Network Security Control Node Blacklist Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network systems with multiple subnets, when one subnet is attacked, only the directly affected subnet implements security measures, leaving other subnets vulnerable to similar attacks due to lack of coordination, thereby compromising the overall network security.

Innovation Solution

A method and apparatus where a control node collects alarm information on attack sources, sorts them by threat level, and generates a blacklist to alert and prepare unattacked subnets, enabling them to take defensive measures against identified high-risk sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each subnet independently implements security measures only when directly attacked, then the security response is simple and localized, but the overall network security deteriorates because unattacked subnets remain vulnerable to the same attack sources

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity coordination mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into multiple subnets, each with its own security device. The control node collects alarm information from all subnets and generates separate blacklists for each subnet based on their specific vulnerability assessments, allowing localized security responses while maintaining overall network security coordination

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A control node acts as an intermediary between subnets and security devices. It collects alarm information from all subnets, analyzes attack sources, determines vulnerability levels, and distributes appropriate blacklists to subnets, enabling centralized coordination without requiring direct complex interactions between all subnets

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a control node collects alarm information from all subnets and generates blacklists for unattacked subnets, then the overall network security improves through proactive defense, but the control node's processing complexity and time increase

Engineering Contradiction:
Improveproactive network securityVSAvoidblacklist generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The control node proactively generates blacklists for unattacked subnets before they are actually attacked, based on alarm information from other subnets. This preliminary defensive action allows subnets to prepare security measures in advance, reducing response time when attacks occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control node dynamically adjusts blacklist generation based on vulnerability parameters. It calculates vulnerability levels for each subnet against each attack source, and only generates blacklists for subnets that exceed threshold vulnerability levels, reducing unnecessary processing for highly secure subnets

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the control node calculates vulnerability levels and generates customized blacklists for each subnet, then the security precision improves, but the computational complexity increases

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidcontrol node processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Each subnet receives a customized blacklist tailored to its specific vulnerability profile rather than a universal blacklist. The control node assesses each subnet's security measures and generates targeted blacklists, ensuring each subnet has appropriate security coverage for its specific risk profile

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The control node uses multiple parameters to assess vulnerability including security measure strength, attack source threat level, and subnet configuration. It dynamically adjusts blacklist generation based on these parameters, generating blacklists only when vulnerability exceeds thresholds, thereby managing computational complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10476897B2Method and apparatus for improving network security
Publication Date: 2019.11.12 HUAWEI TECH CO LTD
  • US10476897B2 patent drawing
  • US10476897B2 patent drawing
  • US10476897B2 patent drawing

AI summary

A method and an apparatus for improving network security. The method includes obtaining, by a control node, alarm information, where the alarm information includes address information of an attack source that attacks a subnet of at least two subnets and identification information of the attacked subnet of the at least two subnets, using, by the control node, the alarm information to sort the attack sources in descending order of threat levels, and using a sorting result as a blacklist, and sending, by the control node, the obtained blacklist to at least one subnet that is not attacked yet in the network system. The method and apparatus are applicable to collaborative defense among multiple subnets.