Enterprise Web Application Security via Behavioral Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web applications are vulnerable to various attacks due to their unique nature, which traditional network security measures cannot effectively protect, and existing application protection solutions are inadequate in providing tailored and automated security profiles, leading to increased risks of data breaches and compliance issues.

Innovation Solution

A behavioral-based security model with collaborative detection modules and a centralized security manager that monitors network traffic, identifies anomalies, and coordinates responses across an enterprise to prevent attacks, using dynamic profiling and automated threat analysis to create tailored security profiles for each Web application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security measures are used, then general network protection is provided, but Web application-specific security threats cannot be effectively protected

Engineering Contradiction:
ImproveWeb application security protectionVSAvoidApplication-specific security tailoring
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system is segmented into multiple independent components: distributed detection modules deployed at individual network locations, a centralized security manager, and application-specific security profiles. Each component operates independently but contributes to the overall security function, allowing the system to address both general network protection and application-specific threats effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates customized security profiles for each Web application based on local characteristics and requirements. Each application receives tailored security rules and detection parameters specific to its functionality, rather than applying uniform security measures across all applications. This enables effective protection adapted to each application's unique threat landscape.

Inventive Principle:
Principle #3Local quality

2Reliability

If manual security profile creation is used, then customized security protection is achieved, but manual overhead and complexity increase

Engineering Contradiction:
ImproveSecurity profile accuracyVSAvoidSecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically generates security profiles by analyzing application behavior patterns and traffic characteristics. The centralized security manager autonomously creates, updates, and distributes security rules without requiring manual intervention from security administrators. This self-service capability maintains high security profile accuracy while eliminating manual overhead and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of application traffic patterns and behavior during normal operation to pre-generate security profiles before threats occur. By continuously monitoring and learning application characteristics in advance, the system prepares security rules proactively, reducing the need for reactive manual configuration and simplifying security management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized security management is implemented, then enterprise-wide threat coordination is achieved, but impact on network operations increases

Engineering Contradiction:
ImproveEnterprise-wide security coordinationVSAvoidNetwork operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The centralized security manager acts as an intermediary that coordinates security responses across the enterprise without directly interfering with network operations. It receives security events from distributed detection modules, processes them centrally, and sends coordinated response instructions back to the appropriate modules. This intermediary role enables enterprise-wide threat coordination while minimizing impact on network productivity through efficient, non-intrusive communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7934253B2System and method of securing web applications across an enterprise
Publication Date: 2011.04.26 TRUSTWAVE HOLDINGS INC
  • US7934253B2 patent drawing
  • US7934253B2 patent drawing
  • US7934253B2 patent drawing

AI summary

A system and method for protection of Web based applications are described. The techniques described provide an enterprise wide approach to preventing attacks of Web based applications. Individual computer networks within the enterprise monitor network traffic to identify anomalous traffic. The anomalous traffic can be identified by comparing the traffic to a profile of acceptable user traffic when interacting with the application. The anomalous traffic, or security events, identified at the individual computer networks are communicated to a central security manager. The central security manager correlates the security events at the individual computer networks to determine if there is an enterprise wide security threat. The central security manager can then communicate instructions to the individual computer networks so as to provide an enterprise wide solution to the threat.