Automated Security Compliance Scripting via Native OS Capabilities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for determining compliance with software security guideline sets (SSGS) are inefficient and prone to inaccuracies due to reliance on manual evaluations and complex third-party software, which fail to keep pace with evolving cybersecurity threats, requiring a more rapid and automated approach to assess security status.

Innovation Solution

The method utilizes the native operating system's command line interface to create a Security Check Script (SCS) that automates the evaluation of a computer system's compliance with SSGS, reducing the need for additional software and leveraging existing embedded software functionality to simplify the evaluation process and provide a rapid, accurate assessment of security status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual evaluation methods are used to determine SSGS compliance, then evaluation accuracy can be maintained through human judgment, but evaluation time and complexity increase significantly

Engineering Contradiction:
Improvecompliance evaluation accuracyVSAvoidevaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables the computer system to self-evaluate its own compliance status with SSGS by executing scripts within its native operating environment, eliminating the need for external evaluators while maintaining accurate compliance determination through automated checks of system configurations, security settings, and policy adherence

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual human evaluation processes are replaced with automated script-based systems that execute within the native operating system, substituting mechanical human judgment with algorithmic compliance checking that achieves both speed and accuracy through systematic automated assessment

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If complex third-party software is deployed to automate compliance evaluation, then evaluation speed increases, but system complexity and cost increase

Engineering Contradiction:
Improveevaluation speedVSAvoidsoftware complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The native operating system's existing command-line interface and scripting capabilities are leveraged to perform multiple functions including compliance evaluation, data collection, and reporting, eliminating the need for specialized third-party software while achieving rapid automated assessment through the system's built-in tools

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The compliance evaluation functionality is extracted from complex external software systems and implemented directly within the native operating system using its existing scripting capabilities, removing the dependency on third-party tools and reducing overall system complexity while maintaining evaluation speed

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If extensive code is used to perform automated compliance checks, then evaluation accuracy improves, but maintenance and update costs increase

Engineering Contradiction:
Improvecompliance assessment accuracyVSAvoidmaintenance cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The system uses the computer's native operating system and its built-in scripting environment to perform compliance self-assessment, eliminating the need for extensive external code while maintaining accurate evaluation through the system's inherent capabilities and reducing maintenance burden by leveraging already-supported native tools

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10360408B1Method and system for computer self-determination of security protocol compliance
Publication Date: 2019.07.23 SECURESTRUX LLC
  • US10360408B1 patent drawing
  • US10360408B1 patent drawing
  • US10360408B1 patent drawing

AI summary

A method and system for automating the evaluation of a computer system under a Software Security Guideline Set (SSGS) using the internal scripts and the script generating capability of the computer system under evaluation to perform much of the evaluation of the SSGS. The method and systems arranged in accordance therewith generate a security check script that adds automation to the otherwise laborious process of checking for compliance with an SSGS. By using the systems own software and script generating capabilities the computer system under review is in one sense using its own capability to check itself for compliance with an SSGS. The use of the software and data from the operating system of the computer system under review greatly simplifies the complexity of the programming necessary for such automation of SSGS compliance check, dramatically reducing the lines of code to perform such compliance evaluations. The information provided by this invention enables the owners of such systems to put them in a better state of operation.