Secure Configuration Evaluation Tool for Automated STIG Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated systems for compliance evaluation and remediation, such as the 'Gold Disk' tool, often result in devices becoming inoperable due to harmful or incompatible updates, and are limited to legacy systems like Windows XP, making them unsuitable for modern enterprise environments. There is a need for a more platform-neutral, automated solution that can efficiently apply Security Technical Implementation Guides (STIGs) across various operating systems and applications.

Innovation Solution

The development of a Secure Configuration Evaluation, Remediation, and Reporting Tool (SCERRT) that provides a modular system with user interfaces for selecting and applying software updates and patches, ensuring compatibility and granular control over configuration management, security, and operational factors, capable of supporting multiple operating systems like Windows and Linux, and applications like McAfee and Adobe Flash.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated tools like Gold Disk are used to apply security updates, then remediation speed is improved, but system reliability deteriorates due to harmful or incompatible updates rendering devices inoperable

Engineering Contradiction:
Improveremediation speedVSAvoidsystem operability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the automated remediation process into multiple phases: evaluation phase (assessing impact before applying updates), user interface phase (providing selective control), and remediation phase (applying updates). This segmentation allows the system to maintain speed while adding layers of control and verification to prevent harmful effects.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback mechanisms where the system evaluates the impact of proposed updates before applying them, and provides user feedback interfaces allowing operators to review and select which updates to apply. This feedback loop prevents盲目 application of potentially harmful updates while maintaining automated efficiency.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If legacy systems like Windows XP are supported by automated tools, then compatibility is improved, but adaptability deteriorates as these systems are no longer supported or even usable

Engineering Contradiction:
Improveplatform compatibilityVSAvoidsystem support status
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal remediation platform that can evaluate and apply security updates across multiple operating systems including Windows, Linux, and other platforms. The system uses platform-neutral evaluation criteria and generates appropriate remediation actions for each platform, making it adaptable to diverse environments without being tied to legacy systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual remediation of STIGs is performed, then system reliability is maintained through careful control, but productivity deteriorates as it takes weeks to complete

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidremediation time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary evaluation and classification of security updates before actual remediation. The system assesses the impact of each update, identifies safe remediation paths, and prepares execution plans in advance. This preliminary action allows the system to execute remediation rapidly while maintaining the reliability and accuracy of manual processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the system to automatically evaluate, plan, and execute remediation actions without requiring manual intervention for each step. The automated evaluation of update impacts and self-directed application of safe updates dramatically reduces remediation time from weeks to hours while maintaining configuration accuracy through systematic evaluation.

Inventive Principle:
Principle #25Self-service

4Productivity

If automated remediation tools are used without user input, then productivity is improved, but device complexity increases due to harmful or incompatible updates

Engineering Contradiction:
Improveremediation automation levelVSAvoidsystem configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic user interface that adapts to the evaluation results and presents relevant selection options based on the specific system state and proposed updates. The interface dynamically adjusts the level of user involvement required, providing granular control where needed while maintaining automation where safe, thus balancing productivity with manageable complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10462186B2Secure configuration evaluation, remediation, and reporting tool (SCERRT)
Publication Date: 2019.10.29 THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY
  • US10462186B2 patent drawing
  • US10462186B2 patent drawing
  • US10462186B2 patent drawing

AI summary

Various embodiments and related methods are provided that can include or operate a variety of modular systems such as a group of user interfaces and software modules which receive inputs from the user interfaces to perform Secure Configuration Evaluation, Remediation, and Reporting Tool tasks. Exemplary modules can include a scan or current state module to populate and/or identify a current state configuration as well as collecting available information on available vulnerability patches or system updates, a software, update, and/or patch configuration selection module that generates a “picklist” user interface for all available software, patches or updates or optionally patches or updates that meet one or more search criteria associated with a baseline data, a data store with install files for all selected or available software, patches or updates selected with the picklist user interface, an installer export package system to generate install packages, and an access/use verification system.