Network Entity Map for Automated Security Rule Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in managing large numbers of security rules across numerous network entities, leading to inefficiencies and potential flaws in network security due to the complexity of manually managing and updating these rules.

Innovation Solution

A network management device generates a map of network entities based on their attributes, creating network entity relationship rules that can be easily converted into security rules, simplifying the management of security policies and automating updates by defining relationships and changes within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual management of security rules is implemented across numerous network entities, then security coverage can be achieved, but the complexity of managing and updating rules increases significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidsecurity rule management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security rule generation system that acts as an intermediary between network entities and security policies. This system automatically generates security rules by analyzing network traffic patterns and entity relationships, eliminating the need for manual rule creation and management across numerous network entities, thus reducing management complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables security rules to be self-generated and self-updated based on automatic analysis of network traffic and entity relationships. The security rule generation system continuously monitors network conditions and automatically adjusts rules without human intervention, allowing the security infrastructure to serve itself and reducing the administrative burden

Inventive Principle:
Principle #25Self-service

2Reliability

If manual updates of security rules are performed, then security policies can be maintained, but resource consumption and administrative burden increase

Engineering Contradiction:
Improvesecurity policy maintenanceVSAvoidadministrative resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The security rule generation system operates continuously and automatically, maintaining security policies through ongoing analysis of network traffic and entity relationships. This continuous automated operation eliminates the need for periodic manual updates, ensuring security policies remain current without consuming administrative resources

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system implements feedback mechanisms where security rules are automatically adjusted based on analyzed network traffic patterns and detected threats. This closed-loop approach ensures security policies are maintained through automatic responses to changing conditions, eliminating the need for manual intervention and reducing administrative resource consumption

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security rules are implemented for all network entities, then security coverage is improved, but the time required to manage and update rules increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidrule management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network entity relationships and traffic patterns to pre-generate appropriate security rules before threats occur. By preparing security rules in advance based on automated analysis, the system ensures comprehensive coverage is ready immediately without requiring time-consuming manual rule creation when needed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes security rule parameters based on analyzed network conditions, entity types, and threat levels. This automated parameter adjustment allows comprehensive security coverage to be maintained across diverse network entities without manual intervention, significantly reducing the time required to adapt security rules to changing network configurations

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10645121B1Network traffic management based on network entity attributes
Publication Date: 2020.05.05 JUNIPER NETWORKS INC
  • US10645121B1 patent drawing
  • US10645121B1 patent drawing
  • US10645121B1 patent drawing

AI summary

A device may include one or more input components and one or more processors to: receive network entity data for a network entities operating on a network, the network entity data indicating network entity attributes associated with the network entities. The device may generate a map of the network entities based on the network entity data, the map of the network entities defining, for each network entity included in the map of the plurality of network entities, a relationship between the network entity and at least one other network entity included in the plurality of network entities. In addition, the device may identify a network entity relationship rule based on the map of the network entities and perform an action based on the network entity relationship rule.