SDN Compliance Component for Security Posture Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing compliance with varying security requirements in Software Defined Networking (SDN) environments is challenging due to conflicting security standards across different platforms and modules, which can lead to security compromises if not properly managed.

Innovation Solution

A centralized compliance component that monitors and manages security posture across the SDN environment, detecting potential compliance issues, notifying administrators, and preventing changes that may compromise security, while recommending adjustments to meet multiple security standards such as FEDRAMP, GDPR, and PCI requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized compliance component is implemented to monitor and manage security posture across the SDN environment, then security compliance and detection capability are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A centralized compliance component is introduced as an intermediary between the management plane and control plane in the SDN environment. This component receives security requirements from the management plane, monitors compliance status across the network, and communicates with control plane elements to enforce security policies. The intermediary handles the complexity of coordinating multiple security standards and platforms, thereby improving overall security compliance without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple security standards are enforced across different platforms and modules, then security coverage is improved, but conflict and management difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanagement difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized compliance component is designed with multi-functionality to handle multiple security standards simultaneously. It can receive, interpret, and enforce different security requirements from various platforms and modules within a unified framework. This universal approach allows the system to maintain comprehensive security coverage across FEDRAMP, GDPR, PCI, and other standards while managing them through a single coordinated mechanism rather than separate independent systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The compliance component dynamically adjusts security parameters and policies based on the specific requirements of different platforms and modules. It can modify security configurations, encryption requirements, and compliance thresholds according to the particular needs of each service or platform while maintaining overall security integrity. This parameter flexibility allows multiple security standards to coexist without direct conflict.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If real-time monitoring of security posture is implemented, then detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The compliance component implements continuous monitoring of security posture across the SDN environment by maintaining persistent connections with network elements and continuously receiving status updates. Rather than periodic sampling, the system maintains an ongoing view of compliance status, enabling real-time detection of security issues. This continuous action ensures comprehensive detection capability while the centralized architecture optimizes processing efficiency.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

Network elements and services are equipped with self-reporting capabilities that automatically provide compliance status information to the centralized component. This self-service approach reduces the processing burden on the monitoring system, as data is collected passively from sources that already maintain their own security state information, rather than requiring active querying and analysis of all system components.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11489721B2Dynamic compliance management
Publication Date: 2022.11.01 VMWARE INC
  • US11489721B2 patent drawing
  • US11489721B2 patent drawing
  • US11489721B2 patent drawing

AI summary

The disclosure provides an approach for compliance management in a network. Embodiments include receiving, by a manager, a system health plugin. Embodiments include determining a configuration change for a network. Embodiments include receiving data indicating a current security posture of the network. Embodiments include determining an impact to the security posture of the network based on the configuration change. Embodiments include generating a notification relating to the impact to the security posture of the network. Embodiments include receiving a decision relating to the configuration change in response to the notification. Embodiments include performing an action based on the decision.