Network Security Evaluation System Using Modular Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face overwhelming security complexities due to various equipment and technologies, making it difficult for proprietors to make intelligent and optimized decisions on security enhancements, as existing solutions fail to effectively evaluate and improve network security levels.

Innovation Solution

A system and method that evaluates a network's security level by identifying security elements, determining their relationships with threats and assets, and providing recommendations for enhancements, using a security model that includes a user interface, inventory library, and parametric determination processes to optimize security architecture based on cost and risk considerations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security evaluation is implemented across all network equipment and technologies, then security level improvement is achieved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security evaluation system divides the network into multiple evaluation units, each corresponding to specific network equipment or technology components. Each evaluation unit independently assesses security aspects of its designated portion, allowing comprehensive coverage while managing complexity through modular segmentation of the evaluation process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary security evaluation platform that mediates between various network equipment and the overall security assessment. This intermediary layer standardizes interactions with different equipment types, simplifying the evaluation process while maintaining comprehensive security analysis across diverse network components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed security analysis of all network components is performed, then security weaknesses are identified, but time and computational resources are consumed

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidevaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security evaluations on selected evaluation units rather than requiring exhaustive analysis of every single component simultaneously. This partial action approach allows detailed security analysis of critical areas while reducing overall evaluation time, enabling phased or prioritized assessment based on security needs.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system establishes pre-defined evaluation criteria and security models before conducting actual security assessments. By preparing evaluation frameworks, metrics, and standards in advance, the system reduces the time required during actual security analysis while maintaining comprehensive and accurate evaluation of network components.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple security evaluation metrics are used to assess network security, then evaluation comprehensiveness is improved, but decision-making complexity increases

Engineering Contradiction:
Improveevaluation comprehensivenessVSAvoiddecision-making ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system combines multiple security evaluation metrics and results from different evaluation units into a unified security assessment. By merging individual evaluation outcomes into an integrated view, the system maintains comprehensive evaluation capabilities while simplifying the presentation of results for decision-makers, consolidating complex data into actionable security insights.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10116682B2System and method for evaluating and enhancing the security level of a network system
Publication Date: 2018.10.30 SECURITY INCLUSION NOW USA LLC
  • US10116682B2 patent drawing
  • US10116682B2 patent drawing
  • US10116682B2 patent drawing

AI summary

Examples described herein provide for a system that evaluates a security level of a network system. Additionally, examples described herein evaluate a security level of a network system in order to enable a determination of components that can be used to enhance the security level of the network system.