Network Micro-segmentation for Rapid Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in quickly and effectively mitigating cyber threats, such as malware and ransomware, as they often require human intervention, which is slow and can lead to prolonged downtime and increased risk of infection spread.

Innovation Solution

A computer-implemented method and system that determines affinities between network components, assesses risks, and automatically reconfigures the network using software-defined networking (SDN) to isolate threats, restrict malware spread, and maintain application uptime through automated actions like micro-segmentation and firewall configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If automated network reconfiguration is implemented, then response speed to cyber threats is improved, but system complexity increases

Engineering Contradiction:
Improveresponse speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The network is divided into multiple segments or zones that can be independently controlled. When a threat is detected, only the affected segment needs to be isolated rather than shutting down the entire network, enabling fast response while maintaining overall system functionality and reducing the complexity impact.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Network reconfiguration rules and policies are pre-established and stored in advance. When a threat is detected, the system automatically executes pre-planned actions such as isolating specific segments or applying firewall rules, eliminating the need for real-time complex decision-making and reducing response time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network shutdown is executed to contain threats, then security is improved, but service availability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of shutting down the entire network, the system segments the network into isolated zones. Only the infected or compromised segments are disconnected from the rest of the network, allowing secure containment of threats while maintaining service availability for unaffected parts of the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the network are treated differently based on their risk level. Critical segments that are infected are isolated, while healthy segments continue to operate normally. This localized approach ensures security through isolation while preserving service availability for non-affected areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11546354B2Network shutdown for cyber security
Publication Date: 2023.01.03 KYNDRYL INC
  • US11546354B2 patent drawing
  • US11546354B2 patent drawing
  • US11546354B2 patent drawing

AI summary

A method includes: determining, by a computer device, affinities between components in a networked computer system; determining, by the computer device, a risk level of each of the components; determining, by the computer device, a risk level of the networked computer system; detecting, by the computer device, a threat in the networked computer system; determining, by the computer device, an action based on the threat, the risk level of ones of the components affected by the threat, and the risk level of the system; and reconfiguring, by the computer device, the networked computer system based on the determined action.