Automated Security Policy Auditing System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and auditing dynamic and frequently changing security policies across computer networks is challenging due to the complexity of hundreds or thousands of rules, making it difficult for security departments to track and maintain security measures effectively.

Innovation Solution

A computerized method and system for automated auditing of security policies that involves obtaining log records, counting matching records, and generating records with rule identifiers and counters to analyze the usage of objects and rules, facilitating the discovery of obsolete objects, ranking objects by usage, and providing recommendations for optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies include hundreds or thousands of rules to provide comprehensive protection, then security coverage is improved, but policy complexity and difficulty of tracking increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security policy into hierarchical structures with policy sets, rule sets, and individual rules. It introduces classification mechanisms that divide policies into categories (e.g., by destination, service, protocol) to make the complex rule base more manageable. The segmentation allows security departments to navigate and track specific policy areas without being overwhelmed by the entire policy complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary auditing system that acts as a mediator between security policies and security departments. This intermediary component automatically tracks, monitors, and reports on policy usage and changes, reducing the manual tracking burden on security departments while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security policies are made dynamic and frequently changing to adapt to evolving threats, then adaptability is improved, but difficulty of tracking and maintaining policies increases

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidease of tracking
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms through automated auditing that continuously monitors policy changes and usage patterns. The system provides feedback to security departments about which policies are actively used, which are obsolete, and how policies are performing, enabling informed decisions about policy maintenance while allowing dynamic updates to respond to evolving security threats.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The auditing system performs self-service functions by automatically tracking its own operations, monitoring policy changes, and generating reports without requiring manual intervention. This automation reduces the operational burden on security departments while maintaining the ability to adapt policies dynamically.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual tracking of security policies is performed to maintain accuracy, then policy management quality is improved, but time consumption and labor requirements increase

Engineering Contradiction:
Improvepolicy tracking accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical tracking processes with automated computer-based auditing systems. The system automatically logs, monitors, and analyzes security policy changes and usage patterns, eliminating the need for manual tracking while maintaining high accuracy. This substitution dramatically reduces time consumption and labor requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies and representations of security policies that can be automatically analyzed and tracked. By maintaining digital representations of policy states and usage patterns, the system enables automated monitoring and reporting without requiring continuous manual verification, thus reducing time consumption while preserving tracking accuracy.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8819762B2System and method for auditing a security policy
Publication Date: 2014.08.26 TUFIN SOFTWARE TECH
  • US8819762B2 patent drawing
  • US8819762B2 patent drawing
  • US8819762B2 patent drawing

AI summary

Provided a computerized system and method of automated auditing a range of rules associated with an enforced security policy. The method comprises automated obtaining log records assigned to a first rule within the range of rules and logged during a counted period, each said log record comprising a unique rule identifier and recorded values of respective arguments comprised in the rule; counting a number of records matching certain recorded values and logged within certain time intervals within the counted period (counted values); and automated generating a counted log record assigned to said rule, said record comprising the unique rule identifier, the counted period, recorded values of the rule arguments and respective counted values. The method further comprises obtaining a plurality of objects engaged in said first rule; resolving a first object among said plurality of objects to a set of resolved values; matching said resolved values to the recorded values of the respective arguments, said recorded values comprised in the counted log record assigned to said rule; counting each match in accordance with respective counted value, thus giving rise to a plurality of matching values of the resolved values; and using the plurality of matching values for analysis related to usage of the first object.