Cross-Network Security Control System for Server Attack Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face limitations in handling server attacks, as they may not be equipped to handle all types of attacks, leading to potential unaddressed threats if only a single type of security system is used.

Innovation Solution

A control system is implemented across multiple networks, featuring a handling unit, determination unit, and request unit that allows for the identification of capable security systems to handle server attacks, enabling the transfer of attack handling requests between networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single security system is used on a network, then the system complexity is reduced, but the ability to handle diverse server attacks is limited

Engineering Contradiction:
Improveability to handle diverse server attacksVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security handling function into multiple specialized security systems, each capable of handling specific types of server attacks. Instead of one system trying to handle all attacks, multiple systems segment the attack handling responsibilities, with each system specializing in particular attack types this improves adaptability while managing complexity through functional division

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security collaboration framework where multiple security systems can work together to handle various attack types. The system determines which security system should handle each attack based on attack characteristics, enabling a multi-functional approach where different security systems provide different specialized capabilities across the network

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security systems are deployed across networks, then the ability to handle server attacks is improved, but the coordination and request management becomes more complex

Engineering Contradiction:
Improveserver attack handling capabilityVSAvoidcoordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the determination unit receives information about server attacks and evaluates which security system should handle them. The system continuously monitors attack patterns and adjusts the distribution of handling requests based on the capabilities and current state of each security system, creating a self-regulating coordination mechanism

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a determination unit as an intermediary that mediates between attacking targets and multiple security systems. This intermediary evaluates attack characteristics and decides which security system should handle each request, simplifying the coordination complexity by centralizing the decision-making process rather than requiring direct peer-to-peer coordination between all security systems

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security systems can request handling from other networks, then the coverage of attack handling is expanded, but the network communication overhead increases

Engineering Contradiction:
Improveattack handling coverageVSAvoidnetwork communication overhead
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent performs preliminary evaluation of attack characteristics before initiating cross-network communication. The determination unit assesses whether the attacking network has capable security systems that can handle the attack, and only then requests handling from external networks. This preliminary action reduces unnecessary communication overhead by avoiding requests to networks that cannot provide helpful security handling

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11570206B2Control system, control determination device, and control method
Publication Date: 2023.01.31 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11570206B2 patent drawing
  • US11570206B2 patent drawing
  • US11570206B2 patent drawing

AI summary

A handling apparatus (14a) handles a server attack taking place on a network (1Na) or handles a server attack as requested by a security system provided on another network. In accordance with a determination that it is not possible to handle the server attack by the handling apparatus (14a), the control determination apparatus (12a) makes a request to another security system (1Sb) capable of handling the server attack to handle the server attack. A centralized control apparatus (11) determines whether the server attack taking place on the network (1Na) can be handled on another network.