Automated Security Configuration Profile Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security configuration processes for network entities are time-consuming, error-prone, and not scalable, requiring manual analysis and implementation, leading to inconsistent configurations and inefficiencies.

Innovation Solution

A method and entity for generating security configuration profiles using network entity information, deployment information, and feedback, with a risk score calculation to determine profile provision, incorporating machine learning for automation and adaptation to evolving security best practices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual security configuration process is used with security expert analysis, then security configuration accuracy is improved, but time consumption and complexity increase significantly

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system enables self-service through automated profile generation where the security configuration entity automatically generates profiles based on collected network entity information and deployment information, eliminating the need for manual expert analysis while maintaining configuration accuracy through systematic automated processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of security expert analysis with an automated computational system that collects information, generates profiles, calculates risk scores, and provides feedback automatically, substituting human manual operations with machine-based automated procedures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Manufacturing precision

If manual security configuration is performed for each network entity, then configuration accuracy is maintained, but scalability and productivity deteriorate

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidscalability
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system achieves universality by creating a reusable security configuration profile that can be applied to multiple network entities of the same type. The generated profile serves as a template that can be deployed across numerous entities simultaneously, enabling the system to handle both individual and bulk configuration needs efficiently

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by generating security configuration profiles in advance based on collected information about network entities. These pre-generated profiles are stored and can be quickly deployed when needed, eliminating the need to perform manual configuration analysis at the time of deployment and significantly improving scalability

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security analysis and script development is performed manually, then security configuration quality is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity configuration qualityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing the security configuration process into distinct modular components: information collection module, profile generation module, risk score calculation module, and feedback provision module. Each module handles a specific aspect of the process independently, making the overall complex process manageable and maintainable through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security configuration entity that acts as a mediator between the raw network entity information and the final security configuration deployment. This intermediary automatically processes information, generates profiles, calculates risks, and provides feedback, simplifying the operational complexity by centralizing the coordination function

Inventive Principle:
Principle #24Intermediary (Mediator)

4Stability of the object's composition

If manual security configuration updates are performed through snapshots and checks, then configuration consistency is monitored, but maintenance time and operational overhead increase

Engineering Contradiction:
Improveconfiguration consistencyVSAvoidmaintenance time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system implements feedback by automatically calculating risk scores for generated profiles and providing feedback information to improve future profile generation. This continuous feedback loop automatically monitors and maintains configuration quality without requiring manual snapshots and checks, reducing maintenance time while ensuring consistency through automated validation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240015175A1Generation of a security configuration profile for a network entity
Publication Date: 2024.01.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240015175A1 patent drawing
  • US20240015175A1 patent drawing
  • US20240015175A1 patent drawing

AI summary

There is provided mechanisms for generating a security configuration profile for a network entity. A method is performed by a security configuration entity. The method comprises generating the security configuration profile for the network entity based on network entity information, deployment information, and feedback information for a previously generated security configuration profile. The method comprises determining, based on calculating a risk score for the generated security configuration profile, whether the security configuration profile is to be provided towards the network entity or not. The method comprises generating feedback information for the security configuration profile based on the risk score, the network entity information, and the deployment information.