Network Traffic Rules Controller for Automated Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network infrastructure is vulnerable to security attacks due to manual configuration of network traffic routing rules, which is time-consuming, costly, and complex, especially in large and complex networks, leading to potential network insecurity.

Innovation Solution

A method involving a network traffic rules controller that identifies infrastructure and end-host devices, generates and disseminates network traffic rules to route traffic between end-hosts through infrastructure devices while blocking unauthorized communication from end-hosts to infrastructure devices, using IP and MAC addresses, and applying rules at various layers to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of network traffic routing rules is used, then network administrators can control traffic flow, but the process becomes time-consuming, costly, and complex in large networks

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating network traffic routing rules based on current network topology and security requirements, eliminating the need for time-consuming manual configuration. The controller proactively identifies infrastructure devices and end-hosts, and pre-configures appropriate routing rules before security threats arise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network traffic routing rule controller operates autonomously to monitor network changes, generate updated routing rules, and disseminate them to relevant devices. This self-service capability allows the system to adapt to network changes automatically without requiring continuous manual intervention from administrators.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of network traffic routing rules is used, then network administrators can control traffic flow, but the complexity and cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The controller automatically monitors network topology changes, identifies affected infrastructure devices and end-hosts, generates appropriate routing rules, and disseminates them to the correct devices. This self-service automation eliminates the complexity of manual rule configuration and updates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network traffic patterns and infrastructure device status, using this feedback to dynamically adjust and update routing rules. This closed-loop approach ensures that the routing configuration remains optimal and secure without requiring manual analysis or intervention.

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If manual updates to network traffic routing rules are delayed, then configuration stability is maintained, but network vulnerability increases

Engineering Contradiction:
Improveconfiguration stabilityVSAvoidnetwork security
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The system transitions from static manual configuration to dynamic automated rule generation and dissemination. The controller continuously adapts routing rules in response to network topology changes, ensuring that security configurations remain current without causing instability through frequent manual interventions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The controller implements continuous monitoring of network changes and automatically triggers rule updates when necessary. This feedback mechanism ensures that routing rules are updated promptly in response to actual network conditions, maintaining both stability and security without requiring constant manual attention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10498700B2Transmitting network traffic in accordance with network traffic rules
Publication Date: 2019.12.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10498700B2 patent drawing
  • US10498700B2 patent drawing
  • US10498700B2 patent drawing

AI summary

In an example implementation according to aspects of the present disclosure, a method may include identifying, by a computing system, an infrastructure device and an end-host device within a network. The method may further include disseminating, by the computing system, network traffic rules to the infrastructure device, the network traffic rules to route network traffic between end-host devices through the infrastructure device. Further, the network traffic transmitted from a first end-host device to a second end-host device is passed through the infrastructure device to the second end-host device in accordance with the network traffic rules, and network traffic transmitted from the first end-host device to the infrastructure device is blocked by the infrastructure device in accordance with the network traffic rules.