Preconfigured Security Policy for New Computer Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Newly purchased computers often arrive with outdated security software, making them vulnerable to infections before users can update them, as manufacturers update hard disk images infrequently, leading to increased support costs and product returns.

Innovation Solution

Implementing a preconfigured security update policy that restricts new computers to only connect with preapproved hosts, blocking unauthorized connections and allowing updates only from trusted sites, ensuring the system is brought up to date before general Internet connectivity is allowed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manufacturers preconfigure security software on new computers, then security protection is provided, but the security software becomes outdated quickly due to infrequent updates

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime for updates to become outdated
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring a restricted connectivity policy on the computer before deployment. This policy proactively limits the computer's ability to connect to unauthorized hosts, preventing infections before they can occur. The restricted policy acts as a preliminary protective measure that remains in effect until security updates are applied.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If new computers are allowed to connect to the Internet immediately, then users can update security software, but the computers become vulnerable to infections during the update period

Engineering Contradiction:
Improveability to update softwareVSAvoidvulnerability to infections
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by creating a specialized, restricted connectivity environment for update purposes. Instead of allowing general Internet access, the system permits connections only to specifically approved update hosts. This localized, targeted approach to connectivity enables necessary software updates while isolating the system from general Internet threats.

Inventive Principle:
Principle #3Local quality

3Reliability

If a restricted connectivity policy is applied to new computers, then infection risk is reduced, but the complexity of managing update connections increases

Engineering Contradiction:
Improveinfection preventionVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling the computer to automatically connect to pre-approved update hosts without requiring user intervention or complex manual configuration. The restricted policy is pre-configured with necessary update host information, allowing the system to service its own update needs autonomously while maintaining security restrictions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7540013B2System and methodology for protecting new computers by applying a preconfigured security update policy
Publication Date: 2009.05.26 CHECK POINT SOFTWARE TECH INC
  • US7540013B2 patent drawing
  • US7540013B2 patent drawing
  • US7540013B2 patent drawing

AI summary

A system and methodology for protecting new computers by applying a preconfigured security update policy is described. In one embodiment, for example, a method is described for controlling connections to a computer upon its initial deployment, the method comprises steps of: upon initial deployment of the computer, applying a preconfigured security policy that establishes a restricted zone of preapproved hosts that the computer may connect to upon its initial deployment; receiving a request for a connection from the computer to a particular host; based on the preconfigured security policy, determining whether the particular host is within the restricted zone of preapproved hosts; and blocking the connection if the particular host is not within the restricted zone of preapproved hosts.