Network Security Policy Conflict Resolution via Normalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cybersecurity platforms are fragmented, leading to conflicts between different security applications, resulting in false positives and false negatives due to inconsistent decision-making, which can compromise network security and disrupt workflows.

Innovation Solution

A system and method for identifying and reconciling inconsistencies between network security applications by using a normalization model to compare and reconcile security policies, potentially involving a machine-learning classification system to automatically resolve conflicts and apply a least-privilege policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple specialized security applications are deployed to protect against varying attacks, then security coverage is improved, but conflicts between applications increase leading to false positives and false negatives

Engineering Contradiction:
Improvesecurity coverageVSAvoiddecision consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal normalization layer that translates security policies from multiple specialized applications into a common standardized format. This normalization model enables different security applications (email security, file analysis, behavioral analysis, network traffic scrutiny, DevOps pipeline protection) to communicate and coordinate their decisions through unified policy representations, thereby maintaining security coverage while resolving conflicts and improving decision consistency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security policies are enforced strictly to block potential threats, then security vulnerabilities are reduced, but legitimate workflows are disrupted causing network downtime and productivity loss

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork uptime
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where security application decisions are monitored and evaluated. When conflicts or false positives are detected through the normalization model, the system provides feedback to adjust policy enforcement. This allows strict security policies to maintain protection while automatically adapting to prevent unnecessary workflow disruptions, balancing security reliability with network productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10601876B1Detecting and actively resolving security policy conflicts
Publication Date: 2020.03.24 CYBER ARK SOFTWARE LTD
  • US10601876B1 patent drawing
  • US10601876B1 patent drawing
  • US10601876B1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for identifying inconsistencies between network security applications. Techniques include identifying a plurality of network security applications, each having a corresponding network security policy; determining that at least one of the plurality of network security applications has a corresponding network security policy that does not comply with a normalization model; implementing the network security policy that does not comply with the normalization model on an endpoint computing resource; determining a result of the implementing with respect to a requested action on the endpoint computing resource; identifying, based on the result of the implementing, at least one inconsistency between how the plurality of network security applications address the requested action; and performing, based on the identifying of the inconsistency, at least one of: generating a report identifying the inconsistency, or reconciling the identified inconsistency.