Bilateral Inheritance Model for Network Security Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer and network security intelligence processes typically manage security data independently of network architecture, failing to provide comprehensive security intelligence by only associating descriptive information with individual IP addresses, thus lacking context across network entities.
Innovation Solution
A bilateral inheritance model structure is introduced, where security attributes are associated with multiple network elements in a hierarchical manner, allowing attributes to be inherited from parents to children and vice versa, providing a richer context for security intelligence data management across various network entities such as top-level entities, autonomous systems, IP address ranges, and fully qualified domain names.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security attributes are tracked only at the individual IP address level, then detailed security information is available for specific devices, but context and relationships across network entities are lost
Solution Approach 1:
The patent implements a nested hierarchical data structure where network entities are organized in nested levels (autonomous systems containing IP address blocks containing individual IP addresses). Each level contains attributes specific to that level while inheriting attributes from parent levels, allowing detailed security information at the IP level to be nested within broader network context at higher hierarchical levels.
Solution Approach 2:
The hierarchical data structure serves multiple functions simultaneously: it tracks detailed security attributes at the individual IP level, maintains network context at higher levels, enables bidirectional attribute inheritance, and provides a unified framework for security analysis across all network entities. This multi-functional structure resolves the contradiction by making the same system serve both detailed tracking and contextualization needs.
2Productivity
If security intelligence is managed independently of network architecture, then simple data processing is achieved, but comprehensive security intelligence across network entities cannot be provided
Solution Approach 1:
The patent segments security intelligence management into distinct hierarchical levels (autonomous systems, IP address blocks, individual IP addresses), where each segment processes and stores attributes appropriate to its level. This segmentation allows efficient localized processing at each level while maintaining connections to higher levels for comprehensive context, resolving the contradiction between processing efficiency and intelligence completeness.
3Loss of information
If a hierarchical structure with bidirectional inheritance is implemented, then rich context and analytic capabilities are provided across network entities, but system complexity increases
Solution Approach 1:
The patent merges the attributes of parent and child entities into a unified hierarchical data structure. Each entity in the hierarchy contains both its own native attributes and inherited attributes from parent levels, creating a consolidated view that reduces the need for separate attribute management systems and simplifies the overall structure despite the hierarchical relationships.
4Reliability
If attributes are mapped bidirectionally between parent and child data structures, then comprehensive security intelligence is available at all levels, but data management complexity increases
Solution Approach 1:
The hierarchical data structure implements self-service attribute inheritance where each data structure automatically inherits attributes from its parent and can propagate its attributes to child structures. This automatic inheritance mechanism reduces the need for manual attribute mapping and complex management procedures, as the system self-manages the attribute propagation bidirectionally across the hierarchy.
Data Source
AI summary
Current approaches to managing security intelligence data often address both threat and malicious behavior at the individual computer level, tracked by the Internet Protocol (IP) address. For example, important facts, observed behavior, and other indications that are tracked by security organizations are only tracked with respect to individual IP addresses. Bilateral network inheritance generally refers to inheriting a variety of attributes from parents to children and from children to parents in a computer network hierarchy. The computer network hierarchy may comprise various entities such as, for example, top level entities, autonomous systems, address ranges, and individual IP addresses.


