Automated Security Rule-Set Generation from Network Logs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring security gateways, especially in complex network architectures, requires significant manual effort and prior knowledge of IT resources and connectivity requirements, necessitating an automated method for generating operational rule-sets.
Innovation Solution
An automated method for generating a security rule-set involves obtaining log records of communication events, generating a preliminary rule-set of permissive rules, dividing these rules into non-overlapping sets, and processing them to create an operational rule-set that covers the log records, reducing human involvement and error.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual configuration of security gateway rule-set is performed, then configuration accuracy and security policy compliance are improved, but configuration time and operational complexity increase significantly
Solution Approach 1:
The system enables automated self-configuration of security gateway rule-sets by collecting log records from the network environment, analyzing communication patterns, and automatically generating optimized security rules without requiring manual security expert intervention. The automated rule-generation system processes log data to create initial rule-sets that are then refined through iterative optimization.
Solution Approach 2:
The system performs preliminary analysis of network traffic patterns by collecting and processing log records before final rule-set deployment. This preliminary action includes identifying communication patterns, determining security requirements, and pre-generating rule candidates that are later optimized and validated against security policies.
2Productivity
If automated rule-generation is implemented, then configuration time and operational complexity are reduced, but rule-set optimization and security policy compliance become more challenging
Solution Approach 1:
The system implements dynamic rule-set optimization through iterative processes that continuously refine security rules based on analyzed log records and security requirements. The optimization is dynamic as it adapts to changing network conditions and security threats by processing ongoing log data and updating rule-sets accordingly.
Solution Approach 2:
The system incorporates feedback mechanisms where generated rule-sets are evaluated against security policies and network traffic patterns, with results fed back into the optimization process. This feedback loop enables continuous improvement of rule quality by identifying and correcting suboptimal rules based on actual network behavior and security requirements.
Data Source
AI summary
There are provided a method of generation of a security rule-set and a system thereof. The method includes: obtaining a group of log records of communication events resulting from traffic related to the security gateway; generating a preliminary rule-set of permissive rules, said set covering the obtained group of log records; generating, with the help of mapping the generated preliminary rule-set to the obtained group of log records, a rule-set of non-overlapping rules covering the group of log records; and generating an operational rule-set by processing the generated rule-set of non-overlapping rules, said processing including mapping the generated rule-set of non-overlapping rule to the obtained group of log records.


