Selective Microservice Replication for Network Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Intrusion Detection and Prevention Systems (NIDPS) deployed in multi-cloud service meshes are resource-intensive, leading to increased costs and performance issues, even though most users are legitimate and not involved in suspicious activities.

Innovation Solution

The solution involves selectively deploying network intrusion prevention and protection tools in a multi-cloud service mesh, allowing administrators to choose which clusters have prevention capabilities. Once a user profile is identified as involved in intrusion or suspicious activities, the system routes that user to prevention clusters, optimizing resource usage and reducing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NIDPS is deployed across all clusters in multi-cloud service mesh, then network intrusion protection coverage is improved, but deployment cost and resource consumption increase exponentially

Engineering Contradiction:
Improvenetwork intrusion protection coverageVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by deploying NIDPS selectively only in specific clusters (e.g., production clusters) rather than uniformly across all clusters. The system identifies which clusters require prevention capabilities based on traffic patterns and intrusion risk, allocating resources only where needed to maintain protection coverage while reducing overall deployment cost.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the multi-cloud service mesh into different cluster types (production clusters requiring prevention vs. development/staging clusters). By dividing the infrastructure into segments with different security requirements, the system can deploy NIDPS only in necessary segments, avoiding exponential cost increase while maintaining adequate protection coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If NIDPS is deployed in all clusters, then intrusion detection capability is improved, but system performance and resource availability deteriorate

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements local quality by providing intrusion detection and prevention capabilities only in production clusters where they are most critical, while allowing development and staging clusters to operate without these resource-intensive components. This selective deployment maintains effective intrusion detection capability where needed while preserving overall system performance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by deploying NIDPS only to the extent necessary for production workloads rather than providing full prevention capabilities across all clusters. This partial deployment achieves adequate intrusion detection capability for critical systems while avoiding the performance penalty of over-provisioning security resources throughout the entire multi-cloud environment.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If prevention capabilities are enabled in all clusters, then security coverage is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security management by enabling prevention capabilities only in production clusters while maintaining simpler operation modes in development and staging clusters. This segmentation reduces operational complexity by limiting the scope of complex security management tasks to only those clusters where they are actually needed, while still maintaining comprehensive security coverage for critical production workloads.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250141906A1Network intrusion based intelligent replication of microservices in a multi cloud service mesh
Publication Date: 2025.05.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250141906A1 patent drawing
  • US20250141906A1 patent drawing
  • US20250141906A1 patent drawing

AI summary

A network intrusion prevention and protection deployment method, system, and computer program product for providing security in a multi-cloud service mesh, the computer-implemented method including selectively deploying, via an instruction from an administrator, a network intrusion prevention and protection tool in a multi-cloud service mesh.