Sandbox Security Policy Analysis for Faster Access Troubleshooting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT operations face significant challenges in identifying and remediating application connectivity issues in large network infrastructures, requiring extensive manual troubleshooting and domain knowledge, leading to increased mean time to detect and resolve problems.
Innovation Solution
An Application Access Analyzer (AAA) is introduced, providing an automated solution that uses AI and ML to analyze network connectivity, security policies, and user authentication, offering actionable verdicts and root cause analysis to quickly identify and remediate application access issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual troubleshooting is used to identify and remediate application connectivity issues, then domain knowledge and expertise can be applied, but the mean time to detect and resolve problems increases significantly
Solution Approach 1:
The system enables self-service automated troubleshooting by having the platform itself perform root cause analysis and remediation actions without requiring manual intervention from domain experts. The automated policy analysis engine independently identifies connectivity issues, determines root causes, and executes remediation policies.
Solution Approach 2:
The patent replaces manual mechanical troubleshooting processes with an automated electronic system that uses AI/ML algorithms to analyze network data, identify connectivity issues, and execute remediation actions. The mechanical process of manual inspection and decision-making is substituted with automated computational analysis.
2Productivity
If automated analysis is implemented to reduce manual troubleshooting, then mean time to resolve issues decreases, but system complexity increases
Solution Approach 1:
The system segments the complex automated analysis into distinct functional modules: data collection module, policy analysis module, root cause determination module, and remediation execution module. This segmentation allows each component to handle specific tasks independently, making the overall complex system more manageable and maintainable.
Solution Approach 2:
The patent introduces an automated policy analysis engine as an intermediary between raw network data and remediation actions. This intermediary layer processes and analyzes collected data, determines root causes, and formulates appropriate remediation policies, simplifying the interaction between different system components.
3Loss of energy
If comprehensive automated analysis is provided, then operational costs are reduced, but the system requires significant computational resources and infrastructure
Solution Approach 1:
The system applies partial action by analyzing only the specific subset of network data and policies relevant to the current connectivity issue being investigated, rather than processing all available data comprehensively. This targeted approach reduces unnecessary computational resource consumption while still achieving effective root cause analysis.
Solution Approach 2:
The patent utilizes parameter changes through AI/ML algorithms that dynamically adjust analysis depth and computational intensity based on the complexity and urgency of the detected issue. The system can modify processing parameters such as data collection scope, analysis granularity, and remediation thoroughness to optimize the balance between operational cost reduction and computational resource consumption.
Data Source
AI summary
Security policy analysis is disclosed. Configuration information, including at least one policy, associated with a live production security appliance, is received. The received configuration information is used to instantiate the policy in a sandbox environment. The sandbox environment is used to evaluate a proposed change to the configuration information, including by building a model using the received configuration information.


