Microservice Network Path Identification for Security Policy Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions require significant computational resources and storage to apply security policies to all possible connections between servers, leading to inefficiencies as the number of servers and connections increases, making it difficult to monitor and protect network environments effectively.

Innovation Solution

A management microservice is implemented to efficiently determine active connections between servers, identifying only specific communication paths and applying security policies to those paths, reducing the computational resources needed for analysis and protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are applied to all possible connections between servers, then network security coverage is improved, but computational resources and storage requirements increase significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the network connections into two categories: actual active connections and potential inactive connections. The security system only applies security policies to active connections that are currently in use, rather than pre-configuring policies for all possible server-to-server connections. This segmentation allows the system to maintain comprehensive security coverage for actual traffic while avoiding the computational overhead of managing security policies for nonexistent or inactive connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by applying security policies only to the subset of connections that are actually active, rather than applying policies to all possible connections. The system dynamically identifies and monitors only the necessary connections, performing security checks partially rather than universally, thereby reducing computational resource consumption while maintaining adequate security protection.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If security policies are applied to all possible connections between servers, then network security coverage is improved, but storage requirements increase significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the connection management approach by maintaining security policy information only for active connections rather than all possible connections. The system divides the connection space into active and inactive segments, storing security policy data only for the active segment, thereby significantly reducing storage requirements while maintaining security coverage for actual network traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by storing security policy information only for the partial set of active connections rather than all possible connections. This selective storage approach reduces the quantity of data that must be retained in memory and storage systems, directly addressing the storage requirement challenge while preserving security effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If all possible server connections are monitored, then security threat detection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring scope to focus only on active connections rather than all possible connections. By dividing the network space into active and inactive segments, the system reduces the complexity of connection tracking and security policy management while maintaining threat detection capability for actual network traffic flows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial monitoring by applying security surveillance only to active connections rather than all possible connections. This partial action approach reduces the complexity of the monitoring system, decreasing the number of connections that must be tracked and managed, while still providing adequate threat detection for actual network activity.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If comprehensive security monitoring is implemented across all server connections, then security protection effectiveness is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the configuration management task by focusing only on active connections rather than all possible connections. This segmentation simplifies the operational burden on system administrators, who only need to manage security policies for currently active connections, making the system easier to operate and configure while maintaining effective security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action to configuration management by requiring security policy configuration only for active connections rather than all possible connections. This reduces the operational complexity and ease of operation, allowing administrators to manage fewer security policies while maintaining adequate protection effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10911493B2Identifying communication paths between servers for securing network communications
Publication Date: 2021.02.02 FORTINET INC
  • US10911493B2 patent drawing
  • US10911493B2 patent drawing
  • US10911493B2 patent drawing

AI summary

Systems, methods, and apparatuses enable a microservice to identify server-to-server communication paths between servers in a networked environment. The system identifies a server connected to a security microservice managed by a management microservice. The system deploys a security policy on the identified server, and identifies the server-to-server communication paths between the identified server and one or more of a plurality of servers. The system identifies the active communication paths from the identified server to one or more of a plurality of servers, or a subset of communication paths determined based on search criteria. When the system identifies servers of the one or more of the plurality of servers without an existing security policy, the system processes the identified server. In one embodiment, processing the identified servers includes applying a security policy to the identified servers.