Recursive Multi-Layer Network Security Examination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems, particularly firewalls, face challenges in managing large sets of rules and detecting advanced cyber threats that breach internal networks by exploiting East-West traffic flows, leading to data theft and security breaches.

Innovation Solution

The implementation of recursive multi-layer examination methods for computer network security remediation, which involves identifying malicious nodes and communications by analyzing metadata and risk scores, and autonomically generating a declarative security policy to compile low-level firewall rules, thereby enhancing security breach detection and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware firewall creates a barrier between internal and external networks, then network security is improved, but attackers can still breach internal networks by exploiting East-West traffic flows

Engineering Contradiction:
Improvenetwork securityVSAvoidlateral movement attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into multiple zones or domains with different security levels, implementing micro-segmentation within the internal network. This divides the previously monolithic internal network into smaller, isolated segments that prevent lateral movement of attackers between segments, thereby maintaining security while allowing controlled communication within segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security enforcement point or policy enforcement agent between network segments that monitors and controls East-West traffic flows. This intermediary examines traffic between internal nodes, detects malicious behavior, and enforces security policies to block lateral movement attacks while permitting legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If recursive multi-layer examination is implemented to detect malicious communications, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvemalicious behavior detectionVSAvoidexamination system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-establishing security policies, baseline behavior profiles, and examination rules before actual traffic analysis. Metadata such as node characteristics, communication patterns, and security contexts are pre-computed and stored, enabling the recursive examination to operate efficiently by comparing actual traffic against these pre-established criteria rather than analyzing everything from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds another dimension to traffic analysis by examining not only the content of communications but also metadata dimensions such as temporal patterns, spatial relationships between nodes, protocol anomalies, and behavioral contexts. This multi-dimensional examination approach improves detection precision by analyzing traffic from multiple angles simultaneously, while the dimensional organization of analysis helps manage system complexity through structured processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10382467B2Recursive multi-layer examination for computer network security remediation
Publication Date: 2019.08.13 GRYPHO5 LLC
  • US10382467B2 patent drawing
  • US10382467B2 patent drawing
  • US10382467B2 patent drawing

AI summary

Computer-implemented methods and apparatuses for recursive multi-layer examination for computer network security remediation may include: identifying one or more first communications originating from or directed to a first node; identifying at least one of a protocol and an application used for each of the one or more first communications; examining each of the one or more first communications for malicious behavior; receiving a first risk score for each of the one or more first communications responsive to the examining; determining the first risk score associated with one of the one or more first communications exceeds a first predetermined threshold; and indicating the first node and a second node in communication with the first node via the one of the one or more first communications are malicious. Exemplary methods may further include: providing the identified malicious nodes and communications originating from or directed to the malicious nodes.