Automated Security Policy Auditing System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing and auditing dynamic and frequently changing security policies across computer networks is challenging due to the complexity of hundreds or thousands of rules, making it difficult for security departments to track and maintain security measures effectively.
Innovation Solution
A computerized method and system for automated auditing of security policies that involves obtaining log records, counting matching records, and generating records with rule identifiers and counters to analyze the usage of objects and rules, facilitating the discovery of obsolete objects, ranking objects by usage, and providing recommendations for optimization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies include hundreds or thousands of rules to provide comprehensive protection, then security coverage is improved, but policy complexity and difficulty of tracking increase
Solution Approach 1:
The patent segments the security policy into hierarchical structures with policy sets, rule sets, and individual rules. It introduces classification mechanisms that divide policies into categories (e.g., by destination, service, protocol) to make the complex rule base more manageable. The segmentation allows security departments to navigate and track specific policy areas without being overwhelmed by the entire policy complexity.
Solution Approach 2:
The patent introduces an intermediary auditing system that acts as a mediator between security policies and security departments. This intermediary component automatically tracks, monitors, and reports on policy usage and changes, reducing the manual tracking burden on security departments while maintaining comprehensive security coverage.
2Adaptability or versatility
If security policies are made dynamic and frequently changing to adapt to evolving threats, then adaptability is improved, but difficulty of tracking and maintaining policies increases
Solution Approach 1:
The patent implements feedback mechanisms through automated auditing that continuously monitors policy changes and usage patterns. The system provides feedback to security departments about which policies are actively used, which are obsolete, and how policies are performing, enabling informed decisions about policy maintenance while allowing dynamic updates to respond to evolving security threats.
Solution Approach 2:
The auditing system performs self-service functions by automatically tracking its own operations, monitoring policy changes, and generating reports without requiring manual intervention. This automation reduces the operational burden on security departments while maintaining the ability to adapt policies dynamically.
3Measurement precision
If manual tracking of security policies is performed to maintain accuracy, then policy management quality is improved, but time consumption and labor requirements increase
Solution Approach 1:
The patent replaces manual mechanical tracking processes with automated computer-based auditing systems. The system automatically logs, monitors, and analyzes security policy changes and usage patterns, eliminating the need for manual tracking while maintaining high accuracy. This substitution dramatically reduces time consumption and labor requirements.
Solution Approach 2:
The patent creates digital copies and representations of security policies that can be automatically analyzed and tracked. By maintaining digital representations of policy states and usage patterns, the system enables automated monitoring and reporting without requiring continuous manual verification, thus reducing time consumption while preserving tracking accuracy.
Data Source
AI summary
Provided a computerized system and method of automated auditing a range of rules associated with an enforced security policy. The method comprises automated obtaining log records assigned to a first rule within the range of rules and logged during a counted period, each said log record comprising a unique rule identifier and recorded values of respective arguments comprised in the rule; counting a number of records matching certain recorded values and logged within certain time intervals within the counted period (counted values); and automated generating a counted log record assigned to said rule, said record comprising the unique rule identifier, the counted period, recorded values of the rule arguments and respective counted values. The method further comprises obtaining a plurality of objects engaged in said first rule; resolving a first object among said plurality of objects to a set of resolved values; matching said resolved values to the recorded values of the respective arguments, said recorded values comprised in the counted log record assigned to said rule; counting each match in accordance with respective counted value, thus giving rise to a plurality of matching values of the resolved values; and using the plurality of matching values for analysis related to usage of the first object.


