Multi-node affinity examination for network security remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security systems, particularly firewalls, face challenges in managing complex rule sets and detecting malicious activities within internal networks, as attackers often breach networks by exploiting East-West traffic flows to reach critical assets.

Innovation Solution

The implementation of multi-node affinity-based examination methods and systems that analyze communication patterns and risk scores to identify malicious nodes and communications, generating a graphical user interface to visualize network relationships and facilitate security remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware firewall creates a barrier between internal and external networks, then network security is improved, but attackers can still breach internal networks by exploiting East-West traffic flows

Engineering Contradiction:
Improvenetwork securityVSAvoidlateral movement attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the internal network into multiple zones or domains, implementing micro-segmentation that divides the network into smaller, isolated segments. This prevents lateral movement by attackers as each segment is separated by security policies that control East-West traffic flows, allowing security to be enforced at granular levels rather than just at the network perimeter.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security system that monitors and controls traffic between network segments. This intermediary layer analyzes East-West traffic flows and enforces security policies, acting as a mediator between different network zones to prevent malicious communications while allowing legitimate traffic to pass through.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multi-node affinity-based examination analyzes communication patterns to identify malicious nodes, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvemalicious node detectionVSAvoidexamination system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-establishing affinity relationships and communication patterns between nodes before security incidents occur. The system builds a baseline of normal communication behaviors and node relationships in advance, which enables faster and more accurate detection of malicious activities without requiring complex real-time analysis of every packet.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical analysis systems with affinity-based examination that leverages pre-computed relationships and metadata. Instead of using resource-intensive deep packet inspection for every communication, the system substitutes this with lighter-weight affinity matching against pre-established node relationships and communication patterns.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the system generates graphical user interface to visualize network relationships, then ease of operation is improved, but processing time increases

Engineering Contradiction:
Improvesecurity analysis easeVSAvoidGUI generation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent creates simplified copies or representations of the network topology and node relationships for display in the graphical user interface. Instead of processing and displaying all raw network data, the system generates condensed visual representations that capture essential security-relevant information, reducing processing time while maintaining ease of operation for security analysts.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements partial action by generating and displaying only the most critical network relationships and node affinities in the graphical interface, rather than rendering complete network topology. This selective visualization approach reduces processing time while providing sufficient information for security operations, showing only the portions of network data most relevant to current threats.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9762599B2Multi-node affinity-based examination for computer network security remediation
Publication Date: 2017.09.12 GRYPHO5 LLC
  • US9762599B2 patent drawing
  • US9762599B2 patent drawing
  • US9762599B2 patent drawing

AI summary

Multi-node affinity-based examination for computer network security remediation is provided herein. Exemplary methods may include receiving a query that includes a selection of Internet protocol (IP) addresses belonging to nodes within a network, obtaining characteristics for the nodes, determining communications between the nodes and communications between the nodes and any other nodes not included in the selection, determining a primary affinity indicative of communication between the nodes and a secondary affinity indicative of communication between the nodes and the other nodes not included in the selection, and generating a graphical user interface (GUI) that includes representations of the nodes in the range and the other nodes outside the range, placing links between the nodes in the selection and the other nodes not included in the selection based on the primary affinity and the secondary affinity, and providing the graphical user interface to a user.