Network Security Assessment via Topological Data Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face challenges in efficiently assessing and optimizing security properties, especially in dynamic environments, due to limitations in modeling network alterations and their impact on security configurations, leading to potential vulnerabilities and interference between tasks sharing the same infrastructure.

Innovation Solution

A method using a data model of network infrastructure with nodes and links to represent and analyze alterations, automatically deriving changes in security properties, determining paths, and assessing candidate alterations to ensure given security properties are met, utilizing object-oriented databases for efficient path queries and recursive searches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network configuration changes are made manually to adapt to changing business demands, then the network can be reconfigured, but the process is expensive, error-prone, and time-consuming

Engineering Contradiction:
Improvenetwork reconfiguration capabilityVSAvoidreconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining configuration templates and using automated discovery programs to model network topologies before changes are needed. This allows the system to rapidly deploy pre-planned configurations and assess security implications automatically, eliminating manual reconfiguration steps and reducing both time and error rates while maintaining adaptability to business demands

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automated network discovery programs that continuously monitor and model network topology changes, and through automated security assessment mechanisms that evaluate configuration changes without human intervention. This self-acting system reduces manual labor, accelerates reconfiguration, and maintains security compliance automatically

Inventive Principle:
Principle #25Self-service

2Productivity

If multiple tasks share the same physical IT infrastructure, then resource utilization improves, but security isolation between tasks deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary layer in the form of a virtualized network model that sits between the physical infrastructure and multiple tasks. This model includes virtual switches, routers, and security policies that provide logical isolation between tasks while allowing them to share physical resources. The automated security assessment mechanism acts as another intermediary that continuously verifies isolation requirements are met, maintaining both resource utilization and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the physical network into multiple virtual network instances through modeling and configuration management. Each task operates in its own segmented virtual environment with defined security boundaries, while physically sharing the same infrastructure. This segmentation approach enables high resource utilization while maintaining strong security isolation through automated policy enforcement and assessment

Inventive Principle:
Principle #1Segmentation

3Reliability

If automated security assessment mechanisms are implemented, then security properties can be evaluated, but system complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy or model of the network topology that mirrors the physical infrastructure. Security assessment is performed on this simplified model rather than the complex physical system. This copying approach allows automated security evaluation without adding complexity to the actual network infrastructure, as the model can be manipulated and analyzed independently while maintaining accuracy in security property assessment

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9083748B2Modelling network to assess security properties
Publication Date: 2015.07.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9083748B2 patent drawing
  • US9083748B2 patent drawing
  • US9083748B2 patent drawing

AI summary

A method of assessing a network uses a model (450) having nodes (100, 110) to represent parts of the network infrastructure and the application services, and having links to represent how the nodes influence each other. Dependencies or effects of the application services are found by determining paths through the nodes and links of the model (530). Such assessment can be useful for design, test, operations, and diagnosis, and for assessment of which parts of the infrastructure are critical to given services, or which services are dependent on, or could have an effect on a given part of the infrastructure. The dependencies or effects can encompass reachability information. The use of a model having links and nodes can enable more efficient processing, to enable larger or richer models. What changes in the dependencies or effects result from a given change in the network can be determined (830).