Network Security Policy Conflict Resolution via Normalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern cybersecurity platforms are fragmented, leading to conflicts between different security applications, resulting in false positives and false negatives due to inconsistent decision-making, which can compromise network security and disrupt workflows.
Innovation Solution
A system and method for identifying and reconciling inconsistencies between network security applications by using a normalization model to compare and reconcile security policies, potentially involving a machine-learning classification system to automatically resolve conflicts and apply a least-privilege policy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple specialized security applications are deployed to protect against varying attacks, then security coverage is improved, but conflicts between applications increase leading to false positives and false negatives
Solution Approach 1:
The patent implements a universal normalization layer that translates security policies from multiple specialized applications into a common standardized format. This normalization model enables different security applications (email security, file analysis, behavioral analysis, network traffic scrutiny, DevOps pipeline protection) to communicate and coordinate their decisions through unified policy representations, thereby maintaining security coverage while resolving conflicts and improving decision consistency.
2Reliability
If security policies are enforced strictly to block potential threats, then security vulnerabilities are reduced, but legitimate workflows are disrupted causing network downtime and productivity loss
Solution Approach 1:
The patent implements a feedback mechanism where security application decisions are monitored and evaluated. When conflicts or false positives are detected through the normalization model, the system provides feedback to adjust policy enforcement. This allows strict security policies to maintain protection while automatically adapting to prevent unnecessary workflow disruptions, balancing security reliability with network productivity.
Data Source
AI summary
Disclosed embodiments relate to systems and methods for identifying inconsistencies between network security applications. Techniques include identifying a plurality of network security applications, each having a corresponding network security policy; determining that at least one of the plurality of network security applications has a corresponding network security policy that does not comply with a normalization model; implementing the network security policy that does not comply with the normalization model on an endpoint computing resource; determining a result of the implementing with respect to a requested action on the endpoint computing resource; identifying, based on the result of the implementing, at least one inconsistency between how the plurality of network security applications address the requested action; and performing, based on the identifying of the inconsistency, at least one of: generating a report identifying the inconsistency, or reconciling the identified inconsistency.


