Automated Security Policy Configuration for Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for configuring computer systems to comply with enterprise security policies are complex and difficult to implement, especially for personal devices, due to the numerous actions required and the complexity of configurations, often resulting in incomplete or partial compliance.

Innovation Solution

A system and method that includes a policy application module to determine configuration parameters, an instruction forming module to generate and execute configuration change instructions, and a database of security policies, which automatically configures a computer system to align with selected security policies, ensuring secure access to a corporate network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration actions are performed according to security policies, then security compliance is achieved, but the complexity and difficulty of configuration increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service configuration by automatically generating and executing configuration instructions on the employee's personal computer system without requiring manual user intervention. The instruction forming module creates configuration change instructions that are automatically applied, allowing the system to configure itself according to security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-generating configuration instructions based on security policies before actual configuration is needed. The instruction forming module prepares configuration change instructions in advance, and the system checks whether these pre-generated instructions are applicable to the current system state, enabling automated configuration execution.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration actions are performed according to security policies, then security compliance is achieved, but the time and effort required increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The automated configuration system eliminates manual user involvement in the configuration process. The policy application module automatically determines whether configuration is needed, the instruction forming module generates the necessary instructions, and the system executes them without user intervention, significantly reducing the time and effort required compared to manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Configuration instructions are generated and prepared in advance by the instruction forming module based on security policies. The system checks applicability of these pre-generated instructions to the current system state, enabling rapid automated execution without requiring users to spend time understanding or performing manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If configuration instructions are automatically generated and executed, then configuration complexity is reduced, but the risk of incorrect configuration increases

Engineering Contradiction:
Improveconfiguration easeVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system incorporates feedback mechanisms by checking whether generated configuration instructions are applicable to the current system state before execution. The policy application module determines configuration needs based on the current state, and the system validates instruction applicability, providing feedback loops that ensure configuration accuracy and prevent incorrect modifications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The configuration system is dynamic and adaptive to the current system state. The instruction forming module generates configuration instructions that are tailored to the specific state of the computer system, and the policy application module dynamically determines whether configuration is needed based on current conditions, ensuring that automated configuration remains accurate and context-appropriate.

Inventive Principle:
Principle #15Dynamics

4Manufacturing precision

If comprehensive configuration checks are performed, then configuration accuracy is improved, but the processing time increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs partial configuration checks by determining whether configuration is needed based on the current system state and security policy requirements. Rather than performing exhaustive checks on all possible configuration parameters, the system focuses on relevant checks that ensure sufficient accuracy for security compliance while minimizing processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2998897B1System and method for configuring a computer system according to security policies
Publication Date: 2018.11.14 AO KASPERSKY LAB
  • EP2998897B1 patent drawingFigure 1
  • EP2998897B1 patent drawingFigure 2
  • EP2998897B1 patent drawingFigure 3

AI summary

Method and system for configuration of a computer system according to security policies. The configuration of an employee's personal computer system according to the security policies of the corporate network provides for security of access to the corporate network. Configuration change instructions are generated according to the security policy and applied to the configuration of the computer system. The configuration system includes at least one computer system used to access a corporate network, a policy application module configured to determine configuration parameters of the computer system and to pass the configuration data to an instruction forming module. The computer system is configured according to the selected security policy by execution of at least one configuration change instruction. The configuration system also includes a database of security policies.