Distributed Security Modules Eliminate Network Chokepoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions create chokepoints that make networks vulnerable to attacks due to the concentration of security appliances, leading to inefficiencies and over-protection of resources.
Innovation Solution
Decomposing virtual security appliances into security modules and assigning them to different network nodes based on a selected workflow pattern and cost model, optimizing resource usage and distribution across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security appliances are deployed at additional locations throughout the network to alleviate chokepoints, then network vulnerability to attack or disruption is reduced, but computing resources are substantially sacrificed
Solution Approach 1:
The patent segments the monolithic security software solution into multiple security functions that can be distributed across different network nodes. Each security function is implemented as a separate module that can be independently deployed and executed on different virtual machines, eliminating the need for multiple full instances of the complete security solution.
Solution Approach 2:
The patent creates a universal security framework where a single security software solution can serve multiple locations simultaneously by distributing its functions across the network. The security appliance at one location provides security services to multiple other locations through networked security functions, eliminating the need for separate deployments at each site.
2Reliability
If additional security appliances are deployed to reduce chokepoints, then network security is improved, but each security appliance becomes over-protected and under-utilized
Solution Approach 1:
The patent segments the security software into modular functions that can be dynamically assigned and load-balanced across multiple physical appliances. This allows traffic to be distributed evenly among available security functions, ensuring high utilization of each appliance while maintaining redundant security coverage.
Solution Approach 2:
The patent implements dynamic load balancing and failover mechanisms that automatically adjust traffic distribution based on the current state and utilization of security appliances. When one appliance becomes overloaded or fails, traffic is dynamically rerouted to other appliances with available capacity, optimizing resource utilization in real-time.
3Reliability
If a monolithic security software solution is deployed, then comprehensive security coverage is achieved, but chokepoints are created that make the network vulnerable
Solution Approach 1:
The patent segments the monolithic security solution into modular security functions that can be distributed across multiple network nodes. Each node runs only the security functions it needs, eliminating single points of failure while maintaining comprehensive security coverage through the distributed architecture.
4Ease of operation
If security appliances are concentrated at specific locations, then security enforcement is simplified, but network efficiency is reduced due to traffic steering requirements
Solution Approach 1:
The patent creates a universal security framework where security functions are distributed throughout the network rather than concentrated at specific locations. Each network node can independently execute security functions, eliminating the need for centralized traffic steering while maintaining consistent security enforcement across the entire network.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Providing security for one or more network flows may include a security deployment node decomposing one or more virtual security appliances (265) of a logical security architecture (255) into security modules (310). The security deployment node orders the security modules (310) into a sequence (320) that implements a selected workflow pattern (400). The selected workflow pattern (400) may be selected from a workflow pattern database, and may define the security to be provided for a flow, for example, according to known best practices. The sequence (320) is then divided into segments (330), and the segments (330) are assigned to different groups (220) of network nodes (230) in a network (200). For each segment (330), an assignment of each security module (310) in the segment (330) to a network node (230) within the group (220) to which the segment (330) is assigned is computed. The network (200) is then configured according to the assignments.