2:
The patent introduces an automated analysis engine as an intermediary between raw network data and human operators. This intermediary component performs the complex security policy analysis, topological correlation, and root cause identification tasks, translating complex multi-domain data into simplified actionable insights. The intermediary absorbs the analytical complexity, presenting only essential findings to operators without requiring them to understand the underlying complex processes.
3Productivity
If automated analysis tools are implemented to reduce troubleshooting time, then mean time to resolve issues decreases, but the system requires sophisticated AI and machine learning capabilities
Solution Approach 1:
The automated analysis engine is designed as a universal multi-functional system that performs multiple troubleshooting functions: network connectivity testing, DNS resolution analysis, authentication verification, security policy evaluation, and topological correlation. By consolidating these diverse functions into a single unified platform with integrated machine learning models, the system achieves high productivity without requiring separate complex AI systems for each function, reducing overall system complexity while maintaining fast resolution capabilities.
Data Source
AI summary
Security policy analysis is disclosed. Configuration information, including at least one policy, associated with a live production security appliance, is received. The received configuration information is used to instantiate the policy in a sandbox environment. The sandbox environment is used to evaluate a proposed change to the configuration information, including by building a model using the received configuration information.


