Network Security Platform Using Virtual Machine Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in detecting and mitigating network security threats due to the complexity of integrating disparate security products from different vendors, which often require specialized training and are incompatible, leading to suboptimal solutions and difficulties in maintaining a comprehensive firewall in increasingly electronic environments.

Innovation Solution

A scalable network security detection and prevention platform that uses virtual machines to interface with intrusion monitoring services, allowing for dynamic selection and deselection of security services, and employs a common data format and scripting to automate reactions to threats, enabling interoperability between different security products and flexible scaling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple disparate security products from different vendors are integrated, then security coverage is improved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into independent virtual machine instances, each running a separate security product from different vendors. This segmentation allows multiple security products to operate independently without direct integration complexity, while the virtualization platform provides unified management and coordination, thus maintaining comprehensive security coverage while reducing integration difficulty.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtualization platform acts as an intermediary layer between multiple disparate security products and the underlying infrastructure. It provides standardized interfaces and abstraction, enabling security products from different vendors to communicate and coordinate through a common platform without direct point-to-point integration, thereby reducing system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If specialized training is provided for security products, then operational capability is improved, but time and resource investment increase

Engineering Contradiction:
Improveoperational capabilityVSAvoidtraining time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The virtualization platform provides self-service capabilities through automated threat detection, response orchestration, and centralized management interfaces. Security operations can be performed through standardized workflows and automated responses, reducing the need for specialized training while maintaining high operational capability. The system handles complex security tasks automatically, requiring minimal human intervention and expertise.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If security products are incrementally added based on dynamic need, then adaptability is improved, but architectural efficiency deteriorates

Engineering Contradiction:
Improvedynamic scalabilityVSAvoidarchitectural efficiency
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic scalability through virtual machine instances that can be instantiated, configured, and terminated on-demand based on security needs. The virtualization platform dynamically allocates resources and manages security product lifecycles, allowing the system to adapt to changing security requirements without creating architectural inefficiencies. New security products can be added as virtual machine instances and automatically integrated into the existing framework.

Inventive Principle:
Principle #15Dynamics

4Reliability

If vendor-specific systems are used, then product functionality is improved, but interoperability deteriorates

Engineering Contradiction:
Improveproduct functionalityVSAvoidvendor interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtualization platform provides universal interoperability by implementing standardized interfaces and communication protocols that work with security products from multiple vendors. Each vendor-specific security product maintains its full functionality within its virtual machine instance, while the platform enables cross-vendor coordination and data sharing through common interfaces, thus preserving product capabilities while achieving vendor interoperability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11388200B2Scalable network security detection and prevention platform
Publication Date: 2022.07.12 SERVICENOW INC
  • US11388200B2 patent drawing
  • US11388200B2 patent drawing
  • US11388200B2 patent drawing

AI summary

This disclosure provides a network security architecture that permits installation of different software security products as virtual machines (VMs). By relying on a common data format and standardized communication structure (e.g., using pre-established, cross-platform messaging), a general architecture can be created and used to dynamically build and reconfigure interaction between both similar and dissimilar security products. Examples are provided where an intrusion monitoring system (IMS) can be used to detect network threats based on distributed threat analytics, passing detected threats to other security products (e.g., products with different capabilities from different vendors) to trigger automatic, dynamically configured communication and reaction. A network security provider using this infrastructure can provide hosted or managed boundary security to a diverse set of clients, each on a customized basis.