Security Control Verification Subsystem for Database Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in efficiently verifying and continuously monitoring security control settings across multiple managed computers, particularly due to varying security requirements and frequent changes in computer group memberships and configurations, which are time-consuming and complex to manage.

Innovation Solution

A security control verification and monitoring subsystem that associates appropriate security benchmarks with computer groups, verifies compliance through clientless profiling, and continuously monitors settings by comparing them against defined benchmarks, using a tree-structured database management system to produce reports and update records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual computers are manually checked against security benchmarks, then compliance verification can be performed, but the process becomes time-consuming and complex, especially when computer group memberships and configurations change frequently

Engineering Contradiction:
Improvesecurity compliance verificationVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically performs security compliance verification without requiring manual intervention. The verification subsystem continuously monitors computer security settings, compares them against applicable benchmarks, and generates compliance reports automatically, eliminating the need for manual checking while maintaining reliable verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors security control settings and provides feedback by comparing current settings against security benchmarks. When changes occur, the system detects them and updates compliance status accordingly, enabling continuous verification without manual re-checking

Inventive Principle:
Principle #23Feedback

2Reliability

If security control settings are manually verified on each computer, then compliance can be assessed, but the complexity increases significantly when computers are re-assigned among different groups or when group security requirements change

Engineering Contradiction:
Improvesecurity control complianceVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification subsystem serves multiple functions: it automatically identifies applicable security benchmarks based on computer group membership, retrieves the appropriate benchmark criteria, performs compliance comparison, and generates reports. This multi-functional approach simplifies the verification process while maintaining reliable compliance assessment across dynamically changing computer groups

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces a central verification subsystem that acts as an intermediary between computers and security benchmarks. This subsystem manages the complexity by automatically determining which benchmarks apply to each computer based on its group assignment, eliminating the need for manual determination of applicable requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If continuous monitoring of security controls is implemented, then ongoing compliance can be ensured, but the system complexity and resource requirements increase

Engineering Contradiction:
Improvecontinuous compliance monitoringVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification subsystem operates continuously to monitor security control settings and compare them against applicable benchmarks. The system maintains persistent monitoring without interruption, ensuring ongoing compliance detection while using efficient comparison algorithms to minimize resource consumption

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8225409B2Security control verification and monitoring subsystem for use in a computer information database system
Publication Date: 2012.07.17 BELARC
  • US8225409B2 patent drawing
  • US8225409B2 patent drawing
  • US8225409B2 patent drawing

AI summary

A security control verification and monitoring subsystem of a managed computer system performs security control verification operations regularly and for each security control verification operation determines the applicable security benchmark level for use by a given computer. The subsystem assigns security risk categories to groups of computers based, for example, on overall system or group administrator supplied potential impact settings and/or system type and business or information type selections. The subsystem further associates the security risk categories with security benchmark levels based on mapping information supplied by the overall system or group administrator. The subsystem then directs the computer to benchmark definition files based on the assigned security risk category, the associated security benchmark level and attributes of the computer. The subsystem performs the security control verification operations whenever the computer performs computer profile data update operations, and thus, monitors essentially continuously the security control compliance of the computer. The subsystem stores the results of the security verification operations and includes the results in reports for the system, group or computer.