Unified Security Rule Classification Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of multiple security products and vendors in enterprise networks makes it difficult to configure, monitor, and enforce an effective security policy, as each product has unique interfaces, technologies, and security rules, leading to inefficiencies and high administrative burdens.

Innovation Solution

A method and system for classifying security rules from different security products into a unified security decision engine using normalization, vectorization, and classification models, allowing for the association of rules with cyber-solution categories and security services, independent of specific product vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security products from different vendors are deployed to protect against various threats, then the security coverage and detection capability are improved, but the system complexity and administrative burden increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security products and their rules into a unified security policy framework. The system merges rules from different vendors (Cisco, McAfee, etc.) and product types (IDS, anti-virus, WAF) into a common rule structure that can be centrally managed and enforced across the enterprise network, reducing the complexity of managing multiple separate security systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal rule structure that can accommodate multiple types of security rules from different vendors and product categories. The unified framework provides multi-functionality by handling intrusion detection, malware detection, web application firewall rules, and other security functions through a single policy management system, eliminating the need for separate management interfaces for each product.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security products with unique interfaces and configurations are used, then the detection capability against different threats is enhanced, but the ease of operation and configuration is reduced

Engineering Contradiction:
Improvedetection capabilityVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments security rules into standardized categories and attributes that can be independently managed. Each rule is broken down into components such as rule ID, description, severity, action, and vendor-specific parameters, allowing administrators to configure and manage security policies at a high level without dealing with the complexity of individual product interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a unified policy management system that acts as an intermediary between administrators and multiple security products. This intermediary layer translates high-level security policies into vendor-specific configurations, shielding administrators from the complexity of different product interfaces while maintaining full detection capabilities across all security products.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If vendor-specific security rules are used in each security product, then the effectiveness of individual products is optimized, but the ability to enforce unified security policy across the enterprise is compromised

Engineering Contradiction:
Improveproduct effectivenessVSAvoidpolicy enforcement flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms vendor-specific rule parameters into a unified parameter structure. Each security rule is represented with standardized attributes (rule ID, description, severity, action, target) while preserving vendor-specific details in a structured format. This allows the system to maintain product effectiveness by retaining vendor-specific logic while enabling unified policy enforcement through standardized parameter management.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If extensive security expertise is required to manage multiple security products, then the security policy effectiveness can be maintained, but the productivity and time required for integration and maintenance decreases

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidintegration speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements automated rule classification and policy generation capabilities that reduce the need for expert intervention. The system automatically categorizes incoming security rules, identifies conflicts, and generates unified security policies based on predefined criteria and enterprise security requirements, enabling faster integration and maintenance with reduced expertise requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10673903B2Classification of security rules
Publication Date: 2020.06.02 CYBEREASON INC
  • US10673903B2 patent drawing
  • US10673903B2 patent drawing
  • US10673903B2 patent drawing

AI summary

A system and method for method for generating a security rule classification model comprises receiving at least one security rule from at least one attack database of a first security product of a plurality of different security products; normalizing each of the at least one security rule; generating a vector for each of the least one normalized security rule; classifying each generated vector to a security engine within a security service using a classification sub-model to generate a preliminary classification model, wherein the classification sub-model is provided from previous classification of security rules for a security product of the plurality of different security products that is different than the first security product; determining a score for the preliminary classification model; and validating the preliminary classification model as the security rule classification model, when the score is over a predefined threshold.