Security Maintenance Manager for Network Policy Drift

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing environments face increased security risks due to manual maintenance workloads for network access policies, as changes in network segments often result in unsecured configurations, leaving them vulnerable to malicious users, and conventional access management systems lack efficient mechanisms for automated security and policy enforcement.

Innovation Solution

A security maintenance manager detects unsecure network policies by comparing active and expected configurations, automatically modifying the active configuration to align with pre-defined policies, thereby restricting unsecured ports and ensuring consistent security across network segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual maintenance of network access policies is performed, then security policies can be customized and applied, but administrative workload increases significantly and security risks arise from human error

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidadministrative workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by automatically detecting configuration drift and remediating unsecure network policies without human intervention. The drift detection mechanism continuously monitors network segment configurations and automatically corrects deviations from expected secure states, eliminating the need for manual security policy maintenance while ensuring consistent enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback through continuous monitoring of network segment configurations against expected configurations. When drift is detected (i.e., when actual configuration deviates from expected secure configuration), the system automatically triggers remediation actions to restore security compliance, creating a closed-loop control system that maintains security without manual intervention.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If network segments are dynamically changed (adding resources, virtual machines), then computing environment flexibility increases, but security policy compliance decreases due to configuration drift

Engineering Contradiction:
Improvenetwork segment flexibilityVSAvoidsecurity policy compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The drift detection mechanism provides continuous feedback on configuration compliance, automatically identifying when dynamic changes to network segments cause deviations from expected secure configurations. This enables real-time monitoring and automatic remediation of security policy violations that occur during dynamic environment changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system establishes expected configurations in advance that define secure network policies for network segments. By pre-defining what secure configurations should look like, the system can automatically detect and remediate drift caused by dynamic changes, ensuring security compliance is maintained proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If automated drift detection and remediation is implemented, then security consistency is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity configuration consistencyVSAvoidaccess management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The automated system uses feedback mechanisms to continuously compare actual network segment configurations against expected secure configurations. This feedback loop enables automatic detection of configuration drift and triggers remediation actions, ensuring security consistency without requiring complex manual management processes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically remediating detected configuration drift without human intervention. The automated remediation process restores security compliance by applying corrective actions to network segment configurations, reducing the need for complex administrative procedures while maintaining security consistency.

Inventive Principle:
Principle #25Self-service

4Reliability

If continuous monitoring of network policies is performed, then security violations are detected faster, but computational resources are consumed

Engineering Contradiction:
Improvesecurity violation detection speedVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements continuous monitoring through feedback mechanisms that track configuration changes in network segments. By continuously comparing actual configurations against expected secure configurations, the system quickly detects security violations while using efficient comparison algorithms that minimize computational overhead.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system focuses monitoring efforts on critical security configurations and high-risk network segments, applying partial monitoring where full continuous monitoring would be excessive. This approach detects security violations quickly in areas of highest risk while conserving computational resources in lower-risk areas.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11438387B2Access management system with a security maintenance manager
Publication Date: 2022.09.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11438387B2 patent drawing
  • US11438387B2 patent drawing
  • US11438387B2 patent drawing

AI summary

Methods, systems, and computer storage media for providing detection of unsecure network policies in a network segment and automatically remediating the unsecure policies based on pre-defined network policies in a computing environment. In particular, a security maintenance manager of an access management system in the computing environment detects an unsecure network policy based on comparing an active configuration of the network segment to an expected configuration of the network segment and modifies the active configuration to at least restore restrictions of network policies of the expected configuration to the active configuration. In operation, the security maintenance manager periodically accesses an active configuration record for the network segment and compares the active configuration record to an expected configuration record for the network segment. Based on comparing the active configuration record to the expected configuration record, restrictions are remediated (e.g., modified or added) to restore restrictions of the expected configuration record.