Network Security Assessment via Topological Data Modeling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in efficiently assessing and optimizing security properties, especially in dynamic environments, due to limitations in modeling network alterations and their impact on security configurations, leading to potential vulnerabilities and interference between tasks sharing the same infrastructure.
Innovation Solution
A method using a data model of network infrastructure with nodes and links to represent and analyze alterations, automatically deriving changes in security properties, determining paths, and assessing candidate alterations to ensure given security properties are met, utilizing object-oriented databases for efficient path queries and recursive searches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network configuration changes are made manually to adapt to changing business demands, then the network can be reconfigured, but the process is expensive, error-prone, and time-consuming
Solution Approach 1:
The patent applies preliminary action by pre-defining configuration templates and using automated discovery programs to model network topologies before changes are needed. This allows the system to rapidly deploy pre-planned configurations and assess security implications automatically, eliminating manual reconfiguration steps and reducing both time and error rates while maintaining adaptability to business demands
Solution Approach 2:
The system implements self-service through automated network discovery programs that continuously monitor and model network topology changes, and through automated security assessment mechanisms that evaluate configuration changes without human intervention. This self-acting system reduces manual labor, accelerates reconfiguration, and maintains security compliance automatically
2Productivity
If multiple tasks share the same physical IT infrastructure, then resource utilization improves, but security isolation between tasks deteriorates
Solution Approach 1:
The patent introduces an intermediary layer in the form of a virtualized network model that sits between the physical infrastructure and multiple tasks. This model includes virtual switches, routers, and security policies that provide logical isolation between tasks while allowing them to share physical resources. The automated security assessment mechanism acts as another intermediary that continuously verifies isolation requirements are met, maintaining both resource utilization and security
Solution Approach 2:
The system segments the physical network into multiple virtual network instances through modeling and configuration management. Each task operates in its own segmented virtual environment with defined security boundaries, while physically sharing the same infrastructure. This segmentation approach enables high resource utilization while maintaining strong security isolation through automated policy enforcement and assessment
3Reliability
If automated security assessment mechanisms are implemented, then security properties can be evaluated, but system complexity increases
Solution Approach 1:
The patent creates a virtual copy or model of the network topology that mirrors the physical infrastructure. Security assessment is performed on this simplified model rather than the complex physical system. This copying approach allows automated security evaluation without adding complexity to the actual network infrastructure, as the model can be manipulated and analyzed independently while maintaining accuracy in security property assessment
Data Source
AI summary
A method of assessing a network uses a model (450) having nodes (100, 110) to represent parts of the network infrastructure and the application services, and having links to represent how the nodes influence each other. Dependencies or effects of the application services are found by determining paths through the nodes and links of the model (530). Such assessment can be useful for design, test, operations, and diagnosis, and for assessment of which parts of the infrastructure are critical to given services, or which services are dependent on, or could have an effect on a given part of the infrastructure. The dependencies or effects can encompass reachability information. The use of a model having links and nodes can enable more efficient processing, to enable larger or richer models. What changes in the dependencies or effects result from a given change in the network can be determined (830).


