Unified Command Translator for Multi-Vendor Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, managing and applying security actions across various software configurations and applications from different distributors becomes cumbersome and inefficient, as each application requires distinct processes for implementing security actions, such as blocking IP addresses, which can vary significantly between different firewall systems from different providers.

Innovation Solution

A unified feature set database is provided that recommends features for security applications, allowing administrators to use a single command in a unified application language that can be translated into specific operations across multiple applications, regardless of their distributor, thereby simplifying the implementation of security actions across different computing assets with varying software configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security applications from different distributors are deployed to provide comprehensive security coverage, then security reliability is improved, but device complexity increases due to managing different software configurations and application processes

Engineering Contradiction:
Improvesecurity coverageVSAvoidsoftware configuration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal command structure that allows a single security command to be executed across multiple security applications from different distributors. The command translator component converts vendor-specific commands into a standardized format that can be understood by various security applications, enabling one command to perform multiple security functions across different products while maintaining vendor-specific functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The command translator serves as an intermediary between the security management system and multiple vendor-specific security applications. It receives commands in a standardized format, translates them into vendor-specific commands, and executes them across different security applications, thereby mediating between the need for unified management and vendor-specific implementation details.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If vendor-specific commands are used for each security application, then application-specific functionality is maintained, but ease of operation deteriorates due to requiring different processes for each application

Engineering Contradiction:
Improveapplication-specific functionalityVSAvoidsecurity action implementation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system provides a universal command interface that maintains vendor-specific functionality through translation. A single standardized command can trigger vendor-specific security actions across different applications, allowing administrators to operate all security tools through one unified interface while each application retains its specialized capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The command translator changes the parameter format of security commands from vendor-specific formats to a standardized format and back. By transforming command parameters between different representations, the system enables unified operation while preserving application-specific functionality through parameter translation rather than requiring separate operation procedures.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive security monitoring is implemented across all computing assets, then security detection capability is improved, but loss of time increases due to manual management of multiple applications

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidadministrator management time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security management system performs automatic command translation and execution across multiple security applications without requiring manual intervention. The system self-manages the complexity of coordinating multiple vendor-specific applications, allowing administrators to simply issue standardized commands while the system handles the time-consuming translation and execution coordination automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The command translator intermediary automates the coordination between security monitoring requirements and multiple applications. It automatically translates monitoring commands, manages execution timing, and coordinates responses across different security applications, thereby reducing the time administrators would otherwise spend manually managing comprehensive security monitoring across multiple tools.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11652849B2Identifying recommended feature sets based on application feature popularity
Publication Date: 2023.05.16 CISCO TECHNOLOGY INC
  • US11652849B2 patent drawing
  • US11652849B2 patent drawing
  • US11652849B2 patent drawing

AI summary

Systems, methods, and software described herein provide for identifying recommended feature sets for new security applications. In one example, a method of providing recommended feature sets for a new security application includes identifying a request for the new security application, and determining a classification for the new security application. The method further provides identifying related applications to the new security application based on the classification, and identifying a feature set for the new security application based on features provided in the related applications.