Automated Security Policy Generation from Role-Play Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security policies within organizations is complex due to the need for in-depth technical knowledge and the difficulty in translating business security requirements into technology-specific designs, often resulting in inefficient and costly processes.

Innovation Solution

A security framework that allows business security analysts to role-play specific roles, recording transactions, and automatically generating and optimizing security policies, which are then deployed across the organization, simplifying the policy authoring and deployment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If security policies are manually configured by administrators, then security control and precision can be achieved, but the complexity of the process increases and requires in-depth technical knowledge

Engineering Contradiction:
Improvesecurity policy precisionVSAvoidpolicy configuration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that translates high-level business security requirements into technology-specific security policies. This intermediary layer (the translation system) mediates between the business domain and IT implementation, eliminating the need for administrators to directly understand complex technical policy configurations while maintaining precision through automated translation rules and models.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of policy configuration with an automated translation system. Instead of administrators manually configuring policies using technical knowledge, the system automatically translates business requirements into security policies, substituting human expertise with an automated translation mechanism that reduces complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security administrators manually translate business requirements to technology-specific policies, then security control can be maintained, but the time and cost required increases significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the system to translate and configure security policies automatically without requiring continuous human intervention. The translation system operates autonomously to convert business requirements into security policies, allowing the organization to maintain security control while significantly reducing the time and resources required for policy configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes translation rules, models, and mappings in advance that enable automated policy generation. By preparing the translation framework beforehand, the system can quickly translate new business requirements into security policies without requiring time-consuming manual analysis and configuration each time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If existing security frameworks are used to enforce policies, then security enforcement can be achieved, but the frameworks cannot precisely represent all business security requirements

Engineering Contradiction:
Improvesecurity enforcementVSAvoidrequirement representation precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent transforms business security requirements into the specific parameter format required by security frameworks through automated translation. The system maps business domain concepts and requirements into the technical parameters and structures that security enforcement frameworks can process, maintaining precision by preserving the essential security intent while adapting to framework constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8640195B2Method and system for automating security policy definition based on recorded transactions
Publication Date: 2014.01.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8640195B2 patent drawing
  • US8640195B2 patent drawing
  • US8640195B2 patent drawing

AI summary

Following development of an application, the application is deployed in a pre-production environment. A user role plays against that application, typically by performing one or more operations as a particular user in a particular group. As the operator role plays, access logs are written, and these logs are then analyzed and consolidated into a set of commands that drive a policy generator. The policy generator creates an optimized security policy that it then deploys to one or more enforcement points. In this manner, the framework enables automated configuration and deployment of one or more security policies.