Automated Security Policy Generation via Threat Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security management systems are inefficient in responding to cyber threats due to manual, labor-intensive processes for configuring policies to mitigate and resolve network attacks, and lack centralized threat visualization and automated control of security devices.

Innovation Solution

An integrated security management system that provides centralized threat visualization and automated control of security devices, featuring a sophisticated user interface, threat data aggregation, and automated policy generation and deployment, enabling administrators to interact with graphical representations of threats to configure and update security policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual processes are used to configure security policies, then administrators can control security devices, but the process becomes labor-intensive and inefficient

Engineering Contradiction:
Improvesecurity response efficiencyVSAvoidmanual configuration burden
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables automated self-service through the policy generation module that automatically creates security policies based on aggregated threat data, eliminating the need for manual administrator intervention in policy creation and deployment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated electronic systems including threat data aggregation, automated policy generation, and electronic policy deployment across security devices

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If centralized threat visualization is implemented, then administrators can monitor threats in real-time, but system complexity increases

Engineering Contradiction:
Improvethreat information visibilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system merges multiple security devices and their threat data into a single centralized management interface, allowing administrators to monitor and control all security threats from one unified location without managing each device separately

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized management system acts as an intermediary between distributed security devices and administrators, aggregating threat data from multiple sources and presenting unified visualizations while managing the complexity internally

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If automated policy generation is used, then security response speed improves, but policy accuracy may be compromised

Engineering Contradiction:
Improvepolicy deployment speedVSAvoidpolicy configuration accuracy
Core Design Contradiction:
SpeedVSManufacturing precision

Solution Approach 1:

The system incorporates feedback mechanisms where the policy generation module uses aggregated threat data to automatically adjust and refine security policies, ensuring accuracy while maintaining rapid automated deployment capabilities

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary threat analysis and policy generation based on aggregated data before deployment, allowing automated creation of accurate policies based on pre-analyzed threat patterns and characteristics

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3166280B1Integrated security system having threat visualization and automated security device control
Publication Date: 2019.07.03 JUNIPER NETWORKS INC
  • EP3166280B1 patent drawingFigure 1
  • EP3166280B1 patent drawingFigure 2
  • EP3166280B1 patent drawingFigure 3

AI summary

Techniques are described for taking direct actions, such as selectively blocking or allowing traffic and applications, while monitoring events from a graphical representation of threats. As such, the administrator in an enterprise interacts with the graphical representation of threats rendered by the security management system to automatically invoke a policy/rule module of the security management system to configure and update security policies for the security devices deployed throughout the computer networks of the enterprise. An administrator may, for example, interact with the representation of threats rendered by the threat control module based on the data aggregated from the distributed security devices and, responsive to the interaction, the security management system may identify a relevant set of the security devices, automatically construct security policies having ordered rules within the policies for the identified set of security devices, and automatically communicate and install the policies in the identified set of security devices.