Perimeter Defense System Coordinating Security Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security solutions in network systems are inadequate in mitigating various types of cyber-attacks, particularly large-scale or complex attacks, as they operate independently and are not scalable or dynamic, leading to inefficiencies in defense coordination and adaptation to changing network architectures and attack campaigns.

Innovation Solution

A perimeter defense system that receives and analyzes traffic to detect potential cyber-attacks, reconfiguring protection resources through bi-directional signaling to mitigate threats, allowing for flexible and adaptive defense strategies across multiple protection resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each security service operates independently to detect and mitigate cyber-attacks, then individual security services can be configured for specific attack types, but coordination among security services is poor and large-scale attacks cannot be effectively mitigated

Engineering Contradiction:
Improveattack mitigation capabilityVSAvoidcoordination capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple independent security services into a unified coordinated defense system. The system integrates firewalls, intrusion detection systems, and other security services, enabling them to work together through shared threat intelligence and coordinated response mechanisms to effectively mitigate large-scale attacks

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where security services share threat detection results and attack patterns with each other. This feedback loop enables continuous improvement of defense strategies and allows the system to adapt to evolving threats through learned attack patterns

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If static security configurations are used to detect and mitigate cyber-attacks, then implementation is simple, but the system cannot adapt to changes in network architecture or dynamic attack campaigns

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoiddynamic adaptation capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent transforms static security configurations into dynamic adaptive systems. Security policies and detection rules are automatically adjusted based on real-time traffic analysis, detected attack patterns, and network condition changes, enabling the system to adapt to both architectural changes and evolving attack campaigns

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements self-service capabilities through automated threat detection, analysis, and response. The security services autonomously learn from traffic patterns, identify attacks, and adjust configurations without manual intervention, maintaining simplicity while achieving dynamic adaptation

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple specialized security services are deployed to handle different attack types, then coverage of various attack vectors is improved, but the system becomes complex and difficult to coordinate

Engineering Contradiction:
Improveattack coverageVSAvoidsystem coordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal coordination platform that manages multiple specialized security services. This platform provides unified threat intelligence sharing, centralized policy management, and coordinated response mechanisms, allowing diverse security services to work together through standardized interfaces while maintaining their specialized capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10887347B2Network-based perimeter defense system and method
Publication Date: 2021.01.05 RADWARE LTD
  • US10887347B2 patent drawing
  • US10887347B2 patent drawing
  • US10887347B2 patent drawing

AI summary

A method and system for perimeter defense of a network are provided. The method comprises receiving, at a system deployed in a perimeter of the network, traffic to or from the network, wherein the network includes a plurality of protection resources; determining, based on the received traffic, at least one potential cyber-attack; and upon determining the at least one potential cyber-attack, causing a mitigation reconfiguration of at least one protection resource of the plurality of protection resources, wherein the mitigation reconfiguration includes reconfiguring each of the at least one protection resource to mitigate the at least one potential cyber-attack.