Security Policy Tracking with Incident Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in effectively implementing and tracking security policy coverage, objectively assessing policy effectiveness, and identifying potential security threats, making it difficult to monitor and respond to security policy violations in a timely and efficient manner.

Innovation Solution

The method involves creating rules based on security policies, parsing log data to determine variable values, evaluating rules, generating security events, and recording these events to identify violations, anomalies, and generating alerts, with the ability to associate geographic regions and analyze statistical data for network security assessment and reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are created to address network risks, then security coverage is improved, but implementation and enforcement difficulty increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy implementation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically parses logs, evaluates rules, generates security events, and sends alerts without requiring manual intervention. The monitoring system serves itself by continuously analyzing network data and enforcing security policies through automated workflows, reducing the operational burden on security personnel while maintaining comprehensive security coverage

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops by monitoring security events, generating alerts when policies are violated, and providing visibility into security posture through dashboards and reports. This feedback mechanism enables real-time adjustment and enforcement of security policies, making implementation more effective and manageable

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If continuous monitoring of security policy violations is implemented, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity violation detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The monitoring system is divided into distinct modular components: log parsing module, rule evaluation module, security event generation module, and alert notification module. Each component performs a specific function independently, making the overall complex system manageable through clear separation of concerns and enabling targeted optimization of individual modules

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses universal log parsing capabilities that can handle multiple log formats and sources, and rule evaluation mechanisms that work across different security policies. This multi-functionality reduces complexity by avoiding the need for separate specialized systems for each security monitoring task

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11558407B2Enterprise policy tracking with security incident integration
Publication Date: 2023.01.17 DEFENSESTORM INC
  • US11558407B2 patent drawing
  • US11558407B2 patent drawing
  • US11558407B2 patent drawing

AI summary

The present invention relates to methods, processes, and systems for monitoring security policy violations in a computer network. Details of such monitoring include creating a rule according to a security policy, determining if the rule is violated by a value of a variable, and recording security events and comparing the number of events to a threshold.