Network Threat Mitigation via Universal Message Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network threat mitigation techniques are inefficient in rapidly deploying mitigation operations across different types of network devices, as they often require device-specific interventions and lack effective authentication and feedback mechanisms.

Innovation Solution

A controller communicates device-independent threat mitigation messages to network devices, which convert the messages into device-specific operations using locally stored rules, ensuring rapid deployment and authentication, while allowing for feedback to maintain state information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-specific interventions are used for threat mitigation, then each network device can be protected, but the deployment efficiency and speed are reduced

Engineering Contradiction:
Improvethreat mitigation effectivenessVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a universal message format that can be applied across multiple network device types (routers, switches, firewalls, etc.). The controller sends standardized threat mitigation messages that contain device-independent parameters, allowing the same message structure to serve multiple device types simultaneously, thereby improving deployment efficiency while maintaining broad applicability and effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If device-independent parameters are used in messages, then the same message can be sent to different network devices, but the messages must be converted to device-specific operations

Engineering Contradiction:
Improvemessage compatibilityVSAvoidconversion complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the threat mitigation message into distinct components: device-independent parameters (threat identification, mitigation actions) and device-specific parameters (converted locally using stored rules). This segmentation allows the core message structure to remain simple and universal, while the conversion complexity is isolated to local rule-based translation at each device, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If authentication mechanisms are implemented, then message security is improved, but additional processing time is required

Engineering Contradiction:
Improvemessage authenticationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication by having network devices pre-store authentication rules and credentials before receiving threat mitigation messages. When a message arrives, the device can quickly verify its authenticity against pre-stored rules without requiring complex real-time authentication protocols, thus maintaining security while minimizing additional processing time.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If feedback mechanisms are implemented, then state information can be maintained, but the system complexity increases

Engineering Contradiction:
Improvestate information retentionVSAvoidfeedback system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where network devices send status responses back to the controller after processing threat mitigation messages. The controller maintains state information about each device's threat mitigation status and can send follow-up messages or updates based on this feedback. This allows the system to track and maintain state information without requiring complex distributed state management at each device, centralizing state tracking at the controller.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9083737B2Mitigating threats in a network
Publication Date: 2015.07.14 CISCO TECHNOLOGY INC
  • US9083737B2 patent drawing
  • US9083737B2 patent drawing
  • US9083737B2 patent drawing

AI summary

Mitigating threats in a network includes receiving a message at a network device. The message includes device-independent parameters generated in response to a threat. The network device converts the parameters into one or more device-specific operations and then performs the operations to mitigate the threat.