Network Management System Threat Mirroring for Security Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Increasing frequency and sophistication of network attacks pose a significant threat to complex networks, making it challenging for administrators to detect and respond to potential security threats in a timely manner, especially with the increased use of external access points that render networks vulnerable to malicious activities.
Innovation Solution
A method and system for managing potential security threats involve monitoring network data at a network management system, identifying threat types, and mirroring suspicious data to a specialized threat assessment system for evaluation, utilizing threat assessment systems like IDS, IPS, and UTM to detect and mitigate anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If networks use increasingly larger and complex structures with more network systems, then network capacity and functionality are improved, but network vulnerability to attacks increases
Solution Approach 1:
The patent segments network monitoring and threat assessment into separate specialized systems. The network management system handles routine monitoring while threat assessment systems (IDS, IPS, UTM) handle security analysis, allowing each component to be optimized independently and reducing overall system complexity despite increased network capacity
2Ease of operation
If external network access points are increased to improve user access, then user connectivity is improved, but network security vulnerability increases
Solution Approach 1:
The patent introduces threat assessment systems as intermediary layers between external access points and network systems. These systems (IDS, IPS, UTM) act as mediators that inspect and filter traffic, allowing user access while blocking malicious activities before they reach the network
3Difficulty of detecting and measuring
If network administrators increase monitoring capacity to detect threats timely, then threat detection capability is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent extracts threat assessment functionality from the general network management system and places it in dedicated threat assessment systems. This separation allows the network management system to remain simple while threat detection capability is enhanced through specialized hardware and software components
Data Source
AI summary
Methods, systems and computer readable mediums storing computer executable programs for managing a potential security threat to a network are disclosed. Network data received at a network system within a network is monitored at a network management system. A determination is made at the network management system regarding whether the network data received at the network system poses a potential security threat to the network. A threat type associated with the potential security threat is identified at the network management system based on the determination. A threat assessment system operable to evaluate the identified threat type is identified at the network management system. A command is issued from the network management system to the network system to mirror network data received at the network system to the identified threat assessment system.


