Network Security Apparatus Segmentation for Node Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security technologies face issues such as resource utilization on communication nodes, additional network traffic generation, and malware propagation during software updates and log transmission, which can impact system performance and security.

Innovation Solution

A network security apparatus and method that monitor and manage communication nodes without using their resources, generate minimal additional traffic, and transmit security logs over a separate network, using a separate communication port to prevent malware propagation and ensure compliance with security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security software is installed on communication nodes, then network security monitoring capability is improved, but system performance deteriorates due to resource consumption

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention separates the security monitoring function from the communication node by deploying a dedicated network security apparatus. This segmentation allows security monitoring to operate independently without consuming communication node resources, thus maintaining system performance while improving security monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network security apparatus acts as an intermediary between communication nodes and the security monitoring network. It intercepts and analyzes traffic without requiring resources from the communication nodes themselves, resolving the contradiction between monitoring capability and system performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security software updates and log transmissions are performed through the communication node's network, then security management is improved, but additional network traffic increases load on the network

Engineering Contradiction:
Improvesecurity management capabilityVSAvoidnetwork traffic volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The invention introduces a separate dimension for security communications by establishing a dedicated security monitoring network port on the network security apparatus. This allows security updates and log transmissions to occur on a separate network channel, eliminating additional traffic on the communication node's network while maintaining security management capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If communication with external networks is enabled for security software updates, then security software currency is improved, but malware propagation risk increases

Engineering Contradiction:
Improvesecurity software currencyVSAvoidmalware propagation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network security apparatus serves as an intermediary that controls and filters all external communications. Security software updates are obtained through this controlled interface, which validates and sanitizes incoming data, thus maintaining software currency while blocking malware propagation paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The invention converts the potential harm of external communication into a benefit by using the network security apparatus to actively monitor, filter, and block malicious content while allowing legitimate security updates. The same communication channel that could propagate malware is transformed into a protected pathway for security maintenance.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Reliability

If network security apparatus is deployed to monitor communication nodes, then security monitoring capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network security apparatus is designed as a multi-functional device that combines security monitoring, traffic filtering, log management, and update distribution capabilities in a single unit. This universality improves security monitoring capability while minimizing the increase in device complexity by consolidating multiple functions into one apparatus rather than adding separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9444845B2Network security apparatus and method
Publication Date: 2016.09.13 ELECTRONICS & TELECOMM RES INST
  • US9444845B2 patent drawing
  • US9444845B2 patent drawing
  • US9444845B2 patent drawing

AI summary

A network security apparatus includes a management unit, a security policies monitoring unit, a security monitoring unit, a log security check unit, and a log transmission unit. The management unit receives network security apparatus setting information, security policies and log generation policies from the outside. The security policies monitoring unit checks whether the security policies comply with a set format. If the security policies comply with the set format, the security monitoring unit monitors whether a communication node communicates in compliance with the security policies. The log security check unit generates a monitoring log based on the log generation policies, and checks whether the monitoring log complies with a log setting format. If the monitoring log complies with the log setting format, the log transmission unit transmits the security log to the outside, thereby performing the outside network security.