Microservice-Based Network Security Policy Update
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security infrastructures struggle to recognize and mitigate attacks within internal networks, as they primarily focus on external threats and lack real-time analysis capabilities, allowing attack activity to spread unchecked across resources.
Innovation Solution
Implementing security microservices across resources to monitor and evaluate data traffic within the network, enabling the detection of attack activity and updating security policies to prevent the spread of attacks by correlating activity across different levels of the network hierarchy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security applications use rules to determine whether to allow or block network traffic at the network boundary, then the security policy enforcement is simple and straightforward, but the system cannot recognize some network activity as attack activity when it first reaches an externally accessible resource, allowing attacks to spread unchecked within the internal network
Solution Approach 1:
The patent segments the security monitoring function into distributed microservices deployed across multiple resources within the internal network. Each microservice independently monitors traffic at its location, enabling granular detection of attack activity throughout the network rather than relying on a single boundary-level security device. This segmentation allows the system to maintain simplicity at each node while achieving comprehensive coverage across the entire network.
Solution Approach 2:
The patent adds a new dimension to security monitoring by deploying monitoring capabilities not just at the network boundary (external-facing layer) but also within the internal network hierarchy at multiple levels. This multi-dimensional approach includes monitoring at the resource level, application level, and network level, enabling detection of attacks that penetrate the boundary and allowing the system to correlate activity across different hierarchical dimensions to identify compromised resources.
2Productivity
If security devices act as border guards at the network boundary, then the security architecture is simple and easy to implement, but the system is fooled by new attacks and has difficulty analyzing behavior in real-time within the internal network
Solution Approach 1:
The patent implements preliminary action by proactively deploying monitoring microservices across resources before attacks occur. These microservices are pre-configured to collect and analyze traffic data in real-time, enabling the system to detect and respond to new attack patterns as they emerge within the network rather than reacting after detection at the boundary. The microservices continuously monitor and correlate activity, maintaining readiness to identify compromised resources immediately upon attack detection.
Solution Approach 2:
The patent implements feedback mechanisms where microservices continuously monitor traffic patterns and feed this information back to update security policies in real-time. When a microservice detects suspicious activity or a compromised resource, it provides feedback that triggers automated policy updates across the network, enabling dynamic adaptation to new attack patterns. This feedback loop allows the system to learn from observed behavior and adjust security measures continuously without manual intervention.
3Reliability
If existing security systems only monitor traffic at the network boundary, then the security infrastructure is simple and cost-effective, but the system cannot extend detection capability within the internal network to prevent attack propagation
Solution Approach 1:
The patent implements universality by designing microservices that perform multiple security functions within a single component. Each microservice can monitor traffic, detect attacks, analyze behavior patterns, correlate activity across resources, and trigger policy updates simultaneously. This multi-functional approach eliminates the need for separate specialized devices for each security task, reducing the overall quantity of security components while maintaining comprehensive protection capabilities throughout the internal network.
Solution Approach 2:
The patent implements self-service by enabling microservices to autonomously perform security analysis and policy updates without requiring centralized control for each decision. Each microservice independently monitors its local traffic, detects suspicious patterns, correlates activity with other microservices, and automatically adjusts security policies at its resource. This self-service capability reduces the need for additional centralized management components while maintaining reliable attack mitigation across the distributed network.
Data Source
AI summary
Systems, methods, and apparatuses enable updating security policies in response to detecting attack activity or security threats. In an embodiment, security microservices detect attack activity sent between resources within an internal network. In response, the security microservices correlate the attack activity to externally accessible resources that were the initial entry point for the attack activity to the internal network. Based on this correlation, the security microservices update security policies bi-directionally to prevent the spread of future attack activity in the internal network between resources at a same level in the internal network and between resources at different levels in the internal network.


