Decoupled Network Security Software for Distributed Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The perimeter-based security model is inflexible and ineffective in adapting to evolving security threats, particularly with the increased adoption of bring-your-own-device policies, which introduces additional security concerns due to the potential for malicious software and rogue code within legitimate software.
Innovation Solution
Decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment, allowing for on-demand access to security services through open APIs, enabling each asset to be protected according to its specific requirements rather than the collective requirements of all assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If perimeter-based security model with dedicated hardware security appliances is used, then security protection is provided for the network, but flexibility and adaptability to evolving security threats deteriorates
Solution Approach 1:
The patent segments the traditional monolithic security appliance into separate virtual security functions (VNFs) that can be independently deployed, managed, and updated. Each security function (firewall, IDS, IPS, etc.) becomes a separate virtual component that can be dynamically provisioned based on specific threat requirements, enabling flexible adaptation while maintaining comprehensive security protection.
Solution Approach 2:
The patent implements dynamic security by allowing security functions to be dynamically created, moved, scaled, and updated in the distributed environment. Security policies and threat signatures can be updated in real-time without hardware changes, and security services can be dynamically allocated to different network segments based on evolving threats and traffic patterns.
2Reliability
If perimeter-based security model with dedicated hardware devices is used, then security functions are provided, but rapid deployment and updating capability deteriorates
Solution Approach 1:
The patent uses virtualization to create virtual copies of security functions that can be rapidly deployed across the distributed environment. Virtual security appliances can be instantiated from templates and copied to multiple locations simultaneously, enabling rapid deployment of security updates and new security functions without physical hardware installation delays.
Solution Approach 2:
The patent implements preliminary action by pre-configuring security function templates and threat signature databases that can be quickly instantiated when needed. Security updates and new security functions can be prepared in advance and rapidly deployed across the distributed environment without requiring time-consuming hardware installation and configuration.
3Reliability
If collective security requirements for all assets are applied, then perimeter protection is achieved, but specific asset security requirements are not met
Solution Approach 1:
The patent applies local quality by allowing each virtual security function to be customized with specific security policies, rules, and parameters tailored to the requirements of individual assets or asset groups. Different security levels and types can be applied to different assets within the same network, enabling precise protection matching each asset's specific needs while maintaining overall perimeter security.
Data Source
AI summary
Concepts and technologies are disclosed herein for decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment. A computer system includes a processor that can execute computer-executable instructions to perform various operations. The processor can perform operations to provide security services to one or more customer platforms. The operations can include receiving a network security software component from a security service provider, and deploying the network security software component within a distributed computing environment so that the network security software component can be executed by a computing resource of the distributed computing environment to provide a security service to the customer platform(s). The network security software component includes a software component that has been decoupled from a hardware component of a network security device by the security service provider.


