Probing Logic for Access Control Policy Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion Detection Systems (IDS) face challenges in effectively monitoring and validating the integrity of access control policies in software targets, as existing methods require complex understanding of applications and intrusion vectors, making it difficult to detect policy compromises and privilege escalations.

Innovation Solution

The implementation of a probing logic that actively tests access control policies by executing forbidden operations and creating predetermined observable side effects, allowing for continuous monitoring and detection of intrusions without requiring deep knowledge of the software target's behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing IDS methods are used to monitor access control policies, then detection capability is provided, but the system complexity and difficulty of understanding application behavior increase significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a probing logic as an intermediary component that mediates between the IDS and the software target. This probing logic executes predefined operations and generates observable side effects, serving as a bridge that simplifies the monitoring process while maintaining reliable detection capability without requiring deep understanding of the target application's internal behavior

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified model or copy of the access control policy enforcement through the probing logic. Instead of directly analyzing complex application behavior, the system uses a predetermined set of probing operations that replicate potential intrusion scenarios, making detection simpler while maintaining reliability

Inventive Principle:
Principle #26Copying

2Reliability

If existing IDS methods are used to detect policy compromises, then intrusion detection is provided, but the requirement for deep knowledge of intrusion vectors increases complexity

Engineering Contradiction:
Improveintrusion detectionVSAvoidease of deployment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-defining a set of probing operations that represent potential intrusion vectors before deployment. These probing operations are prepared in advance and stored in the probing logic, eliminating the need for operators to have deep knowledge of intrusion vectors during deployment while maintaining reliable intrusion detection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The probing logic performs self-service by automatically executing predefined operations and generating observable side effects without requiring external expertise. The system self-manages the detection process using predetermined knowledge of potential intrusion vectors, making deployment easier while maintaining detection reliability

Inventive Principle:
Principle #25Self-service

3Productivity

If active probing is implemented to test access control policies, then detection efficiency is improved, but the need for predetermined side effects increases system design complexity

Engineering Contradiction:
Improvedetection efficiencyVSAvoidprobing logic design
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the detection process into distinct components: predefined probing operations, execution engine, and observable side effect monitoring. This segmentation allows each component to be independently designed and optimized, improving detection efficiency while managing design complexity through modular architecture where the probing logic contains predetermined side effects as discrete elements

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11449618B2Active testing of access control policy
Publication Date: 2022.09.20 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11449618B2 patent drawing
  • US11449618B2 patent drawing
  • US11449618B2 patent drawing

AI summary

A method is provided, comprising actively testing the access control policy of a software target using a probing logic. The method further comprises determining whether an intrusion in the software target has occurred based on monitored side effects. According to the method, the probing logic is to execute at least one operation that is forbidden by the access control policy. The probing logic is further to create at least one predetermined observable side effect based on the successful execution of the operation.