Security Configuration Evaluation System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional software security systems have obscure and opaque configuration settings, making it difficult for end users and administrators to understand and modify them, leading to reluctance in altering configurations due to uncertainty about the impact on system behavior.

Innovation Solution

A computer-implemented method that identifies a live security configuration, establishes a test configuration with differing settings, records results of protective actions under both configurations, and generates an alternate result by performing protective actions using the test configuration without applying changes to the system, allowing for comparison and informed decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators alter configuration settings of a software security system, then the system behavior can be optimized, but the uncertainty about impact on system behavior prevents administrators from making alterations

Engineering Contradiction:
Improveconfiguration optimizationVSAvoidsystem behavior predictability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary evaluation of configuration changes by simulating their impact before actual deployment. A configuration evaluator assesses potential modifications to security software configurations by analyzing simulated system behaviors under proposed configurations, allowing administrators to understand impacts before committing changes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to administrators about the potential impact of configuration changes. The configuration evaluator generates reports showing how proposed configuration alterations would affect system behavior, enabling informed decision-making while maintaining reliability through predictable, assessed changes.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If configuration settings are made more accessible and understandable, then ease of operation improves, but the complexity of explaining multiple interacting settings increases

Engineering Contradiction:
Improveconfiguration understandabilityVSAvoidconfiguration explanation complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The configuration evaluator acts as an intermediary between complex security software configurations and administrators. It translates complex configuration parameters and their interactions into understandable impact assessments, showing administrators how specific settings affect system behavior without requiring them to understand all underlying complexities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the representation of configuration parameters from raw technical settings to meaningful impact descriptions. Instead of presenting administrators with numerous technical parameters, the configuration evaluator transforms these into understandable assessments of system behavior changes, making configuration management easier while managing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10318742B1Systems and methods for evaluating security software configurations
Publication Date: 2019.06.11 GEN DIGITAL INC
  • US10318742B1 patent drawing
  • US10318742B1 patent drawing
  • US10318742B1 patent drawing

AI summary

The disclosed computer-implemented method for evaluating security software configurations may include (1) identifying, within a software security system, a live configuration that includes active configuration settings applied by the software security system when protecting a computing system, (2) establishing a test configuration that includes at least one configuration setting that is different from the live configuration, (3) recording a live result of the software security system performing a protective action using the live configuration, (4) generating an alternate result of the protective action by performing the protective action using the test configuration instead of the live configuration and without applying changes resulting from the protective action to the computing system, and (5) performing a security action based on the live result of the protective action and the alternate result of the protective action. Various other methods, systems, and computer-readable media are also disclosed.