Microservice-Based Network Security Policy Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security infrastructures struggle to recognize and mitigate attacks within internal networks, as they primarily focus on external threats and lack real-time analysis capabilities, allowing attack activity to spread unchecked across resources.

Innovation Solution

Implementing security microservices across resources to monitor and evaluate data traffic within the network, enabling the detection of attack activity and updating security policies to prevent the spread of attacks by correlating activity across different levels of the network hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security applications use rules to determine whether to allow or block network traffic at the network boundary, then the security policy enforcement is simple and straightforward, but the system cannot recognize some network activity as attack activity when it first reaches an externally accessible resource, allowing attacks to spread unchecked within the internal network

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring function into distributed microservices deployed across multiple resources within the internal network. Each microservice independently monitors traffic at its location, enabling granular detection of attack activity throughout the network rather than relying on a single boundary-level security device. This segmentation allows the system to maintain simplicity at each node while achieving comprehensive coverage across the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to security monitoring by deploying monitoring capabilities not just at the network boundary (external-facing layer) but also within the internal network hierarchy at multiple levels. This multi-dimensional approach includes monitoring at the resource level, application level, and network level, enabling detection of attacks that penetrate the boundary and allowing the system to correlate activity across different hierarchical dimensions to identify compromised resources.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If security devices act as border guards at the network boundary, then the security architecture is simple and easy to implement, but the system is fooled by new attacks and has difficulty analyzing behavior in real-time within the internal network

Engineering Contradiction:
Improvereal-time analysis capabilityVSAvoidsecurity architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by proactively deploying monitoring microservices across resources before attacks occur. These microservices are pre-configured to collect and analyze traffic data in real-time, enabling the system to detect and respond to new attack patterns as they emerge within the network rather than reacting after detection at the boundary. The microservices continuously monitor and correlate activity, maintaining readiness to identify compromised resources immediately upon attack detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where microservices continuously monitor traffic patterns and feed this information back to update security policies in real-time. When a microservice detects suspicious activity or a compromised resource, it provides feedback that triggers automated policy updates across the network, enabling dynamic adaptation to new attack patterns. This feedback loop allows the system to learn from observed behavior and adjust security measures continuously without manual intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If existing security systems only monitor traffic at the network boundary, then the security infrastructure is simple and cost-effective, but the system cannot extend detection capability within the internal network to prevent attack propagation

Engineering Contradiction:
Improveattack mitigation effectivenessVSAvoidnumber of security components
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements universality by designing microservices that perform multiple security functions within a single component. Each microservice can monitor traffic, detect attacks, analyze behavior patterns, correlate activity across resources, and trigger policy updates simultaneously. This multi-functional approach eliminates the need for separate specialized devices for each security task, reducing the overall quantity of security components while maintaining comprehensive protection capabilities throughout the internal network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by enabling microservices to autonomously perform security analysis and policy updates without requiring centralized control for each decision. Each microservice independently monitors its local traffic, detects suspicious patterns, correlates activity with other microservices, and automatically adjusts security policies at its resource. This self-service capability reduces the need for additional centralized management components while maintaining reliable attack mitigation across the distributed network.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10484418B2Systems and methods for updating security policies for network traffic
Publication Date: 2019.11.19 FORTINET INC
  • US10484418B2 patent drawing
  • US10484418B2 patent drawing
  • US10484418B2 patent drawing

AI summary

Systems, methods, and apparatuses enable updating security policies in response to detecting attack activity or security threats. In an embodiment, security microservices detect attack activity sent between resources within an internal network. In response, the security microservices correlate the attack activity to externally accessible resources that were the initial entry point for the attack activity to the internal network. Based on this correlation, the security microservices update security policies bi-directionally to prevent the spread of future attack activity in the internal network between resources at a same level in the internal network and between resources at different levels in the internal network.