Network Role Grouping via Bi-Connected Components

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing large enterprise networks is challenging due to the complexity of network topology and the need for early detection of security violations, as existing methods rely on ad hoc human guesses and lack efficient techniques for grouping nodes based on connection patterns.

Innovation Solution

A computer-implemented method that groups nodes in a network by identifying bi-connected components in host connection set data and merging groups with similar connection habits, using connectivity graphs and k-neighborhood graphs to assign unique identifiers and form larger groups based on observed connection patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network management is conducted on a host-by-host basis, then detailed monitoring and control are achieved, but the complexity and cost increase significantly for large networks

Engineering Contradiction:
Improvemonitoring detailVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments hosts into groups based on their connection patterns and roles within the network. By dividing the network into logical groups (such as servers, clients, workstations), the system reduces management complexity while maintaining detailed monitoring capabilities at the group level rather than treating each host individually

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network roles as an intermediary concept between individual hosts and network policies. Roles serve as mediators that aggregate host characteristics and connection patterns, allowing administrators to manage networks through role-based policies rather than host-by-host configurations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If ad hoc human guesses are used to determine logical relationships, then network topology can be understood, but accuracy and consistency deteriorate

Engineering Contradiction:
Improvetopology understandingVSAvoidrelationship accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent enables the network to self-classify hosts into roles based on their actual connection patterns and communication behavior. Rather than relying on manual configuration or human interpretation, the system automatically detects and assigns roles based on observed network traffic, improving both accuracy and consistency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual human analysis of network topology with automated computational algorithms that process connection data to identify roles and relationships. This substitution of mechanical human judgment with automated systems improves precision while maintaining ease of operation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If network segmentation is implemented to provide fault isolation and mitigate worm spread, then security improves, but network complexity increases

Engineering Contradiction:
Improvefault isolationVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic role-based segmentation where network groups are automatically formed and adjusted based on real-time connection patterns. This dynamic approach allows the network to adapt its segmentation structure in response to changing conditions, providing effective fault isolation while reducing manual configuration complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters for network segmentation from static, manually-defined segments to dynamic, data-driven groups based on connection patterns. By using connection habit data and bi-connected components as segmentation parameters, the system achieves effective isolation while simplifying deployment and maintenance

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If the number of policies is made open ended to accommodate different user privileges, then flexibility improves, but management difficulty increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidpolicy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal role-based policy framework that can accommodate multiple access control scenarios through a single mechanism. Roles serve as multi-functional units that can be assigned different policy sets, allowing the system to handle diverse user privileges without requiring separate policy management for each user type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges individual host policies into unified role-based policies. By combining the access control requirements of multiple hosts into their respective roles, the system reduces the total number of policies that need to be managed while maintaining the flexibility to address different user privileges through role assignments

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8090809B2Role grouping
Publication Date: 2012.01.03 RIVERBED TECH LLC
  • US8090809B2 patent drawing
  • US8090809B2 patent drawing
  • US8090809B2 patent drawing

AI summary

Techniques to assign nodes in a network to groups of nodes includes grouping nodes on a network into groups based on host connection set data by identifying bi-connected components in the host connection set data; and merging groups with similar connection habits as determined by examining the host connection set data into larger groups.