Blockchain Event Storage for Granular Network Security Decisions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in safely and reliably storing massive network security information and defending against attacks, with issues in associating security policy queries and achieving accurate, granular protection.
Innovation Solution
A blockchain-based big data analysis and decision-making system that utilizes on-chain storage for a key mapping table, separates network attack data at appropriate granularity, and performs event-based analysis to enhance network security protection, integrating cloud computing for historical data consolidation and intelligent decision-making.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If traditional database tools are used to store and manage network security information, then data storage capacity is limited, but the system cannot handle massive network security data effectively
Solution Approach 1:
The patent divides the data storage system into two parts: traditional database for structured security data and blockchain for unstructured security event data. This segmentation allows each storage system to handle its appropriate data type optimally, expanding overall storage capacity while maintaining data security through blockchain's distributed ledger technology
Solution Approach 2:
The patent combines traditional database storage with blockchain storage into a hybrid architecture. The database handles structured security information while blockchain stores unstructured security event data with cryptographic hashing, creating a unified system that leverages the strengths of both technologies to achieve both large-scale storage and high reliability
2Speed
If security policy queries are performed without proper association mechanisms, then query speed is fast, but association relationships are lost leading to inaccurate security decisions
Solution Approach 1:
The patent implements a feedback mechanism where security events are hashed and stored in blockchain, creating a verifiable association between events and security policies. The system continuously monitors and verifies these associations, providing feedback that ensures data integrity and prevents loss of association relationships while maintaining efficient query performance
Solution Approach 2:
The patent introduces cryptographic hashing as an intermediary mechanism that links security events to security policies. The hash values serve as intermediaries that maintain association relationships between unstructured event data and structured policy data, enabling accurate security decisions without compromising query speed
3Ease of manufacture
If network security data is not separated by granularity, then data collection is simple, but accurate and differentiated protection cannot be achieved
Solution Approach 1:
The patent segments security data into structured data (stored in traditional database) and unstructured security event data (stored in blockchain). This segmentation enables differentiated protection strategies where different data types receive appropriate security measures, achieving both ease of collection through automated classification and precision in protection through tailored security policies
4Device complexity
If massive network security data is stored without distributed architecture, then storage management is centralized and simple, but system reliability and security are reduced
Solution Approach 1:
The patent segments the storage architecture into centralized database components for structured data and distributed blockchain components for unstructured security events. This segmentation provides distributed redundancy for security-critical data, improving reliability and security while maintaining manageable complexity through clear separation of concerns
Data Source
AI summary
A blockchain-based big data analysis and decision-making system and method implement consolidation of a key mapping table preset by the system. On-chain storage of a blockchain can be adopted, thereby avoiding missing an association relationship of security policy query when performing decision-making in network security events. By taking a security event as a unit, network attack data can be separated at an appropriate granularity more reasonably by analyzing network security attack events and fault events and performing targeted decision-making based on event-based attack information, thereby implementing differentiated protection of network security and more accurate granularity of network security protection. Based on security attack big data in a cloud computing system, event-based security information big data can be migrated to a cloud to consolidate storage. The system can acquire relevant information of historical security events out of band to assist in performing blockchain-based event-based target intelligent big data analysis and decision-making.


