Network Security Management via Modular Node Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential growth of digital data requires effective management of network storage security, particularly in scalable infrastructure as a Service (IaaS) environments, where accurate tracking of physical and virtual storage devices is crucial but often not adequately addressed.

Innovation Solution

An apparatus and method comprising an inventory module, a survey module, and a security module to identify and analyze nodes within a network of virtual local area networks and storage area networks, detecting irregularities and generating notifications to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network security management methods are used, then implementation is simpler, but security monitoring coverage and detection accuracy are insufficient

Engineering Contradiction:
Improveirregularity detection accuracyVSAvoidsecurity management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security management system is segmented into four distinct modules: inventory module for node identification, survey module for information gathering, observation module for irregularity detection, and security module for notification. This segmentation allows each module to specialize in specific tasks, improving detection accuracy while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary observation module that acts as a mediator between the survey module (which gathers raw data) and the security module (which takes action). This intermediary analyzes network traffic and node information to detect irregularities, enhancing detection precision without requiring the security module to directly handle all raw data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive node tracking is implemented, then security monitoring improves, but system resource consumption increases

Engineering Contradiction:
Improvestorage device tracking accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The inventory module performs preliminary action by identifying and cataloging all network nodes before security monitoring begins. The survey module then gathers baseline information about each node's normal behavior and characteristics. This preliminary characterization enables the observation module to detect irregularities more efficiently by comparing current activity against established baselines, reducing the need for continuous comprehensive resource-intensive monitoring.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module provides feedback by generating notifications when irregularities are detected. This feedback loop allows the system to focus resources on nodes exhibiting suspicious behavior while maintaining efficient monitoring of normal nodes. The continuous feedback mechanism enables dynamic resource allocation based on actual security needs rather than uniform high-resource consumption across all nodes.

Inventive Principle:
Principle #23Feedback

3Loss of time

If real-time security monitoring is implemented, then irregularity detection timeliness improves, but system complexity increases

Engineering Contradiction:
Improveirregularity detection timeVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The observation module implements continuous monitoring of network nodes, maintaining constant surveillance of node activities and behaviors. This continuous useful action ensures that irregularities are detected as they occur rather than periodically, minimizing detection time. The continuous operation is managed efficiently through the modular architecture, where each component performs its specific function continuously without requiring complex coordination.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The real-time monitoring function is segmented across multiple specialized modules: the inventory module continuously maintains node registries, the survey module continuously gathers node information, the observation module continuously analyzes for irregularities, and the security module continuously prepares notifications. This segmentation of continuous actions into specialized modules achieves real-time detection while managing system complexity through clear module boundaries and responsibilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10243996B2LAN/SAN network security management
Publication Date: 2019.03.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10243996B2 patent drawing
  • US10243996B2 patent drawing
  • US10243996B2 patent drawing

AI summary

An apparatus for managing network security includes an inventory module, a survey module, an observation module, and a security module. The inventory module identifies each node of a network. The survey module gathers information for each node of the network. The security module generates notifications to one or more users in response to the observation module detecting one or more irregularities.