Microservice Network Path Identification for Security Policy Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions require significant computational resources and storage to apply security policies to all possible connections between servers, leading to inefficiencies as the number of servers and connections increases, making it difficult to monitor and protect network environments effectively.
Innovation Solution
A management microservice is implemented to efficiently determine active connections between servers, identifying only specific communication paths and applying security policies to those paths, reducing the computational resources needed for analysis and protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are applied to all possible connections between servers, then network security coverage is improved, but computational resources and storage requirements increase significantly
Solution Approach 1:
The patent segments the network connections into two categories: actual active connections and potential inactive connections. The security system only applies security policies to active connections that are currently in use, rather than pre-configuring policies for all possible server-to-server connections. This segmentation allows the system to maintain comprehensive security coverage for actual traffic while avoiding the computational overhead of managing security policies for nonexistent or inactive connections.
Solution Approach 2:
The patent implements partial action by applying security policies only to the subset of connections that are actually active, rather than applying policies to all possible connections. The system dynamically identifies and monitors only the necessary connections, performing security checks partially rather than universally, thereby reducing computational resource consumption while maintaining adequate security protection.
2Reliability
If security policies are applied to all possible connections between servers, then network security coverage is improved, but storage requirements increase significantly
Solution Approach 1:
The patent segments the connection management approach by maintaining security policy information only for active connections rather than all possible connections. The system divides the connection space into active and inactive segments, storing security policy data only for the active segment, thereby significantly reducing storage requirements while maintaining security coverage for actual network traffic.
Solution Approach 2:
The patent applies partial action by storing security policy information only for the partial set of active connections rather than all possible connections. This selective storage approach reduces the quantity of data that must be retained in memory and storage systems, directly addressing the storage requirement challenge while preserving security effectiveness.
3Reliability
If all possible server connections are monitored, then security threat detection is improved, but device complexity increases
Solution Approach 1:
The patent segments the monitoring scope to focus only on active connections rather than all possible connections. By dividing the network space into active and inactive segments, the system reduces the complexity of connection tracking and security policy management while maintaining threat detection capability for actual network traffic flows.
Solution Approach 2:
The patent implements partial monitoring by applying security surveillance only to active connections rather than all possible connections. This partial action approach reduces the complexity of the monitoring system, decreasing the number of connections that must be tracked and managed, while still providing adequate threat detection for actual network activity.
4Reliability
If comprehensive security monitoring is implemented across all server connections, then security protection effectiveness is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments the configuration management task by focusing only on active connections rather than all possible connections. This segmentation simplifies the operational burden on system administrators, who only need to manage security policies for currently active connections, making the system easier to operate and configure while maintaining effective security protection.
Solution Approach 2:
The patent applies partial action to configuration management by requiring security policy configuration only for active connections rather than all possible connections. This reduces the operational complexity and ease of operation, allowing administrators to manage fewer security policies while maintaining adequate protection effectiveness.
Data Source
AI summary
Systems, methods, and apparatuses enable a microservice to identify server-to-server communication paths between servers in a networked environment. The system identifies a server connected to a security microservice managed by a management microservice. The system deploys a security policy on the identified server, and identifies the server-to-server communication paths between the identified server and one or more of a plurality of servers. The system identifies the active communication paths from the identified server to one or more of a plurality of servers, or a subset of communication paths determined based on search criteria. When the system identifies servers of the one or more of the plurality of servers without an existing security policy, the system processes the identified server. In one embodiment, processing the identified servers includes applying a security policy to the identified servers.


