Dynamic Security Module Configuration for Network Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in optimizing the execution of security tasks across diverse hardware configurations in enterprise networks, leading to inefficient resource utilization and inadequate protection against modern malware threats, as they often duplicate functionality and struggle to balance resource allocation and risk levels.

Innovation Solution

A dynamic configuration system that collects client configuration data, installs appropriate security modules, monitors and analyzes task execution statistics, and reconfigures both client and server modules to optimize security task execution, delegating tasks based on priority and resource availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security modules are installed on all client computers, then network security coverage is improved, but system resource consumption increases

Engineering Contradiction:
Improvenetwork security coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments security functionality by dividing the network into zones (DMZ, internal network, etc.) and assigning different security module configurations to clients based on their location and role. This allows selective deployment of security modules rather than universal installation, reducing overall resource consumption while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by configuring security modules according to specific client characteristics, network zone requirements, and threat profiles. Each client receives a customized security configuration appropriate to its local context, avoiding unnecessary resource consumption from universally deploying identical security modules across all systems.

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple security modules are deployed, then protection against various threats is improved, but device complexity increases

Engineering Contradiction:
Improveprotection coverageVSAvoidsecurity module configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing security modules with multi-functional capabilities that can operate across different network zones and threat scenarios. A single security module can provide multiple functions (firewall, intrusion detection, antivirus) depending on configuration, reducing the total number of modules needed while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies dynamics by making security module configurations adaptable and changeable based on evolving threat landscapes and network conditions. The system can dynamically enable or disable specific module functions, update configurations, and adjust security policies without requiring complete redeployment of the security architecture.

Inventive Principle:
Principle #15Dynamics

3Productivity

If security tasks are centralized on server, then resource allocation efficiency is improved, but response time to local threats worsens

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidresponse time
Core Design Contradiction:
ProductivityVSSpeed

Solution Approach 1:

The patent extracts critical security functions from centralized server management and places them directly on client devices. Local security agents on clients can independently detect and respond to threats without waiting for server instructions, while still reporting to and receiving policy updates from the centralized server, thus achieving both fast local response and efficient resource allocation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary action by pre-configuring security modules on clients with local decision-making capabilities and pre-loaded security policies. Clients are prepared in advance to autonomously respond to common threat patterns without requiring real-time server intervention, enabling immediate local response while maintaining centralized coordination for complex scenarios.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2472817B1System and method for optimization of execution of security tasks in local network
Publication Date: 2017.01.18 AO KASPERSKY LAB
  • EP2472817B1 patent drawingFigure 1
  • EP2472817B1 patent drawingFigure 2
  • EP2472817B1 patent drawingFigure 3A

AI summary

A system and method for dynamic configuration of the security modules for optimization of execution of security tasks are provided. The system includes: a client detection unit that finds the clients on the network; a client data collection unit that determines hardware/software configurations of each detected client; a security module selection and installation unit that selects required modules for each client from a modules database; a statistics collection unit that collects the security tasks execution statistics from user modules and from client modules; and a re-configuration unit that reconfigures the client and server modules based on the collected statistics in order to optimize execution of the security tasks.