Security Policy Discovery via Runtime Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security policy determination methods are specification-oriented, making it difficult to create customized policies and verify their enforcement, as they lack feedback from the system's current configuration, leading to potential incorrect implementations and labor-intensive processes.

Innovation Solution

The method involves discovering an implicitly enforced security policy in a computer system environment, generating an enforceable isolation policy, and mapping physical and virtual systems into separate execution environments, using tools like Integrity Management Architecture and analyzing configuration files and system run-time information to create a holistic approach to security policy discovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If specification-oriented security policy determination is used, then security policy can be determined by querying system configuration, but it is difficult to create customized policies and verify their enforcement

Engineering Contradiction:
Improveease of security policy creationVSAvoidverification of policy enforcement
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements feedback by monitoring actual system behavior and comparing it against specified security policies. The system observes runtime interactions between applications and resources, then feeds this information back to verify whether policies are being enforced correctly. This closes the loop between policy specification and actual enforcement, enabling verification that was previously impossible with static configuration queries alone.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by automatically discovering and analyzing its own security policy enforcement behavior. Through self-monitoring of application executions, resource access patterns, and policy violation detection, the system can autonomously verify whether its configured security policies are being properly enforced without requiring external manual verification processes.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If default security policy is used, then initial policy configuration is simplified, but it requires manual modification to fit unique application environments

Engineering Contradiction:
Improveinitial policy configurationVSAvoidcustomization to application environment
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by transitioning security policies from static default configurations to dynamic, adaptive policies. The system continuously monitors actual application behavior and resource access patterns, then automatically adjusts security policies to match the unique characteristics of each application environment. This enables policies to evolve and adapt over time rather than remaining fixed after manual configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically discovering and analyzing its own security policy enforcement behavior. Through self-monitoring of application executions, resource access patterns, and policy violation detection, the system can autonomously verify whether its configured security policies are being properly enforced without requiring external manual verification processes.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If manual security policy modification is performed, then policy can be customized for unique environment, but the process is labor-intensive

Engineering Contradiction:
Improvecustomized security policyVSAvoidtime for policy creation
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically discovering and analyzing its own security policy enforcement behavior. Through self-monitoring of application executions, resource access patterns, and policy violation detection, the system can autonomously verify whether its configured security policies are being properly enforced without requiring external manual verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback by monitoring actual system behavior and comparing it against specified security policies. The system observes runtime interactions between applications and resources, then feeds this information back to verify whether policies are being enforced correctly. This closes the loop between policy specification and actual enforcement, enabling verification that was previously impossible with static configuration queries alone.

Inventive Principle:
Principle #23Feedback

4Productivity

If security policy is determined without system feedback, then initial configuration is faster, but incorrect implementations may go undetected

Engineering Contradiction:
Improvespeed of policy determinationVSAvoidcorrectness of policy implementation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback by monitoring actual system behavior and comparing it against specified security policies. The system observes runtime interactions between applications and resources, then feeds this information back to verify whether policies are being enforced correctly. This closes the loop between policy specification and actual enforcement, enabling verification that was previously impossible with static configuration queries alone.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8839345B2Method for discovering a security policy
Publication Date: 2014.09.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8839345B2 patent drawing
  • US8839345B2 patent drawing
  • US8839345B2 patent drawing

AI summary

Techniques for mapping at least one physical system and at least one virtual system into at least two separate execution environments are provided. The techniques include discovering an implicitly enforced security policy in an environment comprising at least one physical system and at least one virtual system, using the discovered policy to create an enforceable isolation policy, and using the isolation policy to map the at least one physical system and at least one virtual system into at least two separate execution environments. Techniques are also provided for generating a database of one or more isolation policies.