Automated Security Benchmark Compliance Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring a target computing platform for security benchmark compliance is challenging due to the complexity of managing numerous configuration parameters and ensuring they fall within specified acceptable ranges, as defined by security benchmarks like STIGs, requiring significant expertise and ongoing validation.
Innovation Solution
A method and system that filter configuration parameters from a source platform to a subset corresponding to a security checklist, presenting permissible value ranges in a user interface, allowing alternative values within those ranges to be applied to a target platform, with alerts for non-compliant parameters and user input for acceptance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If configuration parameters are manually configured for security benchmark compliance, then compliance accuracy is improved, but device complexity and time consumption increase significantly
Solution Approach 1:
The patent copies configuration parameters from a source platform that already meets security benchmark compliance to a target platform. The migration module retrieves configuration parameters from the source platform and applies them to the target platform, eliminating the need for manual configuration while maintaining compliance accuracy. This is evidenced by the automated retrieval and application of configuration parameters across platforms.
Solution Approach 2:
The system performs self-service by automatically identifying, retrieving, and applying configuration parameters without requiring manual intervention. The migration module autonomously filters parameters based on security benchmarks, validates compliance, and applies configurations, reducing both complexity and time consumption while maintaining reliability.
2Productivity
If all configuration parameters are migrated from source to target platform, then migration completeness is improved, but compliance validation difficulty increases
Solution Approach 1:
The migration module extracts only the necessary configuration parameters related to security benchmarks from the source platform, filtering out unnecessary parameters. This extraction process maintains migration completeness for compliance-critical parameters while reducing the overall parameter set, thereby improving productivity without increasing validation difficulty.
Solution Approach 2:
The system implements feedback mechanisms to validate compliance automatically. The migration module checks whether migrated configuration parameters meet security benchmark requirements and provides feedback on compliance status, making validation easier and more automated rather than manually difficult.
3Reliability
If security benchmark compliance is enforced strictly, then security reliability is improved, but ease of operation deteriorates due to rigid configuration requirements
Solution Approach 1:
The patent allows parameter changes by enabling modification of configuration parameters during migration. The system retrieves parameters from the source platform, allows validation and modification of these parameters, and applies the (possibly modified) parameters to the target platform. This maintains security reliability through benchmark compliance while improving ease of operation by allowing necessary adjustments.
Solution Approach 2:
The configuration migration process is made dynamic by allowing parameters to be modified after retrieval but before application. The system transitions from static rigid configuration to dynamic flexible configuration, where parameters can be adjusted based on target platform specificities while maintaining security compliance, thus improving ease of operation.
Data Source
AI summary
A method for migrating security benchmark compliance content from a source platform to a target platform includes filtering a set of configuration parameters in a source platform to a subset of configuration parameters, each of the parameters corresponding to a respectively different entry in a security checklist of a security benchmark. Then, a listing is presented in a user interface of each of the configuration parameters and for each configuration parameter, a corresponding entry in the security checklist regulating the configuration parameter according to a range of values. Finally, the configuration parameters in the subset are applied to a target platform excepting for at least one of the configuration parameters. Instead, alternative value within the range is received as input in the user interface and is applied to the target platform in lieu of the at least one of the configuration parameters.

