Auto-scaling Network Security Microservices Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security solutions face challenges in scaling to meet high traffic volumes and maintaining up-to-date threat signatures, especially in cloud environments, due to the complexity and resource inefficiency of deploying and managing network security appliances.

Innovation Solution

A dynamic, load-based, auto-scaling network security microservices architecture that allows for independent scaling of security services, enabling efficient deployment, updating, and resource allocation across a hierarchy of microservices within a datacenter.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security appliances are deployed throughout the datacenter, then network security protection is provided, but it is not economically or administratively feasible to provide the number of appliances needed to monitor high traffic volumes

Engineering Contradiction:
Improvenetwork security protectionVSAvoidnumber of appliances
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the monolithic network security appliance into multiple independent microservices (e.g., threat detection microservice, signature management microservice, traffic analysis microservice). Each microservice handles specific security functions independently, allowing the system to scale selectively based on traffic demands without deploying numerous full-featured appliances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security platform where a single infrastructure hosts multiple security microservices that can serve different parts of the datacenter network. This multi-functional platform replaces the need for multiple specialized appliances, as the same infrastructure can dynamically allocate security resources to different network segments based on demand.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If the number of network security appliances is scaled out, then monitoring capacity increases, but scaling is complex and time-consuming

Engineering Contradiction:
Improvemonitoring capacityVSAvoidscaling complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the security platform automatically provisions, configures, and manages microservice instances based on monitored traffic patterns and threat levels. The system self-adjusts resource allocation without manual intervention, eliminating the complex administrative tasks associated with traditional appliance scaling.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic scaling capabilities where security microservices can be automatically instantiated, scaled, or terminated based on real-time traffic conditions and threat assessments. This dynamic approach replaces static appliance deployments, allowing the system to adapt monitoring capacity flexibly without the time-consuming processes of traditional scaling.

Inventive Principle:
Principle #15Dynamics

3Reliability

If network security appliances are deployed, then security monitoring is provided, but it is difficult to keep the appliances up to date with the latest threat signatures

Engineering Contradiction:
Improvesecurity monitoringVSAvoidupdating threat signatures
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements continuous automated updates of threat signatures and security policies through a centralized management system that continuously receives, validates, and distributes updated signature sets to all security microservices. This continuous update mechanism ensures security monitoring remains current without manual intervention, replacing the periodic update cycles of traditional appliances.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent incorporates feedback loops where security microservices continuously report their operational status, detected threats, and performance metrics to a central management platform. This feedback enables the system to automatically adjust signature sets and update configurations based on emerging threat patterns, keeping the security monitoring system current without manual updates.

Inventive Principle:
Principle #23Feedback

4Reliability

If network security appliances are deployed, then network security is provided, but it is difficult to deploy appliances, especially in cloud computing environments

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the mechanical/physical deployment of network security appliances with a virtualized software-based microservice architecture. Security functions are implemented as software containers or virtual machines that can be deployed through standard cloud orchestration tools, eliminating the need for physical hardware installation and making deployment straightforward in cloud computing environments.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3469781B1Dynamic, load-based, auto-scaling network security microservices architecture
Publication Date: 2023.08.30 FORTINET INC
  • EP3469781B1 patent drawingFigure 1
  • EP3469781B1 patent drawingFigure 2
  • EP3469781B1 patent drawingFigure 3

AI summary

System, methods, and apparatuses used to monitor network traffic of a datacenter and report security threats are described. For example, one embodiment scales out a hierarchy of microservices in a security system. In particular, the embodiment calls for scaling out a hierarchy of microservices in such a security system, creating a new microservice of a first hierarchy, configuring data plane connectivity between the new microservice and a microservice of a second, higher-level hierarchy; configuring data plane connectivity between the new microservice and a microservice of a third, lower-level hierarchy; and configuring the microservices of the third level of hierarchy to include the new microservice in load balancing decisions to the first hierarchy.