Network Management System Threat Mirroring for Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Increasing frequency and sophistication of network attacks pose a significant threat to complex networks, making it challenging for administrators to detect and respond to potential security threats in a timely manner, especially with the increased use of external access points that render networks vulnerable to malicious activities.

Innovation Solution

A method and system for managing potential security threats involve monitoring network data at a network management system, identifying threat types, and mirroring suspicious data to a specialized threat assessment system for evaluation, utilizing threat assessment systems like IDS, IPS, and UTM to detect and mitigate anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If networks use increasingly larger and complex structures with more network systems, then network capacity and functionality are improved, but network vulnerability to attacks increases

Engineering Contradiction:
Improvenetwork capacityVSAvoidnetwork vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network monitoring and threat assessment into separate specialized systems. The network management system handles routine monitoring while threat assessment systems (IDS, IPS, UTM) handle security analysis, allowing each component to be optimized independently and reducing overall system complexity despite increased network capacity

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If external network access points are increased to improve user access, then user connectivity is improved, but network security vulnerability increases

Engineering Contradiction:
Improveuser accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces threat assessment systems as intermediary layers between external access points and network systems. These systems (IDS, IPS, UTM) act as mediators that inspect and filter traffic, allowing user access while blocking malicious activities before they reach the network

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If network administrators increase monitoring capacity to detect threats timely, then threat detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts threat assessment functionality from the general network management system and places it in dedicated threat assessment systems. This separation allows the network management system to remain simple while threat detection capability is enhanced through specialized hardware and software components

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8365292B2Methods and systems for managing a potential security threat to a network
Publication Date: 2013.01.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8365292B2 patent drawing
  • US8365292B2 patent drawing
  • US8365292B2 patent drawing

AI summary

Methods, systems and computer readable mediums storing computer executable programs for managing a potential security threat to a network are disclosed. Network data received at a network system within a network is monitored at a network management system. A determination is made at the network management system regarding whether the network data received at the network system poses a potential security threat to the network. A threat type associated with the potential security threat is identified at the network management system based on the determination. A threat assessment system operable to evaluate the identified threat type is identified at the network management system. A command is issued from the network management system to the network system to mirror network data received at the network system to the identified threat assessment system.