Security Control Point In-Place Validation via Simulated Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for validating security control points within communication networks are inadequate, as they lack granular testing capabilities and can burden the target system, potentially exposing it to threats due to insufficient visibility and intelligence regarding protection mechanisms.

Innovation Solution

Implementing an in-place testing method where a security control point processes simulated communication flows, using a test initiator system to generate and transmit encapsulated flows, which are then processed through the security control point's protection mechanisms without being delivered to the actual target system, allowing for remote, automatic, and programmatic determination of behavior and protection levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If generic live testing is used to validate security control points, then some level of protection validation is achieved, but the testing lacks granular detail and cannot test all source/destination variations

Engineering Contradiction:
Improvetesting granularityVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The testing system is segmented into multiple specialized components: a test initiation system for generating test flows, a security control point for processing flows, and a result analysis system for evaluating outcomes. This segmentation enables granular testing of specific protection mechanisms while maintaining manageable system complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A test initiation system acts as an intermediary between the testing framework and the security control point. This intermediary generates and transmits encapsulated test flows, enabling detailed granular testing without requiring direct complex interactions between all testing components and the security control point, thus managing complexity while achieving precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If endpoint agents are deployed to coordinate with network level approaches, then visibility of protection mechanisms is improved, but the target system experiences increased burden that may affect its service provision

Engineering Contradiction:
Improvevisibility of protection mechanismsVSAvoidtarget system burden
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The testing burden is extracted from the target system by conducting all security control point validation tests remotely through the test initiation system. The target system remains passive and does not need to run additional agents or processes, thereby maintaining full visibility of protection mechanisms through remote testing while imposing minimal burden on the target system's operational capacity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security control point performs self-validation by processing encapsulated test flows and generating its own protection behavior outputs. This self-service approach enables comprehensive visibility into protection mechanisms without requiring external agents on the target system, as the SCP itself demonstrates its protection capabilities through controlled test flow processing.

Inventive Principle:
Principle #25Self-service

3Reliability

If simulated communication flows are processed through the security control point without delivery to the target system, then the target system is protected from testing burden, but the testing must be conducted remotely with encapsulated flows

Engineering Contradiction:
Improvetarget system protectionVSAvoidflow encapsulation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Test communication flows are nested within encapsulated packets that include both the test data and control information. This nesting structure allows the test flows to be transmitted through the security control point in a standardized format that protects the target system while enabling comprehensive testing. The encapsulation complexity is managed through structured packet formats that integrate test functionality within standard network protocol frameworks.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11757915B2Exercising security control point (SCP) capabilities on live systems based on internal validation processing
Publication Date: 2023.09.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11757915B2 patent drawing
  • US11757915B2 patent drawing
  • US11757915B2 patent drawing

AI summary

A security control point (SCP) that protects target computing system is tested in-place and while active. The approach is initiated the SCP receiving and processing one or more “simulated” communication flows. To this end, a test initiator system is configured to generate and transmit communication flows to the SCP being tested. The SCP extracts the encapsulated flow, and then processes that flow through one or more of the SCP's configured protection mechanisms. Thus, the SCP processes the simulated communication flow as though it were a real session, and thus to determine what actions, if any, should be taken with respect to that flow. After processing, the simulated session traffic is shunted or otherwise diverted away from the target computing system. The results of the SCP's processing, however, are output to other systems (e.g., logging or alerting mechanisms), or they are returned to the test initiation system, e.g., for correlation, reporting, and the like.