Network Impact Analyzer for Dynamic SDN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security management faces challenges in efficiently identifying and mitigating cyber threats due to the complexity of network data and the dynamic nature of software-defined networks (SDNs), which can hinder traditional security policies and create opportunities for adversaries to subvert network operations.

Innovation Solution

A network security management system that conducts conversational natural language dialogs with users to interpret high-level remedial actions and dynamically generates executable instructions for reconfiguring the network, integrating with SDN technology to adaptively manage and secure the network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security policies are deployed statically across the entire network infrastructure, then security consistency is maintained, but the system lacks adaptability to dynamic threats and changing network conditions

Engineering Contradiction:
Improvesecurity consistencyVSAvoidadaptability to dynamic threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that can be modified in real-time based on detected threats and network conditions. The system transitions from static, pre-defined security rules to dynamically adjustable policies that adapt to changing threats, allowing the network to respond flexibly to new attack vectors while maintaining security consistency through centralized control.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If complex network data is presented to administrators in detailed formats, then complete information is available for decision-making, but the complexity increases and response time decreases

Engineering Contradiction:
Improveinformation completenessVSAvoidadministrator response time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent segments complex network security data into hierarchical levels of detail, allowing administrators to access summary views for quick decision-making while enabling drill-down capabilities for complete information when needed. This segmentation reduces cognitive load and response time while preserving access to comprehensive data when required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a temporal dimension to data presentation by providing real-time alerts for critical threats alongside historical analysis capabilities. This allows administrators to respond immediately to urgent issues while maintaining access to comprehensive historical data for strategic decision-making, effectively separating time-critical from non-time-critical information needs.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If software-defined networking enables dynamic reconfiguration of network flows, then network flexibility and programmability are improved, but security vulnerabilities increase due to potential subversion of network operations

Engineering Contradiction:
Improvenetwork programmabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security layer that monitors and controls SDN reconfiguration operations. This intermediary security module acts as a gatekeeper between the SDN controller and network devices, validating reconfiguration requests against security policies and blocking potentially malicious changes while allowing legitimate dynamic reconfiguration, thus enabling network flexibility without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops that monitor network reconfiguration operations for anomalous patterns indicative of attacks. When potential security threats are detected in reconfiguration requests, the system automatically adjusts security policies to block suspicious operations while maintaining legitimate dynamic reconfiguration capabilities, creating a self-regulating security mechanism that adapts to emerging threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10205637B2Impact analyzer for a computer network
Publication Date: 2019.02.12 SRI INTERNATIONAL
  • US10205637B2 patent drawing
  • US10205637B2 patent drawing
  • US10205637B2 patent drawing

AI summary

Network management technology as disclosed herein performs an impact analysis of actual or hypothetical network commands, and presents the impact analysis results to facilitate the user's understanding of the predicted consequences of the actual or hypothetical commands on network operations, management, or security.