Automated Network Security Entity Configuration via Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunications network security configurations require manual updates and are inefficient in adapting to changes in network infrastructure, leading to potential security vulnerabilities and increased risk of human error.

Innovation Solution

A method and system for automatically defining and updating traffic rules for network security entities using a centralized or decentralized approach, integrating security configuration with network configuration, allowing for real-time updates and reduced manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If manual updates of traffic rules are performed for network security entities, then configuration accuracy can be maintained, but time consumption and human error risk increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidtime consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system enables self-service automation where the network management system automatically generates, updates, and configures traffic rules for network security entities based on current network state, eliminating manual intervention while maintaining configuration accuracy through automated consistency checks and validation mechanisms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring traffic rules templates and security policies in advance, then automatically instantiating and updating them when network changes occur, reducing both time consumption and potential human error in manual configuration processes

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If manual configuration of security entities is used, then implementation simplicity is maintained, but adaptability to network changes deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to network changes
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system transforms static manual configuration into a dynamic automated process that continuously monitors network infrastructure changes and automatically updates security entity traffic rules in real-time, maintaining simplicity through standardized interfaces while achieving high adaptability through event-driven automation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the network management system continuously monitors network state changes and automatically triggers traffic rule updates in response to detected changes, ensuring security configurations remain adapted to current network conditions without requiring manual intervention

Inventive Principle:
Principle #23Feedback

3Productivity

If automated configuration is implemented, then productivity and speed are improved, but system complexity increases

Engineering Contradiction:
Improveconfiguration speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system achieves high productivity through a universal automated configuration framework that handles multiple security entities and diverse traffic rule types through standardized processes and interfaces, reducing the need for entity-specific manual configuration while maintaining manageable system complexity through abstraction and reuse

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3179691B1Configuring a network security entity
Publication Date: 2021.03.03 AIRBUS DEFENCE & SPACE OY
  • EP3179691B1 patent drawingFigure 1A~1B
  • EP3179691B1 patent drawingFigure 2~3
  • EP3179691B1 patent drawingFigure 4~8

AI summary

To facilitate traffic configuration of a security entity, such as a firewall or an IDPS, connected to a first network entity, when a network management message comprising network configuration information of at least a second network element or information on a communication is received (501), a set of traffic rules for the security entity is defined using the received information and configuration information of the first network element.